Executive Order 14093 · Signed Mar 27, 2023

88 FR 18957 · Published Mar 30, 2023 · Effective on signing

Share

Prohibition on Use by the United States Government of Commercial Spyware That Poses Risks to National Security

surveillance technologynational securitycybersecurityintelligence oversightforeign policy

Signed by President Joseph R. Biden Jr.

The order prohibits all U.S. federal executive agencies from making operational use of commercial spyware that poses significant counterintelligence or security risks, or that has been misused by foreign governments to suppress dissent, target journalists, or surveil Americans without legal authorization.

It establishes a government-wide vetting and certification framework — anchored by recurring classified intelligence assessments from the Director of National Intelligence — to ensure that any spyware the government touches does not contribute to human rights abuses or expose U.S. systems and personnel to foreign exploitation.

What this order does

What it orders

The order directs all federal executive agencies to refrain from operational use of commercial spyware when a credible determination shows that the spyware poses significant counterintelligence or security risks to the U.S. government, or that it has been or risks being misused by a foreign government or person. Before any agency deploys commercial spyware operationally, a designated senior official — limited to the Secretary of Defense, Attorney General, Secretary of Homeland Security, Director of National Intelligence, CIA Director, or NSA Director — must personally certify that the product clears these risk standards. The agency must also notify the National Security Advisor at least seven days before operational use begins. The Director of National Intelligence must issue a classified intelligence assessment within 90 days and semiannually thereafter to keep agencies informed of known risks.

Agencies must review all existing commercial spyware uses within 90 days of the first intelligence assessment and discontinue any that fail the risk test as quickly as possible without compromising ongoing operations. Within 180 days of signing, each agency that may use such spyware must develop internal controls and oversight procedures. Waivers are available for up to one year in extraordinary circumstances, but only from the same short list of senior officials, and the President must be notified within 72 hours. Testing, research, cybersecurity, and criminal-investigation uses are explicitly exempted from the operational-use ban.

Who it affects

All federal executive departments and agencies that procure or operationally use commercial spyware; senior officials (Secretary of Defense, Attorney General, DNI, CIA and NSA Directors, DHS Secretary) who bear personal certification and waiver authority; the Federal Acquisition Security Council; and commercial spyware vendors whose products may be barred from U.S. government contracts.

Why it matters

Federal agencies can no longer quietly adopt commercial surveillance tools without senior-level sign-off tied to specific risk criteria. Existing spyware contracts must be audited and may be terminated. Vendors whose products have been misused by repressive governments risk being effectively locked out of the U.S. government market.

What must happen and when

How the order is supposed to work

The framework works in stages: the DNI issues a classified risk assessment within 90 days and every six months thereafter, pulling together intelligence, financial, sanctions, and export-control data. Agencies use that assessment as a baseline before procuring or deploying spyware. A named senior official must personally certify every operational deployment — that obligation cannot be delegated further down the chain — and must notify the National Security Advisor at least seven days in advance. The Federal Acquisition Security Council folds the assessments into supply-chain risk reviews. Waivers of up to one year require both a senior official's sign-off and Presidential notification within 72 hours, creating a paper trail but no hard external enforcement mechanism.

Actions and deadlines

  • Director of National Intelligence issues first classified intelligence assessment on foreign commercial spyware risksWithin 90 days of signing
  • Director of National Intelligence issues semiannual classified intelligence assessments on commercial spyware risksSemiannually after the first assessment
  • APNSA convenes agencies to discuss each intelligence assessment and share commercial spyware informationWithin 30 days of each intelligence assessment issuance
  • Each agency reviews all existing operational commercial spyware uses and discontinues those posing significant risksWithin 90 days of the first intelligence assessment
  • Each agency that may operationally use commercial spyware develops internal controls and oversight proceduresWithin 180 days of signing
  • Agency heads submit report to APNSA on findings from review of existing commercial spyware usesUpon completing the review required by Section 2(h)
  • Agency heads notify APNSA of commercial spyware procured for exempt purposes (testing, research, cybersecurity)Within 45 days of such procurement
  • Agency heads submit report to APNSA on actions taken to implement this order, including internal controls developedWithin 6 months of signing
  • Agency heads submit annual report to APNSA identifying existing, terminated, and newly purchased commercial spywareWithin 1 year of signing, and annually thereafter
  • Relevant official notifies President through APNSA of any decision to issue or revoke a spyware-use waiverWithin 72 hours of waiver determination

Agencies directed to act

Office of the Director of National IntelligenceDepartment of DefenseDepartment of JusticeDepartment of Homeland SecurityCentral Intelligence AgencyNational Security AgencyFederal Acquisition Security CouncilDepartment of State

Authority and reach

Authorities cited

Article II

Constitutional grant of executive power to the President, including national security and foreign affairs authority.

Executive Order

Ask GovernmentReporter about this order

Ask anything about what this order does, who it affects, and how it changes policy.

Executive Order 14093: Prohibition on Use by the United States Government of Commercial Spyware That Poses Risks to National Security | EO Reporter