Strengthening and Promoting Innovation in the Nation's Cybersecurity
The order directs federal civilian agencies and their software and cloud vendors to implement dozens of specific cybersecurity improvements — covering software supply chain attestations, communications encryption, post-quantum cryptography, AI-assisted threat detection, and digital identity fraud prevention — with deadlines ranging from 30 days to 3 years.
It also immediately expands the sanctions authority established by a 2015 executive order to explicitly cover ransomware attacks, election infrastructure tampering, and knowing receipt of stolen data — allowing Treasury to block the assets of a broader set of foreign cyber actors.
What this order does
What it orders
The order directs federal civilian executive branch agencies, software providers selling to the federal government, and cloud service providers to meet a cascading series of cybersecurity requirements. Software vendors must submit machine-readable security attestations and supporting evidence to a central CISA repository; NIST must update its Secure Software Development Framework; and OMB must require agencies to follow updated supply chain risk management guidance. Agencies must encrypt DNS traffic, email, and voice and video communications; register their internet address blocks; deploy post-quantum cryptographic algorithms; and enroll endpoints in CISA's persistent threat-hunting program. The order also directs investments in AI-assisted cyber defense, minimum cybersecurity standards for contractors, and Internet-of-Things device labeling requirements for federal vendors.
Section 9 immediately amends Executive Order 13694 (2015) to expand the class of foreign actors whose U.S.-held assets can be frozen by Treasury to include ransomware attackers, those who tamper with election infrastructure, and entities that knowingly receive stolen data. National Security Systems and classified "debilitating impact systems" are carved out of the main provisions but must receive parallel requirements developed by NSA and the Committee on National Security Systems.
Who it affects
Federal civilian executive branch agencies facing dozens of new IT security mandates; software companies and cloud providers selling to the federal government who must submit attestations and meet new contracting standards; federal contractors subject to minimum cybersecurity requirements; state benefits programs and financial institutions affected by digital identity guidance; and foreign cyber actors now subject to expanded sanctions criteria.
Why it matters
Software vendors selling to the federal government now face binding attestation and artifact requirements that CISA can verify and publicly report on. Federal agencies must encrypt communications and adopt quantum-resistant cryptography on firm timetables. Foreign ransomware operators and election-infrastructure attackers face broader asset-blocking exposure under the expanded sanctions authority.
What must happen and when
How the order is supposed to work
The order operates as a cascading series of deadlines: NIST and CISA first issue technical standards or guidance; OMB converts those into binding agency requirements; the FAR Council then amends procurement rules to extend the same obligations to contractors. CISA serves as the central verification hub, gaining persistent access to agency endpoint detection tools and running a program to audit software vendor attestations. Failures in attestation validation are publicly posted by the National Cyber Director and may be referred to the Attorney General. National Security Systems are exempt from the main provisions but receive a parallel NSA-led requirements process. The order's implementation depends on appropriations and existing legal authority.
Actions and deadlines
- OMB Director recommends FAR contract language requiring software providers to submit attestations to CISA's RSAA
- NIST establishes industry consortium at National Cybersecurity Center of Excellence for secure software development guidance
- CISA provides guidance on submitting machine-readable attestations to RSAA, including common data schema
- NIST updates Special Publication 800-53 to provide guidance on securely deploying patches and updates
- OMB requires agencies to comply with NIST SP 800-161 cybersecurity supply chain risk management guidance
- FCEB agencies register all assigned internet number resources with a regional internet registry
- CISA publishes template contract language requiring DNS resolver products to support encrypted DNS
- NSA develops cybersecurity requirements for National Security Systems and debilitating impact systems
- OMB issues guidance requiring agencies to inventory all major information systems and provide inventory to CISA or DoD
- FCEB agencies create and publish Route Origin Authorizations for all IP address blocks they hold
- National Cyber Director recommends internet routing security contract language to FAR Council
- FCEB agencies enforce encrypted and authenticated email transport between clients and servers
- CISA and OMB jointly issue open source software security recommendations to agencies
- National Cyber Director submits study of FCEB space ground systems to OMB
- NIST, Energy, DHS, and NSF prioritize funding for large-scale cyber defense datasets accessible to researchers
- NIST publishes preliminary update to the Secure Software Development Framework
- CISA develops and releases concept of operations enabling timely access to agency endpoint detection and response data
- FCEB agencies enable encrypted DNS protocols wherever existing clients and servers support them
- CISA releases list of product categories where post-quantum cryptography products are widely available
- OMB establishes requirement for expanded authenticated transport-layer email encryption between agency email servers
- OMB requires agencies to enable transport and end-to-end encryption for voice, video, and instant messaging
- CNSS reviews and updates policies and guidance on space system cybersecurity
- NIST evaluates and issues minimum cybersecurity practices guidance for industry sectors
- NIST develops guidelines for secure management of cloud access tokens and cryptographic keys
- NIST issues practical guidance supporting remote digital identity verification using digital identity documents
- DoD and OMB issue requirements for agencies to support Transport Layer Security 1.3 by January 2, 2030
- OMB issues revised guidance including updates to OMB Circular A-130 addressing modern cybersecurity architectures
Agencies directed to act
Authority and reach
What this order changes
Amends Executive Order 13694