Executive Order 14144 · Signed Jan 16, 2025

90 FR 6755 · Published Jan 17, 2025 · Effective on signing

Share

Strengthening and Promoting Innovation in the Nation's Cybersecurity

cybersecurityfederal IT securitysoftware supply chainartificial intelligencequantum computing

Signed by President Joseph R. Biden Jr.

The order directs federal civilian agencies and their software and cloud vendors to implement dozens of specific cybersecurity improvements — covering software supply chain attestations, communications encryption, post-quantum cryptography, AI-assisted threat detection, and digital identity fraud prevention — with deadlines ranging from 30 days to 3 years.

It also immediately expands the sanctions authority established by a 2015 executive order to explicitly cover ransomware attacks, election infrastructure tampering, and knowing receipt of stolen data — allowing Treasury to block the assets of a broader set of foreign cyber actors.

What this order does

What it orders

The order directs federal civilian executive branch agencies, software providers selling to the federal government, and cloud service providers to meet a cascading series of cybersecurity requirements. Software vendors must submit machine-readable security attestations and supporting evidence to a central CISA repository; NIST must update its Secure Software Development Framework; and OMB must require agencies to follow updated supply chain risk management guidance. Agencies must encrypt DNS traffic, email, and voice and video communications; register their internet address blocks; deploy post-quantum cryptographic algorithms; and enroll endpoints in CISA's persistent threat-hunting program. The order also directs investments in AI-assisted cyber defense, minimum cybersecurity standards for contractors, and Internet-of-Things device labeling requirements for federal vendors.

Section 9 immediately amends Executive Order 13694 (2015) to expand the class of foreign actors whose U.S.-held assets can be frozen by Treasury to include ransomware attackers, those who tamper with election infrastructure, and entities that knowingly receive stolen data. National Security Systems and classified "debilitating impact systems" are carved out of the main provisions but must receive parallel requirements developed by NSA and the Committee on National Security Systems.

Who it affects

Federal civilian executive branch agencies facing dozens of new IT security mandates; software companies and cloud providers selling to the federal government who must submit attestations and meet new contracting standards; federal contractors subject to minimum cybersecurity requirements; state benefits programs and financial institutions affected by digital identity guidance; and foreign cyber actors now subject to expanded sanctions criteria.

Why it matters

Software vendors selling to the federal government now face binding attestation and artifact requirements that CISA can verify and publicly report on. Federal agencies must encrypt communications and adopt quantum-resistant cryptography on firm timetables. Foreign ransomware operators and election-infrastructure attackers face broader asset-blocking exposure under the expanded sanctions authority.

What must happen and when

How the order is supposed to work

The order operates as a cascading series of deadlines: NIST and CISA first issue technical standards or guidance; OMB converts those into binding agency requirements; the FAR Council then amends procurement rules to extend the same obligations to contractors. CISA serves as the central verification hub, gaining persistent access to agency endpoint detection tools and running a program to audit software vendor attestations. Failures in attestation validation are publicly posted by the National Cyber Director and may be referred to the Attorney General. National Security Systems are exempt from the main provisions but receive a parallel NSA-led requirements process. The order's implementation depends on appropriations and existing legal authority.

Actions and deadlines

  • OMB Director recommends FAR contract language requiring software providers to submit attestations to CISA's RSAAWithin 30 days of signing
  • NIST establishes industry consortium at National Cybersecurity Center of Excellence for secure software development guidanceWithin 60 days of signing
  • CISA provides guidance on submitting machine-readable attestations to RSAA, including common data schemaWithin 60 days of OMB's recommendations to FAR Council
  • NIST updates Special Publication 800-53 to provide guidance on securely deploying patches and updatesWithin 90 days of signing
  • OMB requires agencies to comply with NIST SP 800-161 cybersecurity supply chain risk management guidanceWithin 90 days of signing
  • FCEB agencies register all assigned internet number resources with a regional internet registryWithin 90 days of signing
  • CISA publishes template contract language requiring DNS resolver products to support encrypted DNSWithin 90 days of signing
  • NSA develops cybersecurity requirements for National Security Systems and debilitating impact systemsWithin 90 days of signing
  • OMB issues guidance requiring agencies to inventory all major information systems and provide inventory to CISA or DoDWithin 90 days of signing
  • FCEB agencies create and publish Route Origin Authorizations for all IP address blocks they holdWithin 120 days of signing
  • National Cyber Director recommends internet routing security contract language to FAR CouncilWithin 120 days of signing
  • FCEB agencies enforce encrypted and authenticated email transport between clients and serversWithin 120 days of signing
  • CISA and OMB jointly issue open source software security recommendations to agenciesWithin 120 days of signing
  • National Cyber Director submits study of FCEB space ground systems to OMBWithin 120 days of signing
  • NIST, Energy, DHS, and NSF prioritize funding for large-scale cyber defense datasets accessible to researchersWithin 150 days of signing
  • NIST publishes preliminary update to the Secure Software Development FrameworkWithin 180 days of signing
  • CISA develops and releases concept of operations enabling timely access to agency endpoint detection and response dataWithin 180 days of signing
  • FCEB agencies enable encrypted DNS protocols wherever existing clients and servers support themWithin 180 days of signing
  • CISA releases list of product categories where post-quantum cryptography products are widely availableWithin 180 days of signing
  • OMB establishes requirement for expanded authenticated transport-layer email encryption between agency email serversWithin 180 days of signing
  • OMB requires agencies to enable transport and end-to-end encryption for voice, video, and instant messagingWithin 180 days of signing
  • CNSS reviews and updates policies and guidance on space system cybersecurityWithin 210 days of signing
  • NIST evaluates and issues minimum cybersecurity practices guidance for industry sectorsWithin 240 days of signing
  • NIST develops guidelines for secure management of cloud access tokens and cryptographic keysWithin 270 days of signing
  • NIST issues practical guidance supporting remote digital identity verification using digital identity documentsWithin 270 days of signing
  • DoD and OMB issue requirements for agencies to support Transport Layer Security 1.3 by January 2, 2030Within 180 days of signing
  • OMB issues revised guidance including updates to OMB Circular A-130 addressing modern cybersecurity architecturesWithin 3 years of signing

Agencies directed to act

Office of Management and BudgetCybersecurity and Infrastructure Security AgencyNational Institute of Standards and TechnologyFederal Acquisition Regulatory CouncilDepartment of Homeland SecurityDepartment of CommerceDepartment of DefenseGeneral Services AdministrationNational Aeronautics and Space AdministrationNational Cyber DirectorDepartment of JusticeDepartment of the TreasuryDepartment of StateDepartment of EnergyDepartment of the InteriorNational Oceanic and Atmospheric AdministrationNational Science FoundationSocial Security AdministrationDefense Advanced Research Projects AgencyNational Security AgencyCommittee on National Security SystemsDirector of National Intelligence

Authority and reach

Authorities cited

Article II

Constitutional grant of executive power to the President.

International Emergency Economic Powers Act

Authorizes the President to regulate financial transactions during a declared national emergency involving foreign threats.

National Emergencies Act

Governs how the President declares and manages national emergencies.

Section 212(f) of the Immigration and Nationality Act

Authorizes the President to suspend entry of aliens whose admission is detrimental to national interests.

3 U.S.C. § 301

Allows the President to delegate specific presidential functions to executive branch officers.

What this order changes

Amends Executive Order 13694

Executive Order

Ask GovernmentReporter about this order

Ask anything about what this order does, who it affects, and how it changes policy.

Executive Order 14144: Strengthening and Promoting Innovation in the Nation's Cybersecurity | EO Reporter