Executive Order 14306 · Signed Jun 6, 2025

90 FR 24723 · Published Jun 11, 2025 · Effective on signing

Share

Sustaining Select Efforts To Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144

cybersecuritysoftware standardsquantum computingfederal procurementsanctions

Signed by President Donald Trump

The order amends two prior cybersecurity executive orders — EO 14144 on federal cybersecurity practices and EO 13694 on cyber-related sanctions — stripping out certain provisions, updating threat-framing language to highlight China as the top cyber threat, and imposing new deadlines on federal agencies for software standards, post-quantum cryptography transition, AI vulnerability management, and IoT product labeling.

It also narrows the cyber sanctions authority in EO 13694, changing 'any person' to 'any foreign person' in two key provisions, which limits who can be targeted under that emergency sanctions regime.

What this order does

What it orders

The order amends EO 14144 by deleting several provisions from the Biden-era cybersecurity order and replacing them with updated directives. It replaces the policy statement to name the People's Republic of China as the most active cyber threat, alongside Russia, Iran, and North Korea. It then sets a series of agency deadlines: NIST must establish an industry consortium for secure software development guidance, update patch-deployment guidance in NIST SP 800-53, and publish a revised Secure Software Development Framework (SSDF). CISA must release a list of product categories where post-quantum cryptography products are available. NSA and OMB must issue requirements for agencies to adopt TLS 1.3 or a successor by January 2, 2030. Agencies must integrate AI software vulnerability management into existing processes, and the FAR Council must amend procurement rules to require US Cyber Trust Mark labeling on consumer IoT products sold to the federal government by January 4, 2027.

The order also amends EO 13694, the long-standing cyber sanctions authority, by replacing "any person" with "any foreign person" in two subsections — narrowing the sanctions authority so it no longer formally reaches domestic actors. General provisions confirm no new enforceable rights are created and implementation is subject to available appropriations.

Who it affects

Federal agencies with cybersecurity responsibilities, particularly NIST, CISA, NSA, OMB, the Department of Defense, and the FAR Council. Commercial vendors selling consumer IoT products to the federal government face new labeling requirements. Foreign persons engaged in malicious cyber activity face a sanctions regime whose scope is now explicitly limited to non-U.S. actors.

Why it matters

Federal agencies must meet a cascade of hard deadlines through 2025 and 2027 to update software security standards, prepare encrypted systems for quantum computing threats, and adopt AI-based vulnerability tracking. Companies selling connected devices to the government will need US Cyber Trust Mark certification. The narrowing of cyber sanctions to foreign persons removes domestic actors from formal coverage under EO 13694.

What must happen and when

How the order is supposed to work

Implementation runs in parallel tracks. NIST leads the software standards work — establishing an industry consortium by August 2025, updating patch guidance by September 2025, and publishing a revised SSDF by December 2025 with a final version 120 days later. CISA and NSA run the post-quantum cryptography track toward a 2030 compliance target. OMB oversees a separate three-year cycle to revise federal IT management guidance. The FAR Council has one year to begin amending procurement rules, with vendor compliance due by January 2027. No dedicated enforcement mechanism beyond existing agency authority is established.

Actions and deadlines

  • Establish a consortium with industry at the National Cybersecurity Center of Excellence for secure software development guidance2025-08-01
  • Update NIST SP 800-53 to provide guidance on securely deploying patches and updates2025-09-02
  • Develop and publish a preliminary update to the Secure Software Development Framework (SSDF)2025-12-01
  • Publish final version of the updated SSDFWithin 120 days of publishing the preliminary SSDF update
  • Release a list of product categories where post-quantum cryptography products are widely available2025-12-01
  • NSA and OMB each issue requirements for agencies to support TLS 1.3 or successor by January 2, 20302025-12-01
  • Ensure cyber defense research datasets are accessible to the academic research community2025-11-01
  • Incorporate AI software vulnerability management into agencies' existing vulnerability management processes2025-11-01
  • Establish a pilot program for a rules-as-code approach to machine-readable cybersecurity policyWithin 1 year of signing
  • FAR Council members take steps to amend the FAR to require US Cyber Trust Mark labeling for consumer IoT vendor products by January 4, 2027Within 1 year of signing
  • OMB Director issue guidance including revisions to OMB Circular A-130 for federal information system securityWithin 3 years of signing

Agencies directed to act

Department of CommerceNational Institute of Standards and TechnologyDepartment of Homeland SecurityCybersecurity and Infrastructure Security AgencyNational Security AgencyOffice of Management and BudgetDepartment of DefenseDepartment of EnergyNational Science FoundationOffice of the Director of National IntelligenceFederal Acquisition Regulatory Council

Authority and reach

Authorities cited

Article II

Constitutional grant of executive power to the President.

International Emergency Economic Powers Act

Authorizes the President to regulate commerce and freeze assets in response to foreign threats.

National Emergencies Act

Establishes procedures for declaring and managing national emergencies.

Immigration and Nationality Act § 212(f)

Allows the President to suspend entry of certain classes of noncitizens.

3 U.S.C. § 301

Authorizes the President to delegate functions to executive branch officers.

What this order changes

Amends Executive Order 13694

Executive Order

Ask GovernmentReporter about this order

Ask anything about what this order does, who it affects, and how it changes policy.

Executive Order 14306: Sustaining Select Efforts To Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144 | EO Reporter