EO 13984Executive OrderTrump 45 · R Quiet signal

Executive Order 13984

Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber- Enabled Activities

This executive order requires U.S. cloud computing (IaaS) providers to verify the identity of foreign customers and maintain detailed records, with regulations due within 180 days. It also authorizes special measures including account restrictions for foreign jurisdictions or persons involved in malicious cyber activities, and mandates reports on industry information sharing within 120-240 days.

Impact dates

  1. Attorney General and DHS submit report with recommendations to President

  2. Commerce Secretary proposes identity verification regulations for notice and comment

  3. Commerce Secretary proposes special measures regulations for notice and comment

  4. Earliest date special measures may be imposed (180 days after final Section 1 regulations)

  5. Attorney General and DHS engage industry and solicit feedback on information sharing

Key directives

  • Commerce Secretary shall propose identity verification regulations for foreign IaaS account holders within 180 days
  • Regulations must specify minimum identity verification standards, required records, and third-party access limitations
  • Commerce Secretary may exempt providers or account types that meet security best practices
  • Commerce Secretary shall propose special measures regulations for certain foreign jurisdictions or persons within 180 days
  • Special measures include prohibitions or conditions on accounts for foreign persons in targeted jurisdictions or specific foreign persons
  • Special measures cannot take effect earlier than 180 days after final identity verification regulations are issued
  • Attorney General and DHS shall engage industry on information sharing within 120 days
  • Attorney General and DHS shall submit recommendations report to President within 240 days, including liability protection recommendations and gaps in current law
  • Commerce Secretary shall identify funding requirements and incorporate into annual budget submissions
  • Executive Order 13694 reporting authority amended to include Commerce Secretary

Who is ordered

Timeline

Immediate

  • EO takes effect upon signing; no immediate compliance obligations for providers

Near term (90d)

  • Attorney General and DHS must engage industry on information sharing (120 days from signing, i.e., by May 19, 2021)

Long term

  • Commerce Secretary must propose identity verification regulations (180 days, i.e., by July 18, 2021)
  • Commerce Secretary must propose special measures regulations (180 days, i.e., by July 18, 2021)
  • Attorney General and DHS must submit report with recommendations to President (240 days, i.e., by September 16, 2021)
  • Special measures cannot be imposed earlier than 180 days after final identity verification regulations issued

Risks & tensions

  • Vague threshold for 'significant number' of malicious actors triggering special measures creates enforcement uncertainty
  • Competitive disadvantage concerns for U.S. providers if foreign competitors face fewer verification requirements
  • Potential tension between surveillance-like record-keeping and privacy expectations; no explicit privacy safeguards mentioned
  • Exemption authority (Section 1(c)) for security-best-practice providers may create uneven compliance landscape
  • Dependent on annual budget appropriations (Section 4), creating implementation risk if unfunded
  • Information sharing recommendations (Section 3) may conflict with existing contractual or liability frameworks without legislative changes
Executive Order 13984: Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber- Enabled Activities · Executive Orders