EO 14028Executive OrderBiden · D Quiet signal

Executive Order 14028

Improving the Nation's Cybersecurity

This executive order mandates comprehensive cybersecurity reforms across the federal government, requiring adoption of zero-trust architecture, cloud modernization, multi-factor authentication, and encryption. It establishes new software supply chain security standards including Software Bill of Materials (SBOM) requirements, creates a Cyber Safety Review Board for incident review, and removes contractual barriers to threat information sharing between IT/OT service providers and federal agencies.

Impact dates

  1. FAR Council review and public comment on IT/OT contract language

  2. FAR Council review and public comment on incident reporting recommendations

  3. FAR Council review and public comment on standardized cybersecurity requirements

  4. FCEB agencies evaluate data types and sensitivity

  5. OMB federal cloud-security strategy

  6. CISA cloud-security technical reference architecture

  7. CISA identification of critical software categories (following NIST definition)

  8. OMB review of FAR contract requirements for IT/OT providers

  9. Agency cloud adoption plans and Zero Trust Architecture plans due

  10. CISA cloud-service governance framework

  11. GSA begins FedRAMP modernization

  12. Commerce publication of minimum SBOM elements

  13. NIST publication of critical software security guidance

  14. NIST publication of software testing guidelines

  15. DOD and DHS establish directive sharing procedures

  16. NIST publication of critical software definition

  17. DHS recommendation of incident reporting contract language to FAR Council

  18. NSA recommendations for National Security Systems detection improvements

  19. NIST solicitation for software supply chain standards input

  20. CISA EDR implementation recommendations to OMB

Key directives

  • OMB to review FAR contract requirements for IT/OT providers within 60 days
  • FAR Council to publish proposed FAR updates within 90 days of OMB recommendations
  • Secretary of Homeland Security and OMB to ensure service provider data sharing within 120 days
  • DHS to recommend incident reporting contract language within 45 days
  • Agency heads to update cloud adoption plans and develop Zero Trust Architecture plans within 60 days
  • OMB to develop federal cloud-security strategy within 90 days
  • CISA to develop cloud-security technical reference architecture within 90 days
  • CISA to develop cloud-service governance framework within 60 days
  • FCEB agencies to evaluate data types and sensitivity within 90 days
  • Agencies to adopt multi-factor authentication and encryption within 180 days
  • CISA to establish cloud cybersecurity collaboration framework within 90 days
  • GSA to begin FedRAMP modernization within 60 days

Who is ordered

Timeline

Immediate

  • Contractual barriers to threat information sharing must be identified for removal
  • Federal policy establishes ICT service provider incident reporting requirements

Near term (90d)

  • OMB review of FAR contract requirements for IT/OT providers (60 days)
  • NIST solicitation for software supply chain standards input (30 days)
  • Agency plans for cloud adoption and Zero Trust Architecture due (60 days)
  • CISA cloud-service governance framework due (60 days)
  • OMB issuance of EDR requirements for FCEB agencies (90 days from CISA recommendations)
  • MOAs with CISA for Continuous Diagnostics and Mitigation data access due (75 days)

Long term

  • NIST preliminary software supply chain security guidelines (180 days)
  • Agency adoption of multi-factor authentication and encryption (180 days)
  • NIST additional guidelines for periodic review of software supply chain standards (360 days)
  • FAR amendments requiring software supplier compliance attestations (1 year)
  • NIST review of IoT and software labeling pilot programs (1 year)
  • Commerce Department report on software supply chain progress to President (1 year)

Risks & tensions

  • Ambiguity around 'to the maximum extent consistent with Federal records laws' may create implementation gaps for encryption and MFA
  • Vendor compliance costs for SBOM generation and secure development environments may reduce competition for federal contracts
  • Centralized CISA access to agency data raises privacy and civil liberties tensions despite stated protections
  • Zero Trust Architecture timeline lacks specific enforcement mechanisms beyond planning requirements
  • Legacy software remediation plans may become indefinite extensions rather than genuine compliance
  • Coordination burden across OMB, DHS, CISA, NIST, NSA, DOD creates risk of fragmented implementation
  • National Security Systems exemptions create dual-track system that may leave gaps in civilian protection
Executive Order 14028: Improving the Nation's Cybersecurity · Executive Orders