Director of CISA
Executive orders directing the Director of CISA · 8 in Search.
Related departments
Orders
8 shown
Securing the Nation Against Advanced Cryptographic Attacks
This executive order mandates a government-wide transition to post-quantum cryptography (PQC) to protect against future quantum computing threats. It sets specific deadlines for federal agencies to migrate high-value assets and high-impact systems to PQC standards, requires new procurement rules for contractors, and establishes coordination roles across OMB, NIST, CISA, and NSA.
Promoting Advanced Artificial Intelligence Innovation and Security
This executive order directs federal agencies to strengthen cybersecurity defenses using advanced AI tools, establishes a voluntary framework for frontier AI model developers to collaborate with government on security assessments, creates an AI cybersecurity clearinghouse for vulnerability coordination, and prioritizes criminal enforcement against AI-enabled cyberattacks. It emphasizes collaboration with industry rather than mandatory regulation.
Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens
This executive order directs multiple Cabinet departments to combat transnational cybercrime, fraud, and predatory schemes targeting Americans—including scam centers, ransomware, sextortion, and financial fraud often backed by foreign regimes. It mandates reviews and action plans to create a new operational cell for interagency coordination, establishes a Victims Restoration Program, and authorizes diplomatic consequences including sanctions, visa restrictions, and trade penalties against nations that tolerate such criminal activity.
Sustaining Select Efforts To Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144
This executive order amends two prior cybersecurity orders: it narrows the scope of sanctions under EO 13694 to target only foreign persons, and substantially revises EO 14144 by removing several Biden-era provisions while adding new deadlines for NIST guidance, post-quantum cryptography transition, AI vulnerability management, and Federal Acquisition Regulation updates for IoT security labeling.
Strengthening and Promoting Innovation in the Nation's Cybersecurity
This executive order mandates comprehensive cybersecurity reforms across the federal government, focusing on securing software supply chains, hardening federal systems and communications, combating identity fraud, and integrating AI into cyber defense. It establishes numerous deadlines for agencies to implement technical requirements including encrypted DNS, routing security, post-quantum cryptography, and enhanced threat-hunting capabilities. The order builds on EO 14028 and the National Cybersecurity Strategy with specific procurement rule changes and operational directives.
Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern
This executive order restricts countries of concern from accessing Americans' bulk sensitive personal data and U.S. government-related data through new regulations on data transactions, submarine cable licensing, and federal research funding. It directs the Attorney General and Homeland Security to issue regulations within 180 days to prohibit or restrict high-risk data transfers while avoiding broad data localization requirements or commercial decoupling. The order also mandates reports on genomic data risks and prior data transfers, with security requirements based on NIST cybersecurity frameworks.
Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence
This executive order establishes a comprehensive, government-wide framework for governing AI development and use, directing federal agencies to develop safety standards, require reporting from companies building large AI models, protect against AI-enabled cyber and biological threats, safeguard civil rights and privacy, and build federal AI workforce capacity. It invokes the Defense Production Act and International Emergency Economic Powers Act to impose reporting obligations on AI developers and cloud infrastructure providers regarding dual-use foundation models and foreign user transactions.
Improving the Nation's Cybersecurity
This executive order mandates comprehensive cybersecurity reforms across the federal government, requiring adoption of zero-trust architecture, cloud modernization, multi-factor authentication, and encryption. It establishes new software supply chain security standards including Software Bill of Materials (SBOM) requirements, creates a Cyber Safety Review Board for incident review, and removes contractual barriers to threat information sharing between IT/OT service providers and federal agencies.