Technology
Sustaining Select Efforts To Strengthen The Nation’s Cybersecurity And Amending Executive Order 13694
The order refocuses federal cybersecurity policy on secure software, post-quantum encryption, artificial intelligence, and safer government technology purchases.
Listen to the summary
0:00
It sets deadlines for stronger federal cyber standards and prepares government systems for emerging AI and quantum-computing threats. It also narrows cyber-related property-blocking authorities to foreign persons.
What the order does
- Directs the National Institute of Standards and Technology to update secure software development and patch-management guidance.
- Requires cybersecurity agencies to identify widely available post-quantum products and mandate modern encryption protocols across federal systems by January 2, 2030.
- Expands academic access to federal cyber-defense datasets while protecting confidential business and national-security information.
- Requires defense, homeland security, and intelligence officials to integrate AI vulnerabilities into incident tracking, response, reporting, and information sharing.
- Orders updated federal cybersecurity guidance and a pilot program for machine-readable cyber rules.
- Directs procurement officials to pursue rules requiring covered federal Internet-of-Things vendors to use the U.S. Cyber Trust Mark by January 4, 2027.
- Generally exempts national-security and other designated high-impact systems from most provisions.
- Limits specified cyber-sanctions authorities to foreign persons.
Who it affects
- Federal agencies operating information systems and buying connected products.
- Technology vendors supplying software and consumer Internet-of-Things products to the Federal Government.
- Cybersecurity researchers receiving broader access to government research datasets.
- Foreign persons involved in significant malicious cyber activity.