Legis
Technology
Executive order · Friday 6 June 2025

Sustaining Select Efforts To Strengthen The Nation’s Cybersecurity And Amending Executive Order 13694

The order refocuses federal cybersecurity policy on secure software, post-quantum encryption, artificial intelligence, and safer government technology purchases.

Listen to the summary
0:00

It sets deadlines for stronger federal cyber standards and prepares government systems for emerging AI and quantum-computing threats. It also narrows cyber-related property-blocking authorities to foreign persons.

What the order does

  • Directs the National Institute of Standards and Technology to update secure software development and patch-management guidance.
  • Requires cybersecurity agencies to identify widely available post-quantum products and mandate modern encryption protocols across federal systems by January 2, 2030.
  • Expands academic access to federal cyber-defense datasets while protecting confidential business and national-security information.
  • Requires defense, homeland security, and intelligence officials to integrate AI vulnerabilities into incident tracking, response, reporting, and information sharing.
  • Orders updated federal cybersecurity guidance and a pilot program for machine-readable cyber rules.
  • Directs procurement officials to pursue rules requiring covered federal Internet-of-Things vendors to use the U.S. Cyber Trust Mark by January 4, 2027.
  • Generally exempts national-security and other designated high-impact systems from most provisions.
  • Limits specified cyber-sanctions authorities to foreign persons.

Who it affects

  • Federal agencies operating information systems and buying connected products.
  • Technology vendors supplying software and consumer Internet-of-Things products to the Federal Government.
  • Cybersecurity researchers receiving broader access to government research datasets.
  • Foreign persons involved in significant malicious cyber activity.