Legis
Technology
Executive order · Friday 6 June 2025

Sustaining Select Efforts To Strengthen The Nation’s Cybersecurity And Amending Executive Order 13694

Listen to the summary
0:00
  • Authority: The President uses powers under the Constitution and various laws to amend Executive Order 14144 regarding cybersecurity.

  • Amendments to Executive Order 14144:

    • Section adjustments: Multiple subsections are struck and redesignated, simplifying the structure of the order.
    • Policy focus: The new policy emphasizes the persistent cyber threats from nations like China, Russia, Iran, and North Korea, stressing the need for enhanced cybersecurity measures.
  • Actions by Agencies:

    • The Secretary of Commerce and NIST are directed to develop guidance on secure software practices and ensure timely updates to published standards.
    • Agencies are tasked with addressing vulnerabilities related to Border Gateway Protocol and preparing for quantum computing risks by transitioning to post-quantum cryptography.
    • A focus on artificial intelligence (AI) is established, promoting research accessibility and vulnerability management in AI systems.
  • Policy Alignment and Implementation:

    • Agencies are instructed to align cybersecurity policies with best practices and reduce risks in Federal information systems.
    • A pilot program for machine-readable policy guidance is to be established, alongside requirements for IoT products to carry Cyber Trust Mark labeling by 2027.
  • Further Amendments to Previous Orders:

    • Changes to Executive Order 13694 specify that references to "any person" are replaced with "any foreign person," tightening the scope of action against malicious cyber activities.
  • General Provisions:

    • The order clarifies the limits of its authority, and it specifies that it does not create enforceable rights against the U.S. or its entities.
    • Implementation of the order is subject to legal compliance and available appropriations.