in effect
This is an executive order signed June 6, 2025, that revises two earlier cybersecurity executive orders — EO 14144 (January 2025) and EO 13694 (April 2015). It keeps selected provisions from those orders while removing others, updates the stated policy to name China as the top cyber threat, and sets new deadlines for specific federal agencies to take concrete cybersecurity actions.
NIST must, by August 1, 2025, launch an industry consortium to develop guidance on secure software development, and by December 1, 2025, publish a preliminary update to its Secure Software Development Framework (SSDF), with a final version due 120 days later. NIST must also update its security controls publication (SP 800-53) by September 2, 2025, to cover how agencies should safely deploy software patches. On quantum computing, CISA must publish a list of products supporting post-quantum cryptography by December 1, 2025, and agencies must support TLS 1.3 (a modern encryption standard) no later than January 2, 2030. Federal agencies must also, within one year, begin a pilot program to publish cybersecurity policy in machine-readable form, and the Federal Acquisition Regulation must be updated to require that consumer Internet-of-Things devices sold to the federal government carry the U.S. Cyber Trust Mark label by January 4, 2027. A narrow but significant legal change is made to EO 13694: the sanctions authority for malicious cyber activities is narrowed so it applies only to foreign persons, not any person.
Federal agencies — particularly the Departments of Commerce, Homeland Security, Defense, and Energy, along with OMB and NSA — must meet the specific deadlines and implement the new requirements. Private-sector companies that sell software or Internet-of-Things hardware to the federal government will face new labeling and security-practice requirements under the updated acquisition rules. Academic researchers gain potential access to previously restricted government cybersecurity datasets for defense research.