Executive Order 14028
Executive Order 14028 is a presidential order issued on May 12, 2021, directing U.S. federal agencies to strengthen their cybersecurity and improve the integrity of the software they use. It assigns work to multiple agencies, including NIST, and pushes agencies to adopt modern security approaches such as zero trust principles. It is a directive to federal agencies rather than a standalone technical standard or control catalog.
Executive Order 14028, titled 'Improving the Nation's Cybersecurity,' was issued May 12, 2021 (published in the Federal Register on May 17, 2021) and charges multiple federal agencies with actions to enhance cybersecurity and software supply chain integrity. Among its assignments, it directs NIST to develop guidance on software supply chain security, including publishing a definition of 'critical software,' and pushes agencies to adopt zero trust cybersecurity principles and adjust their network architectures accordingly. As an executive order, EO 14028 applies to federal executive branch agencies and directs subsequent implementing guidance and deliverables from bodies such as NIST, CISA, and GSA; practitioners should note that the order itself sets direction and deadlines for those agencies rather than serving as a security control baseline, and the specific implementing publications derived from it should be consulted for detailed requirements. The evidence provided here does not establish the full set of applicable provisions, deadlines, or downstream artifacts, which readers should verify against the current authoritative text.
Why it matters
Executive Order 14028 marked a significant shift in how the federal government approaches cybersecurity, moving beyond incident response toward proactive measures such as software supply chain integrity and zero trust principles. Because it charges multiple agencies, including NIST, CISA, and GSA, with concrete deliverables, it functions as the origin point for a broad body of downstream guidance that compliance officers and system owners now encounter in their day-to-day work. Understanding the order helps practitioners trace where subsequent requirements come from and why certain expectations, such as a defined notion of 'critical software,' entered federal practice.
Who it's relevant to
Inside EO 14028
Common questions
Answers to the questions practitioners most commonly ask about EO 14028.