Skip to main content
Category: Laws & Executive Orders

Executive Order 14028

Also known as: EO 14028, Improving the Nation's Cybersecurity, Executive Order on Improving the Nation's Cybersecurity
Simply put

Executive Order 14028 is a presidential order issued on May 12, 2021, directing U.S. federal agencies to strengthen their cybersecurity and improve the integrity of the software they use. It assigns work to multiple agencies, including NIST, and pushes agencies to adopt modern security approaches such as zero trust principles. It is a directive to federal agencies rather than a standalone technical standard or control catalog.

Formal definition

Executive Order 14028, titled 'Improving the Nation's Cybersecurity,' was issued May 12, 2021 (published in the Federal Register on May 17, 2021) and charges multiple federal agencies with actions to enhance cybersecurity and software supply chain integrity. Among its assignments, it directs NIST to develop guidance on software supply chain security, including publishing a definition of 'critical software,' and pushes agencies to adopt zero trust cybersecurity principles and adjust their network architectures accordingly. As an executive order, EO 14028 applies to federal executive branch agencies and directs subsequent implementing guidance and deliverables from bodies such as NIST, CISA, and GSA; practitioners should note that the order itself sets direction and deadlines for those agencies rather than serving as a security control baseline, and the specific implementing publications derived from it should be consulted for detailed requirements. The evidence provided here does not establish the full set of applicable provisions, deadlines, or downstream artifacts, which readers should verify against the current authoritative text.

Why it matters

Executive Order 14028 marked a significant shift in how the federal government approaches cybersecurity, moving beyond incident response toward proactive measures such as software supply chain integrity and zero trust principles. Because it charges multiple agencies, including NIST, CISA, and GSA, with concrete deliverables, it functions as the origin point for a broad body of downstream guidance that compliance officers and system owners now encounter in their day-to-day work. Understanding the order helps practitioners trace where subsequent requirements come from and why certain expectations, such as a defined notion of 'critical software,' entered federal practice.

Who it's relevant to

Federal Agency Information System Security Managers and CISOs
Because EO 14028 applies to federal executive branch agencies and directs them to adopt zero trust principles and adjust network architectures, agency security leaders are directly responsible for translating the order's direction into implementation plans and for tracking the downstream guidance issued by NIST, CISA, and GSA.
Government Contractors and Software Suppliers
The order's emphasis on software supply chain integrity, including NIST's charge to develop supply chain security guidance and a definition of 'critical software,' is relevant to vendors supplying software to federal agencies. Contractors should confirm which specific implementing requirements apply to their offerings against current authoritative sources rather than relying on the order's text alone.
Compliance Officers and Auditors
Those assessing federal cybersecurity posture need to understand EO 14028 as the policy origin for numerous implementing publications. Since the order sets direction and deadlines for agencies rather than serving as a control baseline, auditors should map obligations to the derived guidance and verify provisions and timelines against the current authoritative text.
Policy and Governance Teams
Staff responsible for interpreting federal directives will find EO 14028 central to understanding the government's push toward zero trust and software supply chain security, and useful for tracing how multi-agency assignments produced the broader ecosystem of implementing guidance.

Inside EO 14028

Software Supply Chain Security
Directs the establishment of enhanced security standards for the software supply chain, including guidance for secure software development practices and the development of criteria to evaluate the security of software, which NIST was tasked with issuing. Practitioners should verify the current NIST guidance (such as the Secure Software Development Framework) against official sources for specifics.
Zero Trust Architecture
Encourages federal agencies to advance toward zero trust architecture as part of modernizing cybersecurity approaches. The Order generally frames zero trust as a strategic direction; detailed implementation guidance is elaborated in subsequent agency and CISA/OMB documents rather than the Order itself.
Incident Reporting and Information Sharing
Addresses the removal of contractual barriers that may limit sharing of threat and incident information between IT and OT service providers and federal agencies, and promotes improved information sharing about cyber threats and incidents.
Endpoint Detection and Response (EDR)
Promotes the deployment of endpoint detection and response capabilities across federal civilian agencies to improve detection of and response to cybersecurity incidents on government networks.
Multi-Factor Authentication and Encryption
Calls for the adoption of multi-factor authentication and encryption for data at rest and in transit within federal systems, subject to agency implementation timelines set through follow-on guidance.
Scope of Applicability
Applies primarily to federal executive branch agencies and, through contractual and procurement mechanisms, to their vendors and service providers. It does not by itself impose binding requirements on state, local, tribal, and territorial governments or private-sector entities outside federal contracting relationships.

Common questions

Answers to the questions practitioners most commonly ask about EO 14028.

Does Executive Order 14028 by itself impose binding cybersecurity requirements on private sector companies?
Not directly in most cases. As an executive order, EO 14028 primarily directs federal agencies to take action, such as developing standards, issuing guidance, and updating acquisition regulations. Its effect on the private sector generally flows indirectly through subsequent agency actions, such as contract clauses, procurement requirements, and guidance issued by bodies like NIST, OMB, and CISA. Companies should confirm which downstream requirements actually apply to them rather than assuming the order itself is a compliance obligation. Verify specific obligations against current authoritative sources and applicable contract terms.
Does complying with Executive Order 14028 mean an organization has satisfied FedRAMP, FISMA, or DoD RMF requirements?
No. EO 14028 is a policy directive and does not replace or automatically satisfy separate authorization and compliance frameworks. FedRAMP authorization, FISMA obligations for federal civilian systems, and the RMF process for DoD systems each have their own scope, governing authorities, and requirements. Actions taken to align with EO 14028 may overlap with these frameworks, but each must be assessed on its own terms. Confirm applicability and scope against the relevant governing publications and agency guidance.
How should an agency or contractor determine which specific tasks under EO 14028 apply to them?
Because EO 14028 tasks federal agencies with producing follow-on standards, guidance, and regulatory changes, the practical obligations are found in those downstream products rather than the order text alone. Organizations should trace the relevant guidance issued by the responsible bodies and identify which apply to their system categorization, information type, and contractual relationship. Readers should verify the current status and content of any implementing guidance against official sources, as these items are issued and revised over time.
What role does NIST guidance play in implementing EO 14028?
The order generally directs NIST to develop or update guidance in several areas addressed by the order. Implementation for many organizations therefore depends on consulting the applicable NIST publications and confirming their current revision status. Because NIST guidance can be revised and because agency tailoring may apply, organizations should not assume a single fixed set of requirements and should verify the applicable version and scope for their environment.
How does EO 14028 relate to software supply chain security in procurement?
EO 14028 places emphasis on software supply chain security, and its practical impact on procurement generally arises through follow-on guidance and acquisition-related actions taken by federal bodies. Organizations that provide software to the federal government should identify which specific requirements have been incorporated into applicable guidance and contract terms, rather than treating the order as a self-executing procurement standard. Confirm the current requirements and their scope against official sources and specific solicitations or contracts.
Is alignment with EO 14028 a one-time effort or an ongoing responsibility?
Implementation of EO 14028 is generally an ongoing process, because it initiates a series of agency actions and guidance products that are developed and updated over time. Organizations should monitor the status of implementing guidance and any resulting contractual or regulatory requirements as they evolve. This entry does not cover the specific timelines, deliverables, or current status of individual tasks; readers should verify those details against current authoritative sources.

Common misconceptions

Executive Order 14028 directly imposes detailed, enforceable technical requirements that organizations can comply with by reading the Order itself.
The Order primarily directs federal agencies, NIST, CISA, OMB, and others to develop standards, guidance, and follow-on actions. Many operative requirements appear in subsequent agency memoranda and NIST publications, so practitioners should trace requirements to the implementing guidance rather than the Order alone.
The Order applies broadly to all organizations, including private companies and state and local governments.
Its direct reach is generally to federal executive branch agencies and, through procurement and contractual mechanisms, their vendors. Obligations for non-federal entities differ and must be confirmed against applicable contracts and separate authorities.
Meeting the software or zero trust directions referenced in the Order equates to being secure or fully compliant.
Compliance with directives is not the same as security, and the Order's directions are implemented through evolving guidance subject to revision. Practitioners should verify the current authoritative text and treat these as ongoing programs rather than one-time checklists.

Best practices

Trace each obligation back to its implementing document (such as the relevant NIST publication or OMB memorandum) rather than relying on the Executive Order text alone, and verify you are referencing the current revision.
Confirm applicability to your organization based on your federal contracting relationships, since direct requirements generally flow to agencies and, through procurement mechanisms, to their vendors.
Track follow-on guidance from NIST, CISA, and OMB over time, as the standards and criteria directed by the Order continue to evolve and be updated.
Prioritize foundational controls referenced in the Order's direction, such as multi-factor authentication and encryption of data at rest and in transit, in line with agency implementation timelines.
For software providers, align secure development practices with the current NIST secure software development guidance and be prepared to attest as required by applicable federal acquisition mechanisms.
Review contracts and service agreements for provisions affecting cyber threat and incident information sharing, and address barriers to sharing consistent with the Order's direction.