Executive Order 14306
Executive Order 14306 is a presidential action, issued in June 2025, that adjusts prior federal cybersecurity policy by continuing certain initiatives while amending two earlier executive orders (13694 and 14144). It reflects an ongoing federal effort to respond to cyber campaigns targeting the United States, and it changes some obligations previously placed on government contractors and software vendors. Because it modifies earlier orders rather than standing entirely alone, its effects should be read together with the executive orders it amends.
EO 14306 is a presidential executive order signed on or about June 6, 2025, titled 'Sustaining Select Efforts to Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144.' It selectively sustains certain cybersecurity initiatives while amending the prior orders it references, and reporting on its provisions indicates it altered the timeline for software vendor compliance obligations, for example, reportedly pausing an imminent requirement for software vendors to formally attest to compliance with the Secure Software Development Framework (SSDF). Practitioners should note that the order operates as an amending instrument, so its operative scope depends on the surviving and modified provisions of EO 13694 and EO 14144. This entry summarizes the order at a high level based on the cited evidence and does not enumerate every provision, effective date, tasking, or agency assignment; readers should consult the official published text (as issued in the Federal Register and referenced by NIST and CISA) to confirm specific requirements, deadlines, and their applicability to federal civilian, defense, or contractor systems, which may differ.
Why it matters
Executive Order 14306, issued on or about June 6, 2025, matters because it changes the federal cybersecurity posture that contractors and software vendors had been preparing to meet. Rather than standing alone, it amends two prior orders, EO 13694 and EO 14144, so its practical effect depends on which earlier provisions survive, which are modified, and which are sustained. For compliance officers and vendors tracking their obligations, this amending structure means the operative requirements cannot be read from EO 14306 in isolation; they must be reconciled against the surviving text of the orders it references.
The order's most widely reported effect is that it reportedly paused an imminent requirement for software vendors to formally attest to compliance with the Secure Software Development Framework (SSDF). Organizations that had scoped work, allocated resources, or built internal timelines around that attestation deadline are directly affected by such a shift. A change in timing is not the same as a change in the underlying security expectation, however, and practitioners should be careful not to treat a paused attestation requirement as the elimination of secure development obligations.
Because EO 14306 issued in June 2025 and reporting on its provisions continues to develop, its interpretation may evolve as agencies implement it and as guidance from bodies such as NIST and CISA is aligned to the amended framework. Readers should verify current requirements, effective dates, and applicability against the official published text rather than relying on secondary summaries, since obligations may differ across federal civilian, defense, and contractor systems.
Who it's relevant to
Inside EO 14306
Common questions
Answers to the questions practitioners most commonly ask about EO 14306.