Skip to main content
Category: Laws & Executive Orders

Executive Order 14306

Also known as: EO 14306, Sustaining Select Efforts to Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144
Simply put

Executive Order 14306 is a presidential action, issued in June 2025, that adjusts prior federal cybersecurity policy by continuing certain initiatives while amending two earlier executive orders (13694 and 14144). It reflects an ongoing federal effort to respond to cyber campaigns targeting the United States, and it changes some obligations previously placed on government contractors and software vendors. Because it modifies earlier orders rather than standing entirely alone, its effects should be read together with the executive orders it amends.

Formal definition

EO 14306 is a presidential executive order signed on or about June 6, 2025, titled 'Sustaining Select Efforts to Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144.' It selectively sustains certain cybersecurity initiatives while amending the prior orders it references, and reporting on its provisions indicates it altered the timeline for software vendor compliance obligations, for example, reportedly pausing an imminent requirement for software vendors to formally attest to compliance with the Secure Software Development Framework (SSDF). Practitioners should note that the order operates as an amending instrument, so its operative scope depends on the surviving and modified provisions of EO 13694 and EO 14144. This entry summarizes the order at a high level based on the cited evidence and does not enumerate every provision, effective date, tasking, or agency assignment; readers should consult the official published text (as issued in the Federal Register and referenced by NIST and CISA) to confirm specific requirements, deadlines, and their applicability to federal civilian, defense, or contractor systems, which may differ.

Why it matters

Executive Order 14306, issued on or about June 6, 2025, matters because it changes the federal cybersecurity posture that contractors and software vendors had been preparing to meet. Rather than standing alone, it amends two prior orders, EO 13694 and EO 14144, so its practical effect depends on which earlier provisions survive, which are modified, and which are sustained. For compliance officers and vendors tracking their obligations, this amending structure means the operative requirements cannot be read from EO 14306 in isolation; they must be reconciled against the surviving text of the orders it references.

The order's most widely reported effect is that it reportedly paused an imminent requirement for software vendors to formally attest to compliance with the Secure Software Development Framework (SSDF). Organizations that had scoped work, allocated resources, or built internal timelines around that attestation deadline are directly affected by such a shift. A change in timing is not the same as a change in the underlying security expectation, however, and practitioners should be careful not to treat a paused attestation requirement as the elimination of secure development obligations.

Because EO 14306 issued in June 2025 and reporting on its provisions continues to develop, its interpretation may evolve as agencies implement it and as guidance from bodies such as NIST and CISA is aligned to the amended framework. Readers should verify current requirements, effective dates, and applicability against the official published text rather than relying on secondary summaries, since obligations may differ across federal civilian, defense, and contractor systems.

Who it's relevant to

Software Vendors Supplying the Federal Government
Vendors that had been preparing to formally attest to Secure Software Development Framework (SSDF) compliance are directly affected by the order's reported pause of that imminent attestation requirement. These organizations should verify their current obligations against the official published text and avoid treating a change in timing as the elimination of underlying secure development expectations.
Government Contractors and Compliance Officers
Contractors and the compliance officers tracking their obligations need to understand that EO 14306 amends EO 13694 and EO 14144 rather than standing alone, so requirements must be read together with the surviving and modified provisions of those earlier orders. Applicability may differ across federal civilian, defense, and contractor systems and should be confirmed against current authoritative sources.
Authorizing Officials and ISSMs at Federal Agencies
Officials responsible for federal system security posture should monitor how their agencies implement the sustained and amended initiatives and how guidance from bodies such as NIST and CISA aligns to the revised framework. Because the order's operative scope depends on amended prior orders, agency-specific interpretation may evolve.
IT Service Providers and Auditors
IT service providers subject to the prior orders' information-sharing and breach-reporting expectations, along with auditors assessing compliance, should confirm which obligations continue, change, or are paused under the amended framework by consulting the official Federal Register text rather than relying on secondary summaries.

Inside EO 14306

Executive Order 14306
A presidential executive order concerning federal cybersecurity policy, published in the Federal Register. Because the specific taskings, effective dates, and agency assignments in the order must be confirmed against the authoritative published text, readers should consult the official Federal Register version directly rather than relying on secondary summaries. This entry does not restate specific provisions that cannot be verified against that official source.
Governing source
Executive orders are issued by the President and, when they direct agency action, are implemented through subsequent agency guidance, regulations, or memoranda (for example from OMB, CISA, or NIST as applicable). The binding operational requirements generally flow from those implementing documents rather than from the order's text alone, and readers should verify which implementing actions apply to their systems.
Scope considerations
Cybersecurity-related executive orders may apply differently across federal civilian agency systems under FISMA, DoD systems under the RMF, and national security systems, and they generally do not directly bind state, local, tribal, or territorial entities or private organizations except through contractual or regulatory mechanisms. The precise scope of EO 14306 should be confirmed against its official text and any implementing guidance.

Common questions

Answers to the questions practitioners most commonly ask about EO 14306.

Does Executive Order 14306 direct NIST to develop guidelines on the secure management of access tokens and cryptographic keys used by cloud service providers?
You should not rely on that characterization. Available review of the published text has not confirmed any tasking in EO 14306 assigning NIST or another body to develop guidelines specifically on secure management of access tokens or cryptographic keys used by cloud service providers. Before attributing any such tasking to this order, verify the operative language directly against the official Federal Register publication and any implementing memoranda, because summaries and secondary sources sometimes misattribute technical taskings across executive orders.
Is Executive Order 14306, on its own, a compliance requirement that agencies or contractors must directly implement?
Generally, an executive order of this type directs federal agencies and sets policy priorities rather than functioning as a self-executing control set that organizations implement line by line. Binding obligations typically flow from the implementing actions that follow, such as agency directives, OMB guidance, or updates to standards maintained by bodies like NIST or CISA. Readers should treat the order as establishing direction and deadlines for agencies and confirm the specific, enforceable requirements in the resulting guidance rather than assuming the order text itself imposes direct technical mandates.
How should a compliance officer track obligations that arise from Executive Order 14306?
In most implementations, the practical obligations from an executive order appear in the follow-on agency guidance, memoranda, or standards updates it directs, often with associated deadlines. A reasonable approach is to identify each tasking in the order, note the responsible agency and any stated timeframe, and monitor for the resulting publications. Because taskings and dates can be revised, confirm the current status of each deliverable against official sources rather than the order text alone.
Does Executive Order 14306 apply to defense systems under the RMF, civilian agency systems under FISMA, or both?
Scope depends on the order's own applicability language and how each agency implements it. Executive orders addressing federal cybersecurity commonly apply across federal civilian executive branch agencies, while defense and national security systems may be addressed separately or through DoD-specific implementation. You should confirm from the order text and implementing guidance whether a given provision reaches DoD RMF systems, civilian FISMA systems, or national security systems, and note that state, local, tribal, and territorial obligations generally differ and are not set by a federal executive order.
Will complying with agency guidance issued under Executive Order 14306 satisfy FedRAMP or CMMC requirements?
Not automatically. Compliance regimes are distinct: FedRAMP authorization, DoD RMF authorization, and CMMC assessment each have their own authorities, baselines, and processes. Actions taken to meet guidance stemming from an executive order do not inherently satisfy a separate authorization or assessment, and satisfying one program does not substitute for another. Confirm each program's requirements independently against its governing publications.
Where should I look for the authoritative text and current status of Executive Order 14306?
The authoritative source is the official Federal Register publication of the order, along with any subsequent amendments, revocations, or implementing memoranda. Because executive orders can be modified or superseded, verify that you are reviewing the current version and check for related OMB, CISA, or agency guidance that operationalizes its provisions before drawing compliance conclusions.

Common misconceptions

An executive order like EO 14306 is self-executing and imposes immediate, detailed technical requirements on agencies and contractors.
Executive orders generally direct agencies to take action within stated timeframes; the specific, enforceable requirements typically arise from subsequent implementing guidance, memoranda, or rulemaking. Practitioners should track those downstream actions rather than assume the order alone establishes controls.
Provisions or agency taskings attributed to EO 14306 in secondary summaries can be relied on as accurate.
Summaries and third-party descriptions sometimes misstate or invent taskings not present in the published order. Any specific provision, agency assignment, or deadline should be verified against the authoritative Federal Register text before being cited or acted upon.
Compliance with an executive order equates to being secure or to satisfying all applicable compliance frameworks.
Following an order's directives is one input to an organization's overall security and compliance posture. It does not by itself satisfy separate obligations under FISMA, the RMF, FedRAMP, or DoD contractual requirements, which must be assessed independently.

Best practices

Read and cite the authoritative Federal Register text of EO 14306 directly, and treat third-party summaries as secondary sources subject to verification.
Track the implementing guidance, memoranda, and rulemaking that agencies such as OMB, CISA, or NIST issue in response to the order, since enforceable requirements generally flow from those documents.
Confirm whether and how the order applies to your specific environment, distinguishing federal civilian systems under FISMA, DoD systems under the RMF, and national security systems, and note that non-federal obligations typically arise only through contract or regulation.
Do not treat any attributed tasking as authoritative unless it can be located in the published order or its official implementing guidance; flag unverifiable claims for legal or compliance review.
Integrate any resulting requirements into your existing continuous monitoring and authorization processes rather than treating them as one-time actions.
Verify current version, effective dates, and any amendments or revocations, as executive orders can be superseded or modified by later orders.