Skip to main content
Category: Laws & Executive Orders

OMB Circular A-130

Also known as: A-130, Managing Information as a Strategic Resource, Management of Federal Information Resources, Circular A-130
Simply put

OMB Circular A-130 is a policy document issued by the Office of Management and Budget that sets government-wide rules for how federal agencies manage their information and information technology. It covers a broad range of topics, including information governance, acquisitions, records management, workforce, and information security and privacy. It is executive-branch policy guidance rather than a law or an executive order.

Formal definition

OMB Circular A-130, titled 'Managing Information as a Strategic Resource,' is the Office of Management and Budget's overarching policy for the management of federal information resources. As revised (the current version was issued in 2016, per the Federal Register notice dated July 28, 2016), it establishes general policy for information governance, acquisitions, records management, open data, workforce, and information security and privacy across federal agencies. The Circular directs agencies to protect federal information and information systems throughout their lifecycle, including establishing minimum management controls and integrating security and privacy into agency processes. As of the applicable revision, its appendices address information security and management (Appendix I) and the protection of personally identifiable information (Appendix II); readers should verify current appendix structure and content against the official OMB text, as prior references to a separate 'Appendix III' reflect earlier versions. Because A-130 is OMB executive-branch policy guidance and not a statute or executive order, its requirements should be read alongside, and not as a substitute for, governing law such as FISMA and implementing standards and guidance issued by NIST.

Why it matters

OMB Circular A-130 sits at the top of the executive-branch policy structure governing how federal agencies treat their information and information systems. It frames information not as an afterthought but as a strategic resource to be managed deliberately across its entire lifecycle, and it directs agencies to build in security and privacy rather than bolt them on. For compliance officers, ISSMs, and authorizing officials, A-130 is the connective tissue that ties statutory obligations, such as those under FISMA, to the standards and guidance agencies implement through NIST publications. Understanding it helps explain why agency requirements are structured the way they are.

A critical point that experts routinely emphasize is that A-130 is OMB executive-branch policy guidance, not a law and not an executive order. Its requirements should be read alongside, and never as a substitute for, governing statutes like FISMA and the implementing standards and guidance issued by NIST. Treating the Circular as if it were itself the source of statutory authority, or conflating it with the underlying law, leads to misplaced reliance and gaps in an agency's compliance reasoning. A-130 directs and organizes agency behavior; the legal obligations themselves generally flow from statute.

Because A-130 requires agencies to adopt a minimum set of management controls and to integrate security and privacy into their processes, it also reinforces the principle that compliance and security are related but not identical. Adopting the minimum management controls the Circular calls for is a floor, not a guarantee of a secure posture. Readers should verify the current text and appendix structure against the official OMB version, since references drawn from earlier revisions may no longer reflect the document as revised.

Who it's relevant to

Compliance Officers and Program Managers
A-130 provides the government-wide policy framework that shapes how agencies plan, budget, govern, acquire, and manage information resources. Compliance staff use it to understand why agency security and privacy requirements are structured as they are, while recognizing that the legal obligations themselves generally derive from statute such as FISMA, not from the Circular alone.
Information System Security Managers (ISSMs)
A-130 directs agencies to protect federal information and information systems throughout their lifecycle and to adopt a minimum set of management controls. ISSMs should treat these as a policy floor that must be integrated with security and privacy across agency processes, and should confirm the current text and appendix structure against the official OMB version.
Authorizing Officials and Privacy Officers
The Circular calls for integrating security and privacy into agency processes, with appendices addressing information security and management (Appendix I) and the protection of personally identifiable information (Appendix II). Officials responsible for authorization and privacy oversight should read A-130 alongside governing law and NIST guidance rather than as a standalone authority.
Auditors and Assessors
A-130 establishes the policy basis for many agency management controls, but it is executive-branch guidance, not a statute or executive order. Auditors should map agency practices to the current revision, avoid citing outdated elements such as a separate 'Appendix III,' and verify appendix content against the official OMB text before drawing conclusions.

Inside A-130

OMB Circular A-130 (overview)
An Office of Management and Budget (OMB) policy document that establishes federal policy for the management of information resources across executive branch agencies. It is executive-branch guidance issued by OMB, not a statute or an executive order, and it directs how agencies govern information, information technology, and related security and privacy responsibilities.
Information resources management policy
The main body of the Circular sets governmentwide policy on managing information as a strategic resource, addressing planning, budgeting, governance, and the lifecycle management of information and information systems within executive branch agencies.
Appendix I - Information security and management responsibilities
In the current (July 28, 2016) revision, Appendix I addresses responsibilities for protecting federal information resources and managing information systems, including information security and related management obligations. Readers should verify the exact scope against the current authoritative text.
Appendix II - Personally Identifiable Information (PII)
In the current revision, Appendix II addresses responsibilities for managing and protecting personally identifiable information (PII) and related privacy obligations. Practitioners should confirm specific requirements against the official published text.
Scope - executive branch agencies
The Circular generally applies to federal executive branch agencies. It does not by itself govern state, local, tribal, or territorial systems, and national security systems may be subject to separate or additional authorities; the reader should confirm applicability for a given system category.

Common questions

Answers to the questions practitioners most commonly ask about A-130.

Is OMB Circular A-130 a law or an executive order?
No. OMB Circular A-130 is a policy document issued by the Office of Management and Budget as executive-branch guidance directing federal agencies in managing information resources. It is not a statute enacted by Congress, nor is it an executive order signed by the President. It implements and operationalizes statutory requirements and other authorities, but it should be cited and understood as OMB policy rather than as a law or executive order. Readers should verify the specific statutory authorities the Circular references against current official text.
Does the security guidance still live in 'Appendix III' of the Circular?
Not in the current version. The July 28, 2016 revision of OMB Circular A-130 is organized differently than older editions that practitioners may remember. The current Circular contains Appendix I, which addresses responsibilities for protecting and managing federal information resources, including information security, and Appendix II, which addresses responsibilities for managing personally identifiable information (PII). The frequently cited 'Appendix III' reflects an outdated structure. Readers should consult the current official text of the Circular to confirm which appendix governs a given topic.
How does OMB Circular A-130 relate to the security controls agencies actually implement?
The Circular sets policy direction for how federal agencies manage information resources and protect information and information systems, but it generally does not itself enumerate specific technical controls. Agencies typically look to control catalogs and guidance maintained by NIST, together with agency-specific tailoring, to implement the policy expectations the Circular establishes. Confirm the current relationship between the Circular and applicable NIST guidance against the authoritative sources, as referenced publications may be updated across revisions.
Which federal agencies does OMB Circular A-130 apply to?
As OMB executive-branch guidance, the Circular generally applies to federal executive agencies in managing their information resources. Its direct applicability does not automatically extend to state, local, tribal, and territorial entities, whose obligations may differ. Application to national security systems and other specialized categories may be subject to distinct treatment or separate authorities. Readers should verify scope and any exceptions against the current text and their agency's implementing policy.
How should a compliance team use the Circular alongside other requirements like FISMA obligations?
The Circular is generally best treated as the overarching OMB policy framework that agencies align with, rather than as a standalone checklist. Compliance teams typically map the Circular's policy expectations to the statutory and technical requirements that govern their systems and to their agency's own implementing directives. Because the Circular, statutes, and technical guidance each carry distinct authority and can be revised independently, teams should confirm current versions of each and how they interrelate before relying on a specific mapping.
Does following OMB Circular A-130 mean an agency has satisfied its authorization requirements?
Not by itself. Aligning with the Circular's policy direction is distinct from completing a system authorization or maintaining an active authority to operate. Authorization is a time-bound decision subject to continuous monitoring, and compliance with policy is not the same as demonstrating security or obtaining an authorization. Teams should treat the Circular as policy input to their broader authorization and continuous monitoring processes and confirm specific authorization requirements against the applicable governing guidance.

Common misconceptions

OMB Circular A-130 is a law or executive order.
It is an OMB policy document, executive-branch guidance issued by the Office of Management and Budget, rather than a statute enacted by Congress or an executive order issued by the President.
OMB Circular A-130 still contains an 'Appendix III' governing security of federal automated information resources.
The former Appendix III reference is outdated. The current (July 28, 2016) revision is organized with Appendix I (information security and management responsibilities) and Appendix II (PII); citations to 'Appendix III' do not reflect the current version.
The Circular's requirements apply uniformly to all government systems, including state and local systems.
The Circular generally applies to federal executive branch agencies. Obligations for state, local, tribal, and territorial systems may differ, and certain system categories may be subject to separate authorities that the reader must verify.

Best practices

Cite the current July 28, 2016 revision and reference only Appendix I (information security and management) and Appendix II (PII); avoid outdated references to 'Appendix III.'
Treat the Circular as OMB executive-branch policy guidance rather than as a statute or executive order when characterizing its authority.
Verify the exact scope and requirements of each appendix against the official published text before relying on them for compliance decisions.
Confirm applicability for the specific system category, recognizing that the Circular generally governs federal executive branch agencies and that other system types may fall under separate authorities.
When applying the Circular to systems involving PII, review Appendix II alongside the applicable privacy obligations for that information.
Recheck the authoritative OMB text periodically, as policy documents may be revised and terminology or organizational structure may change over time.