OMB Circular A-130
OMB Circular A-130 is a policy document issued by the Office of Management and Budget that sets government-wide rules for how federal agencies manage their information and information technology. It covers a broad range of topics, including information governance, acquisitions, records management, workforce, and information security and privacy. It is executive-branch policy guidance rather than a law or an executive order.
OMB Circular A-130, titled 'Managing Information as a Strategic Resource,' is the Office of Management and Budget's overarching policy for the management of federal information resources. As revised (the current version was issued in 2016, per the Federal Register notice dated July 28, 2016), it establishes general policy for information governance, acquisitions, records management, open data, workforce, and information security and privacy across federal agencies. The Circular directs agencies to protect federal information and information systems throughout their lifecycle, including establishing minimum management controls and integrating security and privacy into agency processes. As of the applicable revision, its appendices address information security and management (Appendix I) and the protection of personally identifiable information (Appendix II); readers should verify current appendix structure and content against the official OMB text, as prior references to a separate 'Appendix III' reflect earlier versions. Because A-130 is OMB executive-branch policy guidance and not a statute or executive order, its requirements should be read alongside, and not as a substitute for, governing law such as FISMA and implementing standards and guidance issued by NIST.
Why it matters
OMB Circular A-130 sits at the top of the executive-branch policy structure governing how federal agencies treat their information and information systems. It frames information not as an afterthought but as a strategic resource to be managed deliberately across its entire lifecycle, and it directs agencies to build in security and privacy rather than bolt them on. For compliance officers, ISSMs, and authorizing officials, A-130 is the connective tissue that ties statutory obligations, such as those under FISMA, to the standards and guidance agencies implement through NIST publications. Understanding it helps explain why agency requirements are structured the way they are.
A critical point that experts routinely emphasize is that A-130 is OMB executive-branch policy guidance, not a law and not an executive order. Its requirements should be read alongside, and never as a substitute for, governing statutes like FISMA and the implementing standards and guidance issued by NIST. Treating the Circular as if it were itself the source of statutory authority, or conflating it with the underlying law, leads to misplaced reliance and gaps in an agency's compliance reasoning. A-130 directs and organizes agency behavior; the legal obligations themselves generally flow from statute.
Because A-130 requires agencies to adopt a minimum set of management controls and to integrate security and privacy into their processes, it also reinforces the principle that compliance and security are related but not identical. Adopting the minimum management controls the Circular calls for is a floor, not a guarantee of a secure posture. Readers should verify the current text and appendix structure against the official OMB version, since references drawn from earlier revisions may no longer reflect the document as revised.
Who it's relevant to
Inside A-130
Common questions
Answers to the questions practitioners most commonly ask about A-130.