Executive Order 14028: 2026 Cybersecurity Compliance Updates

Executive Order 14028 sets the cybersecurity requirements that federal civilian agencies and their IT contractors must meet, covering incident reporting, zero trust architecture, software supply chain security, cloud authorization, and logging. The order itself, signed May 12, 2021, remains in effect, but several of the memoranda that implemented it have been rescinded or replaced since early 2025, so the practical compliance picture in 2026 is narrower and more agency-specific than the original text implies.1Federal Register. Improving the Nation’s Cybersecurity

Who Has to Comply

The order’s mandates apply most directly to Federal Civilian Executive Branch agencies. Its text states that “all Federal Information Systems should meet or exceed the standards and requirements for cybersecurity set forth in and issued pursuant to this order.”2The American Presidency Project. Executive Order 14028 – Improving the Nation’s Cybersecurity

The reach extends to contractors. Section 2 targets IT and operational technology service providers, including cloud providers, that sell to federal agencies. The order treats their security posture as inseparable from the government’s own because these vendors “have unique access to and insight into cyber threat and incident information on Federal Information Systems.”2The American Presidency Project. Executive Order 14028 – Improving the Nation’s Cybersecurity Vendors that fail contractual security requirements risk losing existing agreements and being shut out of future federal work.

The legal authority for imposing these terms on contractors sits in the President’s power over federal procurement, codified in Title 40 of the U.S. Code, which lets the government set the conditions under which it buys goods and services.3Office of the Law Revision Counsel. 40 USC Subtitle I – Federal Property and Administrative Services

Cyber Incident Reporting

Before EO 14028, contract terms often blocked IT service providers from voluntarily sharing breach data with the government. Section 2 removed that block. Contractors must promptly report cyber incidents to the contracting agency, and when the affected agency is a civilian executive branch entity, the provider must simultaneously report to CISA. Agencies must also ensure that providers share data with CISA and the FBI as needed for threat response.4Government Publishing Office. Executive Order 14028 – Improving the Nation’s Cybersecurity

For the most severe incidents, the maximum reporting window is three days after initial detection.4Government Publishing Office. Executive Order 14028 – Improving the Nation’s Cybersecurity

Separately, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) extends mandatory reporting beyond federal contractors to critical infrastructure operators more broadly. Covered entities must notify CISA within 72 hours of discovering a significant cyber incident and within 24 hours of making a ransomware payment. As of mid-2026, the final CIRCIA rule is still being finalized, with publication expected in 2026.

Zero Trust Architecture

The order’s most technically ambitious requirement is the shift to Zero Trust Architecture. The traditional model assumed users and devices inside the network perimeter could be trusted. Zero trust drops that assumption and verifies every access request regardless of origin. OMB Memorandum M-22-09 translated the principle into specific goals that FCEB agencies were expected to meet by the end of fiscal year 2024 (September 30, 2024).5Office of Management and Budget. Moving the U.S. Government Toward Zero Trust Cybersecurity Principles

Two requirements anchor the transition. Multi-factor authentication is mandatory for all users accessing federal systems, so stolen passwords alone are not enough to get in. All data must be encrypted both at rest and in transit, including on internal network traffic. The memorandum is explicit that “no network is implicitly considered trusted,” meaning agencies cannot treat a firewall as a substitute for encrypting data moving inside their own walls.5Office of Management and Budget. Moving the U.S. Government Toward Zero Trust Cybersecurity Principles

The FY2024 deadline has passed. Follow-on guidance continues to be issued, and full zero trust adoption across all agencies is still in progress.

Endpoint Detection and Response

OMB Memorandum M-22-01 requires agencies to deploy Endpoint Detection and Response (EDR) tools that continuously monitor connected devices and flag suspicious behavior. Deployments must align with CISA’s technical reference architecture, and endpoint data must be consolidated, retained, and archived in a way that supports analysis. Agencies must give CISA access to their EDR tools for threat hunting and coordinated response, and must confirm that they have budgeted enough to maintain the tools through their full lifecycle, including updates and licensing.6The White House. Improving Detection of Cybersecurity Vulnerabilities and Incidents on Federal Government Systems through Endpoint Detection and Response

Software Supply Chain Security

Section 4 targets the software agencies buy. NIST developed Special Publication 800-218, the Secure Software Development Framework (SSDF), which maps secure coding practices to the order’s requirements.7National Institute of Standards and Technology. Secure Software Development Framework The order also calls for software vendors to provide a Software Bill of Materials (SBOM) with each product, either directly to the purchaser or by publishing it on a public website.4Government Publishing Office. Executive Order 14028 – Improving the Nation’s Cybersecurity

An SBOM lists every component, library, and dependency inside a piece of software so that when a vulnerability surfaces in one component, agencies can quickly identify which products are affected.

How Self-Attestation and SBOM Rules Changed in 2026

OMB Memorandum M-22-18 originally made self-attestation mandatory. Software producers selling to federal agencies had to sign a Secure Software Development Attestation Form confirming they followed the practices in NIST SP 800-218, and agencies had to collect those letters on set timelines.8Cybersecurity and Infrastructure Security Agency. Secure Software Development Attestation Form

That changed in January 2026. OMB Memorandum M-26-05 rescinded both M-22-18 and its companion M-23-16. Under the current framework, self-attestation and SBOM requirements are no longer government-wide mandates. Agencies “may choose” to use the attestation form and “may also choose” to require SBOMs contractually. Each agency head decides what vendor security validation their systems need based on risk. Agencies must still maintain a complete inventory of their software and hardware and develop assurance policies matched to their risk assessments.9Office of Management and Budget. M-26-05 Adopting a Risk-based Approach to Software and Hardware Security

For vendors, the practical effect is uneven pressure. Agencies handling sensitive national security data will likely keep requiring attestation and SBOMs. Others may relax. Vendors selling across multiple agencies are generally better off keeping SBOM capability and SSDF compliance in place, since individual contracts can still demand it.

Cloud Services and FedRAMP

The order directed agencies to accelerate migration to secure cloud infrastructure. The Federal Risk and Authorization Management Program (FedRAMP) provides the standardized security assessment cloud providers must pass before agencies can use them. Congress codified FedRAMP into law in December 2022 as part of the National Defense Authorization Act for Fiscal Year 2023.10FedRAMP. FedRAMP in United States Law

Whether a specific cloud service needs FedRAMP authorization depends on the use case. Services that handle sensitive federal information, require agency-specific configuration, and integrate with enterprise security systems such as identity or single sign-on almost always need it. Services posing negligible risk to federal information, such as publicly available search engines, generally fall outside the program’s scope.11FedRAMP. Scope of FedRAMP Guidelines and Examples OMB Memorandum M-24-15, published in July 2024, overhauled the program’s operational structure.10FedRAMP. FedRAMP in United States Law

Incident Response and Logging

The order established a standardized incident response playbook so every agency follows the same procedures when a threat is detected. CISA was tasked with developing it.12Cybersecurity and Infrastructure Security Agency. Executive Order on Improving the Nation’s Cybersecurity

Section 8 requires detailed logs of network activity to support breach investigations. OMB Memorandum M-21-31 turned this into a tiered logging maturity model, with agencies expected to reach the top tier (EL3) — all logging requirements at every criticality level met — by August 2023.13Office of Management and Budget. M-21-31 Improving the Federal Governments Investigative and Remediation Capabilities Related to Cybersecurity Incidents Complete logs are what let investigators trace how an intruder entered a network, what they accessed, and how far the compromise spread.

One institution created by the order no longer exists. The Cyber Safety Review Board was dissolved in January 2025 when the incoming administration removed all board members. As of mid-2026, it has not been reconstituted, and bipartisan efforts in Congress to restore it have not resulted in legislation.

False Claims Act Enforcement

The most concrete enforcement tool for the order’s contractor requirements is the DOJ’s Civil Cyber-Fraud Initiative, launched in October 2021. The initiative uses the False Claims Act to pursue companies that misrepresent their cybersecurity compliance, sell deficient security products, or fail to report breaches as their federal contracts require. Penalties include treble damages, meaning the government can recover three times its actual losses, plus per-claim fines.

In 2025, DOJ announced eight settlements under the initiative totaling roughly $51.8 million, with individual settlements ranging from about $420,000 to $14.75 million. Five of the eight originated as whistleblower actions, and those whistleblowers collectively received over $4.5 million in shares of the recoveries.

Beyond monetary penalties, contractors found to have willfully violated cybersecurity requirements can be suspended or debarred from future federal contracting. For companies whose revenue depends on federal work, that consequence often outweighs the settlement itself.

What Has Changed Since 2021

EO 14028 has not been revoked. In June 2025, Executive Order 14306 made targeted edits to other cybersecurity executive orders but left EO 14028’s text intact.14The White House. Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144 A Congressional Research Service analysis confirmed that the administration “did not revoke previous cybersecurity executive orders, nor did it direct a review of prior ones.”15Congress.gov. Changes to National Cyber Policy in the Trump Administration

The changes have come through the implementing memoranda. M-26-05 replaced government-wide mandatory self-attestation and SBOM collection with a risk-based, agency-by-agency approach.9Office of Management and Budget. M-26-05 Adopting a Risk-based Approach to Software and Hardware Security The Cyber Safety Review Board was dissolved. The zero trust and logging deadlines from M-22-09 and M-21-31 have formally passed, and follow-on guidance continues as agencies work toward full compliance. The core framework — threat reporting, zero trust, supply chain security, and standardized incident response — remains the foundation of federal cybersecurity policy, even as specific enforcement mechanisms keep shifting.