FCEB Agencies: Definition, CISA Directives, and FISMA Duties

Federal Civilian Executive Branch (FCEB) agencies are the federal civilian departments and independent organizations in the executive branch that must follow cybersecurity standards set by the Cybersecurity and Infrastructure Security Agency (CISA) and the Office of Management and Budget (OMB). The label covers everything in the executive branch outside the Department of Defense and the intelligence community, from Cabinet departments like the Department of State down to small independent commissions. CISA publishes the official roster and uses binding directives to enforce uniform security practices across all of them.1Cybersecurity and Infrastructure Security Agency. Federal Civilian Executive Branch Agencies List

Where the FCEB Definition Comes From

There is no single statute that defines “FCEB” as a term. The category is built from two sections of Title 44 of the U.S. Code read together. Section 3502 defines “agency” broadly to include any executive department, government corporation, government-controlled corporation, or other establishment in the executive branch, along with independent regulatory agencies.2Office of the Law Revision Counsel. 44 USC 3502 – Definitions Section 3552 then draws the cybersecurity boundary by defining “national security system” and separating military and intelligence operations from civilian oversight.3Office of the Law Revision Counsel. 44 USC 3552 – Definitions What is left after those exclusions is the FCEB: the civilian side of the executive branch, subject to CISA’s directive authority.

Which Agencies Are In and Which Are Out

The FCEB umbrella covers Cabinet-level departments and independent agencies alike. Cabinet departments such as the Department of State, the Department of Agriculture, and the Department of Health and Human Services fall under the designation. So do independent agencies including the Social Security Administration, the Environmental Protection Agency, and the Securities and Exchange Commission.4The White House. The Executive Branch CISA’s published list is the working roster for directive compliance and reporting.1Cybersecurity and Infrastructure Security Agency. Federal Civilian Executive Branch Agencies List

Outside the framework: the Department of Defense, all components of the intelligence community, and any system classified as a national security system. Under 44 U.S.C. § 3552, a national security system is any information system whose function involves intelligence activities, cryptologic work related to national security, military command and control, or equipment integral to a weapons system.3Office of the Law Revision Counsel. 44 USC 3552 – Definitions

One nuance matters if you work in or with an excluded agency. Routine administrative systems used for payroll, finance, logistics, or personnel management do not qualify as national security systems even when they sit inside DoD or an intelligence component. Those systems can still fall under civilian cybersecurity requirements.

FISMA: The Law Behind the Rules

The Federal Information Security Modernization Act is the legal backbone of FCEB cybersecurity. FISMA gives OMB oversight authority over agency information security policies and grants CISA the power to administer their implementation.5Office of the Law Revision Counsel. 44 USC 3553 – Authority and Functions of the Director and the Secretary The National Institute of Standards and Technology develops the technical standards agencies use to build their security programs, while CISA handles enforcement and threat response.

Congress updated the law significantly in 2023. The amendments shifted agencies from annual to biennial FISMA reporting, added a requirement for ongoing and continuous risk assessments, and strengthened the definition of “major incident” to include breaches that expose sensitive agency data to foreign entities. The 2023 update also codified the push toward zero trust architecture and least-privilege access as ongoing requirements rather than one-time milestones.6United States Congress. S. Rept. 118-271 – Federal Information Security Modernization Act

How CISA Enforces Security Across the FCEB

CISA’s enforcement power runs primarily through two instruments: Binding Operational Directives (BODs) and Emergency Directives. Both are legally compulsory, and agencies are required to comply under 44 U.S.C. § 3554(a)(1)(B)(ii).7Cybersecurity and Infrastructure Security Agency. BOD 25-01 – Implementing Secure Practices for Cloud Services

Binding Operational Directives

BODs address systemic risks and long-term security gaps. CISA develops them in coordination with OMB, and they apply across the entire FCEB. The Secretary of Homeland Security has the authority to issue them under 44 U.S.C. § 3553(b)(2), covering incident reporting, annual report content, risk mitigation, and other operational standards.5Office of the Law Revision Counsel. 44 USC 3553 – Authority and Functions of the Director and the Secretary A BOD remains in effect until CISA rescinds it or the OMB Director revokes it for being inconsistent with broader policy. Active BODs currently require agencies to remediate vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog on set timelines, run automated asset discovery and vulnerability scans across all IP-addressable network assets every 14 days, and apply secure configuration baselines to cloud services.8Cybersecurity and Infrastructure Security Agency. BOD 23-01 – Implementation Guidance for Improving Asset Visibility and Vulnerability Detection

Emergency Directives

Emergency Directives respond to active, fast-moving threats. Under 44 U.S.C. § 3553(h), the Secretary of Homeland Security can issue one when a known or reasonably suspected threat represents a substantial risk to agency information security. These directives can require any lawful action to protect or mitigate harm, including on systems operated by contractors on the agency’s behalf.9Office of the Law Revision Counsel. 44 USC 3553 – Authority and Functions of the Director and the Secretary The 2023 amendments added reporting duties: CISA must report to Congress on agency compliance with Emergency Directives within seven days of issuance, with updates every 30 days, and on BODs within 30 days with updates every 90 days.6United States Congress. S. Rept. 118-271 – Federal Information Security Modernization Act

What Each Agency Has to Do

Every FCEB agency head is personally responsible for providing information security protections proportional to the risk and potential harm from unauthorized access, disruption, or destruction of agency data. Under 44 U.S.C. § 3554, each agency must run a documented, agency-wide information security program covering several core areas.10Office of the Law Revision Counsel. 44 USC 3554 – Federal Agency Responsibilities

  • Periodic risk assessments, updated on an ongoing basis under the 2023 amendments.
  • Written security policies and procedures that reduce risk cost-effectively and address security through the full lifecycle of each system.
  • Mandatory security awareness training for all personnel, including contractors, who access agency systems.
  • Testing and evaluation of security practices at least annually, and more often for higher-risk systems.
  • A documented process for identifying, implementing, and tracking fixes to known security gaps.
  • Procedures for detecting, reporting, and responding to incidents, with escalation paths for major incidents.

The agency’s Chief Information Officer holds delegated authority for compliance and must report annually to the agency head on the program’s effectiveness, including progress on remedial actions.10Office of the Law Revision Counsel. 44 USC 3554 – Federal Agency Responsibilities

Reporting Incidents

When something goes wrong, reporting duties scale with severity. For major incidents, the statute requires agencies to notify the relevant Congressional committees within seven days of determining that a major incident has occurred, followed by periodic updates.10Office of the Law Revision Counsel. 44 USC 3554 – Federal Agency Responsibilities The 2023 amendments expanded “major incident” to include breaches that affect an agency’s ability to deliver a critical service, compromise high-value assets, or expose sensitive data to a foreign entity. If a common root cause triggers incidents across multiple agencies, the National Cyber Director can declare a major incident at each affected agency simultaneously.6United States Congress. S. Rept. 118-271 – Federal Information Security Modernization Act

Agencies also report to the Federal Information Security Incident Center established under 44 U.S.C. § 3556, which CISA operates.11Cybersecurity and Infrastructure Security Agency. Reporting a Cyber Incident An agency that fails to provide required incident data to CISA during any reporting year must submit a separate noncompliance report to Congress explaining the gap.6United States Congress. S. Rept. 118-271 – Federal Information Security Modernization Act

Oversight and Accountability

Oversight runs on three tracks. Inspectors General or independent external auditors conduct an annual evaluation of each agency’s information security program, scoring it against a five-level maturity model. Level 1 (Ad Hoc) represents reactive, unformalized practices; Level 5 (Optimized) represents fully institutionalized, self-improving programs. OMB considers Level 4 (Managed and Measurable) to represent an effective program, though Inspectors General have discretion to find an agency effective at a lower level if justified by its risk profile.12Cybersecurity and Infrastructure Security Agency. FY 2025 Inspector General FISMA Reporting Metrics Core metrics are assessed every year; supplemental metrics rotate on a two-year cycle, and results flow through the CyberScope reporting tool.

OMB coordinates the policy side, setting government-wide priorities and aligning agency budgets with security mandates. Under the 2023 amendments, agencies must provide ongoing risk assessment updates to OMB, CISA, the National Cyber Director, and the Comptroller General on request. The move from annual to biennial FISMA reporting reduced paperwork while expanded major-incident definitions and noncompliance reporting tightened accountability for actual failures.6United States Congress. S. Rept. 118-271 – Federal Information Security Modernization Act

How the Rules Reach Contractors

The FCEB label technically covers agencies, but the security obligations pass through to third parties. Contractors working with FCEB agencies inherit duties through Federal Acquisition Regulation clause 52.239-1. Contractors cannot disclose details of any security safeguards designed under the contract or provided by the government without written consent from the contracting officer. They must give the government access to facilities, technical capabilities, documentation, records, and databases so the agency can inspect how government data is being protected. And they must immediately notify the agency if new threats emerge or if existing safeguards stop functioning.13Acquisition.GOV. Privacy or Security Safeguards

Emergency Directives can also reach contractors directly. When CISA issues one under 44 U.S.C. § 3553(h), it can require action on any information system operated on behalf of a federal agency, which covers contractor-operated systems.9Office of the Law Revision Counsel. 44 USC 3553 – Authority and Functions of the Director and the Secretary A contractor serving several FCEB agencies may need to comply with directives from each of them at once.