Yes—but only partially. President Joe Biden’s Executive Order 14144, signed January 16, 2025, set out a broad federal cybersecurity program. President Donald Trump’s Executive Order 14306, signed June 6, 2025, amended that program: it removed selected provisions, revised others, and retained technical work on secure software, post-quantum cryptography, artificial-intelligence vulnerability management and related defenses. The orders describe assignments and deadlines, not proof that every task has been completed.
What Biden’s Executive Order 14144 proposed
EO 14144 built on Executive Order 14028 and the National Cybersecurity Strategy. Its stated focus was stronger accountability for software and cloud providers, more secure federal communications and identity systems, and use of emerging technologies across executive-branch agencies and, in some areas, the private sector.
“Improving accountability for software and cloud service providers, strengthening the security of Federal communications and identity management systems, and promoting innovative developments and the use of emerging technologies for cybersecurity across executive departments and agencies (agencies) and with the private sector are especially critical to improvement of the Nation’s cybersecurity.”
President Joseph R. Biden Jr., Executive Order 14144, January 16, 2025
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.#1 Best Overall
The order bundled several separate workstreams:
- Software supply-chain assurance, including machine-readable development attestations, supporting artifacts, centralized validation and publication of results in specified circumstances.
- Updates to the National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF), patch-deployment guidance and federal supply-chain-risk-management practices.
- Endpoint telemetry, threat hunting and a Cybersecurity and Infrastructure Security Agency (CISA) concept of operations, with safeguards such as least privilege and separation of duties.
- Routing security and encrypted Domain Name System (DNS) arrangements.
- Migration planning for post-quantum cryptography (PQC), including a target for Transport Layer Security (TLS) 1.3 or a successor by January 2, 2030.
- Artificial-intelligence-enabled cyber defense and requirements affecting federal contractors.
Each item had assigned actions or dates. An assignment in an executive order is not the same as a completed deployment, procurement change or agency certification.
How Trump’s EO 14306 changed the program
EO 14306 is best understood as a selective amendment and reprioritization, rather than either wholesale adoption or wholesale replacement of Biden’s order. It strikes some subsections and removes details while preserving or substituting requirements in several technical areas.
| Policy area | Position after EO 14306 | What the record establishes |
|---|---|---|
| Secure software | Retained or revised | NIST guidance and SSDF-based demonstrations remain part of the assigned work, along with patch and update guidance. |
| Software attestations and validation | Changed in scope | Some of Biden’s detailed mechanisms were struck or rewritten; the amended text should be consulted for the surviving requirement. |
| Post-quantum cryptography | Retained or revised | Readiness and migration work continue, but the orders do not show that every agency has completed migration. |
| AI security | Retained in a narrower technical form | AI vulnerability and compromise management remains an assigned area. |
| Rules as code | Added or emphasized | The amended order calls for a pilot to express cybersecurity policy in machine-readable form. |
| Consumer IoT procurement | New procurement direction | Covered consumer Internet of Things products supplied to the federal government are to carry the U.S. Cyber Trust Mark by January 4, 2027, subject to the required procurement-rule changes. |
| Broader Biden provisions | Removed or modified | EO 14306 expressly strikes whole provisions and changes the balance between centralized requirements and agency discretion. |
The White House said the changes prioritized technical protections and removed measures it characterized as politically problematic or burdensome. That explanation describes the administration’s rationale; it is not an independent evaluation of the amended order.
Why the surviving pieces form a usable blueprint
Secure software and patching
Both administrations’ orders treat software development and maintenance as a federal security control. The continuing SSDF work, patch guidance and demonstrations give agencies a common vocabulary for integrating security into development pipelines and updating vulnerable systems.
Recommended Free Tools
Rank #3
Post-quantum readiness
PQC provisions provide a long-range migration framework rather than an instant switch. NIST says three finalized PQC standards are ready for implementation and recommends that organizations identify vulnerable algorithms and plan migration. That technical guidance does not demonstrate that federal agencies have met every deadline in either executive order.
AI vulnerability management
The amended order keeps attention on finding and managing vulnerabilities and compromises involving artificial-intelligence systems. This is a defense and risk-management direction, not a finding that federal AI systems are uniformly secure.
Rank #4
Machine-readable policy
A rules-as-code pilot could make cybersecurity requirements easier for agencies and automated tools to interpret consistently. It is a pilot assignment, not evidence of a government-wide operating system for cyber policy.
IoT procurement labeling
The Cyber Trust Mark requirement applies to covered consumer IoT products purchased by the federal government. January 4, 2027, is the stated deadline for the procurement-rule change; it does not mean every covered product already carries the label, nor does it impose a blanket labeling rule on all private-sector sales.
Best Value
What NIST has documented so far
SP 800-53 revision
NIST’s EO 14306 responsibilities identified an update to Special Publication 800-53, along with SSDF work, an industry consortium, patch guidance, cloud token and key guidance, access to cyber-defense research data and a rules-as-code pilot. A draft update was open for comments until August 5, 2025. NIST announced on August 27, 2025, that it had revised the security and privacy control catalog in response to EO 14306 and made it available in multiple electronic formats.
DevSecOps demonstration
On March 24, 2026, NIST described an active DevSecOps guidance project demonstrating SSDF practices in modern pipelines, beginning with an Azure-based example. NIST said additional use cases and analysis were forthcoming. That is evidence of continuing implementation work, not a government-wide completion finding.
The missing scorecard
Public materials do not provide an agency-by-agency accounting of every EO 14306 deadline and deliverable as of September 30, 2026. A missing update cannot by itself prove non-compliance, and the available NIST examples cannot support a claim that all milestones are complete.
Who is covered—and who is not
- Federal executive agencies: The orders primarily direct agencies, their systems, procurement processes and security operations.
- Federal contractors and suppliers: Some provisions affect contractors or software and cloud providers through federal acquisition and security requirements.
- Private organizations generally: The orders are not a blanket cybersecurity law for every U.S. company or individual. Their direct obligations depend on procurement rules, contracts, applicable regulations and other legal authorities.
- Consumer IoT manufacturers: The Cyber Trust Mark direction concerns products supplied to the federal government, not an automatic requirement for every retail product.
What “blueprint” means in practical terms
Biden’s order supplies a broad design: secure the software supply chain, improve detection and identity controls, modernize network protections, prepare for quantum threats and use emerging technology defensively. Trump’s order keeps several of those technical building blocks but removes or rewrites selected mechanisms and shifts emphasis toward narrower, technically framed requirements and agency-level execution.
Free tools Windows power users keep installed
One-click scans. No signup required.
For a federal security leader, the sensible reading is to track the amended text, current NIST guidance, procurement changes and each agency’s assigned deadlines separately. Treating EO 14144 as still intact would be inaccurate; treating EO 14306 as a complete replacement would be equally misleading.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

