Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

President Donald Trump’s June 6, 2025, Executive Order 14306 changed selected parts of earlier federal cybersecurity policy; it did not wholesale repeal either President Joe Biden’s January 2025 order or President Barack Obama’s 2015 order. It removed or revised some requirements while directing continued work on secure software, post-quantum cryptography, encryption, AI vulnerability management, and connected-device security labeling.

Which earlier orders did Executive Order 14306 amend?

Executive Order 14306 amended provisions of Executive Order 14144, signed by Biden on January 16, 2025, and made a narrower change to Obama-era Executive Order 13694, dated April 1, 2015. The legal action is selective: EO 14306 amends specified provisions rather than erasing either order as a whole.

What did Trump’s order remove or change?

The operative text amends EO 14144 section by section, striking selected subsections and changing deadlines or agency responsibilities. One explicit amendment to EO 13694 replaces “any person” with “foreign person” in two specified sanctions-related clauses. That is a limited change to those clauses, not a general repeal of cyber sanctions.

Axios’s June 10, 2025 account describes broader program effects, including removal of a federal-vendor software bill of materials requirement, revoked federal digital-identity efforts, cuts to contractor secure-development attestations and related repository requirements, and scrapped or deprioritized AI cybersecurity research mandates. Axios also characterizes some measures as left in limbo. These are reported program-level interpretations; the scope of any particular change depends on the amended clause, so they should not be read as proof that every related activity was formally terminated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What cybersecurity work continues or was newly directed?

Area What EO 14306 directs or preserves
Secure software development NIST is directed to develop and publish a preliminary update to its Secure Software Development Framework, with practices and examples for secure software development and delivery.
Post-quantum cryptography CISA is directed to identify product categories in which products supporting post-quantum cryptography are widely available.
Encryption Agencies are directed to support TLS 1.3 or a successor no later than January 2, 2030.
AI and cyber defense Agencies are directed to make cyber-defense datasets available to academic researchers to the maximum feasible extent and to integrate management of AI software vulnerabilities and compromises into agency processes.
Machine-readable policy The order directs a pilot for machine-readable cybersecurity policies.
Consumer IoT security The order directs steps toward federal purchasing requirements for consumer IoT devices carrying the U.S. Cyber Trust Mark, with January 4, 2027, as the stated target date for the vendor requirement.

The order opens its AI section by stating: “Artificial intelligence (AI) has the potential to transform cyber defense by rapidly identifying vulnerabilities, increasing the scale of threat detection techniques, and automating cyber defense.” This is the order’s rationale for attention to AI, not a measured finding that these outcomes have already been achieved.

Why did the White House say it changed the policy?

The White House’s June 6, 2025 fact sheet framed EO 14306 as a reprioritization toward technical protection against foreign cyber threats. It criticized aspects of the Biden-era digital-identity, software-accounting, and agency-decision provisions as problematic or distracting, and argued that removing certain measures would prevent abuse. Those are the administration’s advocacy and political claims; the order’s operative text establishes the amendments but does not independently prove every claim in the fact sheet.

Axios described the overall shift as less prescriptive and more decentralized, while noting that selected Biden-era efforts remained. That is the outlet’s interpretation, not wording used by the executive order.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What implementation is documented, and what remains uncertain?

On December 17, 2025, NIST reported that it had released an initial public draft of SSDF Version 1.2 “per Executive Order 14306.” This confirms a follow-on deliverable for secure software development; it does not establish that every agency completed every directive or deadline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On March 6, 2026, the White House released President Trump’s Cyber Strategy for America, describing six policy pillars intended to guide subsequent action and resourcing. The strategy provides later context for the administration’s cybersecurity agenda, but its release alone does not show that each EO 14306 requirement was implemented.

The order also states that implementation must comply with applicable law and depends on available appropriations. Specified sections do not apply to national security systems or certain systems whose disruption could have debilitating impacts, subject to the order’s stated exception. EO 14306 creates no privately enforceable right or benefit. The cited announcements do not provide a comprehensive authoritative checklist confirming completion of every directive.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.