EO 13636Executive OrderObama · D Quiet signal

Executive Order 13636

Improving Critical Infrastructure Cybersecurity

This executive order establishes a voluntary, public-private partnership framework to strengthen cybersecurity protections for U.S. critical infrastructure. It directs federal agencies to improve cyber threat information sharing with private sector entities, mandates development of a Cybersecurity Framework by NIST, creates a voluntary adoption program, and requires identification of the most at-risk critical infrastructure systems.

Impact dates

  1. Agencies report on ineffective/conflicting cybersecurity requirements

  2. Regulatory agencies propose prioritized actions if requirements insufficient

  3. Regulatory agencies report on authority for Framework-based requirements

  4. DHS privacy and civil liberties report due

  5. NIST publishes preliminary Cybersecurity Framework

  6. DHS identifies critical infrastructure at greatest risk

  7. Attorney General, DHS Secretary, DNI issue instructions for unclassified cyber threat reports

  8. DHS establishes procedures to expand Enhanced Cybersecurity Services program

  9. DHS, Treasury, Commerce recommend incentives for voluntary program participation

  10. DOD and GSA recommend cybersecurity procurement standards

Key directives

  • Attorney General, DHS Secretary, DNI to issue instructions for timely unclassified cyber threat reports within 120 days
  • DHS Secretary to expand Enhanced Cybersecurity Services program to all critical infrastructure sectors within 120 days
  • DHS Chief Privacy Officer and Officer for Civil Rights and Civil Liberties to assess privacy/civil liberties risks and release public report within 1 year
  • NIST Director to publish preliminary Cybersecurity Framework within 240 days
  • NIST Director to publish final Cybersecurity Framework within 1 year
  • DHS Secretary to identify critical infrastructure at greatest risk using risk-based approach within 150 days
  • DHS, Treasury, Commerce Secretaries to recommend program incentives within 120 days
  • DOD and GSA to recommend procurement cybersecurity standards within 120 days
  • Sector-Specific Agencies to report annually on voluntary program participation
  • Regulatory agencies to report on authority for Framework-based requirements within 90 days of preliminary Framework publication
  • Regulatory agencies to propose prioritized actions within 90 days of final Framework if current requirements insufficient
  • Agencies to report on ineffective/conflicting requirements within 2 years of final Framework publication

Who is ordered

Timeline

Immediate

  • Establishment of policy coordination through interagency process
  • Direction to increase cyber threat information sharing with private sector

Near term (90d)

  • Attorney General, DHS Secretary, DNI to issue instructions for unclassified cyber threat reports (120 days)
  • DHS to establish procedures expanding Enhanced Cybersecurity Services program (120 days)
  • DHS, Treasury, Commerce to recommend incentives for voluntary program participation (120 days)
  • DOD and GSA to recommend cybersecurity procurement standards (120 days)
  • DHS to identify critical infrastructure at greatest risk (150 days)

Long term

  • NIST to publish preliminary Cybersecurity Framework (240 days)
  • NIST to publish final Cybersecurity Framework (1 year)
  • DHS privacy/civil liberties report due (1 year)
  • Regulatory agencies to report on authority to adopt Framework requirements (90 days after preliminary Framework)
  • Regulatory agencies to propose actions if current requirements insufficient (90 days after final Framework)
  • Agencies to report on ineffective/conflicting cybersecurity requirements (2 years after final Framework)
  • Annual reviews: critical infrastructure identification list, privacy/civil liberties report, voluntary program participation

Risks & tensions

  • Voluntary nature of program may limit adoption rates without sufficient incentives
  • Tension between information sharing and protection of intelligence/law enforcement sources and methods
  • Privacy and civil liberties protections rely on self-assessment without strong enforcement mechanism
  • Annual review requirements create ongoing compliance burden but no stated consequences for non-compliance
  • Framework's technology-neutral approach may result in insufficient specificity for some sectors
  • Potential regulatory gap: EO explicitly states it does not create new regulatory authority, limiting agencies to existing authorities
  • Classification and security clearance processing delays could bottleneck information sharing to private sector
  • Confidential notification process for identified critical infrastructure may create liability concerns for notified entities
Executive Order 13636: Improving Critical Infrastructure Cybersecurity · Executive Orders