EO 14306Executive OrderTrump 47 · R Quiet signal

Executive Order 14306

Sustaining Select Efforts To Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144

This executive order amends two prior cybersecurity orders: it narrows the scope of sanctions under EO 13694 to target only foreign persons, and substantially revises EO 14144 by removing several Biden-era provisions while adding new deadlines for NIST guidance, post-quantum cryptography transition, AI vulnerability management, and Federal Acquisition Regulation updates for IoT security labeling.

Impact dates

  1. FAR IoT Cyber Trust Mark labeling effective for federal vendors

  2. OMB Circular A-130 guidance revision

  3. Agencies must support TLS 1.3 or successor

  4. Rules-as-code pilot establishment

  5. Final SSDF update (within 120 days of preliminary)

  6. Preliminary SSDF update; PQC product category list; TLS 1.3 requirements issued

  7. AI cyber defense datasets accessible to researchers; AI vulnerability management incorporated

  8. NIST SP 800-53 update on patch deployment

  9. NIST consortium for secure software development guidance

Market exposure

Policy exposure mapping — not investment advice. Illustrative public companies are incomplete and not recommendations.

Mechanisms

ProcurementLicensingSubsidy / incentive

Role pressure

  • MixedDownstream manufacturerIoT manufacturers gain clarity on federal labeling requirement but face January 2027 compliance deadline; software developers face updated SSDF and patch guidance requirements
  • ProtectiveEquipment supplierPost-quantum cryptography transition creates demand for new cryptographic products and TLS 1.3 support; CISA product category list will signal market readiness
  • UncertainProject developerRules-as-code pilot and A-130 revision may change compliance automation approaches but specifics undefined
  • MixedDomestic producerNIST consortium participation offers influence over standards but removes prior hardware roots of trust mandate

Geographies

Exposure dates

  • NIST consortium for secure software development guidance
  • NIST SP 800-53 update on patch deployment
  • AI cyber defense datasets accessible to researchers; AI vulnerability management incorporated
  • Preliminary SSDF update; PQC product category list; TLS 1.3 requirements issued
  • FAR IoT Cyber Trust Mark labeling effective for federal vendors
  • Agencies must support TLS 1.3 or successor

Illustrative public companies

Curated watchlist matches by sector/role — incomplete; not a recommendation.

MMM3MGOOGLAlphabetAAPLAppleAMATApplied MaterialsASMLASMLBABoeingAVGOBroadcomCATCaterpillarFCXFreeport-McMoRanGEVGE VernovaGDGeneral DynamicsHONHoneywellINTCIntelQQQInvesco QQQ TrustLMTLockheed MartinMETAMeta PlatformsMUMicron TechnologyMSFTMicrosoftNOCNorthrop GrummanNVDANVIDIAORCLOracleRTXRTXSPYSPDR S&P 500 ETFTSMTSMC

Confidence: medium · Policy alerts

Key directives

  • NIST to establish industry consortium for secure software development guidance by August 1, 2025
  • NIST to update SP 800-53 on patch deployment by September 2, 2025
  • NIST to publish preliminary SSDF update by December 1, 2025; final within 120 days
  • CISA and NSA to release PQC product category list by December 1, 2025
  • NSA and OMB to issue TLS 1.3 requirements for agencies by December 1, 2025, with compliance by January 2, 2030
  • Commerce, Energy, DHS, NSF to make cyber defense datasets accessible by November 1, 2025
  • DOD, DHS, DNI to incorporate AI vulnerability management by November 1, 2025
  • OMB to issue A-130 guidance within 3 years
  • NIST, CISA, OMB to establish rules-as-code pilot within 1 year
  • FAR Council to amend FAR for IoT Cyber Trust Mark labeling by January 4, 2027
  • Narrow EO 13694 sanctions from 'any person' to 'any foreign person'

Who is ordered

Timeline

Immediate

  • EO 13694 sanctions narrowed to 'foreign persons' only
  • Multiple sections of EO 14144 struck (software development provisions, threat-sharing language, specific technical requirements)

Near term (90d)

  • August 1, 2025: NIST consortium for secure software development guidance
  • September 2, 2025: NIST SP 800-53 update on patch deployment
  • November 1, 2025: AI cyber defense datasets accessible to researchers
  • November 1, 2025: AI vulnerability management incorporated into agency processes

Long term

  • December 1, 2025: Preliminary SSDF update; PQC product category list
  • By 120 days after Dec 1, 2025: Final SSDF update (approx. April 2026)
  • January 2, 2030: TLS 1.3 or successor required for agencies
  • January 4, 2027: FAR IoT Cyber Trust Mark labeling requirement for federal vendors
  • Within 1 year: FAR Council pilot on rules-as-code
  • Within 3 years: OMB Circular A-130 revision on modern security architectures

Risks & tensions

  • Narrowing EO 13694 sanctions to 'foreign persons' may reduce leverage against domestic enablers of malicious cyber activity
  • Removal of specific technical provisions (hardware roots of trust, intrusion detection, BGP security language) may weaken baseline security expectations
  • Vague 'as appropriate and consistent with applicable law' qualifier on FAR Council action creates implementation uncertainty
  • 2030 TLS deadline provides long runway but may delay urgent post-quantum readiness
  • Striking Biden-era threat-sharing provisions between DOD/DHS without replacement may create information-sharing gaps
Executive Order 14306: Sustaining Select Efforts To Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144 · Executive Orders