Threat reportThreat IntelligenceTL-2026-0032
White House Revokes Biden-Era Software Security Memorandums
White House Revokes Biden-Era Software Security Memorandums (TL-2026-0032), also tracked as M-22-18 Revocation, is a medium-severity tracked intrusion set scored CVSS 5, first published 2026-02-03. It carries a reported United States nexus and is not formally attributed, affects U.S. Federal Government Federal Software Acquisition, maps to 17 MITRE ATT&CK techniques (T1005, T1021, T1036), and is covered by 12 detection rules and 38 indicators of compromise.
- CVSS
- 5/10Medium
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 12SPL · KQL · Sigma
- IOCs
- 38Indicators of compromise
Key facts for TL-2026-0032
- Threat ID
- TL-2026-0032
- Also known as
- M-22-18 Revocation, M-23-16 Revocation, Federal Software Security Rollback
- Severity
- MEDIUM
- CVSS
- 5 (N/A - Policy Change)
- Status
- SUPERSEDED
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- NONE
- Nation-state nexus
- United States
- Motivation
- REGULATORY
- Target sectors
- Government, Technology, Critical Infrastructure, Defense, All Federal Contractors
- Target regions
- United States
- Detection rules
- 12
- Indicators of compromise
- 38
How White House Revokes Biden-Era Software Security Memorandums works
On January 20, 2025, the Trump administration revoked multiple Biden-era executive orders and policy memorandums that established cybersecurity and software supply chain security requirements for the US federal government and its contractors. Key revocations include: (1) Executive Order 14028 'Improving the Nation's Cybersecurity' (May 2021) — which mandated Zero Trust Architecture adoption, Software Bill of Materials (SBOM) requirements, secure software development attestation, enhanced logging, and incident reporting for federal contractors; (2) Executive Order 14110 'Safe, Secure, and Trustworthy AI' (October 2023) — which established AI safety testing, reporting requirements for dual-use foundation models, and NIST AI Risk Management Framework adoption; (3) National Security Memorandum NSM-8 on cybersecurity of National Security Systems; and (4) Various OMB memorandums implementing these orders including M-22-18 (secure software development attestation) and M-23-16 (zero trust implementation milestones). The revocations create immediate regulatory uncertainty for thousands of federal contractors and software vendors who invested in compliance infrastructure, potentially weakening the software supply chain security improvements catalyzed by the SolarWinds (2020), Log4j (2021), and other major supply chain attacks. While some requirements may be replaced by new policies, the revocation-first approach creates a compliance gap during which previously mandated security practices become voluntary — a policy regression that adversaries can exploit.
The revocation of Biden-era cybersecurity executive orders represents the most significant US federal cybersecurity policy change since the original orders were issued, with cascading implications for software supply chain security, AI governance, and the cybersecurity posture of critical infrastructure.
**Executive Order 14028 — 'Improving the Nation's Cybersecurity' (Revoked):**
Issued May 12, 2021 in direct response to the SolarWinds supply chain attack, Colonial Pipeline ransomware, and Microsoft Exchange (Hafnium) compromise. Key provisions now revoked:
1. **Software Bill of Materials (SBOM)**: Required federal agencies to obtain SBOMs from software vendors, enabling vulnerability tracking across the software supply chain. NTIA published minimum SBOM elements; CISA developed SBOM tooling. Impact of revocation: agencies no longer required to demand SBOMs, reducing supply chain transparency.
2. **Secure Software Development Attestation**: OMB M-22-18 required software vendors to self-attest compliance with NIST Secure Software Development Framework (SSDF). Vendors serving federal government invested significantly in compliance. Revocation removes the mandate, though many vendors will likely maintain practices voluntarily.
3. **Zero Trust Architecture**: OMB M-22-09 established federal Zero Trust strategy with implementation milestones. Federal agencies invested billions in ZTA infrastructure. Revocation removes compliance deadlines, though agencies are unlikely to reverse already-deployed ZTA capabilities.
4. **Enhanced Logging Requirements**: Required agencies to maintain comprehensive logs for incident investigation. Directly addressed the detection gaps exposed by SolarWinds where insufficient logging delayed discovery by months. Revocation weakens forensic capability requirements.
5. **Incident Reporting**: Established timelines for reporting cyber incidents to CISA. Revocation may slow incident sharing between agencies and with private sector.
6. **Endpoint Detection and Response (EDR)**: Required agency-wide EDR deployment. Revocation removes the mandate for agencies that haven't completed deployment.
**Executive Order 14110 — 'Safe, Secure, and Trustworthy AI' (Revoked):**
Issued October 30, 2023, establishing the most comprehensive US AI governance framework:
1. **Dual-Use Foundation Model Reporting**: Required companies developing models above compute thresholds to report safety testing results to the federal government. Revocation removes this transparency requirement as AI capabilities rapidly advance.
2. **AI Safety Testing (Red-Teaming)**: Directed NIST to develop AI safety standards and evaluation frameworks. NIST AI 600-1 (AI Risk Management Framework) was being implemented. Revocation removes the mandate for federal AI safety testing.
3. **Watermarking and Authentication**: Directed development of standards for AI-generated content authentication. Relevant to deepfake detection (connects to TL-0050, TL-0035, TL-0017). Revocation slows authentication standard development.
4. **AI in Critical Infrastructure**: Required assessment of AI risks in critical infrastructure sectors. Revocation removes structured assessment requirements.
**Impact on Software Supply Chain Security:**
The revocations are particularly significant in context of the supply chain attacks documented in our threat database: - **TL-2026-0019** (Malicious OpenClaw Skills): Supply chain attacks via AI agent skill marketplaces — exactly the type of threat that SBOM requirements and secure development attestation help address - **TL-2026-0024** (GlassWorm VS Code Extensions): IDE extension supply chain attacks — SBOM transparency would help track malicious dependencies - **TL-2026-0028** (GuptiMiner/eScan): Software update mechanism compromise — secure development attestation specifically targets update chain integrity - **TL-2026-0025** (Hugging Face Malware): AI model supply chain — the AI EO's reporting requirements would have provided visibility into model security
**The Compliance Gap:**
The most immediate risk is the period between revocation and any replacement policy: - Vendors who invested in SBOM generation, SSDF attestation, and security practices lose their compliance mandate - Budget-constrained organizations may deprioritize security investments that are no longer required - Federal agencies lose leverage to demand security practices from contractors - Adversaries aware of the policy rollback may intensify supply chain targeting during the compliance gap - CISA's role as coordinator may be diminished without executive backing
**Industry Response:**
Major technology companies (Microsoft, Google, Amazon, CrowdStrike) have stated they will maintain enhanced security practices regardless of federal mandates, as the practices represent genuine security improvements. However, smaller contractors and vendors who implemented changes solely for compliance may revert. The cybersecurity industry consensus is that the revocations weaken overall security posture even if individual large companies maintain their practices.
MITRE ATT&CK techniques used in TL-2026-0032
collection
lateral-movement
defense-evasion
initial-access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
execution
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact
persistence
T1505 Server Software Component
credential-access
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
exfiltration
T1567 Exfiltration Over Web Service
resource-development
T1584 Compromise Infrastructure; T1587 Develop Capabilities
reconnaissance
T1591 Gather Victim Org Information; T1596 Search Open Technical Databases
Affected products and versions in White House Revokes Biden-Era Software Security Memorandums
- U.S. Federal Government — Federal Software Acquisition
Vulnerable versions: All federal software procurement
Remediation for White House Revokes Biden-Era Software Security Memorandums
Immediate actions
- Continue existing secure development practices regardless of federal requirements
- Maintain internal SBOM generation and tracking
- Document vendor security attestation status
- Review software supply chain security controls
Workarounds
- Use CISA secure software development resources voluntarily
- Implement internal vendor security assessment program
- Require SBOMs in contracts regardless of federal mandates
Longer-term hardening
- Implement organization-specific software security requirements
- Require vendor security assessments contractually
- Maintain SBOM requirements in procurement language
- Follow NIST SSDF voluntarily as industry best practice
Timeline of White House Revokes Biden-Era Software Security Memorandums
- President Biden issues Executive Order 14028 'Improving the Nation's Cybersecurity' in direct response to SolarWinds supply chain attack (Dec 2020), Colonial Pipeline ransomware (May 2021), and Microsoft Exchange/Hafnium compromise (Mar 2021). Establishes SBOM requirements, secure software development attestation, Zero Trust Architecture mandate, enhanced logging, EDR deployment, and incident reporting timelines. The most comprehensive federal cybersecurity executive order in US history. Source: whitehouse.gov
- OMB issues M-22-09 Federal Zero Trust Architecture Strategy with implementation milestones for all federal agencies. Requires identity-centric security, microsegmentation, and 'never trust, always verify' across all federal networks. Federal agencies begin multi-billion-dollar ZTA migration programs. Source: whitehouse.gov/omb
- OMB issues M-22-18 requiring software vendors selling to the federal government to self-attest compliance with NIST Secure Software Development Framework (SSDF). Establishes SBOM requirements for federal software acquisition. Thousands of vendors begin compliance programs. Source: whitehouse.gov/omb
- President Biden issues Executive Order 14110 on 'Safe, Secure, and Trustworthy AI' — the most comprehensive US AI governance framework. Requires dual-use foundation model reporting, AI safety testing (red-teaming), content authentication standards, and critical infrastructure AI risk assessment. Directs NIST to develop AI safety standards (AI RMF). Significant implications for AI-powered threats documented in TL-0050, TL-0035, TL-0017. Source: whitehouse.gov
- Trump administration revokes Executive Orders 14028 and 14110, along with associated OMB memorandums (M-22-18, M-22-09) and National Security Memorandums. Creates immediate regulatory uncertainty for federal contractors and software vendors who invested in compliance. Cybersecurity and AI governance requirements become voluntary. CISA's coordination role potentially diminished. Industry consensus: weakens overall security posture regardless of individual company commitments.
- The compliance gap begins: previously mandated security practices (SBOM, SSDF attestation, ZTA milestones, AI safety reporting) are no longer required. Major technology companies (Microsoft, Google, Amazon) publicly commit to maintaining practices voluntarily. Smaller contractors and budget-constrained agencies begin reassessing investments. Adversaries aware of policy rollback may intensify supply chain targeting. No replacement executive orders issued as of this date.
- As of 2026-05-29, this policy-tracking item (Jan 2025 revocation of EO 14028/14110, "no replacement issued") is superseded: EO 14306 (Jun 2025) plus OMB M-26-05 (Jan 23 2026) settled the software-security regime, and a Jan 2025 AI EO replaced 14110. The transitional compliance gap it monitored is now a codified, risk-based federal policy.
Sources cited for White House Revokes Biden-Era Software Security Memorandums
- Executive Order 14028 — Improving the Nation's Cybersecurity (Original)
- Executive Order 14110 — Safe, Secure, and Trustworthy AI (Original)
- OMB M-22-18 — Secure Software Development Attestation
- OMB M-22-09 — Federal Zero Trust Strategy
- NIST SP 800-218 — Secure Software Development Framework (SSDF)
- NIST AI Risk Management Framework
- CISA — SBOM Resources
- CISA — Secure by Design
Detection coverage for TL-2026-0032
As of 2026-02-03, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0032 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.