# White House Revokes Biden-Era Software Security Memorandums

> On January 20, 2025, the Trump administration revoked multiple Biden-era executive orders and policy memorandums that established cybersecurity and software supply chain security requirements for the US federal government and its contractors. Key revocations include: (1) Executive Order 14028 'Improving the Nation's Cybersecurity' (May 2021) — which mandated Zero Trust Architecture adoption, Software Bill of Materials (SBOM) requirements, secure software development attestation, enhanced logging, and incident reporting for federal contractors; (2) Executive Order 14110 'Safe, Secure, and Trustworthy AI' (October 2023) — which established AI safety testing, reporting requirements for dual-use foundation models, and NIST AI Risk Management Framework adoption; (3) National Security Memorandum NSM-8 on cybersecurity of National Security Systems; and (4) Various OMB memorandums implementing these orders including M-22-18 (secure software development attestation) and M-23-16 (zero trust implementation milestones). The revocations create immediate regulatory uncertainty for thousands of federal contractors and software vendors who invested in compliance infrastructure, potentially weakening the software supply chain security improvements catalyzed by the SolarWinds (2020), Log4j (2021), and other major supply chain attacks. While some requirements may be replaced by new policies, the revocation-first approach creates a compliance gap during which previously mandated security practices become voluntary — a policy regression that adversaries can exploit.

- **Published:** 2026-02-03T00:10:00Z
- **Last reviewed:** 2026-02-03T00:10:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0032
- **ID:** TL-2026-0032
- **Severity:** MEDIUM (CVSS 5)
- **Category:** THREAT_INTEL
- **Status:** SUPERSEDED
- **Detections:** 12 · **IOCs:** 38 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The revocation of Biden-era cybersecurity executive orders represents the most significant US federal cybersecurity policy change since the original orders were issued, with cascading implications for software supply chain security, AI governance, and the cybersecurity posture of critical infrastructure.

**Executive Order 14028 — 'Improving the Nation's Cybersecurity' (Revoked):**

Issued May 12, 2021 in direct response to the SolarWinds supply chain attack, Colonial Pipeline ransomware, and Microsoft Exchange (Hafnium) compromise. Key provisions now revoked:

1. **Software Bill of Materials (SBOM)**: Required federal agencies to obtain SBOMs from software vendors, enabling vulnerability tracking across the software supply chain. NTIA published minimum SBOM elements; CISA developed SBOM tooling. Impact of revocation: agencies no longer required to demand SBOMs, reducing supply chain transparency.

2. **Secure Software Development Attestation**: OMB M-22-18 required software vendors to self-attest compliance with NIST Secure Software Development Framework (SSDF). Vendors serving federal government invested significantly in compliance. Revocation removes the mandate, though many vendors will likely maintain practices voluntarily.

3. **Zero Trust Architecture**: OMB M-22-09 established federal Zero Trust strategy with implementation milestones. Federal agencies invested billions in ZTA infrastructure. Revocation removes compliance deadlines, though agencies are unlikely to reverse already-deployed ZTA capabilities.

4. **Enhanced Logging Requirements**: Required agencies to maintain comprehensive logs for incident investigation. Directly addressed the detection gaps exposed by SolarWinds where insufficient logging delayed discovery by months. Revocation weakens forensic capability requirements.

5. **Incident Reporting**: Established timelines for reporting cyber incidents to CISA. Revocation may slow incident sharing between agencies and with private sector.

6. **Endpoint Detection and Response (EDR)**: Required agency-wide EDR deployment. Revocation removes the mandate for agencies that haven't completed deployment.

**Executive Order 14110 — 'Safe, Secure, and Trustworthy AI' (Revoked):**

Issued October 30, 2023, establishing the most comprehensive US AI governance framework:

1. **Dual-Use Foundation Model Reporting**: Required companies developing models above compute thresholds to report safety testing results to the federal government. Revocation removes this transparency requirement as AI capabilities rapidly advance.

2. **AI Safety Testing (Red-Teaming)**: Directed NIST to develop AI safety standards and evaluation frameworks. NIST AI 600-1 (AI Risk Management Framework) was being implemented. Revocation removes the mandate for federal AI safety testing.

3. **Watermarking and Authentication**: Directed development of standards for AI-generated content authentication. Relevant to deepfake detection (connects to TL-0050, TL-0035, TL-0017). Revocation slows authentication standard development.

4. **AI in Critical Infrastructure**: Required assessment of AI risks in critical infrastructure sectors. Revocation removes structured assessment requirements.

**Impact on Software Supply Chain Security:**

The revocations are particularly significant in context of the supply chain attacks documented in our threat database:
- **TL-2026-0019** (Malicious OpenClaw Skills): Supply chain attacks via AI agent skill marketplaces — exactly the type of threat that SBOM requirements and secure development attestation help address
- **TL-2026-0024** (GlassWorm VS Code Extensions): IDE extension supply chain attacks — SBOM transparency would help track malicious dependencies
- **TL-2026-0028** (GuptiMiner/eScan): Software update mechanism compromise — secure development attestation specifically targets update chain integrity
- **TL-2026-0025** (Hugging Face Malware): AI model supply chain — the AI EO's reporting requirements would have provided visibility into model security

**The Compliance Gap:**

The most immediate risk is the period between revocation and any replacement policy:
- Vendors who invested in SBOM generation, SSDF attestation, and security practices lose their compliance mandate
- Budget-constrained organizations may deprioritize security investments that are no longer required
- Federal agencies lose leverage to demand security practices from contractors
- Adversaries aware of the policy rollback may intensify supply chain targeting during the compliance gap
- CISA's role as coordinator may be diminished without executive backing

**Industry Response:**

Major technology companies (Microsoft, Google, Amazon, CrowdStrike) have stated they will maintain enhanced security practices regardless of federal mandates, as the practices represent genuine security improvements. However, smaller contractors and vendors who implemented changes solely for compliance may revert. The cybersecurity industry consensus is that the revocations weaken overall security posture even if individual large companies maintain their practices.

## MITRE ATT&CK

- T1591 Gather Victim Org Information
- T1596 Search Open Technical Databases
- T1584 Compromise Infrastructure
- T1587 Develop Capabilities
- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1204 User Execution
- T1505 Server Software Component
- T1036 Masquerading
- T1553 Subvert Trust Controls
- T1685 Disable or Modify Tools
- T1552 Unsecured Credentials
- T1021 Remote Services
- T1005 Data from Local System
- T1567 Exfiltration Over Web Service
- T1485 Data Destruction
- T1486 Data Encrypted for Impact

## Sources

- [Executive Order 14028 — Improving the Nation's Cybersecurity (Original)](https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/)
- [Executive Order 14110 — Safe, Secure, and Trustworthy AI (Original)](https://www.whitehouse.gov/briefing-room/presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/)
- [OMB M-22-18 — Secure Software Development Attestation](https://www.whitehouse.gov/omb/briefing-room/2022/09/14/enhancing-the-security-of-the-software-supply-chain-through-secure-software-development-practices/)
- [OMB M-22-09 — Federal Zero Trust Strategy](https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf)
- [NIST SP 800-218 — Secure Software Development Framework (SSDF)](https://csrc.nist.gov/Projects/ssdf)
- [NIST AI Risk Management Framework](https://www.nist.gov/artificial-intelligence/ai-risk-management-framework)
- [CISA — SBOM Resources](https://www.cisa.gov/sbom)
- [CISA — Secure by Design](https://www.cisa.gov/securebydesign)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0032
