Threat reportPolicyTL-2026-0048
White House Revokes Biden-Era Software Security Memorandums
White House Revokes Biden-Era Software Security Memorandums (TL-2026-0048), also tracked as Software Security Policy Change, is a medium-severity policy threat scored CVSS 5, first published 2026-02-03. It has no confirmed attribution, affects US Federal Government Software Security Requirements, maps to 39 MITRE ATT&CK techniques (T1003, T1021, T1036), and is covered by 14 detection rules and 39 indicators of compromise.
- CVSS
- 5/10Medium
- CVEs
- 0None referenced
- Techniques
- 39MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 14SPL · KQL · Sigma
- IOCs
- 39Indicators of compromise
Key facts for TL-2026-0048
- Threat ID
- TL-2026-0048
- Also known as
- Software Security Policy Change, Federal Security Requirements Rollback
- Severity
- MEDIUM
- CVSS
- 5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
- Status
- MONITORING
- Category
- POLICY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- POLICY
- Target sectors
- Government, Federal Contractors, Software Vendors, Critical Infrastructure, Defense Industrial Base, Healthcare, Financial Services, Energy
- Target regions
- United States
- Detection rules
- 14
- Indicators of compromise
- 39
How White House Revokes Biden-Era Software Security Memorandums works
The White House revoked Executive Order 14028 (Improving the Nation's Cybersecurity) and rescinded or defunded key Biden-era cybersecurity memorandums including NSM-22 (Critical Infrastructure Security), OMB M-22-18 (Software Supply Chain Security for Federal Procurement), and OMB M-21-31 (Federal Logging Requirements). These policy actions create a compliance vacuum affecting 300,000+ federal contractors, software vendors, and critical infrastructure operators who invested billions in meeting EO 14028 requirements. The revocations roll back mandatory SBOM (Software Bill of Materials) submission, vendor self-attestation for secure development practices, federal zero trust architecture mandates, and enhanced logging requirements established after the SolarWinds (2020) and Colonial Pipeline (2021) attacks. The policy vacuum does not eliminate the underlying threats — it eliminates the policy framework that compelled organizations to address them.
Executive Order 14028 — What Was Revoked and Why It Matters:
EO 14028, signed May 12, 2021, was the most comprehensive federal cybersecurity policy in US history. Issued in direct response to the SolarWinds supply chain attack (Dec 2020), the Microsoft Exchange exploitation by Hafnium (Mar 2021), and the Colonial Pipeline ransomware attack (May 2021), it established binding requirements across seven domains:
1. Software Supply Chain Security (Section 4): - Required SBOM (Software Bill of Materials) for all software sold to the federal government - Mandated vendor self-attestation of secure development practices per NIST SSDF (SP 800-218) - Required third-party testing for critical software - Established CISA as the coordinating authority for software supply chain security - Implementation via OMB M-22-18 and M-23-16 - IMPACT OF REVOCATION: Vendors no longer required to provide SBOMs or attest to secure development. Federal procurement loses visibility into software composition.
2. Federal Zero Trust Architecture (Section 3): - Required all federal agencies to adopt zero trust architecture by FY2024 - Defined five pillars: identity, devices, networks, applications, data - Implementation via OMB M-22-09 (Moving the U.S. Government Toward Zero Trust) - Budget: ~$4.5B allocated across federal agencies for ZTA migration - IMPACT OF REVOCATION: Zero trust mandates become optional. Agencies at various stages of implementation face budget uncertainty.
3. Enhanced Logging and Threat Detection (Section 7/8): - Required federal agencies to implement enhanced logging per OMB M-21-31 - Established three tiers: EL0 (basic), EL1 (intermediate), EL2 (advanced), EL3 (highest) - Required centralized log aggregation and 72-hour incident reporting - Required sharing of threat intelligence between agencies and CISA - IMPACT OF REVOCATION: Logging requirements relaxed. Agencies may reduce logging infrastructure investments, degrading threat detection capability.
4. Federal Incident Response (Section 6): - Created standardized incident response playbooks - Required 72-hour notification to CISA for significant incidents - Established government-wide EDR (Endpoint Detection and Response) deployment - IMPACT OF REVOCATION: Incident response coordination framework weakened. EDR deployment mandates removed.
5. Cloud Security (Section 3/4): - Accelerated FedRAMP authorization process - Required cloud service providers to meet enhanced security baselines - Mandated multi-factor authentication for cloud access - IMPACT OF REVOCATION: FedRAMP requirements remain via separate statutory authority but policy urgency diminished.
6. IoT/OT Security (Section 4): - Established IoT security labeling program (Cyber Trust Mark) - Required security baselines for IoT devices in federal procurement - IMPACT OF REVOCATION: IoT labeling program continuation uncertain.
7. Encryption Standards (Section 3): - Required encryption of data at rest and in transit across federal networks - Mandated TLS 1.2+ and deprecation of legacy protocols - IMPACT OF REVOCATION: Encryption requirements revert to pre-EO baseline.
Related Memorandums Affected:
- NSM-22 (National Security Memorandum on Critical Infrastructure Security): Replaced PPD-21, designated 16 critical infrastructure sectors, mandated minimum security requirements. Revocation creates uncertainty about federal critical infrastructure protection framework.
- OMB M-22-18 (Enhancing the Security of the Software Supply Chain through Secure Software Development Practices): Required federal agencies to obtain self-attestation from software producers that they follow NIST SSDF. Required SBOMs for critical software. Directly impacted 300,000+ federal software vendors.
- OMB M-21-31 (Improving the Federal Government's Investigative and Remediation Capabilities Related to Cybersecurity Incidents): Required EL1-EL3 logging maturity across federal agencies. Directly improved threat detection after SolarWinds demonstrated logging gaps.
- OMB M-22-09 (Moving the U.S. Government Toward Zero Trust Cybersecurity Principles): Federal zero trust mandate with FY2024 deadline. Agencies invested $4.5B+ in ZTA migration.
The Compliance Vacuum: - Organizations that invested millions in EO 14028 compliance face uncertainty about whether to continue investments - 'The security requirements haven't changed — the threats haven't diminished — only the policy mandate has been removed' - Private sector organizations that adopted SBOM, SSDF, and ZTA as best practice (not just compliance) will continue regardless - Government contractors face 'compliance whiplash' — requirements imposed then removed within 3-4 years - International implications: EU Cyber Resilience Act (CRA) still requires SBOM — US vendors selling to EU must comply regardless of domestic policy
Threat Landscape Impact: - SolarWinds-class supply chain attacks remain a persistent threat (TL-0016, TL-0060) - Ransomware targeting critical infrastructure continues (Colonial Pipeline pattern) - Nation-state actors (Russia, China, Iran, DPRK) exploit policy gaps and transition periods - The 2020-2021 attack wave that prompted EO 14028 has not abated — it has intensified - Policy revocation signals reduced US government prioritization of cybersecurity, potentially emboldening threat actors
MITRE ATT&CK techniques used in TL-2026-0048
credential-access
T1003 OS Credential Dumping; T1110 Brute Force; T1649 Steal or Forge Authentication Certificates
lateral-movement
T1021 Remote Services; T1210 Exploitation of Remote Services
defense-evasion
T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1550 Use Alternate Authentication Material
discovery
T1046 Network Service Discovery; T1087 Account Discovery; T1580 Cloud Infrastructure Discovery
exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1573 Encrypted Channel
persistence
T1098 Account Manipulation; T1525 Implant Internal Image
initial-access
T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing
collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491 Defacement
defense-impairment
T1553 Subvert Trust Controls; T1578 Modify Cloud Compute Infrastructure; T1685 Disable or Modify Tools
resource-development
T1588 Obtain Capabilities; T1608 Stage Capabilities
reconnaissance
T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains; T1594 Search Victim-Owned Websites
Affected products and versions in White House Revokes Biden-Era Software Security Memorandums
- US Federal Government — Software Security Requirements
Vulnerable versions: Organizations relying solely on mandates
Fixed in: Organizations maintaining voluntary security practices
Remediation for White House Revokes Biden-Era Software Security Memorandums
Patches
- N/A — policy/governance issue, not a software vulnerability
Immediate actions
- Continue SBOM generation and NIST SSDF compliance regardless of federal mandate removal — EU CRA requires it for EU market access
- Maintain zero trust architecture investments — the security value exists independent of federal policy
- Continue enhanced logging at EL2+ levels — SolarWinds-class attacks still require advanced detection
- Preserve CISA relationship and threat intelligence sharing — voluntary participation remains valuable
- Document current security posture for future compliance cycles — policy requirements will likely return
Workarounds
- State-level cybersecurity requirements (California, New York, Virginia) continue to mandate security practices
- Industry-specific regulations (HIPAA, PCI-DSS, SOX, CMMC) provide independent security baselines
- Cyber insurance requirements increasingly mandate SBOM, MFA, EDR, and logging — market-driven compliance
- FedRAMP retains independent statutory authority — cloud security baselines persist
Longer-term hardening
- Adopt NIST CSF 2.0 as voluntary baseline — framework persists beyond any single executive order
- Align with EU Cyber Resilience Act requirements — international compliance obligations remain regardless of US policy
- Invest in SBOM tooling (SPDX, CycloneDX) as engineering practice, not compliance checkbox
- Build security into procurement contracts directly — vendor security requirements don't need federal mandate
- Advocate for bipartisan cybersecurity legislation to replace executive order framework with statutory authority
Timeline of White House Revokes Biden-Era Software Security Memorandums
- SolarWinds supply chain attack discovered. Russian SVR (APT29/Cozy Bear) compromised SolarWinds Orion software update, affecting 18,000+ organizations including 9 federal agencies. Demonstrated critical gaps in software supply chain security and federal logging. Source: https://www.cisa.gov/emergency-directive-21-01
- Microsoft Exchange zero-day exploitation by Chinese state actor Hafnium. Four zero-days (ProxyLogon chain) exploited in the wild, compromising 30,000+ Exchange servers. Reinforced urgency for federal cybersecurity reform.
- Colonial Pipeline ransomware attack by DarkSide. Shut down largest US fuel pipeline for 6 days. $4.4M ransom paid. Directly precipitated EO 14028 signing 5 days later. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a
- President Biden signs Executive Order 14028: Improving the Nation's Cybersecurity. Most comprehensive federal cybersecurity policy in US history. Mandates SBOM, SSDF, zero trust, enhanced logging, incident response, and cloud security across the federal government.
- OMB issues M-21-31: Improving Federal Investigative and Remediation Capabilities. Establishes EL0-EL3 logging maturity model. Requires centralized log aggregation and 72-hour incident reporting. Direct response to SolarWinds logging gaps.
- OMB issues M-22-09: Moving the U.S. Government Toward Zero Trust. Requires federal agencies to achieve zero trust maturity by end of FY2024. Five pillars: identity, devices, networks, applications, data. ~$4.5B allocated for migration.
- NIST publishes SP 800-218: Secure Software Development Framework (SSDF). Provides the technical standard that M-22-18 vendor self-attestation references. Covers secure design, supply chain integrity, vulnerability management.
- OMB issues M-22-18: Enhancing the Security of the Software Supply Chain. Requires federal agencies to obtain vendor self-attestation of SSDF compliance. Mandates SBOMs for critical software. Affects 300,000+ software vendors selling to the federal government.
- NIST publishes Cybersecurity Framework 2.0. Updated from 1.1 with new 'Govern' function. Designed to outlast any single executive order as a voluntary framework. International adoption continues regardless of US policy changes.
- European Parliament adopts Cyber Resilience Act (CRA). Requires SBOM for all products with digital elements sold in the EU. US vendors must comply regardless of domestic policy — international SBOM mandates are independent of US executive orders.
- President Biden signs NSM-22: Critical Infrastructure Security and Resilience. Replaces PPD-21 (2013). Designates 16 critical infrastructure sectors with updated minimum security requirements. Reflects post-Colonial Pipeline lessons learned.
- GAO publishes progress report on EO 14028 implementation. Federal agencies at various stages of compliance. Significant investments in zero trust, logging, SBOM, and vendor attestation infrastructure underway. Source: https://www.gao.gov/products/gao-24-106291
- New administration takes office. Signals intent to review and rescind prior administration executive orders across multiple policy domains including cybersecurity, AI, and critical infrastructure.
- White House revokes EO 14028 and rescinds/defunds associated memorandums (M-22-18, M-22-09, M-21-31, NSM-22). SBOM requirements, vendor self-attestation, zero trust mandates, and enhanced logging requirements removed. 300,000+ federal contractors face compliance uncertainty.
- Compliance vacuum takes effect. Organizations that invested millions in EO 14028 compliance assess whether to continue security investments without federal mandate. Private sector leaders signal intent to maintain SBOM/SSDF/ZTA as best practice regardless.
- Threadlinqs Intelligence analysis: One year after revocation. The threats that prompted EO 14028 have intensified. Supply chain attacks, ransomware, and nation-state exploitation continue. The policy vacuum has not reduced risk — it has removed the framework compelling organizations to address it. Organizations maintaining NIST SSDF, SBOM, and ZTA as voluntary best practice are better positioned than those that treated compliance as a checkbox.
- As of 2026-05-29, the policy rollback this POLICY-category threat tracks is real and actively expanding: OMB M-26-05 (Jan 23 2026) rescinded software-attestation/SBOM mandate M-22-18, and M-26-14 (May 22 2026) just rescinded logging mandate M-21-31 for a risk-based approach. EO 14028 itself was not revoked and zero-trust M-22-09 remains in effect, but the compliance-vacuum trend is ongoing with no CVE/patch, so MONITORING holds.
Sources cited for White House Revokes Biden-Era Software Security Memorandums
- SecurityWeek: White House Scraps 'Burdensome' Software Security Rules
- Executive Order 14028: Improving the Nation's Cybersecurity (May 12, 2021)
- OMB M-22-18: Enhancing the Security of the Software Supply Chain
- OMB M-22-09: Moving the U.S. Government Toward Zero Trust
- OMB M-21-31: Improving Federal Investigative and Remediation Capabilities
- NSM-22: Critical Infrastructure Security and Resilience
- NIST SP 800-218: Secure Software Development Framework (SSDF)
- CISA — Software Bill of Materials (SBOM) Resources
- EU Cyber Resilience Act (CRA) — SBOM Requirements for Products with Digital Elements
- NIST Cybersecurity Framework 2.0
- GAO — Federal Cybersecurity: Implementation of EO 14028 Progress Report
- SolarWinds Supply Chain Attack — CISA Emergency Directive 21-01
- Colonial Pipeline Ransomware — CISA Advisory
Detection coverage for TL-2026-0048
As of 2026-02-03, Threadlinqs Intelligence publishes 14 detection rule(s) for TL-2026-0048 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.