Threat reportPolicyTL-2026-0048

White House Revokes Biden-Era Software Security Memorandums

mediumMONITORING

White House Revokes Biden-Era Software Security Memorandums (TL-2026-0048), also tracked as Software Security Policy Change, is a medium-severity policy threat scored CVSS 5, first published 2026-02-03. It has no confirmed attribution, affects US Federal Government Software Security Requirements, maps to 39 MITRE ATT&CK techniques (T1003, T1021, T1036), and is covered by 14 detection rules and 39 indicators of compromise.

CVSS
5/10Medium
CVEs
0None referenced
Techniques
39MITRE ATT&CK
Actors
0Not attributed
Detection rules
14SPL · KQL · Sigma
IOCs
39Indicators of compromise

Key facts for TL-2026-0048

Threat ID
TL-2026-0048
Also known as
Software Security Policy Change, Federal Security Requirements Rollback
Severity
MEDIUM
CVSS
5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Status
MONITORING
Category
POLICY
First published
Last reviewed
Attribution confidence
NONE
Motivation
POLICY
Target sectors
Government, Federal Contractors, Software Vendors, Critical Infrastructure, Defense Industrial Base, Healthcare, Financial Services, Energy
Target regions
United States
Detection rules
14
Indicators of compromise
39

How White House Revokes Biden-Era Software Security Memorandums works

The White House revoked Executive Order 14028 (Improving the Nation's Cybersecurity) and rescinded or defunded key Biden-era cybersecurity memorandums including NSM-22 (Critical Infrastructure Security), OMB M-22-18 (Software Supply Chain Security for Federal Procurement), and OMB M-21-31 (Federal Logging Requirements). These policy actions create a compliance vacuum affecting 300,000+ federal contractors, software vendors, and critical infrastructure operators who invested billions in meeting EO 14028 requirements. The revocations roll back mandatory SBOM (Software Bill of Materials) submission, vendor self-attestation for secure development practices, federal zero trust architecture mandates, and enhanced logging requirements established after the SolarWinds (2020) and Colonial Pipeline (2021) attacks. The policy vacuum does not eliminate the underlying threats — it eliminates the policy framework that compelled organizations to address them.

Executive Order 14028 — What Was Revoked and Why It Matters:

EO 14028, signed May 12, 2021, was the most comprehensive federal cybersecurity policy in US history. Issued in direct response to the SolarWinds supply chain attack (Dec 2020), the Microsoft Exchange exploitation by Hafnium (Mar 2021), and the Colonial Pipeline ransomware attack (May 2021), it established binding requirements across seven domains:

1. Software Supply Chain Security (Section 4): - Required SBOM (Software Bill of Materials) for all software sold to the federal government - Mandated vendor self-attestation of secure development practices per NIST SSDF (SP 800-218) - Required third-party testing for critical software - Established CISA as the coordinating authority for software supply chain security - Implementation via OMB M-22-18 and M-23-16 - IMPACT OF REVOCATION: Vendors no longer required to provide SBOMs or attest to secure development. Federal procurement loses visibility into software composition.

2. Federal Zero Trust Architecture (Section 3): - Required all federal agencies to adopt zero trust architecture by FY2024 - Defined five pillars: identity, devices, networks, applications, data - Implementation via OMB M-22-09 (Moving the U.S. Government Toward Zero Trust) - Budget: ~$4.5B allocated across federal agencies for ZTA migration - IMPACT OF REVOCATION: Zero trust mandates become optional. Agencies at various stages of implementation face budget uncertainty.

3. Enhanced Logging and Threat Detection (Section 7/8): - Required federal agencies to implement enhanced logging per OMB M-21-31 - Established three tiers: EL0 (basic), EL1 (intermediate), EL2 (advanced), EL3 (highest) - Required centralized log aggregation and 72-hour incident reporting - Required sharing of threat intelligence between agencies and CISA - IMPACT OF REVOCATION: Logging requirements relaxed. Agencies may reduce logging infrastructure investments, degrading threat detection capability.

4. Federal Incident Response (Section 6): - Created standardized incident response playbooks - Required 72-hour notification to CISA for significant incidents - Established government-wide EDR (Endpoint Detection and Response) deployment - IMPACT OF REVOCATION: Incident response coordination framework weakened. EDR deployment mandates removed.

5. Cloud Security (Section 3/4): - Accelerated FedRAMP authorization process - Required cloud service providers to meet enhanced security baselines - Mandated multi-factor authentication for cloud access - IMPACT OF REVOCATION: FedRAMP requirements remain via separate statutory authority but policy urgency diminished.

6. IoT/OT Security (Section 4): - Established IoT security labeling program (Cyber Trust Mark) - Required security baselines for IoT devices in federal procurement - IMPACT OF REVOCATION: IoT labeling program continuation uncertain.

7. Encryption Standards (Section 3): - Required encryption of data at rest and in transit across federal networks - Mandated TLS 1.2+ and deprecation of legacy protocols - IMPACT OF REVOCATION: Encryption requirements revert to pre-EO baseline.

Related Memorandums Affected:

- NSM-22 (National Security Memorandum on Critical Infrastructure Security): Replaced PPD-21, designated 16 critical infrastructure sectors, mandated minimum security requirements. Revocation creates uncertainty about federal critical infrastructure protection framework.

- OMB M-22-18 (Enhancing the Security of the Software Supply Chain through Secure Software Development Practices): Required federal agencies to obtain self-attestation from software producers that they follow NIST SSDF. Required SBOMs for critical software. Directly impacted 300,000+ federal software vendors.

- OMB M-21-31 (Improving the Federal Government's Investigative and Remediation Capabilities Related to Cybersecurity Incidents): Required EL1-EL3 logging maturity across federal agencies. Directly improved threat detection after SolarWinds demonstrated logging gaps.

- OMB M-22-09 (Moving the U.S. Government Toward Zero Trust Cybersecurity Principles): Federal zero trust mandate with FY2024 deadline. Agencies invested $4.5B+ in ZTA migration.

The Compliance Vacuum: - Organizations that invested millions in EO 14028 compliance face uncertainty about whether to continue investments - 'The security requirements haven't changed — the threats haven't diminished — only the policy mandate has been removed' - Private sector organizations that adopted SBOM, SSDF, and ZTA as best practice (not just compliance) will continue regardless - Government contractors face 'compliance whiplash' — requirements imposed then removed within 3-4 years - International implications: EU Cyber Resilience Act (CRA) still requires SBOM — US vendors selling to EU must comply regardless of domestic policy

Threat Landscape Impact: - SolarWinds-class supply chain attacks remain a persistent threat (TL-0016, TL-0060) - Ransomware targeting critical infrastructure continues (Colonial Pipeline pattern) - Nation-state actors (Russia, China, Iran, DPRK) exploit policy gaps and transition periods - The 2020-2021 attack wave that prompted EO 14028 has not abated — it has intensified - Policy revocation signals reduced US government prioritization of cybersecurity, potentially emboldening threat actors

MITRE ATT&CK techniques used in TL-2026-0048

credential-access

T1003 OS Credential Dumping; T1110 Brute Force; T1649 Steal or Forge Authentication Certificates

lateral-movement

T1021 Remote Services; T1210 Exploitation of Remote Services

defense-evasion

T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1550 Use Alternate Authentication Material

discovery

T1046 Network Service Discovery; T1087 Account Discovery; T1580 Cloud Infrastructure Discovery

exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1090 Proxy; T1573 Encrypted Channel

persistence

T1098 Account Manipulation; T1525 Implant Internal Image

initial-access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing

collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491 Defacement

defense-impairment

T1553 Subvert Trust Controls; T1578 Modify Cloud Compute Infrastructure; T1685 Disable or Modify Tools

resource-development

T1588 Obtain Capabilities; T1608 Stage Capabilities

reconnaissance

T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains; T1594 Search Victim-Owned Websites

Affected products and versions in White House Revokes Biden-Era Software Security Memorandums

  • US Federal Government — Software Security Requirements
    Vulnerable versions: Organizations relying solely on mandates
    Fixed in: Organizations maintaining voluntary security practices

Remediation for White House Revokes Biden-Era Software Security Memorandums

Patches

  • N/A — policy/governance issue, not a software vulnerability

Immediate actions

  • Continue SBOM generation and NIST SSDF compliance regardless of federal mandate removal — EU CRA requires it for EU market access
  • Maintain zero trust architecture investments — the security value exists independent of federal policy
  • Continue enhanced logging at EL2+ levels — SolarWinds-class attacks still require advanced detection
  • Preserve CISA relationship and threat intelligence sharing — voluntary participation remains valuable
  • Document current security posture for future compliance cycles — policy requirements will likely return

Workarounds

  • State-level cybersecurity requirements (California, New York, Virginia) continue to mandate security practices
  • Industry-specific regulations (HIPAA, PCI-DSS, SOX, CMMC) provide independent security baselines
  • Cyber insurance requirements increasingly mandate SBOM, MFA, EDR, and logging — market-driven compliance
  • FedRAMP retains independent statutory authority — cloud security baselines persist

Longer-term hardening

  • Adopt NIST CSF 2.0 as voluntary baseline — framework persists beyond any single executive order
  • Align with EU Cyber Resilience Act requirements — international compliance obligations remain regardless of US policy
  • Invest in SBOM tooling (SPDX, CycloneDX) as engineering practice, not compliance checkbox
  • Build security into procurement contracts directly — vendor security requirements don't need federal mandate
  • Advocate for bipartisan cybersecurity legislation to replace executive order framework with statutory authority

Timeline of White House Revokes Biden-Era Software Security Memorandums

  • SolarWinds supply chain attack discovered. Russian SVR (APT29/Cozy Bear) compromised SolarWinds Orion software update, affecting 18,000+ organizations including 9 federal agencies. Demonstrated critical gaps in software supply chain security and federal logging. Source: https://www.cisa.gov/emergency-directive-21-01
  • Microsoft Exchange zero-day exploitation by Chinese state actor Hafnium. Four zero-days (ProxyLogon chain) exploited in the wild, compromising 30,000+ Exchange servers. Reinforced urgency for federal cybersecurity reform.
  • Colonial Pipeline ransomware attack by DarkSide. Shut down largest US fuel pipeline for 6 days. $4.4M ransom paid. Directly precipitated EO 14028 signing 5 days later. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a
  • President Biden signs Executive Order 14028: Improving the Nation's Cybersecurity. Most comprehensive federal cybersecurity policy in US history. Mandates SBOM, SSDF, zero trust, enhanced logging, incident response, and cloud security across the federal government.
  • OMB issues M-21-31: Improving Federal Investigative and Remediation Capabilities. Establishes EL0-EL3 logging maturity model. Requires centralized log aggregation and 72-hour incident reporting. Direct response to SolarWinds logging gaps.
  • OMB issues M-22-09: Moving the U.S. Government Toward Zero Trust. Requires federal agencies to achieve zero trust maturity by end of FY2024. Five pillars: identity, devices, networks, applications, data. ~$4.5B allocated for migration.
  • NIST publishes SP 800-218: Secure Software Development Framework (SSDF). Provides the technical standard that M-22-18 vendor self-attestation references. Covers secure design, supply chain integrity, vulnerability management.
  • OMB issues M-22-18: Enhancing the Security of the Software Supply Chain. Requires federal agencies to obtain vendor self-attestation of SSDF compliance. Mandates SBOMs for critical software. Affects 300,000+ software vendors selling to the federal government.
  • NIST publishes Cybersecurity Framework 2.0. Updated from 1.1 with new 'Govern' function. Designed to outlast any single executive order as a voluntary framework. International adoption continues regardless of US policy changes.
  • European Parliament adopts Cyber Resilience Act (CRA). Requires SBOM for all products with digital elements sold in the EU. US vendors must comply regardless of domestic policy — international SBOM mandates are independent of US executive orders.
  • President Biden signs NSM-22: Critical Infrastructure Security and Resilience. Replaces PPD-21 (2013). Designates 16 critical infrastructure sectors with updated minimum security requirements. Reflects post-Colonial Pipeline lessons learned.
  • GAO publishes progress report on EO 14028 implementation. Federal agencies at various stages of compliance. Significant investments in zero trust, logging, SBOM, and vendor attestation infrastructure underway. Source: https://www.gao.gov/products/gao-24-106291
  • New administration takes office. Signals intent to review and rescind prior administration executive orders across multiple policy domains including cybersecurity, AI, and critical infrastructure.
  • White House revokes EO 14028 and rescinds/defunds associated memorandums (M-22-18, M-22-09, M-21-31, NSM-22). SBOM requirements, vendor self-attestation, zero trust mandates, and enhanced logging requirements removed. 300,000+ federal contractors face compliance uncertainty.
  • Compliance vacuum takes effect. Organizations that invested millions in EO 14028 compliance assess whether to continue security investments without federal mandate. Private sector leaders signal intent to maintain SBOM/SSDF/ZTA as best practice regardless.
  • Threadlinqs Intelligence analysis: One year after revocation. The threats that prompted EO 14028 have intensified. Supply chain attacks, ransomware, and nation-state exploitation continue. The policy vacuum has not reduced risk — it has removed the framework compelling organizations to address it. Organizations maintaining NIST SSDF, SBOM, and ZTA as voluntary best practice are better positioned than those that treated compliance as a checkbox.
  • As of 2026-05-29, the policy rollback this POLICY-category threat tracks is real and actively expanding: OMB M-26-05 (Jan 23 2026) rescinded software-attestation/SBOM mandate M-22-18, and M-26-14 (May 22 2026) just rescinded logging mandate M-21-31 for a risk-based approach. EO 14028 itself was not revoked and zero-trust M-22-09 remains in effect, but the compliance-vacuum trend is ongoing with no CVE/patch, so MONITORING holds.

Sources cited for White House Revokes Biden-Era Software Security Memorandums

Detection coverage for TL-2026-0048

As of 2026-02-03, Threadlinqs Intelligence publishes 14 detection rule(s) for TL-2026-0048 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

14 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
39 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats