# White House Revokes Biden-Era Software Security Memorandums

> The White House revoked Executive Order 14028 (Improving the Nation's Cybersecurity) and rescinded or defunded key Biden-era cybersecurity memorandums including NSM-22 (Critical Infrastructure Security), OMB M-22-18 (Software Supply Chain Security for Federal Procurement), and OMB M-21-31 (Federal Logging Requirements). These policy actions create a compliance vacuum affecting 300,000+ federal contractors, software vendors, and critical infrastructure operators who invested billions in meeting EO 14028 requirements. The revocations roll back mandatory SBOM (Software Bill of Materials) submission, vendor self-attestation for secure development practices, federal zero trust architecture mandates, and enhanced logging requirements established after the SolarWinds (2020) and Colonial Pipeline (2021) attacks. The policy vacuum does not eliminate the underlying threats — it eliminates the policy framework that compelled organizations to address them.

- **Published:** 2026-02-03T04:10:00Z
- **Last reviewed:** 2026-02-03T04:10:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0048
- **ID:** TL-2026-0048
- **Severity:** MEDIUM (CVSS 5)
- **Category:** POLICY
- **Status:** MONITORING
- **Detections:** 14 · **IOCs:** 39 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Executive Order 14028 — What Was Revoked and Why It Matters:

EO 14028, signed May 12, 2021, was the most comprehensive federal cybersecurity policy in US history. Issued in direct response to the SolarWinds supply chain attack (Dec 2020), the Microsoft Exchange exploitation by Hafnium (Mar 2021), and the Colonial Pipeline ransomware attack (May 2021), it established binding requirements across seven domains:

1. Software Supply Chain Security (Section 4):
- Required SBOM (Software Bill of Materials) for all software sold to the federal government
- Mandated vendor self-attestation of secure development practices per NIST SSDF (SP 800-218)
- Required third-party testing for critical software
- Established CISA as the coordinating authority for software supply chain security
- Implementation via OMB M-22-18 and M-23-16
- IMPACT OF REVOCATION: Vendors no longer required to provide SBOMs or attest to secure development. Federal procurement loses visibility into software composition.

2. Federal Zero Trust Architecture (Section 3):
- Required all federal agencies to adopt zero trust architecture by FY2024
- Defined five pillars: identity, devices, networks, applications, data
- Implementation via OMB M-22-09 (Moving the U.S. Government Toward Zero Trust)
- Budget: ~$4.5B allocated across federal agencies for ZTA migration
- IMPACT OF REVOCATION: Zero trust mandates become optional. Agencies at various stages of implementation face budget uncertainty.

3. Enhanced Logging and Threat Detection (Section 7/8):
- Required federal agencies to implement enhanced logging per OMB M-21-31
- Established three tiers: EL0 (basic), EL1 (intermediate), EL2 (advanced), EL3 (highest)
- Required centralized log aggregation and 72-hour incident reporting
- Required sharing of threat intelligence between agencies and CISA
- IMPACT OF REVOCATION: Logging requirements relaxed. Agencies may reduce logging infrastructure investments, degrading threat detection capability.

4. Federal Incident Response (Section 6):
- Created standardized incident response playbooks
- Required 72-hour notification to CISA for significant incidents
- Established government-wide EDR (Endpoint Detection and Response) deployment
- IMPACT OF REVOCATION: Incident response coordination framework weakened. EDR deployment mandates removed.

5. Cloud Security (Section 3/4):
- Accelerated FedRAMP authorization process
- Required cloud service providers to meet enhanced security baselines
- Mandated multi-factor authentication for cloud access
- IMPACT OF REVOCATION: FedRAMP requirements remain via separate statutory authority but policy urgency diminished.

6. IoT/OT Security (Section 4):
- Established IoT security labeling program (Cyber Trust Mark)
- Required security baselines for IoT devices in federal procurement
- IMPACT OF REVOCATION: IoT labeling program continuation uncertain.

7. Encryption Standards (Section 3):
- Required encryption of data at rest and in transit across federal networks
- Mandated TLS 1.2+ and deprecation of legacy protocols
- IMPACT OF REVOCATION: Encryption requirements revert to pre-EO baseline.

Related Memorandums Affected:

- NSM-22 (National Security Memorandum on Critical Infrastructure Security): Replaced PPD-21, designated 16 critical infrastructure sectors, mandated minimum security requirements. Revocation creates uncertainty about federal critical infrastructure protection framework.

- OMB M-22-18 (Enhancing the Security of the Software Supply Chain through Secure Software Development Practices): Required federal agencies to obtain self-attestation from software producers that they follow NIST SSDF. Required SBOMs for critical software. Directly impacted 300,000+ federal software vendors.

- OMB M-21-31 (Improving the Federal Government's Investigative and Remediation Capabilities Related to Cybersecurity Incidents): Required EL1-EL3 logging maturity across federal agencies. Directly improved threat detection after SolarWinds demonstrated logging gaps.

- OMB M-22-09 (Moving the U.S. Government Toward Zero Trust Cybersecurity Principles): Federal zero trust mandate with FY2024 deadline. Agencies invested $4.5B+ in ZTA migration.

The Compliance Vacuum:
- Organizations that invested millions in EO 14028 compliance face uncertainty about whether to continue investments
- 'The security requirements haven't changed — the threats haven't diminished — only the policy mandate has been removed'
- Private sector organizations that adopted SBOM, SSDF, and ZTA as best practice (not just compliance) will continue regardless
- Government contractors face 'compliance whiplash' — requirements imposed then removed within 3-4 years
- International implications: EU Cyber Resilience Act (CRA) still requires SBOM — US vendors selling to EU must comply regardless of domestic policy

Threat Landscape Impact:
- SolarWinds-class supply chain attacks remain a persistent threat (TL-0016, TL-0060)
- Ransomware targeting critical infrastructure continues (Colonial Pipeline pattern)
- Nation-state actors (Russia, China, Iran, DPRK) exploit policy gaps and transition periods
- The 2020-2021 attack wave that prompted EO 14028 has not abated — it has intensified
- Policy revocation signals reduced US government prioritization of cybersecurity, potentially emboldening threat actors

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1591 Gather Victim Org Information
- T1593 Search Open Websites/Domains
- T1199 Trusted Relationship
- T1190 Exploit Public-Facing Application
- T1204 User Execution
- T1525 Implant Internal Image
- T1553 Subvert Trust Controls
- T1070 Indicator Removal
- T1036 Masquerading
- T1649 Steal or Forge Authentication Certificates
- T1580 Cloud Infrastructure Discovery
- T1210 Exploitation of Remote Services
- T1550 Use Alternate Authentication Material
- T1213 Data from Information Repositories
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1071 Application Layer Protocol
- T1485 Data Destruction
- T1594 Search Victim-Owned Websites
- T1588 Obtain Capabilities
- T1608 Stage Capabilities
- T1566 Phishing
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1098 Account Manipulation
- T1685 Disable or Modify Tools
- T1578 Modify Cloud Compute Infrastructure
- T1110 Brute Force
- T1003 OS Credential Dumping
- T1046 Network Service Discovery
- T1087 Account Discovery
- T1021 Remote Services
- T1530 Data from Cloud Storage
- T1048 Exfiltration Over Alternative Protocol
- T1491 Defacement
- T1573 Encrypted Channel
- T1090 Proxy

## Sources

- [SecurityWeek: White House Scraps 'Burdensome' Software Security Rules](https://www.securityweek.com/white-house-scraps-burdensome-software-security-rules/)
- [Executive Order 14028: Improving the Nation's Cybersecurity (May 12, 2021)](https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity)
- [OMB M-22-18: Enhancing the Security of the Software Supply Chain](https://www.whitehouse.gov/wp-content/uploads/2022/09/M-22-18.pdf)
- [OMB M-22-09: Moving the U.S. Government Toward Zero Trust](https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf)
- [OMB M-21-31: Improving Federal Investigative and Remediation Capabilities](https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf)
- [NSM-22: Critical Infrastructure Security and Resilience](https://www.whitehouse.gov/briefing-room/presidential-actions/2024/04/30/national-security-memorandum-on-critical-infrastructure-security-and-resilience/)
- [NIST SP 800-218: Secure Software Development Framework (SSDF)](https://csrc.nist.gov/publications/detail/sp/800-218/final)
- [CISA — Software Bill of Materials (SBOM) Resources](https://www.cisa.gov/sbom)
- [EU Cyber Resilience Act (CRA) — SBOM Requirements for Products with Digital Elements](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act)
- [NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework)
- [GAO — Federal Cybersecurity: Implementation of EO 14028 Progress Report](https://www.gao.gov/products/gao-24-106291)
- [SolarWinds Supply Chain Attack — CISA Emergency Directive 21-01](https://www.cisa.gov/emergency-directive-21-01)
- [Colonial Pipeline Ransomware — CISA Advisory](https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0048
