US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity
Executive Order 14144 of January 2025, as amended by Executive Order 14306 of June 2025, the US Federal cybersecurity order that builds on EO 14028: agencies manage supply chain risk under NIST SP 800-161 and their use of open source software, give CISA the endpoint detection data it needs to hunt threats, secure internet routing with registry agreements and Route Origin Authorizations, enable encrypted DNS, enforce encrypted email connections, encrypt voice, video and messaging by default, support TLS 1.3 by 2 January 2030 and inventory their major systems; cloud providers publish secure configuration baselines and protect signing keys and tokens under FedRAMP; internet providers, DNS product vendors and civil space contractors meet contract requirements; and vendors of consumer connected devices sold to the Government carry the US Cyber Trust Mark by 4 January 2027.
US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity is a compliance framework from United States (Federal executive branch) with 6 domains and 24 controls that map to 3 other frameworks. The largest domains are Sec. 4 Securing Federal communications – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (11 controls), Sec. 3 Improving the cybersecurity of Federal systems – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (8 controls), Sec. 2 Third-party software supply chains – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (2 controls). Every control below carries what it requires and what an assessor expects to see.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit federalregister.govFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Sec. 2 Third-party software supply chains – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity
| Code | Title |
|---|---|
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::2(d) | Sec. 2(d) (now 2(b)) Comply with NIST SP 800-161 and integrate supply chain risk into acquisition |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::2(e) | Sec. 2(e) (now 2(c)) Manage agency use of open source software |
Sec. 3 Improving the cybersecurity of Federal systems – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity
| Code | Title |
|---|---|
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(c)(ii)(A) | Sec. 3(c)(ii)(A) (now 3(a)(ii)(A)) Provide CISA the EDR and SOC data the concept of operations requires |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(c)(v) | Sec. 3(c)(v) (now 3(a)(v)) Enroll EDR endpoints in CISA's Persistent Access Capability |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(c)(vi) | Sec. 3(c)(vi) (now 3(a)(vi)) Tell CISA which systems need extra controls or non-disruption periods |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(d) | Sec. 3(d) (now 3(b)) Provide agency configuration baselines for cloud services (FedRAMP) |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(e) | Sec. 3(e) (now 3(c)) Continually verify the cybersecurity of Federal space systems |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(e)(i)(A) | Sec. 3(e)(i)(A) (now 3(c)(i)(A)) Protect civil space command and control |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(e)(i)(B) | Sec. 3(e)(i)(B) (now 3(c)(i)(B)) Detect, report and recover from anomalous space system activity |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(e)(i)(C) | Sec. 3(e)(i)(C) (now 3(c)(i)(C)) Use secure software and hardware development for civil space systems |
Sec. 4 Securing Federal communications – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity
| Code | Title |
|---|---|
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(b)(i) | Sec. 4(b)(i) Cover internet number resources by a registry agreement and keep registry records current |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(b)(ii) | Sec. 4(b)(ii) Publish Route Origin Authorizations for agency IP address blocks |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(b)(iii) | Sec. 4(b)(iii) Deploy routing security as a contracted internet service provider |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(c)(i) | Sec. 4(c)(i) Support encrypted DNS in products that act as DNS resolvers |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(c)(ii) | Sec. 4(c)(ii) Enable encrypted DNS wherever clients and servers support it |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(d)(i) | Sec. 4(d)(i) Enforce encrypted, authenticated transport between email clients and servers |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(e)(i) | Sec. 4(e)(i) Enable transport encryption by default for voice, video and messaging |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(e)(ii) | Sec. 4(e)(ii) Use end-to-end encryption by default while keeping records capability |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(f)(ii) | Sec. 4(f)(ii) Support TLS 1.3 or a successor by 2 January 2030 |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(g)(ii) | Sec. 4(g)(ii) Meet FedRAMP key management requirements for access tokens and keys |
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(g)(iii) | Sec. 4(g)(iii) Follow best practice for HSMs and isolation protecting cloud keys |
Sec. 6 Security with and in artificial intelligence – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity
| Code | Title |
|---|---|
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::6(e) | Sec. 6(e) (now 5(b)) Manage AI software vulnerabilities and compromises in vulnerability management |
Sec. 7 Aligning policy to practice – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity
| Code | Title |
|---|---|
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::7(c) | Sec. 7(c) Carry the US Cyber Trust Mark on consumer IoT products sold to Government |
Sec. 8 National security systems and system inventories – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity
| Code | Title |
|---|---|
| us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::8(d) | Sec. 8(d) Inventory major information systems and provide the inventory to the registry |
Your Compliance Coverage
If you comply with US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity, you already cover:
Maps to 3 other frameworks
Coverage is not the same as your position
This page shows what US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity and who does it apply to?
US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity is a compliance framework from United States (Federal executive branch) with 6 domains and 24 controls. Executive Order 14144 of January 2025, as amended by Executive Order 14306 of June 2025, the US Federal cybersecurity order that builds on EO 14028: agencies manage supply chain risk under NIST SP 800-161 and their use of open source software, give CISA the endpoint detection data it needs to hunt threats, secure internet routing with registry agreements and Route Origin Authorizations, enable encrypted DNS, enforce encrypted email connections, encrypt voice, video and messaging by default, support TLS 1.3 by 2 January 2030 and inventory their major systems; cloud providers publish secure configuration baselines and protect signing keys and tokens under FedRAMP; internet providers, DNS product vendors and civil space contractors meet contract requirements; and vendors of consumer connected devices sold to the Government carry the US Cyber Trust Mark by 4 January 2027. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity actually require?
US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity has 24 controls organised across 6 domains. The largest domains are Sec. 4 Securing Federal communications – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (11 controls), Sec. 3 Improving the cybersecurity of Federal systems – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (8 controls), Sec. 2 Third-party software supply chains – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity do I already cover?
US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity maps to 3 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (88% coverage), NIST Cybersecurity Framework 2.0 (63% coverage), NIST SP 800-218 (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity?
Start your US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required