Back to Frameworks

US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity

United States (Federal executive branch)
vExecutive Order 14144 of 16 January 2025 (90 FR 6755) as amended by Executive Order 14306 of 6 June 2025 (90 FR 24723); no later amendment (Federal Register notes checked 27 September 2026)
6 domains
24 controls

Executive Order 14144 of January 2025, as amended by Executive Order 14306 of June 2025, the US Federal cybersecurity order that builds on EO 14028: agencies manage supply chain risk under NIST SP 800-161 and their use of open source software, give CISA the endpoint detection data it needs to hunt threats, secure internet routing with registry agreements and Route Origin Authorizations, enable encrypted DNS, enforce encrypted email connections, encrypt voice, video and messaging by default, support TLS 1.3 by 2 January 2030 and inventory their major systems; cloud providers publish secure configuration baselines and protect signing keys and tokens under FedRAMP; internet providers, DNS product vendors and civil space contractors meet contract requirements; and vendors of consumer connected devices sold to the Government carry the US Cyber Trust Mark by 4 January 2027.

Verified

US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity is a compliance framework from United States (Federal executive branch) with 6 domains and 24 controls that map to 3 other frameworks. The largest domains are Sec. 4 Securing Federal communications – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (11 controls), Sec. 3 Improving the cybersecurity of Federal systems – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (8 controls), Sec. 2 Third-party software supply chains – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (2 controls). Every control below carries what it requires and what an assessor expects to see.

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit federalregister.gov

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Sec. 2 Third-party software supply chains – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity

2 controls
Controls in the Sec. 2 Third-party software supply chains – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity domain of US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity — 2 controls
CodeTitle
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::2(d)Sec. 2(d) (now 2(b)) Comply with NIST SP 800-161 and integrate supply chain risk into acquisition
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::2(e)Sec. 2(e) (now 2(c)) Manage agency use of open source software

Sec. 3 Improving the cybersecurity of Federal systems – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity

8 controls
Controls in the Sec. 3 Improving the cybersecurity of Federal systems – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity domain of US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity — 8 controls
CodeTitle
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(c)(ii)(A)Sec. 3(c)(ii)(A) (now 3(a)(ii)(A)) Provide CISA the EDR and SOC data the concept of operations requires
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(c)(v)Sec. 3(c)(v) (now 3(a)(v)) Enroll EDR endpoints in CISA's Persistent Access Capability
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(c)(vi)Sec. 3(c)(vi) (now 3(a)(vi)) Tell CISA which systems need extra controls or non-disruption periods
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(d)Sec. 3(d) (now 3(b)) Provide agency configuration baselines for cloud services (FedRAMP)
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(e)Sec. 3(e) (now 3(c)) Continually verify the cybersecurity of Federal space systems
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(e)(i)(A)Sec. 3(e)(i)(A) (now 3(c)(i)(A)) Protect civil space command and control
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(e)(i)(B)Sec. 3(e)(i)(B) (now 3(c)(i)(B)) Detect, report and recover from anomalous space system activity
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::3(e)(i)(C)Sec. 3(e)(i)(C) (now 3(c)(i)(C)) Use secure software and hardware development for civil space systems

Sec. 4 Securing Federal communications – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity

11 controls
Controls in the Sec. 4 Securing Federal communications – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity domain of US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity — 11 controls
CodeTitle
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(b)(i)Sec. 4(b)(i) Cover internet number resources by a registry agreement and keep registry records current
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(b)(ii)Sec. 4(b)(ii) Publish Route Origin Authorizations for agency IP address blocks
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(b)(iii)Sec. 4(b)(iii) Deploy routing security as a contracted internet service provider
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(c)(i)Sec. 4(c)(i) Support encrypted DNS in products that act as DNS resolvers
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(c)(ii)Sec. 4(c)(ii) Enable encrypted DNS wherever clients and servers support it
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(d)(i)Sec. 4(d)(i) Enforce encrypted, authenticated transport between email clients and servers
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(e)(i)Sec. 4(e)(i) Enable transport encryption by default for voice, video and messaging
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(e)(ii)Sec. 4(e)(ii) Use end-to-end encryption by default while keeping records capability
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(f)(ii)Sec. 4(f)(ii) Support TLS 1.3 or a successor by 2 January 2030
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(g)(ii)Sec. 4(g)(ii) Meet FedRAMP key management requirements for access tokens and keys
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::4(g)(iii)Sec. 4(g)(iii) Follow best practice for HSMs and isolation protecting cloud keys

Sec. 6 Security with and in artificial intelligence – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity

1 controls
Controls in the Sec. 6 Security with and in artificial intelligence – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity domain of US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity — 1 controls
CodeTitle
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::6(e)Sec. 6(e) (now 5(b)) Manage AI software vulnerabilities and compromises in vulnerability management

Sec. 7 Aligning policy to practice – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity

1 controls
Controls in the Sec. 7 Aligning policy to practice – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity domain of US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity — 1 controls
CodeTitle
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::7(c)Sec. 7(c) Carry the US Cyber Trust Mark on consumer IoT products sold to Government

Sec. 8 National security systems and system inventories – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity

1 controls
Controls in the Sec. 8 National security systems and system inventories – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity domain of US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity — 1 controls
CodeTitle
us-executive-order-14144-strengthening-and-promoting-innovation-in-the-nations-cybersecurity::8(d)Sec. 8(d) Inventory major information systems and provide the inventory to the registry

Your Compliance Coverage

If you comply with US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity, you already cover:

Maps to 3 other frameworks

24 total controls
NIST SP 800-53 Rev 5
21 source controls mapped|20 target controls covered
88%
NIST Cybersecurity Framework 2.0
15 source controls mapped|11 target controls covered
63%
NIST SP 800-218
1 source controls mapped|2 target controls covered
4%

Coverage is not the same as your position

This page shows what US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity and who does it apply to?

US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity is a compliance framework from United States (Federal executive branch) with 6 domains and 24 controls. Executive Order 14144 of January 2025, as amended by Executive Order 14306 of June 2025, the US Federal cybersecurity order that builds on EO 14028: agencies manage supply chain risk under NIST SP 800-161 and their use of open source software, give CISA the endpoint detection data it needs to hunt threats, secure internet routing with registry agreements and Route Origin Authorizations, enable encrypted DNS, enforce encrypted email connections, encrypt voice, video and messaging by default, support TLS 1.3 by 2 January 2030 and inventory their major systems; cloud providers publish secure configuration baselines and protect signing keys and tokens under FedRAMP; internet providers, DNS product vendors and civil space contractors meet contract requirements; and vendors of consumer connected devices sold to the Government carry the US Cyber Trust Mark by 4 January 2027. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity actually require?

US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity has 24 controls organised across 6 domains. The largest domains are Sec. 4 Securing Federal communications – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (11 controls), Sec. 3 Improving the cybersecurity of Federal systems – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (8 controls), Sec. 2 Third-party software supply chains – US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity do I already cover?

US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity maps to 3 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (88% coverage), NIST Cybersecurity Framework 2.0 (63% coverage), NIST SP 800-218 (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity?

Start your US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US Executive Order 14144 - Strengthening and Promoting Innovation in the Nation's Cybersecurity requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required