RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Policy & law

Policy & law / From the archive · 12 May 2021 event · prepared 16 September 2026

An executive order followed the pipeline attack by five days

Executive Order 14028 set federal deadlines for zero trust, a software parts list and a standing incident review board.

govinfo.govprimary record

Improving the Nation's Cybersecurity

Document
17 May 2021
Event
12 May 2021
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

What happened

On 12 May 2021, five days after the Colonial Pipeline shutdown, the President signed Executive Order 14028, Improving the Nation's Cybersecurity. The order directed federal agencies toward zero-trust architecture, required a software bill of materials and baseline secure-development standards for software sold to the government, created the Cyber Safety Review Board to examine significant incidents, and mandated endpoint detection tools and expanded logging across federal networks. It set a cascade of deadlines, from 30 days for initial recommendations to a year for supplier compliance requirements, and tasked the Cybersecurity and Infrastructure Security Agency with several of the specific deliverables.

Confidence and limits

The order's own text, published in the Federal Register, and CISA's own account of its assigned deliverables agree on what was directed and on which pieces, such as the Zero Trust Maturity Model and a cloud security reference architecture, have since been published. What the order's long-term effect has been is harder to state with the same confidence: implementation continues years after signing, several deadlines produced only interim products, and a later order has already revised part of the software-security requirements it created. This article does not attempt to rate the order's overall success, only to record what it required and what has publicly changed since.

Why it mattered

The order converted several ideas that had circulated in security circles for years, zero trust, a software parts list, a standing incident review board, into specific federal deadlines with a named accountable agency. Its software bill of materials provision led directly to the government's definition of SBOM's minimum contents two months later. Its call for a review board produced the body that later examined the Log4j event. Not every element survived unchanged: a June 2025 order tasked NIST with revising the secure-software framework and removed a centralised attestation-validation requirement the 2021 order had set in motion, evidence that even a wide-reaching order is revisited as circumstances and administrations change.

Defensive takeaway

If your organisation sells software to the federal government, or simply wants a defensible baseline, treat the order's underlying artefacts, the Secure Software Development Framework and the practice of shipping a software bill of materials, as current reference points rather than as a single point-in-time compliance exercise, since the requirements built on them keep changing.

  • Can you produce a software bill of materials for your own products or critical vendors today, or only in theory?
  • Have you mapped which of your development practices already satisfy the Secure Software Development Framework's baseline tasks?
  • Do you track which federal cybersecurity requirements have since been revised, rather than assuming the 2021 baseline still applies unchanged?

An executive order is a starting instruction, not a finished system, and the record here is best read as the origin point for several still-evolving federal requirements rather than as a completed reform.

Defensive takeaway

Treat the order's Secure Software Development Framework and software-bill-of-materials practice as current reference points to work toward, not as a single, already-completed compliance milestone.

The order's published text and CISA's own account of its assigned deliverables agree on what was directed and what has since been produced. This article does not rate the order's overall success, since implementation continues years later and some provisions have already been revised.

Sources & reading trail

Improving the Nation's Cybersecurity ↗

The order's full published text, including its sections on zero trust, software supply-chain security, the review board, and compliance deadlines.

government-primary · Source published: 17 May 2021 · Retrieved: 16 September 2026

Secure Software Development Framework (SSDF) ↗

Describes how SP 800-218 maps EO 14028 Section 4(e) clauses to secure-development practices, and that the framework continues to be revised.

standards-body · Source published: Not established · Retrieved: 16 September 2026

Executive Order on Improving the Nation's Cybersecurity ↗

Lists which EO-directed deliverables CISA has published to date, including the Zero Trust Maturity Model and cloud security reference architecture.

government-primary · Source published: Not established · Retrieved: 16 September 2026

Executive Order 14306 — Sustaining Select Efforts to Strengthen the Nation's Cybersecurity ↗

Records that a June 2025 order tasked NIST with revising the secure-software framework and related patch-management guidance.

government-primary · Source published: Not established · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.