Improving the Nation's Cybersecurity
- Document
- 17 May 2021
- Event
- 12 May 2021
- Retrieved
- 16 September 2026
What happened
On 12 May 2021, five days after the Colonial Pipeline shutdown, the President signed Executive Order 14028, Improving the Nation's Cybersecurity. The order directed federal agencies toward zero-trust architecture, required a software bill of materials and baseline secure-development standards for software sold to the government, created the Cyber Safety Review Board to examine significant incidents, and mandated endpoint detection tools and expanded logging across federal networks. It set a cascade of deadlines, from 30 days for initial recommendations to a year for supplier compliance requirements, and tasked the Cybersecurity and Infrastructure Security Agency with several of the specific deliverables.
Confidence and limits
The order's own text, published in the Federal Register, and CISA's own account of its assigned deliverables agree on what was directed and on which pieces, such as the Zero Trust Maturity Model and a cloud security reference architecture, have since been published. What the order's long-term effect has been is harder to state with the same confidence: implementation continues years after signing, several deadlines produced only interim products, and a later order has already revised part of the software-security requirements it created. This article does not attempt to rate the order's overall success, only to record what it required and what has publicly changed since.
Why it mattered
The order converted several ideas that had circulated in security circles for years, zero trust, a software parts list, a standing incident review board, into specific federal deadlines with a named accountable agency. Its software bill of materials provision led directly to the government's definition of SBOM's minimum contents two months later. Its call for a review board produced the body that later examined the Log4j event. Not every element survived unchanged: a June 2025 order tasked NIST with revising the secure-software framework and removed a centralised attestation-validation requirement the 2021 order had set in motion, evidence that even a wide-reaching order is revisited as circumstances and administrations change.
Defensive takeaway
If your organisation sells software to the federal government, or simply wants a defensible baseline, treat the order's underlying artefacts, the Secure Software Development Framework and the practice of shipping a software bill of materials, as current reference points rather than as a single point-in-time compliance exercise, since the requirements built on them keep changing.
- Can you produce a software bill of materials for your own products or critical vendors today, or only in theory?
- Have you mapped which of your development practices already satisfy the Secure Software Development Framework's baseline tasks?
- Do you track which federal cybersecurity requirements have since been revised, rather than assuming the 2021 baseline still applies unchanged?
An executive order is a starting instruction, not a finished system, and the record here is best read as the origin point for several still-evolving federal requirements rather than as a completed reform.
Treat the order's Secure Software Development Framework and software-bill-of-materials practice as current reference points to work toward, not as a single, already-completed compliance milestone.
The order's published text and CISA's own account of its assigned deliverables agree on what was directed and what has since been produced. This article does not rate the order's overall success, since implementation continues years later and some provisions have already been revised.
Sources & reading trail
The order's full published text, including its sections on zero trust, software supply-chain security, the review board, and compliance deadlines.
government-primary · Source published: 17 May 2021 · Retrieved: 16 September 2026
Describes how SP 800-218 maps EO 14028 Section 4(e) clauses to secure-development practices, and that the framework continues to be revised.
standards-body · Source published: Not established · Retrieved: 16 September 2026
Lists which EO-directed deliverables CISA has published to date, including the Zero Trust Maturity Model and cloud security reference architecture.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Records that a June 2025 order tasked NIST with revising the secure-software framework and related patch-management guidance.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.