
What the document says
Executive Order 14306, signed 6 June 2025 and published in the Federal Register on 11 June, rewrites large parts of its predecessor, Executive Order 14144 of 16 January 2025, without replacing it outright. Reading the two side by side shows what changed. The original order's Section 2 directed agencies to draft contract language requiring federal software vendors to submit machine-readable secure-development attestations to a CISA repository; the new order strikes that subsection entirely. The original order's Section 5 directed agencies to expand use of digital identity documents to reduce fraud in public benefits programmes; the new order strikes that section outright and renumbers what follows. What survives, and is updated rather than removed, is the post-quantum cryptography timeline: agencies must still identify widely available post-quantum products by 1 December 2025, and non-national-security systems must still support Transport Layer Security 1.3 by 2 January 2030. The order separately narrows a 2015 sanctions order, changing its target from 'any person' to 'any foreign person' in two subsections, reducing its potential reach to non-foreign actors.
Confidence and limits
Both orders are read here directly from their published text, which is the strongest basis this format allows; there is no interpretive gap between what the document instructs and what is reported. What the text does not supply is motive: neither order explains why attestation and digital-identity provisions were dropped while post-quantum deadlines were kept, and this account does not guess at that reasoning.
Why it mattered
Software attestation was meant to give the federal government a paper trail showing vendors had followed secure development practices before their code ran on government systems; removing the requirement to collect it does not ban the practice, but it removes the mechanism forcing vendors to document it. The post-quantum survival matters differently: those deadlines depend on a physical constraint, the eventual arrival of a cryptographically relevant quantum computer, that does not move with administrations, which likely explains why that timeline continued largely intact while more discretionary reporting and identity provisions did not.
Defensive takeaway
If your organisation sells software to the federal government, do not assume secure-development attestation is now optional in practice just because the specific 2025 mechanism was struck; check current procurement language directly, since agencies retain authority to require it contractually.
- Does your organisation still track which NIST secure-software-development practices it can actually demonstrate, attestation requirement or not?
- Is your post-quantum cryptography migration on a timeline that would meet a January 2030 deadline for TLS 1.3 support?
- Would a change in a single executive order meaningfully change your compliance posture, or does it rest on more durable standards?
Reading amendments against their predecessor, rather than against a headline, is the only reliable way to know what a policy change actually did. Here, the text shows a narrower federal reporting burden and a sanctions order aimed more precisely at foreign persons, alongside continuity on the timeline least within any single administration's control.
If you sell software to the federal government, verify current procurement language directly rather than assuming secure-development attestation is now optional because this mechanism was struck.
Both orders are read directly from their published text, leaving no interpretive gap on what changed; neither document explains why attestation and digital-identity provisions were dropped while post-quantum deadlines were kept.
Sources & reading trail
The order's own text specifying, section by section, which provisions of Executive Order 14144 and 13694 were struck, replaced or retained.
government-primary · Source published: 11 June 2025 · Retrieved: 16 September 2026
The original Executive Order 14144 text, including the software-attestation requirement in Section 2 and the digital-identity provision in Section 5 that the later order struck.
government-primary · Source published: 16 January 2025 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.