RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Policy & law

Policy & law / From the archive · March 2026 event · prepared 16 September 2026

The 2026 cyber strategy dropped the 2023 push for software liability

The March 2026 strategy is far shorter than 2023's and, unlike it, does not call for shifting liability to software makers.

Visual for this record: The 2026 cyber strategy dropped the 2023 push for software liability
Visual published by epic.es, shown for identification of the record. Credit: epic.es · source page ↗ Rights: owner-review-pending.

What the document says

President Trump's Cyber Strategy for America, dated March 2026, is a six-page document organised around six policy pillars: shaping adversary behaviour, promoting what it calls common-sense regulation, modernising federal networks, securing critical infrastructure, sustaining superiority in critical and emerging technologies, and building workforce talent and capacity. Reviewed directly, the document itself states it replaces the prior administration's approach and emphasises speed, deterrence and reducing regulatory burden on industry. Its regulation pillar states an intent to streamline cyber and data regulations, reduce compliance burdens, and address liability, without proposing a specific liability framework for software makers.

That is a marked change from the 2023 National Cybersecurity Strategy it replaces, a thirty-five-page document built around five pillars. That earlier strategy's Strategic Objective 3.3, titled Shift Liability for Insecure Software Products and Services, explicitly called on the Administration to work with Congress on legislation making software makers liable when they fail a duty of care, paired with a safe harbor for companies following secure-development practices. The 2026 strategy contains no equivalent objective; its liability language runs in the opposite direction, toward reducing compliance obligations rather than creating a new one.

Confidence and limits

Both documents were read in full, so their length, structure and the presence or absence of a liability-shifting objective are established directly. Legal commentary, including analysis from the law firm Covington, corroborates that the 2026 strategy is markedly shorter and more high-level than its predecessor, though that commentary was not the source for the liability comparison, which this entry drew from the two texts directly.

Why it mattered

A national strategy does not itself create law, and the 2023 objective never produced federal software liability legislation either. What changed is the executive branch's stated direction of travel: the 2023 document treated market failure in software security as something Congress should correct with a liability shift, while the 2026 document frames liability only as something to streamline away from industry. Readers should not treat either document as describing current law; both describe intent, and the 2023 objective was still unrealised legislation when the 2026 strategy superseded it.

Defensive takeaway

Continue to evaluate vendor contracts, warranties and secure-development commitments on their existing contractual and regulatory terms, since neither strategy document changes what a court or regulator can currently hold a software maker to.

  • Does your vendor risk assessment rely on an assumption that federal software liability reform is imminent, and if so, is that assumption still supported?
  • Has your organisation reviewed the 2026 strategy's six pillars for anything that changes your sector's specific regulatory exposure?
  • Are you tracking software liability proposals in Congress directly, rather than through either administration's strategy document?

Comparing the two documents side by side shows a strategy that grew shorter and less prescriptive, and a specific objective, shifting liability onto software makers, that did not survive the transition from one administration's framing to the next.

Defensive takeaway

Do not assume software liability reform is coming through this strategy; if your risk planning depended on an eventual federal liability regime for vendors, track Congress and sector regulators directly rather than this document.

Both strategy documents were read directly in full. The comparison of length and the absence of a liability-shifting objective in the 2026 text is drawn from the documents themselves; characterising the change as a deliberate reversal rather than a mere omission draws additionally on outside legal commentary.

Sources & reading trail

President Trump's Cyber Strategy for America ↗

Full text of the six policy pillars and the absence of a software liability-shifting objective.

government-primary · Source published: 1 March 2026 · Retrieved: 16 September 2026

National Cybersecurity Strategy ↗

Full text of Strategic Objective 3.3 on shifting liability for insecure software, and the five-pillar structure the 2026 strategy replaces.

government-primary · Source published: 1 March 2023 · Retrieved: 16 September 2026

White House Releases New National Cyber Strategy and Executive Order ↗

Outside legal commentary corroborating that the 2026 strategy is shorter and more high-level than the 2023 strategy.

reputable-original-reporting · Source published: Not established · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.