Improving the Nation's Cybersecurity: NIST’s Responsibilities under the May 2021 Executive Order
Overview:
The President’s Executive Order (EO) on “Improving the Nation’s Cybersecurity (14028)” issued on May 12, 2021, charges multiple agencies – including NIST– with enhancing cybersecurity through a variety of initiatives related to the security and integrity of the software supply chain. The following is from NIST. Cybersecurity professionals need to spend considerable time understanding our resources as provided by NIST, by CISA Executive Order on Improving the Nation’s Cybersecurity | CISA, by Cloud Security Alliance, and by Center for Internet Security CIS Critical Security Controls Version 8 (cisecurity.org). We must understand our audience, the products they consume and design, and meet our obligations as US-certified cyber professionals and regulators. The war is digital. We are this country's defense.
Section 4 of the EO directs NIST to solicit input from the private sector, academia, government agencies, and others and to identify existing or develop new standards, tools, best practices, and other guidelines to enhance software supply chain security. Those guidelines are to include:
- criteria to evaluate software security,
- criteria to evaluate the security practices of the developers and suppliers themselves, and
- innovative tools or methods to demonstrate conformance with secure practices.
The EO calls for NIST to consult with the National Security Agency (NSA), Office of Management and Budget (OMB), Cybersecurity & Infrastructure Security Agency (CISA), and the Director of National Intelligence (DNI) and then to define “critical software” by June 26, 2021.
- NIST published guidance outlining security measures for critical software after consulting with CISA and OMB.
- NIST published guidelines recommending minimum standards for vendors’ testing of their software source code after consulting with the NSA
- NIST is to publish preliminary guidelines, based on stakeholder input and existing documents for enhancing software supply chain security.
Coming soon
- By February 6, 2022, after consulting heads of various agencies, NIST will issue guidance that identifies practices that enhance software supply chain security, with references to standards, procedures, and criteria.
- By May 8, 2022, NIST will publish additional guidelines, including procedures for periodically reviewing and updating guidelines.
The EO also directs NIST to initiate two labeling programs related to the Internet of Things (IoT) and software to inform consumers about the security of their products. Those efforts have initial deadlines of February 6, 2022. Like its other assignments in the EO, NIST will rely heavily on stakeholder ideas and information in carrying out these tasks.
- Cybersecurity Labeling for Consumer IoT and Software: Executive Order Update and Discussion (December 9, 2021)
- 2nd Public Draft SP 800-161 Revision 1 Workshop (December 1, 2021)
- Executive Order 14028: Guidelines for Enhancing Software Supply Chain Security (November 8, 2021)
- Draft NIST SP 800-161 Revision 1 (October 28, 2021) still draft
- Improving the Nation’s Cybersecurity: Progress and Next Steps in Carrying Out Executive Order 14028 (October 14, 2021)
- NIST's Secure Software Development Framework (SSDF) Version 1.1 (September 30, 2021)
Critical Software
The Executive Order (EO) on Improving the Nation’s Cybersecurity (14028) assigns NIST with three specific directives relating to critical software.
First, NIST is to consult with the National Security Agency (NSA), Office of Management and Budget (OMB), Cybersecurity & Infrastructure Security Agency (CISA), and the Director of National Intelligence (DNI) and then to define “critical software” by June 26, 2021.
Second, NIST is to publish guidance outlining security measures for critical software by July 11, 2021, after consulting with CISA and OMB.
Critical Software Definition
Critical Software: Enhancing the Security of the Software Supply Chain
One of NIST’s assignments to enhance the security of the software supply chain called for by May 12, 2021, Presidential Executive Order on Improving the Nation’s Cybersecurity (14028) is to publish a definition of “critical software.”
The executive order (EO) directs the Cybersecurity & Infrastructure Security Agency (CISA) to develop a list of software categories and products in use or in the acquisition process which meet this definition of critical software.
To coordinate the definition with its eventual application, NIST solicited position papers from the community, hosted a virtual workshop to gather input, and consulted with CISA, the Office of Management and Budget (OMB), the Office of the Director of National Intelligence (ODNI), and the National Security Agency (NSA) to develop the definition, the concept of a phased implementation, and a preliminary list of common categories of software that would fall within the scope for the initial phase. Additional guidance on applying this definition for implementing the EO will be forthcoming from CISA and OMB. NIST worked closely with CISA and OMB to ensure that the definition and recommendations are consistent with their plans.
The specific definition of critical software is included in a NIST white paper.
Critical Software Definition - Introduction
October 13, 2021 (this is NIST content summarized so I can link it to other areas and points throughout this site.)
Executive Order (EO) 14028 on Improving the Nation’s Cybersecurity, issued on May 12, 2021, directs the National Institute of Standards and Technology (NIST) to publish a definition of the term critical software.
(g) Within 45 days of the date of this order, the Secretary of Commerce, acting through the Director of NIST, in consultation with the Secretary of Defense acting through the Director of the NSA, the Secretary of Homeland Security acting through the Director of CISA, the Director of OMB, and the Director of National Intelligence, shall publish a definition of the term “critical software” for inclusion in the guidance issued pursuant to subsection (e) of this section. That definition shall reflect the level of privilege or access required to function, integration and dependencies with other software, direct access to networking and computing resources, the performance of a function critical to trust, and potential for harm if compromised.
The EO directs the Cybersecurity & Infrastructure Security Agency (CISA) to use this published definition of critical software to develop a list of software categories and products that are in scope for that definition and thus subject to the further requirements of the EO.
(h) Within 30 days of the publication of the definition required by subsection (g) of this section, the Secretary of Homeland Security acting through the Director of CISA, in consultation with the Secretary of Commerce acting through the Director of NIST, shall identify and make available to agencies a list of categories of software and software products in use or in the acquisition process meeting the definition of critical software issued pursuant to subsection (g) of this section.
To coordinate the definition with its eventual application, NIST solicited position papers from the community, hosted a virtual workshop to gather input, and consulted with CISA, the Office of Management and Budget (OMB), the Office of the Director of National Intelligence (ODNI), and the National Security Agency (NSA) to develop the definition, the concept of a phased implementation, and a preliminary list of common categories of software that would fall within the scope for the initial phase. Additional guidance on applying this definition for implementing the EO will be forthcoming from CISA and OMB. NIST worked closely with CISA and OMB to ensure that the definition and recommendations are consistent with their plans.
This webpage starts with background information and context for the term critical and introduces the concept of a phased approach. It defines the term critical software in the context of the EO and provides a preliminary list of software that meets the definition of EO-critical and is recommended to be included in the initial phase of implementation. The webpage concludes with frequently asked questions (FAQs). CISA will provide the final set of software categories for the initial and future implementation phases.
Critical Software Definition - Background & Approach


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics