The compliance gauntlet isn't just slowing emerging tech vendors — it's eliminating them before agencies ever see what they're missing, writes Irina Denisenko, CEO of Knox Systems.
Agencies are expected to undertake two actions in service of enhanced security: execute a phased migration of cryptographic systems to prepare for quantum computing risk; and submit a PQC migration plan to OMB.
Its formation occurs amid a broader discussion over whether existing laws are suited for cyber activities that increasingly depend on cooperation between the government and private sector.
From inventory support to DARPA's $282M benchmarking initiative, here's where the opportunities are — and what to avoid, write immixGroup’s Joshua Iseler and Grier Egan.
Iran-linked intrusions targeting defense software suppliers are a wake-up call for agencies and contractors, writes Gary Barlet, public sector CTO at Illumio.
The unit will use legal authorizations and technical capabilities to impede cyber threat groups, though company execs say it will not go so far as to hack into adversaries' systems.
“Unlike other Administrations, the Trump Administration will not tinker at the edges and apply partial measures and ambiguous strategies that neglect the growing number and severity of cyber threats,” the strategy said.
The directive gives agencies three months to identify unsupported edge devices, a year to begin removing them and 18 months to eliminate them entirely.
ONCD chief Sean Cairncross also said a bedrock National Cyber Strategy, initially expected last month, is coming “sooner rather than later” without specifying a date.
The General Services Administration's new requirements for protecting controlled unclassified information apply immediately to new contracts, at the contracting officer's discretion.
A new executive branch memorandum instead allows agencies to lean on software bills of materials, or SBOMs, in lieu of a universal attestation framework.
The Trump 2.0 cyber strategy is in development, National Cyber Director Sean Cairncross said, though he did not elaborate on when it would be released.
“This cyber threat actor presents an imminent threat to federal networks using F5 devices and software,” CISA’s directive says. China-linked hackers previously exploited F5 vulnerabilities.
Full implementation of the standard takes effect in a month. In the meantime, a new study shows a compliance gap that could lock unprepared contractors out of defense contracts while cyber vulnerabilities persist.