
AI Agents Are Identities Too: Securing Non-Person Entities in a Zero Trust Architecture
September 30, 2026Cybersecurity Awareness Month 2026: Eight Federal Mandates Reshaping AI, Cyber Defense, and Cryptography
Between December 2025 and June 2026, the federal government issued eight mandates that answer one problem: adversaries now find and exploit weaknesses faster than agency processes can respond. AI-assisted attackers compress the time between a vulnerability’s disclosure and its exploitation. Quantum computing threatens the cryptography that protects data collected today. Both shrink the margin that agencies, and the contractors who support them, used to count on.
This blog covers each mandate in the same order: why it exists, the problem it addresses, and what it requires. They fall into three groups.
- AI governance: EO 14409, NSPM-11, and OMB M-26-04.
- Cyber defense operations: CISA BOD 26-02, CISA BOD 26-04, and OMB M-26-14.
- Cryptography: EO 14412 and OMB M-26-15.
A combined timeline closes the blog post. Most of these documents bind federal civilian agencies or the national security enterprise directly. Contractors and cloud providers meet them through contract terms, FedRAMP requirements, and the FAR. All dates are current as of October 6, 2026.
AI governance: three mandates, three different questions
The AI mandates split by who they govern. EO 14409 addresses AI as a cyber risk and a cyber defense tool. NSPM-11 sets the rules for AI inside national security systems. OMB M-26-04 governs what civilian agencies can buy when the product is a large language model.
EO 14409: Promoting Advanced AI Innovation and Security (June 2, 2026)
Why it exists. The order treats advanced AI as both a security asset and a security risk. Its stated policy is to work with the private sector to modernize government and private-sector systems, harden them against external threats, and protect American intellectual property from theft, without burdensome regulation.
The problem it addresses. Frontier models can discover and exploit software vulnerabilities faster than conventional patching cycles allow. The order creates a voluntary channel for government to assess those capabilities before a model reaches release.
What it requires:
- Within 30 days: the Committee on National Security Systems and the Secretary of War prioritize cyber defense of national security systems and Department of War systems.
- Within 30 days: CISA releases Binding Operational Directives and other guidance to expedite civilian system defense, expand AI-enabled defensive tooling, and extend access to cybersecurity tools, including covered frontier models, to agencies, state and local authorities, and operators such as rural hospitals, community banks, and local utilities.
- Within 30 days: Treasury forms a voluntary AI cybersecurity clearinghouse that coordinates vulnerability scanning, validation, and patch prioritization with industry and critical infrastructure operators.
- Within 30 days: OMB determines whether existing grant funding can go to developers of AI vulnerability detection.
- Within 60 days: OPM expands Tech Force cybersecurity specialist hiring pathways. Treasury, NSA, and CISA build a classified benchmarking process that sets the threshold for a “covered frontier model” and design a voluntary framework giving government up to 30 days of pre-release access.
- No licensing regime: the order bars any mandatory licensing, preclearance, or permitting requirement for AI models.
- Enforcement: the Attorney General prioritizes prosecution of AI-enabled computer intrusion under the Computer Fraud and Abuse Act and related statutes.
CISA issued BOD 26-04 on June 10, inside the order’s 30-day window for CISA directives.
NSPM-11: AI in the National Security Enterprise (June 5, 2026)
Why it exists. The memorandum sets out to speed AI adoption across defense and intelligence, reduce reliance on any single vendor, and keep pace with the way competitors field AI. It rescinds and replaces NSM-25, issued in October 2024.
The problem it addresses. Slow adoption, vendor lock-in, and the risk that a commercial supplier could restrict or alter an AI system a mission depends on.
What it requires. The memo organizes policy around four pillars: adoption, adaptation, assurance, and accountability. It applies to the Department of War, the Intelligence Community, and other agencies with national security roles.
- Vendor control: contract clauses or other means must ensure that no commercial entity or adversary can prevent use of, disable, degrade, or materially modify a mission-critical AI system without government knowledge and approval.
- Contract terminations: agencies must direct termination of contracts with companies that show a repeated pattern of conduct inconsistent with the memo’s policy, including subcontract arrangements. Agency heads can grant waivers of up to one year.
- Within 90 days: the Secretary of War updates DoD Directive 3000.09 on autonomy in weapon systems. CNSS and OMB issue AI governance policy for national security systems, aligned with M-25-21 where appropriate.
- Within 120 days: procurement processes must allow rapid onboarding of leading models from multiple vendors. NSA’s AI Security Center builds private-sector partnerships to protect frontier AI from malicious distillation attacks. The intelligence and defense agencies launch joint AI data and model exchanges.
- Within 120 days: a joint AI risk management strategy sets baseline security practices, and standardized test, evaluation, verification, and validation methodologies go to the White House for review. OPM begins an AI National Security Strategic Reserve of outside talent.
OMB M-26-04: Unbiased AI Principles (December 11, 2025)
Why it exists. The memo implements EO 14319, which requires federally procured LLMs to meet two principles: truth-seeking and ideological neutrality.
The problem it addresses. Agencies had no contractual mechanism to verify how a procured LLM was built, tuned, and filtered.
What it requires:
- New contracts: every solicitation or order for an LLM issued after the memo’s date includes contractual requirements addressing the Unbiased AI Principles. Agencies should modify existing LLM contracts, at the latest before exercising any option that extends performance.
- By March 11, 2026: agencies update procurement policies and create a process for users to report outputs that violate the principles.
- Minimum vendor disclosures: an acceptable use policy, model, system, or data cards, end-user resources, and a feedback mechanism for violating outputs.
- Enhanced disclosures: agencies may request detail on pre- and post-training activity, system prompts, content moderation filters, red-teaming, training outside the United States, bias evaluations, and third-party modifications. They should avoid compelling disclosure of model weights.
- Materiality: agencies should designate the requirements as material to eligibility and payment, which supports termination for default.
- Resellers and integrators: the memo reaches LLMs obtained through intermediaries, so a reseller needs the developer’s cooperation to supply the documentation. Free, open-source LLMs fall outside the contractual requirements but still call for due diligence.
- Sunset: the memo expires two years after issuance, on December 11, 2027, unless OMB extends it.
Cyber defense operations: perimeter, patching, and visibility
Three mandates tighten the operating basics: retire devices that can no longer be patched, patch what is actually dangerous first, and log enough to see an intrusion in progress.
BOD 26-02: Mitigating Risk From End-of-Support Edge Devices (February 5, 2026)
Why it exists. This BOD addresses a specific weakness: unsupported edge devices are especially vulnerable to exploits that target newly discovered, unpatched vulnerabilities. A device its manufacturer no longer patches stays exposed permanently.
The problem it addresses. Firewalls, routers, VPN gateways, load balancers, and wireless access points sit on the network perimeter. Agencies kept running them past end of support, and attackers target exactly those devices.
What it requires (federal civilian agencies):
- Immediately: update vendor-supported edge devices that are running end-of-support software for which updates exist.
- Within 3 months: inventory all devices on CISA’s end-of-support list and report the inventory to CISA. The directive also requires inventories of in-scope edge devices that are, or will become, end-of-support within twelve months.
- Within 12 months: decommission devices that had already reached end of support when the directive issued.
- Within 18 months: replace all identified end-of-support edge devices with vendor-supported equipment that receives current security updates.
- Within 24 months: establish continuous discovery so end-of-support devices do not reappear after the first sweep.
The directive binds federal civilian agencies only. CISA, the FBI, and the UK’s NCSC encourage all organizations to follow the same guidance.
BOD 26-04: Prioritizing Security Updates Based on Risk (June 10, 2026)
Why it exists. This BOD reflects CISA’s response to AI’s effect on the volume of identified vulnerabilities and on the shrinking window in which threat actors exploit them
The problem it addresses. Flat, severity-based remediation deadlines treated every vulnerability as equally urgent. BOD 26-04 supersedes BOD 19-02 and BOD 22-01 and drops CVSS as the required prioritization input.
What it requires:
- A four-factor assessment: whether the asset is publicly exposed, whether the vulnerability is in CISA’s Known Exploited Vulnerabilities (KEV) catalog, whether an adversary can exploit it automatically, and whether exploitation yields partial or total control.
- Risk-tiered deadlines: the highest-risk combination (exposed, in KEV, automatable, total control) carries a three-day deadline plus forensic triage. Lower-risk combinations run 14 or 60 days, and vulnerabilities that meet no risk criterion can wait for the next system upgrade.
- Dynamic clocks: a timeline starts when CISA adds the vulnerability to the KEV catalog or when the agency identifies it on an asset in the CDM dashboard, whichever comes first. Timelines shift as facts change, for example when an agency removes a system from the internet.
- Process updates: agencies revise vulnerability management policies and asset inventories, continue Cyber Hygiene scanning, and refresh exposed IP addresses and domain names quarterly. Agencies not fully automated through CDM report vulnerability status to CISA every seven days.
- By December 7, 2026: agencies begin evaluating and remediating on the new timelines.
The directive does not apply directly to contractors unless a contract requires it, but it tells agencies to review their contracts for needed modifications. FedRAMP will require its new Vulnerability Detection and Response rules by December 7, 2026 to align with it, so cloud service providers face the same date.
OMB M-26-14: Agency Logging and Network Visibility (May 22, 2026)
Why it exists. OMB found that some M-21-31 requirements, such as retaining vast quantities of log data without clear utility, proved neither operationally feasible nor cost-effective. M-26-14 rescinds M-21-31 and replaces it with a risk-based approach.
The problem it addresses. Volume-driven logging mandates drove cost without improving detection, while attackers use automation and AI to move faster across networks.
What it requires:
- Two objectives: continuous event monitoring in near real time, and threat hunting, investigation, response, and forensics after a suspected compromise. Both cover IoT and operational technology that form part of agency systems.
- Retention baseline: logs stay actively searchable for at least six months and retrievable for a year. Logs must be readily available to the agency’s top-level security operations center and carry synchronized timestamps.
- Minimum collection: logs support eleven activities, from identifying the user behind an action and source and destination network addresses, to privilege changes, lateral movement, and attack vectors.
- Incident access: on a known or suspected compromise, agencies provide logs to CISA and the FBI on request.
- Agency Logging Plan: due 90 days after CISA publishes the Logging Reference Architecture, to OMB and CISA.
- Maturity milestones: Basic maturity within 120 days of the Architecture’s release, Intermediate within 180, and Advanced within 320.
CISA published the Logging Reference Architecture on August 20, 2026. That date puts the plan at November 18, 2026, Basic maturity at December 18, 2026, Intermediate at February 16, 2027, and Advanced at July 6, 2027.
Cryptography: dated deadlines for the quantum transition
EO 14412 sets the dates. OMB M-26-15 turns them into agency work. Read together, they replace a long-running 2035 target with 2030 and 2031 deadlines for the highest-value federal systems.
EO 14412: Securing the Nation Against Advanced Cryptographic Attacks (June 22, 2026)
Why it exists. EO 14412 seeks to address the risk that large-scale quantum computers in adversary hands will threaten widely used cryptographic systems. Adversaries can also collect U.S. information now and decrypt it once such computers are operational.
The problem it addresses. Data encrypted today with classical public-key cryptography can outlive the protection around it. The order moves federal systems to NIST-approved post-quantum cryptography (PQC) standards and extends the obligation to contractors.
What it requires:
- Within 30 days: each agency head names a PQC migration lead.
- Within 90 days: OMB issues guidance requiring each agency to review its inventory of high value assets and high-impact systems (excluding national security systems), move those systems to PQC key establishment by December 31, 2030 and PQC digital signatures by December 31, 2031, and submit a plan.
- Within 180 days: NIST starts a PQC migration pilot on its own systems, to finish by December 31, 2027, and revises its cryptographic module validation processes to speed approvals.
- Within 180 days: the FAR Council proposes a rule requiring covered contractors to comply by December 31, 2030 with NIST Federal Information Processing Standards, including those with PQC algorithms.
- Within 270 days: CISA and NIST publish minimum elements for a cryptographic bill of materials (CBOM), which supports automated assessment of the cryptographic assets in hardware and software.
- Within 270 days: the FAR Council proposes a rule extending contractor vulnerability disclosure programs to cover cryptographic vulnerabilities, including missing encryption and non-FIPS-approved algorithms.
The contractor provisions matter to the channel. The deadlines reach vendors through the FAR and procurement, not only through agency migration.
OMB M-26-15: Execution of the Migration to Post-Quantum Cryptography (June 24, 2026)
Why it exists. The memo converts EO 14412 into agency operating requirements. OMB issued it two days after the order, although the order allowed ninety days.
The problem it addresses. Agencies lacked a shared sequence for inventory, prioritization, and migration, and a common view of which systems cannot support PQC at all.
What it requires:
- A migration plan within 120 days: every agency submits a PQC Migration Plan to OMB and the Office of the National Cyber Director, due approximately October 22, 2026. Plans align with NIST IR 8547 and cover system prioritization, milestones, inventory methodology, a cryptographic agility architecture, third-party coordination, and resource estimates.
- Automated discovery: agencies use automated cryptographic inventory and discovery tools, build PQC into zero trust architecture, and coordinate with FedRAMP-authorized cloud providers on shared migration responsibility.
- Replacement of systems that cannot migrate: systems that cannot support PQC or hybrid cryptography are identified for priority replacement or decommissioning.
- Hybrid and TLS 1.3: hybrid architectures are a valid transitional model, and TLS 1.3 is the network-level foundation, with a January 2, 2030 adoption deadline.
- Procurement: agencies build PQC requirements into purchasing. CISA and the Department of War lead PQC migration for multi-agency FedRAMP-authorized cloud services.
The memo sets five phases:
- Strategy, planning, and discovery (2026 to 2027)
- Pilots and early migration (2027 to 2028)
- Prioritized migration of key establishment (2028 to 2030)
- Digital signature migration (2031)
- Full migration of remaining systems (2035)
Combined timeline: December 2025 through 2035
Four deadlines land in the next seventy-three days: October 22, November 18, December 7, and December 18, 2026. Dates for EO 14409, EO 14412, NSPM-11, and M-26-15 are computed from the signing date plus the stated day count. Rows marked “Passed” show only that the date has passed. Public confirmation exists for each issuance date, for the Logging Reference Architecture, and for OMB’s implementing guidance under EO 14412, but not for every agency tasking.
| Date | Mandate | Milestone | Status |
| Dec 11, 2025 | M-26-04 | Issued; LLM contract requirements apply to new solicitations and orders | Passed |
| Feb 5, 2026 | BOD 26-02 | Issued | Passed |
| Mar 11, 2026 | M-26-04 | Agency procurement policies and user-reporting process due | Passed |
| May 5, 2026 | BOD 26-02 | Inventory of devices on CISA’s end-of-support list due | Passed |
| May 22, 2026 | M-26-14 | Issued; M-21-31 rescinded | Passed |
| Jun 2, 2026 | EO 14409 | Signed | Passed |
| Jun 5, 2026 | NSPM-11 | Signed; NSM-25 rescinded | Passed |
| Jun 10, 2026 | BOD 26-04 | Issued | Passed |
| Jun 22, 2026 | EO 14412 | Signed | Passed |
| Jun 24, 2026 | M-26-15 | Issued | Passed |
| Jul 2, 2026 | EO 14409 | 30-day taskings: CNSS and DoW cyber defense, CISA directives, Treasury clearinghouse, OMB grant review | Passed |
| Jul 22, 2026 | EO 14412 | Agency PQC migration leads named | Passed |
| Aug 1, 2026 | EO 14409 | 60-day taskings: covered-model benchmarking, voluntary framework, OPM hiring pathways | Passed |
| Aug 20, 2026 | M-26-14 | CISA publishes the Logging Reference Architecture | Passed |
| Sep 3, 2026 | NSPM-11 | 90-day taskings: DoDD 3000.09 update, national security AI governance policy, compute roadmap, classified annex | Passed |
| Sep 20, 2026 | EO 14412 | OMB implementing guidance due (issued Jun 24 as M-26-15) | Passed |
| Oct 3, 2026 | NSPM-11 | 120-day taskings: multi-vendor procurement, AI Security Center partnerships, AI security strategy, test and evaluation methods, strategic reserve, curriculum | Passed |
| Oct 22, 2026 | M-26-15 | Agency PQC Migration Plans due to OMB and ONCD | Upcoming |
| Nov 18, 2026 | M-26-14 | Agency Logging Plans due | Upcoming |
| Dec 7, 2026 | BOD 26-04 | Agencies begin remediating on the new timelines; FedRAMP VDR rules mandatory | Upcoming |
| Dec 18, 2026 | M-26-14 | Basic (Level 1) maturity across all elements | Upcoming |
| Dec 19, 2026 | EO 14412 | NIST pilot starts; module validation reforms; FAR proposed rule on contractor FIPS compliance | Upcoming |
| Feb 5, 2027 | BOD 26-02 | Decommission edge devices already past end of support at issuance | Upcoming |
| Feb 16, 2027 | M-26-14 | Intermediate (Level 2) maturity | Upcoming |
| Mar 19, 2027 | EO 14412 | CBOM minimum-elements guidance; FAR proposed rule on cryptographic vulnerability disclosure | Upcoming |
| Jul 6, 2027 | M-26-14 | Advanced (Level 3) maturity | Upcoming |
| Aug 5, 2027 | BOD 26-02 | All identified end-of-support edge devices replaced | Upcoming |
| Dec 11, 2027 | M-26-04 | Memo sunsets unless OMB extends it | Upcoming |
| Dec 31, 2027 | EO 14412 | NIST PQC pilot complete | Upcoming |
| Feb 5, 2028 | BOD 26-02 | Continuous edge-device discovery established | Upcoming |
| 2028 to 2030 | M-26-15 | Phase 3: prioritized PQC key-establishment migration | Beyond 24 months |
| Jan 2, 2030 | M-26-15 | TLS 1.3 adoption deadline | Beyond 24 months |
| Dec 31, 2030 | EO 14412 | PQC key establishment on HVAs and high-impact systems; contractor FIPS compliance date | Beyond 24 months |
| Dec 31, 2031 | EO 14412 | PQC digital signatures on the same systems | Beyond 24 months |
| 2035 | M-26-15 | Full migration of remaining systems | Beyond 24 months |
Annual cycles also apply. CISA re-evaluates the Logging Reference Architecture at least once a year and reassesses the BOD 26-04 remediation timelines once per fiscal year. Agencies under NSPM-11 review their AI policies annually.
What agencies and their partners should do now
The four near-term deadlines call for four workstreams. Each maps to a problem category the mandates define, so the work starts from the requirement rather than a product.
- Inventory cryptography (M-26-15, due October 22). Agency migration plans need an inventory methodology, a prioritization strategy, and a plan for systems that cannot support PQC. Start with high value assets and high-impact systems, and flag long-lived data. Add PQC requirements to vendor and procurement documents now, because the FAR rules proposed under EO 14412 will carry them to contractors.
- Align logging to the reference architecture (M-26-14, plan due November 18). Level 1 maturity, due December 18, requires at least 70 percent of IT, OT, and IoT assets captured in a centralized hardware and software asset inventory. Logging coverage cannot exceed inventory coverage, so asset visibility comes first.
- Rebuild vulnerability response around exposure and exploitation (BOD 26-04, effective December 7). The process needs public-exposure tagging of internet-reachable assets, KEV-driven triage, and a path to forensic triage inside three days. Cloud service providers carry the same December 7 date through FedRAMP. Pair this with the BOD 26-02 inventory of edge devices that are or will become end-of-support.
- Document AI offerings (M-26-04, NSPM-11). A vendor selling an LLM to a civilian agency needs the acceptable use policy, model or system cards, end-user resources, and a feedback channel for outputs that violate the Unbiased AI Principles. A reseller depends on the developer to supply them. For national security work, NSPM-11 adds contract terms that keep control of mission-critical AI systems with the government.
These mandates bind agencies directly, but their requirements travel into solicitations, task orders, and FedRAMP rules. A partner that can show readiness against the same milestones answers the agency’s question before the agency asks it.
About FRC
FRC is a public sector-focused value-added reseller headquartered in Erie, Pennsylvania. FRC works with federal, DoD, state and local, and commercial customers on cybersecurity strategy and solution selection. To discuss how these mandates map to your environment, contact the FRC team.



