Authorities library

The mandates our scopes are written against

Official outbound links to executive orders, OMB memoranda, NIST publications, and CISA directives. We cite these in proposals and delivery - not as summaries that replace the source.

Executive orders

EO 14409 Advanced AI Innovation & Security (2026)

2026

Shapes federal AI innovation and security expectations that drive high-impact AI work packages.

EO 14179 Removing Barriers to American Leadership in AI (2025)

2025

Sets the administration's AI acceleration posture that OMB M-25-21 and M-25-22 implement.

America's AI Action Plan (2025)

2025

National AI strategy context for agency AI governance and acquisition work.

EO 14306 Sustaining Select Cybersecurity Efforts (2025)

2025

Continues selected cybersecurity program requirements that inform zero trust and logging scopes.

EO 14144 Strengthening and Promoting Innovation in the Nation's Cybersecurity (2025)

2025

Cyber innovation and resilience mandates that show up in technical volumes.

EO 14028 Improving the Nation's Cybersecurity (2021, as amended)

2021

Foundational zero trust, logging, and supply-chain cybersecurity requirements.

OMB memoranda

OMB M-25-21 Accelerating Federal Use of AI

2025

High-impact determinations, impact assessments, monitoring, and human oversight.

OMB M-25-22 Efficient Acquisition of AI

2025

AI acquisition terms covering data rights, lock-in, and deployment constraints.

OMB M-26-14 Logging & Network Visibility

2026

Logging maturity milestones that rescind and replace M-21-31 expectations.

OMB M-22-09 Federal Zero Trust Strategy

2022

Zero trust pillars for identity, devices, networks, applications, and data.

NIST and frameworks

NIST SP 800-53 Rev. 5

Control baseline for ATO, FedRAMP, and continuous authorization work.

NIST SP 800-171

CUI protection requirements that shape secure AI and infrastructure design.

NIST SP 800-207 Zero Trust Architecture

Reference architecture for zero trust assessments and roadmaps.

NIST AI Risk Management Framework

Risk framing for AI guardrails, evaluation, and governance packages.

FedRAMP (Rev. 5 / 20x)

Authorization path for cloud and AI services entering federal use.

NIST Post-Quantum Cryptography Standards

PQC algorithm standards that drive crypto-agility and migration planning.

CISA directives and programs

CISA BOD 26-04 Risk-Based Vulnerability Remediation

2026

Risk-based remediation that supersedes BOD 19-02 and BOD 22-01.

CISA BOD 23-01 Asset Visibility

2022

Asset discovery and vulnerability detection cadence for CAASM work.

Continuous Diagnostics & Mitigation (CDM)

Federal dashboard and telemetry program tied to visibility scopes.

CISA Secure by Design

Secure product and system design expectations for federal programs.