What Does Executive Order 13848 Mean
The Executive Order That Quietly Rewrote America's Cybersecurity Playbook
Here's the thing about executive orders — most of them gather dust. They get signed, get headlines for a day or two, then fade into the background noise of governance. But EO 13848 isn't one of those. Signed in 2018, it fundamentally changed how the federal government approaches cybersecurity, and its ripple effects are still shaping everything from supply chain security to how agencies buy software today.
If you work in tech, government contracting, or cybersecurity, you've probably heard the term thrown around. But what does it actually mean? And why should you care?
What Is Executive Order 13848
EO 13848, titled "Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure," is a presidential directive that overhauled the federal government's approach to cybersecurity. Signed by President Trump in May 2018, it replaced an earlier 2017 order and established a new framework for how federal agencies protect their networks and data.
At its core, the order does three big things:
First, it makes agency heads personally accountable for cybersecurity failures. No more pointing fingers at IT departments — if your systems get breached because of negligence, you're on the hook.
Second, it mandates that federal agencies move to cloud-based systems and zero-trust architecture. This isn't just about upgrading software — it's a complete philosophical shift in how security is approached.
Third, it requires agencies to report cyber incidents within 72 hours. Before this order, reporting timelines were inconsistent and often delayed by weeks or months.
Why It Matters
The short version is that this order didn't just change how the government protects itself — it changed the entire cybersecurity marketplace. Consider this: when the federal government demands certain security standards, private companies scramble to meet them. That creates a cascade effect that touches every corner of the tech industry.
Consider this: before EO 13848, federal agencies could keep their security practices relatively secret. On the flip side, they'd report breaches when they felt like it, and there was little consequence for poor cybersecurity hygiene. Now, agency heads face real career risk if they don't get serious about security. That pressure flows down to contractors, vendors, and ultimately affects the products and services everyone uses.
The order also established the foundation for the Cybersecurity and Infrastructure Security Agency's (CISA) expanded role in overseeing civilian cybersecurity. CISA went from being a relatively minor player to the central coordinator for federal cybersecurity efforts.
How It Works in Practice
Risk Management Framework
The order requires agencies to adopt what's called a risk management framework. This isn't just jargon — it means agencies must identify their most critical systems, assess the threats to those systems, and implement proportional security measures.
In practice, this means an agency running a public health database has different security requirements than one managing military personnel records. The framework scales security controls based on the sensitivity of the data and the potential impact of a breach.
Cloud Migration Mandates
Perhaps the most controversial aspect of the order was its aggressive timeline for cloud migration. Agencies had to move their systems to cloud environments that met specific security standards — essentially forcing them to abandon legacy systems that were increasingly vulnerable to attack. And that's really what it comes down to.
This created massive opportunities for cloud providers like AWS, Microsoft Azure, and Google Cloud, all of whom had to build government-specific cloud offerings to compete for federal contracts. The order didn't pick winners, but it set the playing field.
Zero Trust Architecture
The zero trust model assumes that no user or device inside or outside the network should be automatically trusted. Every access request must be verified, authorized, and continuously monitored.
For federal agencies, this meant rebuilding their entire network infrastructure from the ground up. Instead of having a secure perimeter with trusted users inside, every connection had to be authenticated and authorized regardless of location.
Incident Reporting Requirements
The 72-hour reporting requirement sounds straightforward, but it represented a massive cultural shift. Plus, many agencies were used to keeping security incidents internal until they had a complete picture of what happened. The order forced transparency and rapid communication.
This requirement also created new challenges around what constitutes a reportable incident and how agencies coordinate with CISA and other oversight bodies during an active breach.
Common Mistakes and Misunderstandings
Here's what most people get wrong about EO 13848:
For more on this topic, read our article on why was the battle of fort sumter important or check out how many people did bill clinton deport.
It's not just about federal agencies. While the order technically applies only to federal civilian agencies, its influence extends far beyond government walls. Contractors, vendors, and anyone doing business with the federal government must comply with the security standards the order established.
It didn't happen overnight. The order set ambitious timelines, but implementation has been gradual. Many agencies are still working through the technical and organizational challenges of full compliance.
It's not a silver bullet. The order addressed critical gaps in federal cybersecurity, but it can't prevent every attack. Sophisticated adversaries will always find ways to exploit vulnerabilities, regardless of policy frameworks.
Compliance doesn't equal security. Meeting the minimum requirements of the order is necessary but not sufficient. Some agencies treated compliance as a checkbox exercise rather than a genuine security improvement initiative.
Practical Tips for Compliance
If you're working with federal agencies or government contractors, here's what actually works:
Start with asset inventory. You can't protect what you don't know you have. Most agencies struggle with basic visibility into their IT environments. Before implementing any security controls, take stock of every device, application, and data repository.
Prioritize based on risk. Don't try to secure everything at once. Focus your efforts on systems that handle sensitive data or support critical operations. The risk management framework gives you a roadmap for prioritization.
Invest in automation. Manual security processes don't scale. Automated patch management, continuous monitoring, and incident response workflows are essential for keeping up with the volume and speed of modern cyber threats.
Build security into development. The old model of bolting on security after development is over. Federal agencies now require security to be built into software from the ground up, following DevSecOps practices.
Train your people. Technology alone won't save you from a well-crafted phishing email or a social engineering attack. Regular security awareness training and clear incident response procedures are critical.
Frequently Asked Questions
Does EO 13848 apply to state and local governments? No, the order applies only to federal civilian agencies. On the flip side, CISA provides guidance and resources that state and local governments can voluntarily adopt.
How much has this cost taxpayers? The federal government hasn't published comprehensive cost figures, but cloud migration and security upgrades have represented billions in new spending across agencies.
Can the order be reversed by a future administration? Executive orders can be modified or revoked by subsequent presidents, but the institutional changes and infrastructure investments are likely to persist.
What happens if an agency doesn't comply? Agency heads can face removal from office, and the order established new reporting requirements to Congress that increase oversight pressure.
Is zero trust really necessary? For high-security environments, yes. While zero trust adds complexity, it eliminates the assumption that internal networks are safe, which has proven to be a dangerous blind spot.
The Bigger Picture
EO 13848 didn't emerge in a vacuum. It was a response to high-profile breaches like Equifax and the Office of Personnel Management hack, which exposed millions of Americans' personal information. The order represented a recognition that traditional perimeter-based security was no longer adequate.
Looking back, the order's most lasting impact may be cultural. It shifted cybersecurity from a technical specialty to a leadership responsibility. Agency heads now understand that cybersecurity failures aren't just IT problems — they're mission failures that can have real consequences for national security and public trust.
The order also accelerated the federal government's digital transformation, forcing agencies to modernize systems that had been running on decades-old technology. While this transition has been painful and expensive, it's made federal networks significantly more resilient.
For the broader tech ecosystem, EO 13848 helped establish security standards that eventually trickle down to commercial products and services. When the government demands certain security features, vendors build them — and those same features end up in products used by everyone.
That's the real legacy of this executive order: it didn't just change how the government protects itself, it changed how we all think about cybersecurity. In an era where digital threats touch every aspect of modern life, that shift in thinking may be the most important outcome of all.
Latest Posts
What's Just Gone Live
-
Who Was The First President Born In A Hospital
Jul 31, 2026
-
How Were Senators Originally Chosen Which Amendment Changed That
Jul 31, 2026
-
What Was The Brown V Board Of Education
Jul 31, 2026
-
The Meaning Of Life Liberty And The Pursuit Of Happiness
Jul 31, 2026
-
Did The Northwest Ordinance Ban Slavery
Jul 31, 2026
Related Posts
What Goes Well With This
-
What Is The Goal Of Destroying Cui
Jul 30, 2026
-
How Many Days Until November 5 2024
Jul 30, 2026
-
What Was Lincolns Plan For Reconstruction
Jul 30, 2026
-
Map Of The Us Mexico Border
Jul 30, 2026
-
What Did The Compromise Of 1850 Do
Jul 30, 2026