In a statement issued by the White House, Trump’s administration accused Biden officials of attempting to “sneak problematic and distracting issues” into cybersecurity policy during their final days in office
Former President Donald Trump has signed a new executive order dismantling several major cybersecurity initiatives introduced by President Joe Biden, marking a sharp reversal in federal digital policy.
In a statement issued by the White House, Trump’s administration accused Biden officials of attempting to “sneak problematic and distracting issues” into cybersecurity policy during their final days in office. The Biden-era projects were formalised in a 15 January directive, just days before Trump assumed the presidency.
Trump’s order eliminates requirements that would have forced software vendors working with the federal government to prove compliance with newly established security standards. It also halts Biden’s push to accelerate the use of quantum-resistant encryption and efforts to prioritise artificial intelligence research in cyber defence.
The White House justified the rollback by arguing that Biden’s directives imposed “unproven and burdensome software accounting processes” that favoured bureaucracy over practical security gains. “President Trump has made it clear that this administration will do what it takes to make America cyber secure,” the fact sheet read, highlighting a renewed emphasis on “technical and organisational professionalism.”
The move signals a fundamental shift in federal cyber regulation. Biden’s original efforts, initiated through a 2021 executive order and expanded in 2024, aimed to improve digital safety by leveraging the government’s vast purchasing power. The idea was to hold software providers accountable by requiring “secure software development attestations” – signed declarations of adherence to best practices – backed by technical data and subjected to review by the Cybersecurity and Infrastructure Security Agency (CISA).
Those measures have now been struck from the federal playbook. Trump’s directive removes the requirement for vendors to submit attestations, CISA’s authority to verify them, and the mandate for the Office of the National Cyber Director to publish review outcomes. It also eliminates language encouraging the referral of non-compliant companies to the Department of Justice.
The Trump administration contends that such frameworks prioritised form over function. “Compliance checklists do not equate to security,” an official familiar with the new order said.
The rollback is likely to draw mixed reactions across industry and policy circles. While some software vendors may welcome the reduced administrative burden, cybersecurity experts have warned that removing federal oversight mechanisms could undermine national cyber resilience, particularly as threats from state-sponsored actors and criminal groups continue to evolve.

