国家安全总统备忘录/NSPM-12
来源:白宫 (White House) | 时间:2026-06-12T19:19:12+00:00
副总统备忘录 国务卿 财政部长 陆军部长 司法部长 内政部长 农业部长 商务部长 劳工部长 卫生和公共服务部部长 住房和住房部部长城市发展部长 [...] 国家安全后总统备忘录/NSPM-12 首先出现在白宫。
总统行动
国家安全总统备忘录/NSPM-12
总统备忘录
2026 年 6 月 12 日
副总统备忘录
国务卿
财政部长
战争部长
司法部长
内政部长
农业部长
商务部长
劳工部长
卫生与公众服务部部长
住房和城市发展局局长
交通运输局局长
能源部长
教育局局长
退伍军人事务部长
国土安全部长
白宫办公厅主任
政策副参谋长兼国土安全顾问
管理和预算办公室主任
国家情报总监
总统科学技术助理
总统国家安全事务助理
总统助理兼总统顾问
参谋长联席会议主席
中央情报局局长
国家安全局局长
一般服务管理局局长
国家网络总监
网络安全和基础设施安全局局长
主题:国家安全系统网络安全国家政策
作为总统,我的首要任务是确保美国能够在有争议的网络环境中执行关键的军事和情报任务,并确保我们的人员能够获得完成这些任务所需的现代、安全技术。战争部 (DOW)、情报界 (IC) 和联邦民事行政部门 (FCEB) 机构作为国家安全系统 (NSS) 拥有或运营该技术。美国政府的政策是在可行的最大程度上保护这些系统,并且行政部门和机构负责人通过政府范围的监督机制对这种保护负责。因此,根据美国宪法和法律(包括《美国法典》第 44 章第 3557 条和《美国法典》第 3 章第 301 条)赋予我的权力,特此命令:
第 1 节。目的 。 (a) 本国家安全总统备忘录规定了国家安全局的原则并建立了网络安全治理。它进一步详细说明了国家安全系统委员会(CNSS)的治理结构以及国家安全局(NSA)局长作为国家安全系统国家管理者的角色。
(b) 本备忘录进一步规定了 NSS 的要求,这些要求相当于或超过 2025 年 6 月 6 日第 14306 号行政命令(持续加强国家网络安全的选择性努力以及修订第 13694 号行政命令和第 14144 号行政命令)中规定的其他联邦信息系统的网络安全要求。
秒。 2.政策 。 (a) 1990年7月5日的国家安全指令42(NSD-42)(国家安全电信和信息系统安全的国家政策)和2022年1月19日的国家安全备忘录8(NSM-8)(关于改进国家安全、国防部和情报社区系统的网络安全的备忘录)特此废除。
(b) 美国政府的政策是为所有国家安全部门培育一个主动、适应性和弹性的网络安全生态系统,以更好地保护国家免受来自老练对手的持续网络威胁。为此,本备忘录为 NSS 的治理以及 NSS 所有者和运营商的责任建立了清晰的权力、角色和责任结构。本备忘录应:
(i) 加强国家网络防御治理和问责制,并重新建立和指定 CNSS 的明确治理角色和权限范围;
(ii) 重新设立并授权 NSS 国家经理来识别新出现的威胁,向 CNSS 提供建议,发布紧急指令,为密码学和密码系统提供权威的最低要求,并通过 CNSS 为分类级别的分离(无论是在系统之间还是在同一系统上)提供直接的技术解决方案;
(iii) 通过促进跨机构、公私伙伴关系和国际联络活动的协调和信息共享,促进协作、标准化和有效的资源管理;和
(iv) 促进有效利用纳税人资金来确保国家社会保障。
秒。 3.国家安全系统委员会。 (a) 重新设立国家安全系统委员会 (CNSS),以加强 DOW、IC 和 FCEB 机构之间的责任和协调,以对所有 NSS 实施必要的网络防御。 CNSS 应在国家安全委员会 (NSC) 工作人员的协调下运作,该工作人员应担任主席。
(i) CNSS 成员应包括:
(A) 战争部长,通过 DOW 首席信息官 (CIO) 行事;
(B) 国家情报总监 (DNI),通过 IC CIO 行事;
(C) 管理和预算办公室 (OMB) 主任,通过联邦 CIO 行事;和
(D) 国家安全局局长担任国家经理,通过副国家经理行事。
(ii) 下列官员可以推荐代表作为 CNSS 成员的顾问:
(A) 司法部长;
(B) 商务部长;
(C) 中央情报局局长;
(D) 负责国家安全事务的总统助理;
(E) 总统科学技术助理;
(F) 国家网络主任;
(G) 参谋长联席会议主席;
(H) 网络安全和基础设施安全局(CISA)主任;和
(一)国家安全委员会认为必要的其他顾问。
(b) CNSS 的目标是:
(i) 为所有 NSS 制定基线网络安全要求;
(ii) 通过成员各自的法定权力和授权,让 NSS 所有者和运营商负责实施所需的安全措施;
(iii) 在机构间论坛、公共论坛、国会和监察长理事会中代表 NSS 生态系统、所有者和运营商对诚信和效率的要求;
(iv) 与 NSS 共享服务提供商协调,在可行的情况下促进安全共享服务的有效使用;和
(v) 促进建立共享平台或论坛,以传播和获取 CNSS 指南和决策、NSS 要求和相关政策,所有 NSS 最终用户 IC、DOW 和 FCEB 机构均可访问。
(c) CNSS 通过其成员按照《美国法典》第 3 章第 301 节行事,应发布适用于所有 NSS 的指令和补充标准,包括根据本节 (c)(i) 和 (c)(ii) 小节发布的指令和标准。拥有或运营 NSS 的机构应遵守 CNSS 发布的所有指令和补充标准。
(i) 为了保护 NSS 免受已知或合理怀疑的信息安全威胁、漏洞或风险的影响,CNSS 可以通过该机构的 CIO、首席信息安全官 (CISO) 或机构负责人指定的其他官员向机构负责人发出指令,要求对该 NSS 的运行采取任何合法行动,以保护系统免受或减轻威胁、漏洞或风险。
(ii) NSS 应达到或超过美国国家标准与技术研究院 (NIST) 发布的网络安全标准的保护级别,除非 CNSS 另有规定。
(A) CNSS 可以发布补充标准,以在适当的情况下调整 NIST 规定的 NSS 基线。
(B) CNSS 政策 (CNSSP) 15 或后续政策或国家管理者的临时指南将构成 NSS 的商业密码标准。
(C) 除非特殊情况
[正文过长,已截取前部进行翻译]
国家安全总统备忘录/NSPM-12
总统备忘录
2026 年 6 月 12 日
副总统备忘录
国务卿
财政部长
战争部长
司法部长
内政部长
农业部长
商务部长
劳工部长
卫生与公众服务部部长
住房和城市发展局局长
交通运输局局长
能源部长
教育局局长
退伍军人事务部长
国土安全部长
白宫办公厅主任
政策副参谋长兼国土安全顾问
管理和预算办公室主任
国家情报总监
总统科学技术助理
总统国家安全事务助理
总统助理兼总统顾问
参谋长联席会议主席
中央情报局局长
国家安全局局长
一般服务管理局局长
国家网络总监
网络安全和基础设施安全局局长
主题:国家安全系统网络安全国家政策
作为总统,我的首要任务是确保美国能够在有争议的网络环境中执行关键的军事和情报任务,并确保我们的人员能够获得完成这些任务所需的现代、安全技术。战争部 (DOW)、情报界 (IC) 和联邦民事行政部门 (FCEB) 机构作为国家安全系统 (NSS) 拥有或运营该技术。美国政府的政策是在可行的最大程度上保护这些系统,并且行政部门和机构负责人通过政府范围的监督机制对这种保护负责。因此,根据美国宪法和法律(包括《美国法典》第 44 章第 3557 条和《美国法典》第 3 章第 301 条)赋予我的权力,特此命令:
第 1 节。目的 。 (a) 本国家安全总统备忘录规定了国家安全局的原则并建立了网络安全治理。它进一步详细说明了国家安全系统委员会(CNSS)的治理结构以及国家安全局(NSA)局长作为国家安全系统国家管理者的角色。
(b) 本备忘录进一步规定了 NSS 的要求,这些要求相当于或超过 2025 年 6 月 6 日第 14306 号行政命令(持续加强国家网络安全的选择性努力以及修订第 13694 号行政命令和第 14144 号行政命令)中规定的其他联邦信息系统的网络安全要求。
秒。 2.政策 。 (a) 1990年7月5日的国家安全指令42(NSD-42)(国家安全电信和信息系统安全的国家政策)和2022年1月19日的国家安全备忘录8(NSM-8)(关于改进国家安全、国防部和情报社区系统的网络安全的备忘录)特此废除。
(b) 美国政府的政策是为所有国家安全部门培育一个主动、适应性和弹性的网络安全生态系统,以更好地保护国家免受来自老练对手的持续网络威胁。为此,本备忘录为 NSS 的治理以及 NSS 所有者和运营商的责任建立了清晰的权力、角色和责任结构。本备忘录应:
(i) 加强国家网络防御治理和问责制,并重新建立和指定 CNSS 的明确治理角色和权限范围;
(ii) 重新设立并授权 NSS 国家经理来识别新出现的威胁,向 CNSS 提供建议,发布紧急指令,为密码学和密码系统提供权威的最低要求,并通过 CNSS 为分类级别的分离(无论是在系统之间还是在同一系统上)提供直接的技术解决方案;
(iii) 通过促进跨机构、公私伙伴关系和国际联络活动的协调和信息共享,促进协作、标准化和有效的资源管理;和
(iv) 促进有效利用纳税人资金来确保国家社会保障。
秒。 3.国家安全系统委员会。 (a) 重新设立国家安全系统委员会 (CNSS),以加强 DOW、IC 和 FCEB 机构之间的责任和协调,以对所有 NSS 实施必要的网络防御。 CNSS 应在国家安全委员会 (NSC) 工作人员的协调下运作,该工作人员应担任主席。
(i) CNSS 成员应包括:
(A) 战争部长,通过 DOW 首席信息官 (CIO) 行事;
(B) 国家情报总监 (DNI),通过 IC CIO 行事;
(C) 管理和预算办公室 (OMB) 主任,通过联邦 CIO 行事;和
(D) 国家安全局局长担任国家经理,通过副国家经理行事。
(ii) 下列官员可以推荐代表作为 CNSS 成员的顾问:
(A) 司法部长;
(B) 商务部长;
(C) 中央情报局局长;
(D) 负责国家安全事务的总统助理;
(E) 总统科学技术助理;
(F) 国家网络主任;
(G) 参谋长联席会议主席;
(H) 网络安全和基础设施安全局(CISA)主任;和
(一)国家安全委员会认为必要的其他顾问。
(b) CNSS 的目标是:
(i) 为所有 NSS 制定基线网络安全要求;
(ii) 通过成员各自的法定权力和授权,让 NSS 所有者和运营商负责实施所需的安全措施;
(iii) 在机构间论坛、公共论坛、国会和监察长理事会中代表 NSS 生态系统、所有者和运营商对诚信和效率的要求;
(iv) 与 NSS 共享服务提供商协调,在可行的情况下促进安全共享服务的有效使用;和
(v) 促进建立共享平台或论坛,以传播和获取 CNSS 指南和决策、NSS 要求和相关政策,所有 NSS 最终用户 IC、DOW 和 FCEB 机构均可访问。
(c) CNSS 通过其成员按照《美国法典》第 3 章第 301 节行事,应发布适用于所有 NSS 的指令和补充标准,包括根据本节 (c)(i) 和 (c)(ii) 小节发布的指令和标准。拥有或运营 NSS 的机构应遵守 CNSS 发布的所有指令和补充标准。
(i) 为了保护 NSS 免受已知或合理怀疑的信息安全威胁、漏洞或风险的影响,CNSS 可以通过该机构的 CIO、首席信息安全官 (CISO) 或机构负责人指定的其他官员向机构负责人发出指令,要求对该 NSS 的运行采取任何合法行动,以保护系统免受或减轻威胁、漏洞或风险。
(ii) NSS 应达到或超过美国国家标准与技术研究院 (NIST) 发布的网络安全标准的保护级别,除非 CNSS 另有规定。
(A) CNSS 可以发布补充标准,以在适当的情况下调整 NIST 规定的 NSS 基线。
(B) CNSS 政策 (CNSSP) 15 或后续政策或国家管理者的临时指南将构成 NSS 的商业密码标准。
(C) 除非特殊情况
[正文过长,已截取前部进行翻译]
Presidential Actions
NATIONAL SECURITY PRESIDENTIAL MEMORANDUM/NSPM-12
Presidential Memoranda
June 12, 2026
MEMORANDUM FOR THE VICE PRESIDENT
THE SECRETARY OF STATE
THE SECRETARY OF THE TREASURY
THE SECRETARY OF WAR
THE ATTORNEY GENERAL
THE SECRETARY OF THE INTERIOR
THE SECRETARY OF AGRICULTURE
THE SECRETARY OF COMMERCE
THE SECRETARY OF LABOR
THE SECRETARY OF HEALTH AND HUMAN SERVICES
THE SECRETARY OF HOUSING AND URBAN DEVELOPMENT
THE SECRETARY OF TRANSPORTATION
THE SECRETARY OF ENERGY
THE SECRETARY OF EDUCATION
THE SECRETARY OF VETERANS AFFAIRS
THE SECRETARY OF HOMELAND SECURITY
THE WHITE HOUSE CHIEF OF STAFF
THE DEPUTY CHIEF OF STAFF FOR POLICY AND HOMELAND SECURITY ADVISOR
THE DIRECTOR OF THE OFFICE OF MANAGEMENT AND BUDGET
THE DIRECTOR OF NATIONAL INTELLIGENCE
THE ASSISTANT TO THE PRESIDENT FOR SCIENCE AND TECHNOLOGY
THE ASSISTANT TO THE PRESIDENT FOR NATIONAL SECURITY AFFAIRS
THE ASSISTANT TO THE PRESIDENT AND COUNSEL TO THE PRESIDENT
THE CHAIRMAN OF THE JOINT CHIEFS OF STAFF
THE DIRECTOR OF THE CENTRAL INTELLIGENCE AGENCY
THE DIRECTOR OF THE NATIONAL SECURITY AGENCY
THE ADMINISTRATOR OF GENERAL SERVICES
THE NATIONAL CYBER DIRECTOR
THE DIRECTOR OF THE CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY
SUBJECT: National Policy for the Cybersecurity of National Security Systems
As President, it is my priority to ensure that the United States can conduct key military and intelligence missions in contested cyber environments and that our personnel have access to the modern, secure technology they need to accomplish these missions. The Department of War (DOW), Intelligence Community (IC), and Federal Civilian Executive Branch (FCEB) Agencies own or operate this technology as National Security Systems (NSS). It shall be the policy of the United States Government that these systems be defended to the greatest extent practicable and that executive department and agency (agency) heads be accountable for this defense through government-wide oversight mechanisms. Therefore, by the authority vested in me by the Constitution and the laws of the United States, including section 3557 of title 44, United States Code, and section 301 of title 3, United States Code, it is hereby ordered:
Section 1 . Purpose . (a) This National Security Presidential Memorandum sets forth principles and establishes cybersecurity governance for NSS. It further details the governance structure of the Committee on National Security Systems (CNSS) and the role of the Director, National Security Agency (NSA) as the National Manager for NSS.
(b) This memorandum further sets forth requirements for NSS that are equivalent to or exceed the cybersecurity requirements for other Federal Information Systems set forth within Executive Order 14306 of June 6, 2025 (Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144).
Sec . 2 . Policy . (a) National Security Directive 42 (NSD‑42) of July 5, 1990 (National Policy for the Security of National Security Telecommunications and Information Systems) and National Security Memorandum 8 (NSM-8) of January 19, 2022 (Memorandum on Improving the Cybersecurity of National Security, Department of Defense, and Intelligence Community Systems) are hereby rescinded.
(b) It shall be the policy of the United States Government to foster a proactive, adaptive, and resilient cybersecurity ecosystem for all NSS to better safeguard the Nation against persistent cyber threats from sophisticated adversaries. To this end, this memorandum establishes a clear structure of authorities, roles, and responsibilities for the governance of NSS as well as accountability for owners and operators of NSS. This memorandum shall:
(i) enhance national cyber defense governance and accountability and re-establish and designate clear governance roles and scope of authorities for the CNSS;
(ii) re-establish and empower a National Manager for NSS to identify emerging threats, advise the CNSS, issue emergency directives, provide authoritative minimum requirements for cryptology and cryptographic systems, and, through the CNSS, direct technical solutions for separation of classification levels (whether between systems or on the same system);
(iii) foster collaboration, standardization, and efficient resource management by promoting coordination and information sharing across agencies, public-private partnerships, and international liaison activities; and
(iv) promote efficient use of taxpayer funds in securing NSS.
Sec . 3 . The Committee on National Security Systems . (a) The Committee on National Security Systems (CNSS) is re-established to enhance accountability and coordination across the DOW, the IC, and FCEB Agencies in implementing necessary cyber defenses on all NSS. The CNSS shall operate under the coordination of a member of the National Security Council (NSC) staff, who shall serve as Chair.
(i) The CNSS members shall consist of:
(A) the Secretary of War, acting through the DOW Chief Information Officer (CIO);
(B) the Director of National Intelligence (DNI), acting through the IC CIO;
(C) the Director of the Office of Management and Budget (OMB), acting through the Federal CIO; and
(D) the Director of the NSA as National Manager, acting through the Deputy National Manager.
(ii) The following officials may recommend representatives as advisors to the members of the CNSS:
(A) the Attorney General;
(B) the Secretary of Commerce;
(C) the Director of the Central Intelligence Agency (CIA);
(D) the Assistant to the President for National Security Affairs;
(E) the Assistant to the President for Science and Technology;
(F) the National Cyber Director;
(G) the Chairman of the Joint Chiefs of Staff;
(H) the Director of the Cybersecurity and Infrastructure Security Agency (CISA); and
(I) any other advisors as the CNSS deems necessary.
(b) The objectives of the CNSS shall be to:
(i) establish baseline cybersecurity requirements for all NSS;
(ii) through the respective statutory and delegated authorities held by the members, hold NSS owners and operators accountable for implementing required security measures;
(iii) represent the requirements of the NSS ecosystem, owners, and operators in interagency fora, public fora, the Congress, and the Council of Inspectors General on Integrity and Efficiency;
(iv) coordinate with NSS shared service providers to promote efficient use of secure shared services where practicable; and
(v) facilitate a shared platform or forum for dissemination and access to CNSS guidance and decisions, NSS requirements, and related policies, accessible by all NSS end-user IC, DOW, and FCEB Agencies.
(c) The CNSS, acting through its members consistent with section 301 of title 3, United States Code, shall issue directives and complementary standards that apply to all NSS, including directives and standards issued under subsections (c)(i) and (c)(ii) of this section. The agencies that own or operate NSS shall comply with all directives and complementary standards issued by the CNSS.
(i) For the purposes of safeguarding NSS from a known or reasonably suspected information security threat, vulnerability, or risk, the CNSS may issue a directive to the head of an agency, through that agency’s CIO, Chief Information Security Officer (CISO), or other officer designated by the head of the agency, to take any lawful action with respect to the operation of that NSS for the purpose of protecting the system from, or mitigating, the threat, vulnerability, or risk.
(ii) NSS shall meet or exceed the protection level of cybersecurity standards issued by the National Institute of Standards and Technology (NIST) unless the CNSS provides otherwise.
(A) The CNSS may issue a complementary standard to adapt NIST-prescribed baselines for NSS where appropriate.
(B) CNSS Policy (CNSSP) 15, or successor policy, or interim guidance from the National Manager, will constitute the commercial cryptographic standard for NSS.
(C) Unless specifically stated by the CNSS or a complementary CNSS issuance exists, all relevant standards issued by NIST shall apply as a minimum baseline to secure NSS.
(d) The CNSS shall have a permanent Executive Secretariat composed of personnel provided by the National Manager. The National Manager shall further provide facilities and support as required. Other agencies shall provide facilities and support as requested by the CNSS, consistent with applicable law.
(i) The Secretary of War, through the DOW CIO, in coordination with the DNI, through the IC CIO, shall be responsible for overseeing the activities of the Executive Secretariat.
(ii) The Executive Secretariat shall be responsible for maintaining an authoritative, machine-readable portal of CNSS guidance applicable to NSS as well as a collaborative environment that is accessible by all NSS owners and operators on Unclassified, Secret, and Top Secret/Sensitive Compartmented Information (TS/SCI) systems.
Sec . 4 . Policy Coordination Committee . (a) A Policy Coordination Committee (PCC) for NSS shall be formed pursuant to National Security Presidential Memorandum 1 of January 20, 2025 (Organization of the National Security Council and Subcommittees).
(i) The PCC shall be chaired by a member of the NSC staff and shall consist of representatives of the members and advisors from the CNSS.
(ii) Agencies that operate NSS may be invited at the discretion of the PCC chair.
(b) The PCC through the CNSS may request an assessment of the cybersecurity posture of NSS government-wide, to include performance metrics, cybersecurity assessment results, and compliance with current policy. The PCC chair may request that the National Manager conduct such assessment.
Sec . 5 . The National Manager for NSS . (a) The Director of the NSA is the National Manager for NSS and will carry out the certain responsibilities in accordance with existing law, Executive Orders, and other Presidential directives. In this capacity the National Manager is responsible for providing technical advice to the CNSS and:
(i) providing recommendations on incident response for security incidents that impact NSS government-wide; and
(ii) as referenced in section 2(b)(ii) of this memorandum, in response to a known or reasonably suspected information security threat, vulnerability, or risk that represents a substantial threat to the information security of NSS, or in response to intelligence of adversary capability and intent to target NSS, the National Manager may issue an emergency directive to the head of an agency, through that agency’s CIO, CISO, or officer designated by the head of the agency, to take any lawful action with respect to the operation of that NSS, including such systems used or operated by another entity on behalf of an agency, for the purpose of protecting the NSS from, or mitigating, the threat, vulnerability, or risk.
(b) The National Manager shall serve as the cryptologic authority for NSS. Through this role, the National Manager shall, in accordance with applicable law and policy:
(i) design, build, test, deliver, and protect cryptographic keys and codes capabilities;
(ii) review, approve, and publish standards related to the security of NSS;
(iii) develop, evaluate and approve techniques, systems, products, solutions, and equipment related to the cybersecurity of NSS, provided that nothing in this provision shall restrict agencies from testing cryptography on NSS that they own or operate;
(iv) operate such printing, fabrication, and other facilities as may be required to perform critical functions related to the provisions of cryptographic, identity, key management, and other technical security material or services;
(v) in consultation with the CNSS, prescribe the minimum standards, methods, and procedures for protecting cryptographic and other technical security material, techniques, and information related to NSS; and
(vi) enter into agreements for the procurement of technical security material and other equipment, their provision to agencies, and, where appropriate, government contractors and foreign governments.
(c) The National Manager shall assess the cybersecurity posture of NSS across the United States Government on behalf of the CNSS and serve as a technical advisor to the CNSS and agencies that own or operate NSS, in alignment with provisions set forth in section 9 of this memorandum. Through this role the National Manager shall:
(i) in consultation with the CNSS, develop government-wide performance metrics for the defense of NSS, and coordinate with the CNSS chair and CNSS members and advisors on any CNSS collection of those metrics on a regular basis from each agency that owns or operates NSS;
(ii) assess the overall security posture of and disseminate information on threats to and vulnerabilities in NSS;
(iii) operate a technical center to evaluate and certify the security of NSS;
(iv) request from the heads of agencies, through an agency’s CIO, CISO, or other officer designated by the head of the agency, such information and technical support as may be needed to discharge the responsibilities assigned herein;
(v) conduct, coordinate, or endorse research and development of techniques and equipment to secure NSS;
(vi) upon request, provide cybersecurity services and technical assistance to NSS owners and operators;
(vii) examine NSS and evaluate their vulnerability to foreign interception and exploitation, provided no examination or monitoring shall be performed without advising the CIO of the agency that owns or operates the NSS; and
(viii) conduct foreign cryptographic and cybersecurity liaison relationships, including by providing information, services, and support and by entering into agreements with foreign governments and with international and private organizations regarding NSS. Any liaison conducted with foreign intelligence or security services shall be carried out in coordination with the Secretary of War, the DNI, and the Director of the CIA in accordance with Executive Order 12333 of December 4, 1981 (United States Intelligence Activities), as amended. Any such agreements shall be coordinated with affected agencies.
(d) The National Manager, through the CNSS, shall establish requirements for cross-domain solutions and alternative technical solutions for the separation of security domains for NSS. Through this role, the National Manager shall:
(i) serve as the principal advisor to NSS owners and operators on cross-domain capabilities;
(ii) develop and maintain community outreach programs and fora focused on cross-domain solutions;
(iii) develop and establish improved security solutions, standards, and technologies for cross-domain solutions; and
(iv) perform comprehensive testing for establishment of approved cross-domain solution products.
(e) NSS owned or operated by civilian agencies play an important role in many military and intelligence missions. Additionally, heads of civilian agencies are accountable for protection of classified material that is stored or processed on NSS that are owned or operated by such agencies. The Director of OMB, with support from the National Manager, and acting through the Federal CIO as appropriate, shall oversee compliance of FCEB Agencies with NSS policies and directives with the exception of agencies and agency components that are part of the IC. National Manager support may include:
(i) collection of metrics and direct assessment of the cybersecurity posture of NSS owned or operated by FCEB Agencies;
(ii) provision of technical assistance upon request to NSS owners and operators on the implementation of the NSS policies; and
(iii) consistent with applicable law, assignment of personnel to the Office of the Federal CIO to align and enhance oversight across FCEB Agencies.
(f) The National Manager may partner and collaborate with the heads of other agencies on matters related to cybersecurity, including with the heads of CISA and NIST, as well as the private sector and academia, to carry out the responsibilities assigned herein in accordance with applicable law and policy.
Sec . 6 . Implementation . (a) Within 30 days of the date of this memorandum, the CNSS shall revise CNSS Directive 900 of May 2013 (Committee on National Security Systems (CNSS) Governing and Operating Procedures), and any other policies as the CNSS deems appropriate, to incorporate the changes set forth in this memorandum.
(b) The CNSS and the National Manager shall take the following steps to harmonize NSS policies:
(i) within 60 days of the date of this memorandum, the CNSS shall issue a roadmap and policy priority areas for NSS to be applied in the next calendar year;
(ii) within 90 days of the date of this memorandum, the CNSS shall determine which National Manager Binding Operational Directives and other National Manager policies, including those related to NSM-8, with the exception of National Manager Emergency Directives, must be maintained and, where appropriate, incorporate those requirements into CNSS Directives. Upon completion of this process, the National Manager shall take necessary steps to rescind all National Manager Binding Operational Directives and Memoranda related to NSM-8 as appropriate; and
(iii) within 90 days of the date of this memorandum, the CNSS shall review all existing CNSS policies, directives, and instructions to determine which should be rescinded or harmonized. The CNSS shall complete rescission or harmonization of identified policies within 90 days of the completion of this review.
(c) Effective incident reporting for incidents that occur on or impact NSS is essential to minimize risk to the critical missions enabled by these systems and drive accountability for owners and operators, including civilian, defense, and intelligence agencies.
(i) Within 60 days of the date of this memorandum, the National Manager shall recommend to the CNSS new or modified incident reporting standards that enable government-wide awareness of incidents impacting NSS. This recommendation shall include thresholds for required reporting of incidents.
(ii) Within 60 days of the receipt of the National Manager’s recommendations, the CNSS shall update applicable CNSS policies to incorporate those recommendations as appropriate.
(iii) Within 60 days of the release of the incident reporting standards described in section 6(c)(i) of this memorandum, agencies shall update their respective incident response policies to incorporate the revised standards, and ensure that all incidents meeting defined thresholds and that occur on or impact NSS are properly reported to the National Manager, IC CIO, DOW CIO, or Federal CIO.
(d) Each agency shall maintain and annually update an inventory of all NSS owned or operated by that agency.
(i) To assist the National Manager in reporting government-wide metrics, agencies shall make inventories available to the National Manager. At a minimum, this inventory must include the number of total information systems, NSS, and non-NSS, owned or operated by the agency.
(ii) Within 60 days of the date of this memorandum, the CNSS shall establish a working group to deconflict the identification and inventory of NSS and non-NSS in FCEB Agencies.
(e) Within 60 days of the date of this memorandum, the National Manager and the Director of OMB, through the Federal CIO, shall develop any memoranda of agreement necessary for the National Manager to assign or detail personnel to the Office of the Federal CIO, consistent with applicable law, to assist in the oversight of NSS owned or operated by FCEB Agencies in accordance with section 5(e) of this memorandum.
Sec . 7 . Adaptation of Executive Order 14306 to National Security Systems . (a) Executive Order 14306 required the development of requirements for NSS that are consistent with the requirements set forth in that order as appropriate and consistent with applicable law. This section implements these requirements for NSS.
(i) Consistent with section 3(b) of Executive Order 14144 of January 16, 2025 (Strengthening and Promoting Innovation in the Nation’s Cybersecurity), as amended by Executive Order 14306, within 120 days of the date of this memorandum, the CNSS shall request from cloud service providers accredited to host NSS, excluding those supporting compartmented intelligence missions, baselines with specifications and recommendations for agency configuration of agency cloud-based systems in order to secure Federal data based on agency requirements. The CNSS will assess these recommendations and make an independent decision as to whether to recommend them to the National Manager. The treatment of existing commercial cloud services provided by the CIA as a Service of Common Concern shall be subject to negotiation between the CIA and the CNSS.
(ii) Within 90 days of the date of this memorandum, the CNSS, in coordination with the Secretary of State, through the Department of State CIO, the Secretary of Commerce, through the Department of Commerce CIO, the Secretary of Energy, through the CIO of the National Nuclear Security Administration, and the Secretary of Homeland Security, through the Department of Homeland Security CIO, shall issue a report on the provisioning of cloud capabilities, to include recommended secure configuration baselines, at the Secret, Top Secret Collateral, TS/SCI, and Top Secret Controlled and Special Access Program levels for FCEB Agencies. This report shall be drafted in coordination with the roadmap on advanced computing resources tasked in National Security Presidential Memorandum 11 of June 5, 2026 (Artificial Intelligence in the National Security Enterprise).
(iii) Within 90 days of the date of this memorandum, the CNSS will review and identify revisions needed to CNSSP-32 of May 2022 (Policy on Cloud Security), to provide guidance and requirements for the secure hosting of NSS in cloud environments.
(b) Secure unclassified communication among agencies is essential in promoting the security of NSS and the missions that these systems support. Within 90 days of the date of this memorandum, the National Manager will provide recommendations to the CNSS on policy to promote government-wide, secure, interoperable unclassified voice and video communication capabilities for mobile and fixed devices among FCEB Agencies, DOW, and the IC.
Sec . 8 . Definitions . For purposes of this memorandum:
(a) The term “agency” has the meaning given to it in 44 U.S.C. 3502(1).
(b) The term “Federal Civilian Executive Branch Agencies” means all agencies except for the Department of War and agencies in the Intelligence Community.
(c) The term “Federal Chief Information Officer” means the Administrator of the Office of Electronic Government appointed pursuant to 44 U.S.C. 3602(b).
(d) The term “National Security System” has the meaning given to that term in 44 U.S.C. 3552(b)(6), 44 U.S.C. 3553(e)(2), and 44 U.S.C. 3553(e)(3).
(e) The term “information system” has the meaning given to it in 44 U.S.C. 3502(8).
Sec . 9 . General Provisions . This memorandum shall not be construed to implicitly alter or supersede existing authorities or contravene existing law, Executive Orders, or Presidential Directives to include authorities conferred to ensure the protection of intelligence sources and methods or to confer the authority to interfere with the means and methods necessary to undertake intelligence collection or covert action operations. This memorandum shall be implemented consistent with applicable law and subject to the availability of appropriations. No implementation measures shall impede the conduct or support of DOW or IC activities, or other activities under provisions of law, and all such implementation measures shall be designed to protect intelligence sources and methods.
DONALD J. TRUMP
NATIONAL SECURITY PRESIDENTIAL MEMORANDUM/NSPM-12
Presidential Memoranda
June 12, 2026
MEMORANDUM FOR THE VICE PRESIDENT
THE SECRETARY OF STATE
THE SECRETARY OF THE TREASURY
THE SECRETARY OF WAR
THE ATTORNEY GENERAL
THE SECRETARY OF THE INTERIOR
THE SECRETARY OF AGRICULTURE
THE SECRETARY OF COMMERCE
THE SECRETARY OF LABOR
THE SECRETARY OF HEALTH AND HUMAN SERVICES
THE SECRETARY OF HOUSING AND URBAN DEVELOPMENT
THE SECRETARY OF TRANSPORTATION
THE SECRETARY OF ENERGY
THE SECRETARY OF EDUCATION
THE SECRETARY OF VETERANS AFFAIRS
THE SECRETARY OF HOMELAND SECURITY
THE WHITE HOUSE CHIEF OF STAFF
THE DEPUTY CHIEF OF STAFF FOR POLICY AND HOMELAND SECURITY ADVISOR
THE DIRECTOR OF THE OFFICE OF MANAGEMENT AND BUDGET
THE DIRECTOR OF NATIONAL INTELLIGENCE
THE ASSISTANT TO THE PRESIDENT FOR SCIENCE AND TECHNOLOGY
THE ASSISTANT TO THE PRESIDENT FOR NATIONAL SECURITY AFFAIRS
THE ASSISTANT TO THE PRESIDENT AND COUNSEL TO THE PRESIDENT
THE CHAIRMAN OF THE JOINT CHIEFS OF STAFF
THE DIRECTOR OF THE CENTRAL INTELLIGENCE AGENCY
THE DIRECTOR OF THE NATIONAL SECURITY AGENCY
THE ADMINISTRATOR OF GENERAL SERVICES
THE NATIONAL CYBER DIRECTOR
THE DIRECTOR OF THE CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY
SUBJECT: National Policy for the Cybersecurity of National Security Systems
As President, it is my priority to ensure that the United States can conduct key military and intelligence missions in contested cyber environments and that our personnel have access to the modern, secure technology they need to accomplish these missions. The Department of War (DOW), Intelligence Community (IC), and Federal Civilian Executive Branch (FCEB) Agencies own or operate this technology as National Security Systems (NSS). It shall be the policy of the United States Government that these systems be defended to the greatest extent practicable and that executive department and agency (agency) heads be accountable for this defense through government-wide oversight mechanisms. Therefore, by the authority vested in me by the Constitution and the laws of the United States, including section 3557 of title 44, United States Code, and section 301 of title 3, United States Code, it is hereby ordered:
Section 1 . Purpose . (a) This National Security Presidential Memorandum sets forth principles and establishes cybersecurity governance for NSS. It further details the governance structure of the Committee on National Security Systems (CNSS) and the role of the Director, National Security Agency (NSA) as the National Manager for NSS.
(b) This memorandum further sets forth requirements for NSS that are equivalent to or exceed the cybersecurity requirements for other Federal Information Systems set forth within Executive Order 14306 of June 6, 2025 (Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144).
Sec . 2 . Policy . (a) National Security Directive 42 (NSD‑42) of July 5, 1990 (National Policy for the Security of National Security Telecommunications and Information Systems) and National Security Memorandum 8 (NSM-8) of January 19, 2022 (Memorandum on Improving the Cybersecurity of National Security, Department of Defense, and Intelligence Community Systems) are hereby rescinded.
(b) It shall be the policy of the United States Government to foster a proactive, adaptive, and resilient cybersecurity ecosystem for all NSS to better safeguard the Nation against persistent cyber threats from sophisticated adversaries. To this end, this memorandum establishes a clear structure of authorities, roles, and responsibilities for the governance of NSS as well as accountability for owners and operators of NSS. This memorandum shall:
(i) enhance national cyber defense governance and accountability and re-establish and designate clear governance roles and scope of authorities for the CNSS;
(ii) re-establish and empower a National Manager for NSS to identify emerging threats, advise the CNSS, issue emergency directives, provide authoritative minimum requirements for cryptology and cryptographic systems, and, through the CNSS, direct technical solutions for separation of classification levels (whether between systems or on the same system);
(iii) foster collaboration, standardization, and efficient resource management by promoting coordination and information sharing across agencies, public-private partnerships, and international liaison activities; and
(iv) promote efficient use of taxpayer funds in securing NSS.
Sec . 3 . The Committee on National Security Systems . (a) The Committee on National Security Systems (CNSS) is re-established to enhance accountability and coordination across the DOW, the IC, and FCEB Agencies in implementing necessary cyber defenses on all NSS. The CNSS shall operate under the coordination of a member of the National Security Council (NSC) staff, who shall serve as Chair.
(i) The CNSS members shall consist of:
(A) the Secretary of War, acting through the DOW Chief Information Officer (CIO);
(B) the Director of National Intelligence (DNI), acting through the IC CIO;
(C) the Director of the Office of Management and Budget (OMB), acting through the Federal CIO; and
(D) the Director of the NSA as National Manager, acting through the Deputy National Manager.
(ii) The following officials may recommend representatives as advisors to the members of the CNSS:
(A) the Attorney General;
(B) the Secretary of Commerce;
(C) the Director of the Central Intelligence Agency (CIA);
(D) the Assistant to the President for National Security Affairs;
(E) the Assistant to the President for Science and Technology;
(F) the National Cyber Director;
(G) the Chairman of the Joint Chiefs of Staff;
(H) the Director of the Cybersecurity and Infrastructure Security Agency (CISA); and
(I) any other advisors as the CNSS deems necessary.
(b) The objectives of the CNSS shall be to:
(i) establish baseline cybersecurity requirements for all NSS;
(ii) through the respective statutory and delegated authorities held by the members, hold NSS owners and operators accountable for implementing required security measures;
(iii) represent the requirements of the NSS ecosystem, owners, and operators in interagency fora, public fora, the Congress, and the Council of Inspectors General on Integrity and Efficiency;
(iv) coordinate with NSS shared service providers to promote efficient use of secure shared services where practicable; and
(v) facilitate a shared platform or forum for dissemination and access to CNSS guidance and decisions, NSS requirements, and related policies, accessible by all NSS end-user IC, DOW, and FCEB Agencies.
(c) The CNSS, acting through its members consistent with section 301 of title 3, United States Code, shall issue directives and complementary standards that apply to all NSS, including directives and standards issued under subsections (c)(i) and (c)(ii) of this section. The agencies that own or operate NSS shall comply with all directives and complementary standards issued by the CNSS.
(i) For the purposes of safeguarding NSS from a known or reasonably suspected information security threat, vulnerability, or risk, the CNSS may issue a directive to the head of an agency, through that agency’s CIO, Chief Information Security Officer (CISO), or other officer designated by the head of the agency, to take any lawful action with respect to the operation of that NSS for the purpose of protecting the system from, or mitigating, the threat, vulnerability, or risk.
(ii) NSS shall meet or exceed the protection level of cybersecurity standards issued by the National Institute of Standards and Technology (NIST) unless the CNSS provides otherwise.
(A) The CNSS may issue a complementary standard to adapt NIST-prescribed baselines for NSS where appropriate.
(B) CNSS Policy (CNSSP) 15, or successor policy, or interim guidance from the National Manager, will constitute the commercial cryptographic standard for NSS.
(C) Unless specifically stated by the CNSS or a complementary CNSS issuance exists, all relevant standards issued by NIST shall apply as a minimum baseline to secure NSS.
(d) The CNSS shall have a permanent Executive Secretariat composed of personnel provided by the National Manager. The National Manager shall further provide facilities and support as required. Other agencies shall provide facilities and support as requested by the CNSS, consistent with applicable law.
(i) The Secretary of War, through the DOW CIO, in coordination with the DNI, through the IC CIO, shall be responsible for overseeing the activities of the Executive Secretariat.
(ii) The Executive Secretariat shall be responsible for maintaining an authoritative, machine-readable portal of CNSS guidance applicable to NSS as well as a collaborative environment that is accessible by all NSS owners and operators on Unclassified, Secret, and Top Secret/Sensitive Compartmented Information (TS/SCI) systems.
Sec . 4 . Policy Coordination Committee . (a) A Policy Coordination Committee (PCC) for NSS shall be formed pursuant to National Security Presidential Memorandum 1 of January 20, 2025 (Organization of the National Security Council and Subcommittees).
(i) The PCC shall be chaired by a member of the NSC staff and shall consist of representatives of the members and advisors from the CNSS.
(ii) Agencies that operate NSS may be invited at the discretion of the PCC chair.
(b) The PCC through the CNSS may request an assessment of the cybersecurity posture of NSS government-wide, to include performance metrics, cybersecurity assessment results, and compliance with current policy. The PCC chair may request that the National Manager conduct such assessment.
Sec . 5 . The National Manager for NSS . (a) The Director of the NSA is the National Manager for NSS and will carry out the certain responsibilities in accordance with existing law, Executive Orders, and other Presidential directives. In this capacity the National Manager is responsible for providing technical advice to the CNSS and:
(i) providing recommendations on incident response for security incidents that impact NSS government-wide; and
(ii) as referenced in section 2(b)(ii) of this memorandum, in response to a known or reasonably suspected information security threat, vulnerability, or risk that represents a substantial threat to the information security of NSS, or in response to intelligence of adversary capability and intent to target NSS, the National Manager may issue an emergency directive to the head of an agency, through that agency’s CIO, CISO, or officer designated by the head of the agency, to take any lawful action with respect to the operation of that NSS, including such systems used or operated by another entity on behalf of an agency, for the purpose of protecting the NSS from, or mitigating, the threat, vulnerability, or risk.
(b) The National Manager shall serve as the cryptologic authority for NSS. Through this role, the National Manager shall, in accordance with applicable law and policy:
(i) design, build, test, deliver, and protect cryptographic keys and codes capabilities;
(ii) review, approve, and publish standards related to the security of NSS;
(iii) develop, evaluate and approve techniques, systems, products, solutions, and equipment related to the cybersecurity of NSS, provided that nothing in this provision shall restrict agencies from testing cryptography on NSS that they own or operate;
(iv) operate such printing, fabrication, and other facilities as may be required to perform critical functions related to the provisions of cryptographic, identity, key management, and other technical security material or services;
(v) in consultation with the CNSS, prescribe the minimum standards, methods, and procedures for protecting cryptographic and other technical security material, techniques, and information related to NSS; and
(vi) enter into agreements for the procurement of technical security material and other equipment, their provision to agencies, and, where appropriate, government contractors and foreign governments.
(c) The National Manager shall assess the cybersecurity posture of NSS across the United States Government on behalf of the CNSS and serve as a technical advisor to the CNSS and agencies that own or operate NSS, in alignment with provisions set forth in section 9 of this memorandum. Through this role the National Manager shall:
(i) in consultation with the CNSS, develop government-wide performance metrics for the defense of NSS, and coordinate with the CNSS chair and CNSS members and advisors on any CNSS collection of those metrics on a regular basis from each agency that owns or operates NSS;
(ii) assess the overall security posture of and disseminate information on threats to and vulnerabilities in NSS;
(iii) operate a technical center to evaluate and certify the security of NSS;
(iv) request from the heads of agencies, through an agency’s CIO, CISO, or other officer designated by the head of the agency, such information and technical support as may be needed to discharge the responsibilities assigned herein;
(v) conduct, coordinate, or endorse research and development of techniques and equipment to secure NSS;
(vi) upon request, provide cybersecurity services and technical assistance to NSS owners and operators;
(vii) examine NSS and evaluate their vulnerability to foreign interception and exploitation, provided no examination or monitoring shall be performed without advising the CIO of the agency that owns or operates the NSS; and
(viii) conduct foreign cryptographic and cybersecurity liaison relationships, including by providing information, services, and support and by entering into agreements with foreign governments and with international and private organizations regarding NSS. Any liaison conducted with foreign intelligence or security services shall be carried out in coordination with the Secretary of War, the DNI, and the Director of the CIA in accordance with Executive Order 12333 of December 4, 1981 (United States Intelligence Activities), as amended. Any such agreements shall be coordinated with affected agencies.
(d) The National Manager, through the CNSS, shall establish requirements for cross-domain solutions and alternative technical solutions for the separation of security domains for NSS. Through this role, the National Manager shall:
(i) serve as the principal advisor to NSS owners and operators on cross-domain capabilities;
(ii) develop and maintain community outreach programs and fora focused on cross-domain solutions;
(iii) develop and establish improved security solutions, standards, and technologies for cross-domain solutions; and
(iv) perform comprehensive testing for establishment of approved cross-domain solution products.
(e) NSS owned or operated by civilian agencies play an important role in many military and intelligence missions. Additionally, heads of civilian agencies are accountable for protection of classified material that is stored or processed on NSS that are owned or operated by such agencies. The Director of OMB, with support from the National Manager, and acting through the Federal CIO as appropriate, shall oversee compliance of FCEB Agencies with NSS policies and directives with the exception of agencies and agency components that are part of the IC. National Manager support may include:
(i) collection of metrics and direct assessment of the cybersecurity posture of NSS owned or operated by FCEB Agencies;
(ii) provision of technical assistance upon request to NSS owners and operators on the implementation of the NSS policies; and
(iii) consistent with applicable law, assignment of personnel to the Office of the Federal CIO to align and enhance oversight across FCEB Agencies.
(f) The National Manager may partner and collaborate with the heads of other agencies on matters related to cybersecurity, including with the heads of CISA and NIST, as well as the private sector and academia, to carry out the responsibilities assigned herein in accordance with applicable law and policy.
Sec . 6 . Implementation . (a) Within 30 days of the date of this memorandum, the CNSS shall revise CNSS Directive 900 of May 2013 (Committee on National Security Systems (CNSS) Governing and Operating Procedures), and any other policies as the CNSS deems appropriate, to incorporate the changes set forth in this memorandum.
(b) The CNSS and the National Manager shall take the following steps to harmonize NSS policies:
(i) within 60 days of the date of this memorandum, the CNSS shall issue a roadmap and policy priority areas for NSS to be applied in the next calendar year;
(ii) within 90 days of the date of this memorandum, the CNSS shall determine which National Manager Binding Operational Directives and other National Manager policies, including those related to NSM-8, with the exception of National Manager Emergency Directives, must be maintained and, where appropriate, incorporate those requirements into CNSS Directives. Upon completion of this process, the National Manager shall take necessary steps to rescind all National Manager Binding Operational Directives and Memoranda related to NSM-8 as appropriate; and
(iii) within 90 days of the date of this memorandum, the CNSS shall review all existing CNSS policies, directives, and instructions to determine which should be rescinded or harmonized. The CNSS shall complete rescission or harmonization of identified policies within 90 days of the completion of this review.
(c) Effective incident reporting for incidents that occur on or impact NSS is essential to minimize risk to the critical missions enabled by these systems and drive accountability for owners and operators, including civilian, defense, and intelligence agencies.
(i) Within 60 days of the date of this memorandum, the National Manager shall recommend to the CNSS new or modified incident reporting standards that enable government-wide awareness of incidents impacting NSS. This recommendation shall include thresholds for required reporting of incidents.
(ii) Within 60 days of the receipt of the National Manager’s recommendations, the CNSS shall update applicable CNSS policies to incorporate those recommendations as appropriate.
(iii) Within 60 days of the release of the incident reporting standards described in section 6(c)(i) of this memorandum, agencies shall update their respective incident response policies to incorporate the revised standards, and ensure that all incidents meeting defined thresholds and that occur on or impact NSS are properly reported to the National Manager, IC CIO, DOW CIO, or Federal CIO.
(d) Each agency shall maintain and annually update an inventory of all NSS owned or operated by that agency.
(i) To assist the National Manager in reporting government-wide metrics, agencies shall make inventories available to the National Manager. At a minimum, this inventory must include the number of total information systems, NSS, and non-NSS, owned or operated by the agency.
(ii) Within 60 days of the date of this memorandum, the CNSS shall establish a working group to deconflict the identification and inventory of NSS and non-NSS in FCEB Agencies.
(e) Within 60 days of the date of this memorandum, the National Manager and the Director of OMB, through the Federal CIO, shall develop any memoranda of agreement necessary for the National Manager to assign or detail personnel to the Office of the Federal CIO, consistent with applicable law, to assist in the oversight of NSS owned or operated by FCEB Agencies in accordance with section 5(e) of this memorandum.
Sec . 7 . Adaptation of Executive Order 14306 to National Security Systems . (a) Executive Order 14306 required the development of requirements for NSS that are consistent with the requirements set forth in that order as appropriate and consistent with applicable law. This section implements these requirements for NSS.
(i) Consistent with section 3(b) of Executive Order 14144 of January 16, 2025 (Strengthening and Promoting Innovation in the Nation’s Cybersecurity), as amended by Executive Order 14306, within 120 days of the date of this memorandum, the CNSS shall request from cloud service providers accredited to host NSS, excluding those supporting compartmented intelligence missions, baselines with specifications and recommendations for agency configuration of agency cloud-based systems in order to secure Federal data based on agency requirements. The CNSS will assess these recommendations and make an independent decision as to whether to recommend them to the National Manager. The treatment of existing commercial cloud services provided by the CIA as a Service of Common Concern shall be subject to negotiation between the CIA and the CNSS.
(ii) Within 90 days of the date of this memorandum, the CNSS, in coordination with the Secretary of State, through the Department of State CIO, the Secretary of Commerce, through the Department of Commerce CIO, the Secretary of Energy, through the CIO of the National Nuclear Security Administration, and the Secretary of Homeland Security, through the Department of Homeland Security CIO, shall issue a report on the provisioning of cloud capabilities, to include recommended secure configuration baselines, at the Secret, Top Secret Collateral, TS/SCI, and Top Secret Controlled and Special Access Program levels for FCEB Agencies. This report shall be drafted in coordination with the roadmap on advanced computing resources tasked in National Security Presidential Memorandum 11 of June 5, 2026 (Artificial Intelligence in the National Security Enterprise).
(iii) Within 90 days of the date of this memorandum, the CNSS will review and identify revisions needed to CNSSP-32 of May 2022 (Policy on Cloud Security), to provide guidance and requirements for the secure hosting of NSS in cloud environments.
(b) Secure unclassified communication among agencies is essential in promoting the security of NSS and the missions that these systems support. Within 90 days of the date of this memorandum, the National Manager will provide recommendations to the CNSS on policy to promote government-wide, secure, interoperable unclassified voice and video communication capabilities for mobile and fixed devices among FCEB Agencies, DOW, and the IC.
Sec . 8 . Definitions . For purposes of this memorandum:
(a) The term “agency” has the meaning given to it in 44 U.S.C. 3502(1).
(b) The term “Federal Civilian Executive Branch Agencies” means all agencies except for the Department of War and agencies in the Intelligence Community.
(c) The term “Federal Chief Information Officer” means the Administrator of the Office of Electronic Government appointed pursuant to 44 U.S.C. 3602(b).
(d) The term “National Security System” has the meaning given to that term in 44 U.S.C. 3552(b)(6), 44 U.S.C. 3553(e)(2), and 44 U.S.C. 3553(e)(3).
(e) The term “information system” has the meaning given to it in 44 U.S.C. 3502(8).
Sec . 9 . General Provisions . This memorandum shall not be construed to implicitly alter or supersede existing authorities or contravene existing law, Executive Orders, or Presidential Directives to include authorities conferred to ensure the protection of intelligence sources and methods or to confer the authority to interfere with the means and methods necessary to undertake intelligence collection or covert action operations. This memorandum shall be implemented consistent with applicable law and subject to the availability of appropriations. No implementation measures shall impede the conduct or support of DOW or IC activities, or other activities under provisions of law, and all such implementation measures shall be designed to protect intelligence sources and methods.
DONALD J. TRUMP