Compliance & Regulations/North America/EO 14028
Sovereign / National · United States — federal agencies and their software vendors

EO 14028

The 2021 Executive Order that introduced SBOM mandates, zero-trust architecture targets, and software vendor attestation requirements.

Regulator
The White House / OMB / CISA
Jurisdiction
United States — federal agencies and their software vendors
Status
Active — guidance continues to be issued by OMB and CISA.
In force since
May 12, 2021
Regulator's source
Who it applies to

All federal agencies, plus any software producer selling into the federal government.

Audit / certification status

Continuous evidence pipeline available; audit support included for all customers.

What it requires

What EO 14028 actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

Software vendors selling to the federal government must self-attest to SSDF (NIST 800-218) compliance.

02

SBOMs for every release artifact, formatted per NTIA minimum elements.

03

Federal agencies must adopt zero-trust architecture per OMB M-22-09.

04

Multi-factor authentication and encryption for data at rest and in transit, with phasing per M-22-09.

05

Endpoint Detection and Response on federal endpoints (M-22-01).

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

Self-attestation form pre-populated from SSDF telemetry.

SBOM auto-generation in CycloneDX, SPDX, and NTIA-compliant formats with VEX.

Zero-trust reference architecture for hosted Safeguard deployments documented on the trust center.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

CISA SSDF attestation form — pre-filled, exported as signed PDF.

Per-release SBOM with VEX annotations.

Mapping table: EO 14028 sections → controls → Safeguard telemetry.

Ready for EO 14028?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing