Skip to content

Governance tracker

Federal cybersecurity, privacy, and technology governance

Every federal cybersecurity, privacy, and information technology (IT) governance document from the Privacy Act of 1974 to today: laws, executive orders, memoranda, directives, standards, and contract rules.

FedXchange's watch checks the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB), the National Archives (NARA), and the Federal Register every day, and the National Institute of Standards and Technology (NIST) every week. New finds appear here the day they are found. The tracker lists public documents only.

Get new governance by emailWhat the statuses meanNames on this page

Found in the last 7 days

Nothing new in the last 7 days.

Skip to the results

Filters

Results

Showing 601 to 631.

Governance documents, sorted by date issued, oldest first. Page 13 of 13.

The table scrolls sideways. Each title opens the document's page.

Governance documents, sorted by date issued, oldest first. Page 13 of 13.
Number, sort A to ZTitle, sort A to ZIssuer, sort A to ZTypeIssued, sort newest firstStatus, sort A to Z
NoneFederal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 5, 24, and 29FAR CouncilProposed ruleJune 23, 2026Proposed
NoneFederal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 3 and 49FAR CouncilProposed ruleJune 23, 2026Proposed
FAR Case 2026-001Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 1, 2, 4, 33, 39, 40, and 53FAR CouncilProposed ruleJune 23, 2026Proposed
M-26-15Execution of the Migration to Post-Quantum CryptographyOMBOMB memorandumJune 24, 2026In effect
NoneFedRAMP Consolidated Rules for 2026GSA and FedRAMPFedRAMP policyJune 25, 2026In effect
SP 800-18 Rev. 2Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for SystemsNISTNIST Special PublicationJune 30, 2026In effect
ISOO Notice 2026-03Department of State Declassification Referral WaiverNARAISOO noticeJuly 9, 2026In effect
EO 14415Securing America's Defense Supply Chains and Ensuring Domestic Acquisition of Critical MaterialsWhite HouseExecutive orderJuly 20, 2026In effect
NoneLogging Reference ArchitectureCISACISA guidanceAugust 2026In effect
NoneFY 2026 & FY 2027 CIO FISMA MetricsCISACISA guidanceAugust 3, 2026In effect
ISOO Notice 2026-04Agencies Eligible to Receive Referrals from Automatic Declassification at 25, 50, and 75 YearsNARAISOO noticeAugust 3, 2026In effect
M-26-17Rescission of M-23-13OMBOMB memorandumAugust 10, 2026In effect
NoneExpanding Capabilities to Combat Transnational Cyber-Enabled CrimeWhite HousePresidential directiveAugust 12, 2026In effect
ISOO Notice 2026-05Appeal Procedures for the Interagency Security Classification Appeals PanelNARAISOO noticeAugust 17, 2026In effect
EO 14421Declaring a National Emergency To Secure the United States Bulk-Power SystemWhite HouseExecutive orderAugust 26, 2026In effect
ISOO Notice 2026-06Standards for GSA Approved Security EquipmentNARAISOO noticeAugust 31, 2026In effect
M-26-18Scaling Use of Login.gov to Deliver a Universal Sign-on for Public ServicesOMBOMB memorandumAugust 31, 2026In effect
NoneHeightened Import Disclosures for Supply Chain VisibilityCISAProposed ruleSeptember 2, 2026Proposed
ISOO Notice 2026-07Executive Agent Guidance for Implementation of the Controlled Unclassified Information ProgramNARAISOO noticeSeptember 2, 2026In effect
ISOO Notice 2026-08Controlled Unclassified Information (CUI) Program Revised Requirements for WaiversNARAISOO noticeSeptember 2, 2026In effect
NoneFederal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 14, 28, 36, and 52FAR CouncilProposed ruleSeptember 18, 2026Proposed
NoneFederal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 9, 27, and 47FAR CouncilProposed ruleSeptember 18, 2026Proposed
NoneFederal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 16, 17, and 35FAR CouncilProposed ruleSeptember 18, 2026Proposed
NoneFederal Acquisition Regulation: Revolutionary FAR Overhaul Parts 8, 12, 13, 15, 38, 44, and 51FAR CouncilProposed ruleSeptember 18, 2026Proposed
NoneGeneral Services Administration Acquisition Regulation; GSAR Implementation of Executive Order 14275, Federal Supply Schedule Ordering ProceduresGSA and FedRAMPProposed ruleSeptember 22, 2026Proposed
ISOO Notice 2026-09Guidance for Use of Classification Authority Block on Standard Form 700NARAISOO noticeSeptember 28, 2026In effect
EO 14432Streamlining Access to Government Services Through America.govWhite HouseExecutive orderSeptember 29, 2026In effect
EO 14434Inaugurating the Era of Super IntelligenceWhite HouseExecutive orderSeptember 29, 2026In effect
NoneGeneral Services Administration Acquisition Regulation; GSAR Implementation of Executive Order 14275, Acquisition of Utility ServicesGSA and FedRAMPProposed ruleOctober 5, 2026Proposed
NoneOverpressure Blast Effects Analysis Burden Reducing ClarificationOtherProposed ruleOctober 5, 2026Proposed
ISOO Notice 2012-03Additional Guidance on Supplemental Controls Required for Safeguarding Classified National Security InformationNARAISOO noticeDate not knownRescinded

What the statuses mean

In effect
Still in force, possibly with amendments.
Proposed
A proposed rule or draft. It may change before it takes effect.
Superseded
Replaced by a newer document or edition.
Rescinded
Cancelled by its issuer.
Withdrawn
Withdrawn by its issuer (NIST's term).
Retired
Closed by its issuer (CISA's term for a directive that has done its job).
Expired
Lapsed on its own terms.

Names on this page

AI
Artificial intelligence
BOD
Binding Operational Directive, issued by CISA
CISA
Cybersecurity and Infrastructure Security Agency
CUI
Controlled Unclassified Information
DFARS
Defense Federal Acquisition Regulation Supplement, the Department of Defense's additions to the FAR
DoD
Department of Defense
ED
Emergency Directive, issued by CISA
EO
Executive order
FAR
Federal Acquisition Regulation, the rules for federal contracts
FASC
Federal Acquisition Security Council
FedRAMP
Federal Risk and Authorization Management Program, run by GSA
FIPS
Federal Information Processing Standard, published by NIST
FISMA
Federal Information Security Modernization Act
GSA
General Services Administration
ISOO
Information Security Oversight Office, part of NARA
IT
Information technology
MFA
Multifactor authentication
NARA
National Archives and Records Administration
NIST
National Institute of Standards and Technology
OMB
Office of Management and Budget
OPM
Office of Personnel Management
PIV
Personal Identity Verification, the federal employee ID card
SBOM
Software bill of materials: a list of the parts in a piece of software

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.