Background
Recent incidents have demonstrated the need for the Federal Government to improve its efforts to identify, deter, protect against, detect, and respond to malicious cyber actions and actors. In particular, threat actors are exploiting the pervasive use of software and the complexity of the underlying code and software development and distribution practices. One of the goals of the EO is to assist in developing a security baseline for critical software products used across the Federal Government. The designation of software as EO-critical will then drive additional activities, including how the Federal Government purchases and manages deployed critical software. In particular, the EO seeks to limit acquisition to software that has met security measures such as use of a secure development process and integrity checks that are defined in Section 4(e) of the EO.
Given the broad scope of the EO and its potential impact on both government operations and the software marketplace, NIST set the following goals for the definition of critical software:
- Clarity – The implementation of the program will drive activity across the entire Federal Government, with impacts on the software industry. Having a clear definition that can be used by the software industry and the Government is vital to the successful implementation of the EO.
- Viability – For the EO to be viable, its implementation must take into consideration how the software industry functions, including product development, procurement, and deployment. The software marketplace is dynamic and evolves continuously. How software is developed, brought into an organization, and used by an organization is changing rapidly. Software is purchased as a product, as part of a product, and as a service. Software is often modular, consisting of many components.
There are many existing definitions and uses of the term critical. Most are based on how technology supports various tasks or processes, such as safety critical or critical infrastructure. The use of the term in the EO is slightly different because it is based not on the context of use, but on the properties of a given piece of software that make it likely to be critical in most use cases. That is, it focuses on critical functions that address underlying infrastructure for cyber operations and security. This is similar to the concept of Federal Civilian Enterprise Essential IT under the High-Value Assets program.
In order to separate the common usage of critical with the definition under the EO, we will use the term EO-critical when it is unclear which usage is being discussed.
Approach
Given the size, scope, and complexity of the software marketplace and the infrastructure needed within the government to implement the EO, NIST has consulted with key agencies regarding the concept of a phased approach for securing the supply chain of EO-critical software. This will allow both the Federal Government and the software industry to implement the EO in an incremental manner, thus providing the opportunity for feedback and improvements to its processes with each additional phase.
Information technology and Cybersecurity
Critical Software - Definition & Explanatory Material
This section provides the definition of EO-critical software. Following that is a table with a preliminary list of software categories recommended for the initial phase along with some explanatory material. At a later date, CISA will provide the authoritative list of software categories that are within the scope of the definition and to be included in the initial phase of implementation. A pointer to that information will be provided here when available.
Finally, there is a set of FAQs at the bottom of the page that provides answers to questions that may arise about the interpretation of the definition, the phased approach, and other related topics.
EO-critical software is defined as any software that has, or has direct software dependencies upon, one or more components with at least one of these attributes:
- is designed to run with elevated privilege or manage privileges.
- has direct or privileged access to networking or computing resources.
- is designed to control access to data or operational technology.
- performs a function critical to trust; or,
- operates outside of normal trust boundaries with privileged access.
The definition applies to the software of all forms (e.g., standalone software, software integral to specific devices or hardware components, cloud-based software) purchased for, or deployed in, production systems and used for operational purposes. Other use cases, such as software solely used for research or testing that is not deployed in production systems, are outside of the scope of this definition. (See FAQ #10 and FAQ #11.)
NIST recommends that the initial EO implementation phase focus on standalone, on-premises software that has security-critical functions or poses similar significant potential for harm if compromised. Subsequent phases may address other categories of software such as:
- software that controls access to data.
- cloud-based and hybrid software.
- software development tools such as code repository systems, development tools, testing software, integration software, packaging software, and deployment software.
- software components in boot-level firmware; or
- software components in operational technology (OT).
The table below provides a preliminary list of software categories considered to be EO-critical. This table is provided to illustrate the application of the definition of EO-critical software to the scope of the recommended initial implementation phase described above. As noted previously, CISA will provide the authoritative list of software categories at a later date.
|
Category of Software |
Description |
Types of Products |
Rationale for Inclusion |
|
Identity, credential, and access management (ICAM) |
Software that centrally identifies, authenticates, manages access rights for, or enforces access decisions for organizational users, systems, and devices |
|
Foundational for ensuring that only authorized users, systems, and devices can obtain access to sensitive information and functions |
|
Operating systems, hypervisors, container environments
|
Software that establishes or manages access and control of hardware resources (bare metal or virtualized/ containerized) and provides common services such as access control, memory management, and runtime execution environments to software applications and/or interactive users |
|
Highly privileged software with direct access and control of underlying hardware resources and that provides the most basic and critical trust and security functions |
|
Web browsers |
Software that processes content delivered by web servers over a network, and is often used as the user interface to device and service configuration functions |
|
|
|
Endpoint security |
Software installed on an endpoint, usually with elevated privileges which enable or contribute to the secure operation of the endpoint or enable the detailed collection of information about the endpoint |
|
|
|
Network control |
Software that implements protocols, algorithms, and functions to configure, control, monitor, and secure the flow of data across a network |
|
|
|
Network protection |
Products that prevent malicious network traffic from entering or leaving a network segment or system boundary |
|
|
|
Network monitoring and configuration |
Network-based monitoring and management software with the ability to change the state of—or with installed agents or special privileges on—a wide range of systems |
|
|
|
Operational monitoring and analysis
|
Software deployed to report operational status and security information about remote systems and the software used to process, analyze, and respond to that information |
|
|
|
Remote scanning |
Software that determines the state of endpoints on a network by performing network scanning of exposed services |
|
|
|
Remote access and configuration management |
Software for remote system administration and configuration of endpoints or remote control of other systems |
|
|
|
Backup/recovery and remote storage |
Software deployed to create copies and transfer data stored on endpoints or other networked devices |
|
|

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics