President Trump’s recent Executive Order on Securing the Nation Against Advanced Cryptographic Attacks focuses on one of the biggest long-term cybersecurity challenges facing the federal government: preparing for a future in which large-scale quantum computing can break many of the cryptographic systems we rely on today. 

That is the headline. But another provision in the Order deserves attention. The Executive Order includes an important directive for the publication of a rule that would require the use of vulnerability disclosure policies (VDPs) by federal contractors. The Hacking Policy Council (HPC) applauds the Administration for including this language. It is a smart, practical step toward making VDPs a baseline cybersecurity practice for companies that support the federal government.

In Section 6(d), the Executive Order directs the Federal Acquisition Regulatory (FAR) Council, in consultation with CISA and NIST, to publish a proposed rule within 270 days amending FAR requirements and contract clauses for contractor vulnerability disclosure programs. Specifically, the proposed rule must ensure that covered contractors implement VDPs consistent with NIST guidelines and that those VDPs incorporate reports of cryptographic vulnerabilities, including testing for a lack of encryption and the use of non-Federal Information Processing Standards (FIPS)-approved algorithms. This policy will help to strengthen the security of federal contractors’ systems.

Federal cybersecurity does not stop at agency networks. Contractors develop, operate, maintain, and secure systems that support government missions every day. When contractors lack clear channels for receiving and handling vulnerability reports through VDPs, security researchers and other third parties may have no reliable way to flag issues before adversaries find and exploit them.

A VDP helps solve that problem. It gives researchers and other reporters a clear place to send information, gives organizations a process for evaluating and responding to reports, and helps move vulnerabilities toward remediation. VDPs are a structured way for organizations to receive, triage, and act on good-faith security reports.

The Executive Order reflects a broader point HPC has long emphasized: vulnerability disclosure is a core part of modern security governance. The federal government has already recognized the value of VDPs for federal agencies. Extending that expectation to covered contractors helps close an important gap and strengthens the broader ecosystem that supports federal systems.

HPC applauds the Administration for recognizing that the post-quantum transition is not only about choosing new algorithms. It is also about building the processes needed to find and fix weaknesses as complex systems change. VDPs are one of those foundational processes.

HPC previously supported legislative efforts to secure this policy outcome, including bills sponsored by Representatives Nancy Mace and Shontel Brown and Senators Mark Warner and James Lankford. While those bills did not become law, the Administration has advanced this objective through executive action. HPC encourages Congress to reinforce this progress by including the policy in the FY27 National Defense Authorization Act (NDAA).Doing so would codify contractor VDP requirements, supporting consistent implementation across the federal enterprise and sending a clear signal that coordinated vulnerability disclosure is an essential part of national defense and supply chain security.

HPC will continue tracking the FAR rulemaking and stands ready to work with policymakers to ensure implementation strengthens cybersecurity while protecting and encouraging good-faith security research.

Frances Schroeder

Read Next

AI-Driven Fraud Scams Are Evolving Fast: What People Should Watch For and Can Do To Protect Themselves, Their Friends, and Family

Fraud scams are nothing new, but the tools and tactics being used have evolved dramatically. Here are the most common threats we are seeing, how use of AI has changed them, and how to potentially prevent them.

From Consensus to Action: The Purpose of the Cyber Operations Policy Coalition

The Cyber Operations Policy Coalition is focused on the operational dimension of cybersecurity policy: the authorities, governance frameworks, and public-private relationships needed to achieve shared security outcomes.

CyberNext BRU 2026 Recap

The Cybersecurity Coalition and the Cyber Threat Alliance hosted the third annual CyberNext BRU bringing together panelists from EU institutions, industry, and academia.