EO 14412's Contractor Vulnerability Disclosure Rule: Key Dates for 2027

A provision inside EO 14412 requires the FAR Council to propose a federal contractor vulnerability disclosure rule by March 19, 2027 — separate from, and years earlier than, the order's 2030 post-quantum compliance deadline. Here's what's confirmed and what remains undefined.

Share
Abstract navy graphic with blue, amber signal lines for EO 14412 contractor vulnerability disclosure rule
💡
TL;DR:
EO 14412 quietly sets a March 2027 deadline for a new federal contractor vulnerability disclosure rule — years ahead of its better-known 2030 encryption deadline. Here's what's confirmed, what's still undefined, and what to track before the proposed rule lands.

What you need to know

  • The change: EO 14412 Section 6(d) requires the FAR Council, within 270 days, to propose a rule amending FAR requirements so covered contractors implement vulnerability disclosure policies (VDPs) incorporating cryptographic vulnerability reporting — testing for lack of encryption and non-FIPS algorithm use.
  • Who is affected: Federal contractors not currently subject to any governmentwide FAR VDP requirement, likely scoped along lines similar to pending legislation, though EO 14412 itself does not define "covered contractor."
  • Why it matters: This is a new obligation category, not an extension of the more widely-covered PQC migration deadline.
  • What to do first: Assign ownership for tracking this rulemaking separately from whoever owns the 2030 PQC compliance timeline.
  • Key date or trigger: Proposed rule due March 19, 2027 — 270 days from signing.

The signal is public. The implications are not.

Members receive deeper analysis and early warnings inside the PolicyEdge AI Intelligence Terminal.

Upgrade to Founding Member
Free risk assessment →