EO 14412's Contractor Vulnerability Disclosure Rule: Key Dates for 2027
A provision inside EO 14412 requires the FAR Council to propose a federal contractor vulnerability disclosure rule by March 19, 2027 — separate from, and years earlier than, the order's 2030 post-quantum compliance deadline. Here's what's confirmed and what remains undefined.
EO 14412 quietly sets a March 2027 deadline for a new federal contractor vulnerability disclosure rule — years ahead of its better-known 2030 encryption deadline. Here's what's confirmed, what's still undefined, and what to track before the proposed rule lands.
What you need to know
- The change: EO 14412 Section 6(d) requires the FAR Council, within 270 days, to propose a rule amending FAR requirements so covered contractors implement vulnerability disclosure policies (VDPs) incorporating cryptographic vulnerability reporting — testing for lack of encryption and non-FIPS algorithm use.
- Who is affected: Federal contractors not currently subject to any governmentwide FAR VDP requirement, likely scoped along lines similar to pending legislation, though EO 14412 itself does not define "covered contractor."
- Why it matters: This is a new obligation category, not an extension of the more widely-covered PQC migration deadline.
- What to do first: Assign ownership for tracking this rulemaking separately from whoever owns the 2030 PQC compliance timeline.
- Key date or trigger: Proposed rule due March 19, 2027 — 270 days from signing.
The signal is public. The implications are not.
Members receive deeper analysis and early warnings inside the PolicyEdge AI Intelligence Terminal.