NSPM-12: The NSS cyber memo agencies cannot ignore
Yuichiro Chino/Getty Images
ByHemant Baidwan
June 15, 2026 02:46 PM ET
COMMENTARY | NSPM-12 dropped last week. Anyone who has spent serious time in federal cybersecurity should read it carefully.
Spend enough time in government and reading policy documents becomes second nature. You learn fast where the wiggle room usually lives. The vague timelines. The "consistent with applicable law" language that gives everyone room to slow walk implementation. NSPM-12 has less of that than most.
There are named officials. Hard deadlines. A governance body with actual authority to issue binding directives. That is different than what we usually see. For agencies that have been waiting for someone to force the issue on National Security System cybersecurity, this is that moment.
Here are three things agencies need to understand right now.
The 90-day cloud security policy deadline
The 90-day window to update cloud security policy for...
Copyright of this story solely belongs to nextgov.com. To see the full text click HERE