The Executive Order (EO) on Improving the Nation’s Cybersecurity (14028) assigns NIST with specific directives relating to critical software.
First, NIST is to consult with the National Security Agency (NSA), Office of Management and Budget (OMB), Cybersecurity & Infrastructure Security Agency (CISA), and the Director of National Intelligence (DNI) and then to define “critical software” by June 26, 2021.
Second, NIST is to publish guidance outlining security measures for critical software by July 11, 2021, after consulting with CISA and OMB.