OMB (Office of Management and Budget)
OMB is the Executive Office of the President's budget and regulatory coordinator. On the cybersecurity side, OMB issues binding directives to federal agencies that flow down to contractors. Circular A-130 sets the baseline for managing federal information. Memorandum M-22-09 pushed agencies toward zero trust. OMB also houses OIRA, which reviews every significant federal rule.
- glossary
- How OMB Affects Contractors
How OMB Affects Contractors
You don't work with OMB directly. OMB tells agencies what to do. Agencies build cybersecurity requirements into contracts, usually through the FAR and DFARS. So when OMB publishes a memo on zero trust or SBOMs, expect to see corresponding FAR Council activity within 12 to 24 months, then contract language a few months after that.
OMB Documents That Matter for Cybersecurity
- OMB Circular A-130: Managing Information as a Strategic Resource. The baseline for agency information management and security.
- OMB Memorandum M-22-09: Moving Federal Agencies Toward a Zero Trust Architecture. Directed agencies to meet specific zero trust objectives.
- OMB Memorandum M-22-18: Enhancing Software Supply Chain Security. Self-attestations and SBOMs for federal software.
- OMB Memorandum M-22-05: Response to Log4j. Required inventory and patching actions for federal systems.
- OMB Memorandum M-24-04: Federal Cybersecurity Implementation Plan for FY 2024.
OIRA: The Regulatory Gatekeeper
OIRA (Office of Information and Regulatory Affairs) sits inside OMB. Under Executive Order 12866, any significant federal regulation (annual economic impact over $200 million, or novel policy issue) has to go through OIRA review before publication. OIRA reviewed the CMMC rule, the FedRAMP modernization rule, and every DFARS cyber amendment. Tracking what's at OIRA tells you what's about to become enforceable.
Watching OMB for Early Signals
Subscribe to whitehouse.gov/omb/information-for-agencies/memoranda. New M-memos typically signal requirements that will become FAR or DFARS changes within a year or two. This is how you see CMMC-style compliance shifts coming before they land in your contracts.