# OMB (Office of Management and Budget) | Secureframe

> OMB Circulars and Memoranda (A-130, M-22-09, M-22-18) drive federal cybersecurity policy. How OMB directives flow through OIRA to FAR/DFARS contract clauses.

canonical: https://secureframe.com/glossary/office-of-management-and-budget

OMB is the Executive Office of the President's budget and regulatory coordinator. On the cybersecurity side, OMB issues binding directives to federal agencies that flow down to contractors. Circular A-130 sets the baseline for managing federal information. Memorandum M-22-09 pushed agencies toward zero trust. OMB also houses OIRA, which reviews every significant federal rule.

### How OMB Affects Contractors

You don't work with OMB directly. OMB tells agencies what to do. Agencies build cybersecurity requirements into contracts, usually through the FAR and DFARS. So when OMB publishes a memo on zero trust or SBOMs, expect to see corresponding FAR Council activity within 12 to 24 months, then contract language a few months after that.

### OMB Documents That Matter for Cybersecurity

- **OMB Circular A-130: Ma**naging Information as a Strategic Resource. The baseline for agency information management and security.
- **OMB Memorandum M-22-09: Moving** Federal Agencies Toward a Zero Trust Architecture. Directed agencies to meet specific zero trust objectives.
- **OMB Memorandum M-22-18: Enhanc**ing Software Supply Chain Security. Self-attestations and SBOMs for federal software.
- **OMB Memorandum M-22-05: Res**ponse to Log4j. Required inventory and patching actions for federal systems.
- **OMB Memorandum M-24-04: Fed**eral Cybersecurity Implementation Plan for FY 2024.

### OIRA: The Regulatory Gatekeeper

OIRA (Office of Information and Regulatory Affairs) sits inside OMB. Under Executive Order 12866, any significant federal regulation (annual economic impact over $200 million, or novel policy issue) has to go through OIRA review before publication. OIRA reviewed the CMMC rule, the FedRAMP modernization rule, and every DFARS cyber amendment. Tracking what's at OIRA tells you what's about to become enforceable.

### Watching OMB for Early Signals

Subscribe to whitehouse.gov/omb/information-for-agencies/memoranda. New M-memos typically signal requirements that will become FAR or DFARS changes within a year or two. This is how you see CMMC-style compliance shifts coming before they land in your contracts.
