 Initiative Number: 1.1.2 Initiative Title: Set cybersecurity requirements across critical infrastructure sectors Initiative Description Through the ongoing National Security Council-led policymaking process, SRMAs and regulators will analyze the cyber risk in their industries and outline how they will use their existing authorities to establish cyber requirements that mitigate risk in their sector, account for sector-specific needs, identify gaps in authorities, and develop proposals to close them. NCS Reference The Federal Government will use existing authorities to set necessary cybersecurity requirements in critical sectors. Where Federal departments and agencies have gaps in statutory authorities to implement minimum cybersecurity requirements…the Administration will work with Congress to close them. Responsible Agency: NSC Contributing Entities: SRMAs, ONCD Completion Date: 2Q FY25 Initiative Number: 1.1.3 Initiative Title: Increase agency use of frameworks and international standards to inform regulatory alignment Initiative Description The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) is refined, improved, and evolves over time. Updates help the performance-based Framework keep pace with technology and threat trends, integrate lessons learned, and move best practice to common practice. NIST is developing a significant update to the Framework: CSF 2.0. NIST will issue the final CSF 2.0 and provide technical assistance on alignment of regulations with international standards and the NIST CSF, as requested by Federal agencies. NCS Reference Regulations should be performance-based, leverage existing cybersecurity frameworks, voluntary consensus standards, and guidance – including the Cybersecurity and Infrastructure Security Agency (CISA)'s Cybersecurity Performance Goals and the National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity... Responsible Agency: NIST Contributing Entities: CISA, SRMAs Completion Date: 1Q FY25 NATIONAL CYBERSECURITY STRATEGY IMPLEMENTATION PLAN 13

Select target paragraph3