
THE 60-SECOND VERSION
The White House released President Trump’s Cyber Strategy for America on March 7, 2026.⁷ Six pillars. Four pages. Zero implementation timelines. The security industry is already lining up to applaud the parts that validate their roadmaps. Here’s a different take: this strategy gets the direction mostly right, dodges the hardest questions, quietly reverses the most consequential policy shift in a decade, and creates a structural dependency on vendors that most CISOs haven’t priced into their strategy yet.⁸
If you run a security program at a critical infrastructure operator, federal supplier, or multinational OEM, this document matters. But not for the reasons the press releases will tell you.
WHAT THE STRATEGY GETS RIGHT
Credit where it’s due. Three pillars contain genuine signal.
Post-quantum cryptography is now federal policy direction, not a conference talking point. Pillar 3 calls for PQC implementation across federal information systems. Pillar 5 doubles down, committing to promote PQC adoption broadly and secure quantum computing. NIST finalized its first three PQC standards (ML-KEM, ML-DSA, and SLH-DSA) in August 2024.² This strategy turns adoption from a forward-looking best practice into a policy trajectory. Every organization in the federal supply chain or critical infrastructure sectors should treat this as a starting gun, not a warning shot.
Supply chain security language maps to real operational requirements. Pillar 4 names energy, telecom, financial systems, data centers, water, and hospitals explicitly. It calls for hardening both IT and OT supply chains, moving away from adversary-country vendors, and securing operational technology environments. The document never uses the words “device identity” or “certificate lifecycle,” but you cannot execute zero-trust in OT environments without authenticated device identity. You cannot verify supply chain integrity without code signing and firmware authentication. The technical requirements are implicit in every sentence.
The US-EU regulatory convergence is now undeniable. This strategy’s direction aligns with the EU Cyber Resilience Act (full enforcement December 11, 2027)³ and the Radio Equipment Directive. Different legal frameworks, converging technical requirements. OEMs selling into both markets face a choice: build one trust architecture that covers both regimes, or run parallel compliance programs at twice the cost. The smart money builds once.
WHAT THE STRATEGY QUIETLY REVERSES
Here’s where the analysis most people are publishing falls short. The most consequential aspect of this strategy isn’t what it says. It’s what it deliberately omits.
The software liability shift is dead. CISOs should be alarmed.
The Biden-era National Cybersecurity Strategy (March 2023) made the boldest policy move in federal cyber in a decade: explicitly shifting liability toward software and technology producers for shipping insecure products.⁴ The logic was straightforward. The organizations best positioned to reduce systemic risk are the ones writing the code, not the ones buying it. Holding producers accountable for security defects creates market incentives that no amount of “shared responsibility” rhetoric ever will.
This strategy drops that concept entirely. Pillar 2, “Promote Common Sense Regulation,” is framed as reducing compliance burdens and streamlining regulations. Read through a CISO’s lens, the practical effect is clear: the responsibility for defense stays on buyers, not producers. The vendor who shipped you vulnerable firmware, the SaaS provider whose API had an authentication bypass, the OT manufacturer who hasn’t patched a known CVE in 18 months: their accountability framework just got lighter, not heavier.
If you’re a CISO, this is the single most important line item in the entire strategy. You are being told to harden your networks, migrate to PQC, deploy AI-driven defense, and secure your OT supply chain, while the vendors selling you the building blocks face less pressure to ship secure products. Plan accordingly.
CISA is conspicuously absent.
The strategy does not mention CISA by name. Not once. This is the primary civilian cybersecurity agency: the organization that coordinates federal-to-private-sector threat intelligence sharing, maintains the Known Exploited Vulnerabilities catalog, leads critical infrastructure incident response, and runs the Joint Cyber Defense Collaborative.⁵ The current administration has been reducing CISA’s staff and budget throughout 2025-2026.
The strategy calls for “unprecedented coordination across government and the private sector.” The question every CISO should ask: who, specifically, executes that coordination at the operational level? If the answer is a diminished CISA with fewer analysts and smaller programs, the strategy’s ambitions exceed its execution capacity. Watch the budget numbers, not the pillar language.
WHAT THE STRATEGY GETS WRONG
Deterrence theory doesn’t port cleanly to cyber.
Pillar 1 is built on an assumption borrowed from conventional military strategy: impose enough cost on adversaries, and they change behavior. In nuclear deterrence, this works because attribution is instant, escalation pathways are understood, and the consequences are existential. Cyber is fundamentally different.
Attribution is slow, uncertain, and often politically contested. Nation-state adversaries (China, Russia, Iran, DPRK) operate with different risk tolerances, escalation thresholds, and strategic objectives. Criminal groups dissolve and reform under new names within weeks. The last decade of increasingly aggressive US offensive cyber operations has not produced a measurable reduction in attacks against American critical infrastructure. Salt Typhoon compromised major US telecom providers during a period of active US cyber operations.⁶
A CISO who builds a security program around the assumption that federal deterrence will meaningfully reduce inbound threat volume is making a bet the evidence doesn’t support. Design for resilience and recovery speed, not for a threat landscape that gets quieter.
“Agentic AI for network defense” is a new attack surface masquerading as a solution.

Pillar 5 commits to rapidly adopting agentic AI to scale network defense and disruption. Autonomous systems making defensive decisions at machine speed, without specified human-in-the-loop requirements, testing frameworks, or failure mode analysis. The strategy contains zero language about AI safety guardrails for these systems.
For CISOs evaluating AI-driven SOC automation, the questions the strategy ignores are the ones that matter most: What happens when an adversary poisons the model’s training data? How do you validate that an autonomous defensive action won’t take down production systems? How do you authenticate an agentic AI system operating across organizational trust boundaries? Who signs the model weights, and how do you verify integrity?
AI is simultaneously the most promising defensive capability and the newest attack surface in your environment. The strategy treats it exclusively as the former. Your risk register should account for both.
“Partner with the private sector” without funding is an unfunded mandate.
The strategy calls on private infrastructure operators to harden supply chains, adopt PQC, implement zero-trust, and deploy AI-driven defense capabilities. It announces no new funding mechanisms, tax incentives, grant programs, or procurement vehicles to support these investments.
Water utilities running on razor-thin municipal budgets. Rural hospitals already struggling with ransomware recovery costs. Small energy cooperatives operating legacy SCADA systems. These organizations are explicitly named in Pillar 4’s critical infrastructure scope. Telling them to upgrade their OT security posture without new resources is not a partnership. It’s a mandate wrapped in the language of collaboration.
If you’re a CISO at a critical infrastructure operator, build your budget justification now. The implementation guidance will follow, and you’ll need investment approval before, not after, the requirements formalize.
THE PILLAR NOBODY’S TAKING SERIOUSLY ENOUGH
Pillar 6: Build Talent and Capacity (or, why your vendor strategy just became your cyber strategy)

The global cybersecurity workforce shortage stands at 3.79 million unfilled positions according to ISC2’s 2025 Workforce Study.¹ The strategy’s language about universities, vocational programs, and industry partnerships is directionally reasonable. But for CISOs who need to execute PQC migration, AI security integration, and OT supply chain hardening simultaneously, the math doesn’t work. Three compounding pressures make this the most consequential gap in the entire strategy:
PQC migration requires skills that barely exist. Cryptographic engineering talent, people who understand lattice-based algorithms, hybrid certificate deployment, protocol-level migration planning, and crypto agility architecture, is extremely scarce. Every customer conversation I have about PQC timelines runs into the same constraint: “Who on my team can actually do this?” The strategy calls for PQC adoption AND workforce development but doesn’t connect the two. You can’t stand up a university program today and have graduates ready for a migration federal policy is already pushing.
AI changes what “cyber talent” means faster than the pipeline can adapt. The strategy calls for AI-driven defense AND workforce expansion. These are in tension. AI-augmented SOCs need fewer traditional analysts but more engineers who can build, tune, and validate autonomous systems. The talent pipeline described in Pillar 6 should be training people to work alongside agentic AI, not backfilling roles that AI is already transforming. CISOs need to rethink team composition now, not wait for a federal workforce initiative that’s years from producing graduates.
The immigration-shaped hole. A significant percentage of the US cybersecurity workforce at the senior engineering and research level is immigrant talent on H-1B and similar visas. The strategy mentions universities, vocational programs, and industry partnerships. It does not mention immigration as a talent pipeline. For CISOs competing for scarce cryptographic and AI security expertise, this omission directly constrains the available talent pool at exactly the moment demand is spiking.
These three pressures compound, and the result reshapes your operating model. PQC skills are scarce. AI security skills are being redefined in real time. Immigration constraints are tightening the aperture on senior technical talent. Taken together, they leave CISOs with a structural inability to staff these programs internally at the pace the strategy demands.
This is why Pillar 6 is really a vendor strategy question in disguise. CISOs will increasingly rely on global systems integrators (Deloitte, Accenture, PwC) for migration program management and on specialized PKI and security vendors (DigiCert, Thales, Entrust) for the cryptographic engineering, tooling, and managed services that make PQC transition, AI trust infrastructure, and supply chain identity operationally feasible. The question is not whether to outsource these functions. It’s whether you’re selecting vendors now with the right roadmap alignment, or scrambling for partner capacity later when every CISO in your sector is competing for the same scarce resources.
WHAT YOU SHOULD DO MONDAY MORNING
1. Run your cryptographic inventory this quarter. You can’t migrate what you can’t see. Prioritize long-lived secrets, firmware signing keys, and anything protecting data that needs confidentiality beyond 2030. If you don’t have the internal crypto engineering talent to scope this (most organizations don’t), engage a vendor or SI now while capacity is available.
2. Evaluate your vendor relationships against three questions. Can your PKI provider execute a hybrid PQC certificate deployment today, not on a future roadmap? Can your SI partner staff a crypto migration team within 90 days? Do your security vendors participate in the standards bodies (NIST, IETF, industry consortia) that will shape whatever implementation guidance follows this strategy? If you’re answering no to any of these, fix your vendor shortlist before the implementation details drop.
3. Build one compliance architecture for US + EU. The directional convergence between this strategy and the EU CRA/RED is real.³ Dual-track compliance programs are a waste of engineering resources. Build to the highest common denominator. If US requirements soften, you’re ahead. If they tighten, you’re ready. If EU timelines hold (and they will), you’re compliant.
4. Put AI defense and AI risk on the same page of your risk register. The strategy treats AI purely as a defensive multiplier. Your board briefing should treat it as both capability and attack surface. If you’re deploying agentic AI in your SOC, document the threat model for that system with the same rigor you’d apply to any other critical control.
5. Brief your board now, not after implementation guidance drops. The organizations that secure budget and vendor commitments in advance of formal mandates avoid the capacity crunch that follows every major federal cybersecurity directive. Use the talking points below.
BOARD TALKING POINTS
If you need to brief your board or risk committee this month:
The US government is converging with the EU on cybersecurity requirements. Building to one standard saves money. Building to two wastes it. Our security architecture should target the highest common denominator across both regimes.
Post-quantum cryptography migration has shifted from theoretical to policy-driven. We need a crypto inventory and migration timeline. Organizations that start now build institutional knowledge. Organizations that wait face emergency migrations under deadline pressure.
Supply chain security extends to device identity and OT environments. If we cannot verify what is connected to our network and who manufactured it, we have a gap this strategy will eventually formalize into requirements.
The talent market cannot support the demand this strategy creates. Our execution plan depends on vendor partnerships for PQC migration, AI security, and supply chain trust. We should be selecting and engaging those partners now, before capacity constraints drive up costs and timelines.¹
Regulatory “streamlining” may reduce our compliance costs, but it does not reduce our threats. Our security investment should be threat-driven and convergence-driven, not calibrated to the compliance minimum.
SOURCES AND REFERENCES
¹ ISC2, “2025 Cybersecurity Workforce Study,” December 2025. Global cybersecurity workforce gap: 3.79 million professionals. https://www.isc2.org/Insights/2025/12/ISC2-Publishes-2025-Cybersecurity-Workforce-Study
² NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 13, 2024. Standards: FIPS 203 (ML-KEM/Kyber), FIPS 204 (ML-DSA/Dilithium), FIPS 205 (SLH-DSA/SPHINCS+). https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
³ EU Cyber Resilience Act: entered into force December 2024; manufacturer vulnerability/incident reporting obligations begin September 11, 2026; full compliance enforcement begins December 11, 2027. https://www.cyberresilienceact.eu/current-state-of-play/
⁴ The White House, “National Cybersecurity Strategy,” March 2023. Strategic Objective 3.3: “Shift Liability for Insecure Software Products and Services.” https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf
⁵ CISA (Cybersecurity and Infrastructure Security Agency) operates the Known Exploited Vulnerabilities (KEV) catalog, Joint Cyber Defense Collaborative (JCDC), and serves as the national coordinator for critical infrastructure security.
https://www.cisa.gov/
⁶ Salt Typhoon: Chinese state-sponsored threat group that compromised at least nine major US telecommunications providers in 2024-2025, accessing call records, metadata, and in some cases live communications. Disclosed publicly by CISA and FBI in late 2024.
⁷ President Trump, “Cyber Strategy for America,” The White House, March 7, 2026.
⁸ SecurityWeek, “US Cyber Strategy Targets Adversaries, Critical Infrastructure, and Emerging Technologies,” Mike Lennon, March 7, 2026. https://www.securityweek.com/us-cyber-strategy-targets-adversaries-critical-infrastructure-and-emerging-technologies/
Tim McAllister | Field CTO, DigiCert | Active contributor to NIST NCCoE, SAE EVPKI Consortium, CSA Matter, and CharIN industry and standards bodies. Focused on post-quantum cryptography readiness, device trust architecture, and helping critical infrastructure operators navigate the convergence of US and EU cyber compliance requirements. Opinions are my own.