White House issues NSPM to enable private-sector offensive cyber operations against transnational cybercrime
The NSPM expands private‑sector involvement in offensive cyber operations, creating a federally supervised program to target transnational cybercrime.
ADTP Regulatory Watch· August 18, 2026· U.S. Departments of Justice and Homeland Security
ImpactLow 37
Type🖋️ Executive Order
Statusannouncednot law
JurisdictionUS
Effectivenot stated
What happened
On August 12, 2026 the Administration published a National Security Presidential Memorandum establishing a program for vetted private companies to conduct offensive cyber operations against foreign cyber‑enabled transnational criminal organizations. The program requires federal oversight, contractual agreements, and a minimum $1 million bond, with implementation guidance due by October 11, 2026. Participation is subject to U.S. law, including the CFAA, and must be coordinated through a newly created National Coordination Center.
Why it matters for trust and compliance
Its status is announced. It is not law yet. Track it, but do not treat it as an obligation.
The NSPM expands private‑sector involvement in offensive cyber operations, creating a federally supervised program to target transnational cybercrime.
Who is affected
technologygovernmentU.S. Department of JusticeU.S. Department of Homeland Security
Recommended actions
Map the security requirements to existing controls and close gaps.