On August 12, 2026, the Administration published a National Security Presidential Memorandum (“NSPM”) (“Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”) that signals the Administration’s focus on private-sector participation in offensive cyber operations by establishing a federally supervised program to enable private sector participants to conduct offensive cyber operations against “Cyber-Enabled Transnational Criminal Organizations” (“CE-TCOs”).
The NSPM follows Executive Order 14390, which, together with the U.S. National Cybersecurity Strategy, demonstrated the U.S. government’s continued focus on disrupting foreign cyber-enabled criminal organizations that engage in fraud, scams, and related cyber-enabled schemes. The NSPM, which states that “it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime,” signals a potential shift in the U.S. government’s approach to offensive cyber operations by non-government actors. At the same time, the NSPM makes clear that any such operations would be conducted only after U.S. government vetting and authorization, under federal coordination and oversight, and consistent with U.S. law. This post summarizes the NSPM and identifies practical takeaways for private-sector entities that may be considering whether to participate in the program. Additional implementation guidance is expected by mid-October 2026 (60 days after the NSPM publication).
Offensive Cyber Program
The NSPM, which includes certain classified annexes that have not been publicly disclosed, creates a National Coordination Center (“NCC”) and directs it to establish a Program through which vetted private companies (“Participating Companies”) may conduct certain operations against foreign CE-TCOs under the control and oversight of the federal government. The NCC is itself established pursuant to Executive Order 14159 (“Protecting the American People Against Invasion”), which authorized the Departments of Justice and Homeland Security to create “Homeland Security Task Forces” to “end the presence of criminal cartels, foreign gangs, and transnational criminal organizations.” The broad framework includes the following:
- Federal Oversight and Supervision: The Program is led by appointed Program Executives from the U.S. Departments of Justice and Homeland Security and will require that any private sector offensive cyber operations be coordinated across the U.S. national security apparatus, including the Department of War and the U.S. Intelligence Community. The NSPM requires that “any resulting operational action” be “exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government’s lawful authorities.” Notably, the framework expressly contemplates that Program Executives may approve certain “covered cyber operations” that may result in “Critical Outcomes,” defined in the NSPM as actions that will likely “result in the loss of life or serious injury” or “rise to the level of use of force or armed attack under international law.”
- Contract Requirement: Participating Companies must enter into contractual agreements with the U.S. government, undergo “rigorous vetting,” and adhere to “strict operational procedures.” The NSPM also authorizes the Departments of Justice and Homeland Security to require that Participating Companies maintain a bond or escrow of at least $1 million that would be forfeited should the Participating Company fail to comply with its contractual obligations.
- Peer-to-Peer Information Sharing: Participating Companies are permitted to enter into commercial agreements with:
- Other private entities to receive threat information collected in the course of those entities’ normal business activities “for the purpose of proposing responsive cyber operations to the NCC”; and
- Federal, state, local, tribal, and territorial agencies, “which will identify CE-TCO threats” to the Participating Companies “in a manner that enables them to propose cyber operations to the NCC that address those threats.”
- Compliance with Constitution and Applicable Law: Program activities are to be conducted “in accordance with” the Constitution and other applicable laws, including the Computer Fraud and Abuse Act (“CFAA”) and other international obligations of the United States.
Forthcoming Implementing Guidance
The NSPM sets out a 60-day timeline for Program Executives to provide implementation guidance, which falls on October 11, 2026. Among other requirements, the guidance must address:
- Participant Eligibility: Establish minimum standards for Participating Companies—including technical proficiency, prior cyber operations performance, facility security, personnel vetting, competence, and reliability—and require disclosure to the NCC of all commercial agreements entered into under the Program. The criteria should “enable participation by both large companies, which provide critical capacity, and smaller, more agile companies, which may be better suited for specialized or discrete tasks.”
- Operational Workflows: In conformance with a classified annex, the Departments of State, Treasury, War, Justice, and the Intelligence Community are instructed to establish an operational workflow for the Program, including inter-agency deconfliction procedures and:
- An adjudicatory framework to ensure approved operations target only CE-TCOs and account for other U.S. government equities;
- Standardized rubrics and templates for target identification and surveillance and operational packages; and
- Certain reporting requirements for Participating Companies.
- Escalation, Minimization, and Incident Notification: Set out procedures to minimize risk to U.S. persons, U.S.-based information systems, or information systems controlled by U.S. persons, and to immediately notify the Program Executives of operational activity that exceeds the approved parameters. Additionally, Participating Companies must immediately notify the NCC of imminent cyber-attacks against United States critical infrastructure or if an approved operation may result in Critical Outcomes (as defined above).
Considerations for Private Sector Participants
Consistent with the Administration’s other recent actions, the Program demonstrates the continued interest on leveraging U.S. private sector capabilities to address new and emerging cybersecurity threats—and in particular, on countering the threats posed by TCOs. At the same time, although the Program signals a potential shift in the Administration’s approach to private-sector participation in offensive cyber operations, it underscores that any such activity will remain subject to careful federal review and approval to ensure alignment with U.S. foreign policy and national security interests and to mitigate unintended consequences. While public-private partnerships to combat cybercrime are not new, the NSPM creates a new framework for such collaboration, with additional guidance that the NSPM anticipates will be forthcoming this fall. Potential participants may wish to consider the following:
- Review Participant Obligations and Protections. As the NSPM contemplates a framework where private sector participants would enter into contracts with U.S. government entities and be subject to close supervision by U.S. government stakeholders, entities considering participation might want to carefully evaluate the obligations that would attach and potential protections that participants would receive under this framework—including under relevant contracts, as well as the “rigorous vetting” and “strict operational procedures” contemplated by the NSPM.
- Assess U.S. Enforcement and other Legal Risks. While private sector participants might receive certain protections when they undertake activities pursuant to U.S. government supervision, oversight, and approval, the publicly-accessible portions of the NSPM do not specifically direct the Department of Justice and other agencies as to enforcement of potentially applicable federal laws, including the CFAA. Note, however, that language in the NSPM closely mirrors the CFAA’s language excepting “lawfully authorized investigative, protective, or intelligence activity of” law enforcement and intelligence agencies. See 18 U.S.C. § 1030(f).
- Assess Cross-border Risks. Even where activities are conducted under U.S. government supervision and approval, Participating Companies may wish to assess potential additional risks arising from offensive cyber operations, including the possibility of retaliatory targeting by cyber threat actors and the potential application or enforcement of foreign laws against U.S. companies involved in offensive cyber operations that impact foreign jurisdictions.
- Secondary Effects for Non-Participants. As the NSPM explicitly permits peer-to-peer information sharing among private entities for purposes of proposing responsive cyber operations, non-participants who are engaged in information sharing activities should consider whether these information flows counsel in favor of any changes to their existing information sharing practices.
- Monitor Implementation Guidance. With Program Executives required to issue implementation guidance by October 11, 2026, entities interested in participation should monitor forthcoming guidance on participant eligibility criteria, operational workflows, and compliance requirements.