MemorandumThe White HouseAugust 12, 2026

Federal program lets vetted U.S. tech firms run government-directed cyber operations

A White House memorandum creates a program for vetted U.S. companies to carry out cyber surveillance and disruptive operations under DOJ and DHS control to counter foreign cyber criminal groups.

Summary

What it does

  • Creates a Program, run by the National Coordination Center (NCC), to authorize vetted U.S. companies ("Participating Companies") to conduct two kinds of operations under federal control: Cyber Surveillance Operations and Cyber Effects Operations against foreign cyber-enabled transnational criminal organizations (CE‑TCOs).

Who runs and oversees it

  • Co-Executive Directors: one from the Department of Justice (designated by the Attorney General) and one from the Department of Homeland Security (designated by the Secretary). They approve operations after coordination, but may not approve operations that would result in "Critical Outcomes."
  • The NCC must ensure all activities comply with the Constitution, U.S. law (including 18 U.S.C. 1030), and international obligations.

Key rules, limits, and safeguards

  • Participating Companies must sign contracts with DOJ or DHS and undergo rigorous vetting and ongoing annual evaluations.
  • Companies may have commercial agreements to receive threat information from private entities and to coordinate with federal, state, local, tribal, and territorial agencies.
  • The Program can require participating firms to maintain a bond or escrow of at least $1 million, forfeitable for non‑compliance.
  • Procedures must ensure review and any required authorization (including by DOJ) before targeting a U.S. person or U.S. system; companies must stop and notify the NCC and DOJ if operations exceed approved parameters or risk Critical Outcomes.

Deadlines and reporting

  • Within 60 days: Program Executive Directors must establish consensus operating procedures governing eligibility, workflows, deconfliction, reporting, and legal review.
  • Within 180 days and annually thereafter: the Program Executive Directors must produce and submit a status report on the Program.

Definitions to know

  • Cyber Surveillance Operation: unauthorized or excess-access activity aimed at collecting information while remaining undetected.
  • Cyber Effects Operation: activity that manipulates, degrades, disrupts, or destroys information systems or infrastructure.
  • Critical Outcomes: likely loss of life, serious injury, or actions rising to use of force/armed attack under international law.

Why it matters

  • The memo expands government use of private-sector cyber capabilities to identify and disrupt foreign cybercriminal networks, while creating written procedures, oversight roles, and reporting requirements to limit operations that could affect U.S. persons or cause severe harm.

Related links

Source: The White House

Official text