MEMORANDUM FOR THE VICE PRESIDENT
THE SECRETARY OF STATE
THE SECRETARY OF THE TREASURY
THE SECRETARY OF WAR
THE ATTORNEY GENERAL
THE SECRETARY OF COMMERCE
THE SECRETARY OF ENERGY
THE SECRETARY OF HOMELAND SECURITY
THE ASSISTANT TO THE PRESIDENT AND CHIEF OF STAFF
THE DIRECTOR OF NATIONAL INTELLIGENCE
THE ASSISTANT TO THE PRESIDENT FOR SCIENCE AND TECHNOLOGY
THE DIRECTOR OF THE CENTRAL INTELLIGENCE AGENCY
THE DIRECTOR OF THE OFFICE OF MANAGEMENT AND BUDGET
THE ASSISTANT TO THE PRESIDENT FOR NATIONAL SECURITY AFFAIRS
THE ASSISTANT TO THE PRESIDENT AND DEPUTY CHIEF OF STAFF FOR POLICY AND HOMELAND SECURITY ADVISOR
THE NATIONAL CYBER DIRECTOR
THE CHAIRMAN OF THE JOINT CHIEFS OF STAFF
THE DIRECTOR OF THE NATIONAL SECURITY AGENCY
By the authority vested in me as President by the Constitution and the laws of the United States of America, I hereby direct the following:
Section 1. Purpose. Transnational Criminal Organizations (TCOs) are increasingly threatening American citizens, businesses, and national security. These groups carry out ongoing cyber operations to commit fraud, undermining the nation’s prosperity, security, and freedom. With Executive Order 14390 dated March 6, 2026 (Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens), I instructed the Federal Government to undertake various measures to address cyber-enabled crimes affecting Americans. This memorandum enhances the efforts against TCO-driven cybercrime by engaging the private sector’s innovative capabilities.
The U.S. private sector, known for its innovation and technological advancement, offers a significant cyber advantage. However, it has been underutilized in disrupting cybercriminal networks. Thus, it is the U.S. policy to leverage all national power tools, including private sector innovation, to fight cybercrime. By collaborating with vetted U.S. companies under Federal Government oversight, we aim to strengthen our response to TCO threats and combat transnational cybercrime, fraud, and predatory schemes targeting Americans.
Sec. 2. Establishing the Program. (a) The National Coordination Center (NCC), as per section 6(d) of Executive Order 14159 dated January 20, 2025 (Protecting the American People Against Invasion), will create, manage, and sustain a Program to authorize Participating Companies, as defined in section 4(f) of this memorandum, to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), supervised by the Federal Government. As part of lawful investigatory, protective, or intelligence operations led by Federal law enforcement, this Program shall:
(i) Be overseen by co-Executive Directors from the Department of Justice and the Department of Homeland Security, designated by the Attorney General and the Secretary of Homeland Security, respectively (Program Executive Directors). These directors will have the authority to approve, after mutual coordination, cyber operations conducted by their departments, except those leading to Critical Outcomes, as defined in section 4(b) of this memorandum. Cyber operations will only proceed after coordination between the Program Executive Directors, with actions taken exclusively under Federal Government supervision and lawful authority;
(ii) Require Participating Companies to sign contracts with the Department of Justice or the Department of Homeland Security, ensuring rigorous vetting and adherence to operational procedures as outlined in section 3 of this memorandum; and
(iii) Allow Participating Companies to engage in commercial agreements with:
(A) Private sector entities, from which Participating Companies may receive threat information during normal business activities to propose cyber operations to the NCC; and
(B) Federal, State, local, tribal, and territorial agencies, which will identify CE-TCO threats enabling Participating Companies to propose corresponding cyber operations to the NCC.
(b) The NCC will conduct all Program activities in accordance with the Constitution and applicable U.S. laws and international obligations, including section 1030 of title 18, United States Code, ensuring Participating Companies operate under U.S. Government oversight.
Sec. 3. Implementing Guidance. (a) Within 60 days of this memorandum, the Program Executive Directors, in coordination with the Homeland Security Council, shall establish operating procedures for complete Federal Government oversight and control of Participating Companies’ performance. No operation will be approved unless compliant with these procedures. The procedures shall:
(i) Set minimum standards for Participating Companies to join the Program, including technical proficiency, proven cyber operations performance, facility security, personnel vetting, competence, reliability, and other relevant factors determined by the Program Executive Directors and Homeland Security Council;
(ii) Ensure the Program’s eligibility criteria allow both large companies, providing critical capacity, and smaller, agile companies, suited for specialized tasks, to participate;
(iii) Require Participating Companies to disclose all contractual relationships entered into under section 2(a)(iii) to the NCC;
(iv) Authorize the Department of Justice and the Department of Homeland Security to require Participating Companies to maintain a bond or escrow of at least $1 million, forfeitable upon non-compliance with the contractual agreement under section 2(a)(ii);
(v) Set the operational workflow of the Program, including operational deconfliction across Federal law enforcement, the Department of State, the Department of the Treasury, the Department of War, the Department of Justice, and the U.S. Intelligence Community, in line with the classified annex to this memorandum;
(vi) Provide an adjudicatory framework to ensure operational activities target only CE-TCOs, considering other U.S. Government equities, as per the classified annex;
(vii) Establish standardized rubrics and templates for target identification and processing of Cyber Surveillance and Cyber Effects Operations packages;
(viii) Include reporting requirements for Participating Companies to improve understanding of foreign CE-TCO activities and impact on Americans and the economy, ensuring the NCC is informed of operational activities;
(ix) Ensure Program activities directed at U.S. persons or implicating U.S. Government obligations under the Constitution, Federal law, or international law receive necessary authorization, judicial or otherwise, before operation approval;
(x) Ensure Participating Companies cease operations and notify the NCC if they discover operational activity exceeding approved parameters, such as unintentional targeting of a U.S. person or information system within the U.S.;
(xi) Mandate immediate notification to the NCC if Participating Companies discover an imminent cyber-attack against U.S. critical infrastructure or suspect a Cyber Effects or Cyber Surveillance Operation may lead to Critical Outcomes;
(xii) Clarify that Participating Companies may engage in other lawful defensive cyber operations, but activities authorized by the Program must be under U.S. Government oversight and legal authority;
(xiii) Include procedures for evaluating Participating Companies’ continued Program participation at least annually; and
(xiv) Require the Program Executive Directors to review every cyber operations package and provide written approval and direction before action.
(b) The Program Executive Directors will regularly assess and improve the Program’s operational procedures to maintain effective execution of the objectives outlined in this memorandum. The NCC will also automate Program elements where appropriate, in compliance with applicable law and this memorandum’s requirements.
(c) Within 180 days of this memorandum, and annually thereafter, the Program Executive Directors will report the Program’s status to the Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor and the National Cyber Director.
Sec. 4. Definitions. For this memorandum:
(a) “Cyber Effects Operation” refers to activities conducted through the interconnected network of information technology infrastructure, including the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers, resulting in manipulation, disruption, denial, degradation, or destruction of information systems, networks, or infrastructure controlled by information systems, or information therein.
(b) “Critical Outcomes” are actions that likely result in loss of life, serious injury, or rise to the level of use of force or armed attack under international law.
(c) “Cyber-Enabled Transnational Criminal Organization (CE-TCO)” refers to any foreign group conducting cyber-enabled crime against the U.S. Government, U.S. persons, or U.S. interests, not institutionally part of or directed by a foreign government, unless clear intelligence establishes such a connection.
(d) “Cyber Surveillance Operation” means activities conducted through the network of information systems, including the Internet and telecommunications networks, for collecting information or intelligence from systems and infrastructure, with the intent to remain undetected. These operations include accessing systems without owner authorization or exceeding authorized access, and actions essential to enable Cyber Surveillance Operations, such as minor manipulations or disruptions not intended to affect infrastructure usability.
(e) “Information system” is defined as per section 3502 of title 44, United States Code.
(f) “Participating Companies” are private U.S. companies accepted into the Program, authorized to conduct cyber operations under U.S. Government direction.
(g) “United States person” is defined as per Executive Order 12333.
Sec. 5. General Provisions. (a) Nothing in this memorandum should impair or affect:
(i) The authority granted by law to any executive department or agency, or its head; or
(ii) The functions of the Director of the Office of Management and Budget related to budgetary, administrative, or legislative proposals.
(b) This memorandum will be implemented in accordance with applicable law and contingent on available appropriations.
(c) This memorandum does not create any enforceable right or benefit, substantive or procedural, at law or equity, against the United States, its departments, agencies, entities, officers, employees, or agents, or any other person.
DONALD J. TRUMP

