
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new Binding Operational Directive, 26-04, which emphasizes security updates for Federal Civilian Executive Branch (FCEB) agencies.
This directive is designed to mitigate the risk of cyberattacks on the public sector by mandating that agencies address high-risk vulnerabilities within shortened deadlines, occasionally as brief as three days.
According to CISA, BOD 26-04 “supersedes and revokes” the earlier BOD 19-02 and BOD 22-01, which were introduced in 2019 and 2021, respectively.
The agency states that prioritizing patches is guided by four key factors:
Whether the asset is accessible online to the public
Inclusion of the vulnerability in CISA’s Known Exploited Vulnerabilities (KEV) catalog
If exploitation can be automated for widespread attacks
Whether exploitation grants attackers partial or complete control over a system
Based on these criteria, agencies are given deadlines for fixing security vulnerabilities, with the shortest period being three days.
For less critical scenarios where automated exploitation is unfeasible or only allows partial control, the timeline is set at two weeks.
Scope and implementation
The directive specifically targets U.S. Federal Civilian Executive Branch (FCEB) agencies and the information systems they manage.
This includes government agencies and departments, but excludes certain military systems run by the U.S. Department of Defense, private firms, Intelligence Community systems, and contractors.
Similar to previous directives, this framework is anticipated to shape the broader cybersecurity sector and offer a more defined patching priority indicator.
The directive covers all on-premises federal systems, third-party hosted systems, and FedRAMP/non-FedRAMP cloud environments.
Currently, agencies subject to BOD 26-04 should revise their vulnerability management policies accordingly, update their asset inventories, and automate KEV status reporting.
Vulnerability management processes must be updated within 60 days to use CVE and KEV data as the foundation for remediation decisions.
Within 180 days, all agencies will need to adhere to the new remediation timelines and continuously monitor and report detailed asset metadata.
Test every layer before attackers do
Security teams detect 54% of successful attacks and issue alerts for only 14%. The remainder moves through your environment unnoticed.
The Picus whitepaper demonstrates how breach and attack simulation evaluates your SIEM and EDR rules to prevent threats from evading detection.
Related Articles:
CISA orders feds to patch actively exploited Ivanti flaw by Sunday
GM agrees to $12.75M California settlement over sale of drivers’ data
CISA orders feds to patch exploited Ivanti EPMM flaw by Saturday
CISA flags new SD-WAN flaw as actively exploited in attacks
CISA gives feds three days to patch Ivanti flaw exploited as zero-day