Skip to content
You can now search across every topic, entity and event.What's new
Binding Operational Directive
ConceptUS

Binding Operational Directive

A compulsory CISA directive setting mandatory security actions and deadlines for US federal civilian agencies.

Last refreshed: 24 July 2026 · Appears in 1 active topic

Key Question

The BOD 26-04 clock only starts when CISA catalogues a flaw, so what happens when detection runs a month ahead?

Timeline for Binding Operational Directive

#11 16 Jul

CISA's KEV list runs a month late

Cybersecurity: Threats and Defences
View full timeline →

Background

Binding Operational Directive 26-04 sets the federal patching Deadline that starts once a flaw enters CISA's Known Exploited Vulnerabilities catalogue; the clock lagged real-world exploitation of Fortinet's FortiSandbox by a month in July 2026 because CrowdSec detected the attack weeks before CISA catalogued it.

A Binding Operational Directive is a compulsory instruction from CISA setting mandatory security actions and deadlines for US federal civilian executive-branch agencies. BOD 26-04 prioritises patching by the risk a vulnerability's KEV listing signals, rather than by severity score alone.

CISA faces its first enforcement test at the BOD 26-04 60-day checkpoint in early August 2026, a Deadline set against the agency's own FY27 staffing cuts.

Common Questions
What is a Binding Operational Directive?
A Binding Operational Directive is a compulsory instruction from CISA setting mandatory security actions and deadlines for US federal civilian executive-branch agencies.Source: CISA
When does CISA's BOD 26-04 patching deadline start?
The BOD 26-04 clock starts when CISA adds a flaw to its Known Exploited Vulnerabilities catalogue, which in the FortiSandbox case ran a month behind private detection by CrowdSec.Source: CISA