
Binding Operational Directive
A compulsory CISA directive setting mandatory security actions and deadlines for US federal civilian agencies.
Last refreshed: 24 July 2026 · Appears in 1 active topic
The BOD 26-04 clock only starts when CISA catalogues a flaw, so what happens when detection runs a month ahead?
Timeline for Binding Operational Directive
CISA's KEV list runs a month late
Cybersecurity: Threats and DefencesBackground
Binding Operational Directive 26-04 sets the federal patching Deadline that starts once a flaw enters CISA's Known Exploited Vulnerabilities catalogue; the clock lagged real-world exploitation of Fortinet's FortiSandbox by a month in July 2026 because CrowdSec detected the attack weeks before CISA catalogued it.
A Binding Operational Directive is a compulsory instruction from CISA setting mandatory security actions and deadlines for US federal civilian executive-branch agencies. BOD 26-04 prioritises patching by the risk a vulnerability's KEV listing signals, rather than by severity score alone.
CISA faces its first enforcement test at the BOD 26-04 60-day checkpoint in early August 2026, a Deadline set against the agency's own FY27 staffing cuts.