
Binding Operational Directive
A compulsory CISA directive setting mandatory security actions and deadlines for US federal civilian agencies.
A Binding Operational Directive is CISA's compulsory tool for setting security deadlines on US federal agencies; BOD 26-04, its current version, took effect 10 June 2026 and enters Phase II around 9 August.
Last refreshed: 3 August 2026 · Appears in 1 active topic
The BOD 26-04 clock only starts when CISA catalogues a flaw, so what happens when detection runs a month ahead?
Timeline for Binding Operational Directive
Mentioned in: KEV three-day deadline share fell to 65%
Cybersecurity: Threats and DefencesCISA's KEV list runs a month late
Cybersecurity: Threats and DefencesMentioned in: Phase II asks agencies for paperwork
Cybersecurity: Threats and DefencesBackground
A Binding Operational Directive is a compulsory instrument the Cybersecurity and Infrastructure Security Agency uses to set mandatory security actions and deadlines for US federal civilian executive branch agencies. Directives are numbered sequentially and superseded as CISA revises its approach; BOD 22-01 and BOD 26-04 are successive examples covering vulnerability remediation.
The instrument binds only federal agencies directly; private-sector organisations are not compelled to follow the same deadlines, though many use CISA's directives as an informal benchmark for their own patching priorities.
Directives of this kind differ from legislation in that they do not require congressional action to take effect or be revised; CISA issues and updates them administratively, which lets the mandated deadlines shift relatively quickly as the agency's risk assessment changes.
The current directive enters Phase II
Binding Operational Directives are the mechanism CISA uses to compel federal civilian agencies to take specific security actions by a set Deadline; the current one, BOD 26-04, replaced a flat 14-day default with risk-tiered windows on 10 June 2026. Its Phase II falls due around 9 August, sixty days after issuance, and requires agencies to update internal vulnerability-management procedures and hand copies to CISA on request.
That phase carries no public filing requirement and no way for CISA to name an agency that falls short. A month earlier, the tool's tightened deadlines had already been blamed for a case where CISA's own KEV catalogue lagged active exploitation of a FortiSandbox flaw by a month.