
BOD 22-01
CISA's 2021 KEV mandatory-patch directive for US federal agencies, revoked and superseded by BOD 26-04 on 10 June 2026.
CISA revoked BOD 22-01, its five-year-old fixed-deadline patch directive, on 10 June 2026, replacing it with a risk-tiered model after two 2026 cases exposed its core assumption that a patch always exists.
Last refreshed: 3 August 2026 · Appears in 1 active topic
What replaced BOD 22-01 after CISA revoked it in June 2026?
Timeline for BOD 22-01
Mentioned in: KEV patch clocks fell to three days
Cybersecurity: Threats and DefencesMentioned in: BOD 26-04, a fortnight of triage
Cybersecurity: Threats and DefencesSuperseded by BOD 26-04 on 10 June 2026
Cybersecurity: Threats and Defences: CISA tears up its KEV deadline rulesArista refuses to patch KEV flaw
Cybersecurity: Threats and DefencesExchange repeats the CISA deadline-before-patch trap
Cybersecurity: Threats and DefencesBackground
Binding Operational Directive 22-01 was the CISA instrument that created the Known Exploited Vulnerabilities (KEV) catalogue in November 2021, requiring all US federal civilian executive branch agencies to remediate listed vulnerabilities within fixed deadlines, typically 14 days, compressible to 3 days for Emergency Directives. It ran for nearly five years and produced the KEV catalogue that remains a de facto industry patch benchmark for insurers, procurement teams and security auditors well beyond its federal scope.
BOD 22-01 was drafted on the assumption that a patch or documented workaround would exist before CISA set a Deadline. That assumption fractured in spring 2026 on two fault lines: deadlines set before patches existed, and a vendor's formal refusal to patch at all. CISA revoked the directive on 10 June 2026, replacing it with the risk-tiered BOD 26-04. The KEV catalogue itself continues unchanged; BOD 26-04 inherits it but replaces the compliance mechanics that made BOD 22-01 the most operationally influential US federal cybersecurity directive since FISMA.
CISA retires its fixed-deadline directive
On 10 June 2026 CISA revoked Binding Operational Directive 22-01 entirely and replaced it with BOD 26-04, a risk-tiered model assigning 3-day, 14-day, 60-day or next-upgrade-cycle windows based on exploitation status, severity, asset criticality and patch availability. The revocation created transitional ambiguity for in-flight deadlines, including Arista's 23 June window set under the old order .
Two spring 2026 failure modes drove the change: the Deadline-before-patch pattern, where the Exchange Server OWA zero-day carried a 29 May federal Deadline with the fix arriving sixteen days late , and Arista's formal refusal to patch CVE-2026-7473, the first on-record case of a named vendor declining to fix a KEV-listed flaw . BOD 22-01's fixed 14-day assumption could not absorb either scenario.