Skip to content
You can now search across every topic, entity and event.What's new
BOD 22-01
LegislationUS

BOD 22-01

CISA's 2021 KEV mandatory-patch directive for US federal agencies, revoked and superseded by BOD 26-04 on 10 June 2026.

CISA revoked BOD 22-01, its five-year-old fixed-deadline patch directive, on 10 June 2026, replacing it with a risk-tiered model after two 2026 cases exposed its core assumption that a patch always exists.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

What replaced BOD 22-01 after CISA revoked it in June 2026?

Timeline for BOD 22-01

#12 28 Jul

Mentioned in: KEV patch clocks fell to three days

Cybersecurity: Threats and Defences
#9 4 Jul

Mentioned in: BOD 26-04, a fortnight of triage

Cybersecurity: Threats and Defences
#8 10 Jun

Superseded by BOD 26-04 on 10 June 2026

Cybersecurity: Threats and Defences: CISA tears up its KEV deadline rules
#7 9 Jun

Arista refuses to patch KEV flaw

Cybersecurity: Threats and Defences
#4 15 May

Exchange repeats the CISA deadline-before-patch trap

Cybersecurity: Threats and Defences
View full timeline →

Background

Binding Operational Directive 22-01 was the CISA instrument that created the Known Exploited Vulnerabilities (KEV) catalogue in November 2021, requiring all US federal civilian executive branch agencies to remediate listed vulnerabilities within fixed deadlines, typically 14 days, compressible to 3 days for Emergency Directives. It ran for nearly five years and produced the KEV catalogue that remains a de facto industry patch benchmark for insurers, procurement teams and security auditors well beyond its federal scope.

BOD 22-01 was drafted on the assumption that a patch or documented workaround would exist before CISA set a Deadline. That assumption fractured in spring 2026 on two fault lines: deadlines set before patches existed, and a vendor's formal refusal to patch at all. CISA revoked the directive on 10 June 2026, replacing it with the risk-tiered BOD 26-04. The KEV catalogue itself continues unchanged; BOD 26-04 inherits it but replaces the compliance mechanics that made BOD 22-01 the most operationally influential US federal cybersecurity directive since FISMA.

Key Issues
KEV directive change

CISA retires its fixed-deadline directive

On 10 June 2026 CISA revoked Binding Operational Directive 22-01 entirely and replaced it with BOD 26-04, a risk-tiered model assigning 3-day, 14-day, 60-day or next-upgrade-cycle windows based on exploitation status, severity, asset criticality and patch availability. The revocation created transitional ambiguity for in-flight deadlines, including Arista's 23 June window set under the old order .

Two spring 2026 failure modes drove the change: the Deadline-before-patch pattern, where the Exchange Server OWA zero-day carried a 29 May federal Deadline with the fix arriving sixteen days late , and Arista's formal refusal to patch CVE-2026-7473, the first on-record case of a named vendor declining to fix a KEV-listed flaw . BOD 22-01's fixed 14-day assumption could not absorb either scenario.

Common Questions

Reference

Does the CISA KEV catalogue apply to private companies?
BOD 22-01 only mandates compliance from US federal civilian executive branch agencies. However, the KEV list is widely used by the private sector, insurers, and procurement teams as a minimum patching benchmark.
What is CISA Binding Operational Directive 22-01?
BOD 22-01 is the CISA directive that created the Known Exploited Vulnerabilities catalogue in 2021, compelling US federal civilian agencies to patch listed vulnerabilities within CISA-set deadlines, typically two weeks.Source: CISA
Does the KEV catalogue still apply now that BOD 22-01 has been revoked?
Yes. The KEV catalogue continues under BOD 26-04. The catalogue itself is unchanged; only the compliance mechanics and Deadline structure were replaced. Private-sector insurers and procurement teams still treat KEV listings as the minimum mandatory-patch universe.Source: event
What is BOD 26-04 and how does it differ from BOD 22-01?
BOD 26-04 replaced BOD 22-01 on 10 June 2026. Instead of uniform 14-day or 3-day windows, it assigns remediation deadlines of 3, 14, or 60 days, or the next upgrade cycle, based on four risk dimensions: exploitation status, CVSS score, asset criticality, and patch availability.Source: event
What is BOD 22-01 and why was it revoked?
BOD 22-01 was CISA's 2021 Binding Operational Directive that created the KEV catalogue and required US federal agencies to patch listed flaws within fixed deadlines. CISA revoked it on 10 June 2026 and replaced it with BOD 26-04, a risk-tiered model with four Deadline windows, after spring 2026 exposed two structural failures: deadlines set before patches existed, and a vendor formally refusing to patch.Source: CISA
Was the Exchange Server CVE-2026-42897 patch ever released?
Yes. Microsoft shipped the fix in its June 2026 Patch Tuesday on 9 June 2026, sixteen days after the CISA federal Deadline of 29 May 2026.Source: Microsoft Security Response Center
Can a vendor refuse to fix a vulnerability that CISA has listed in the KEV catalogue?
Yes, in practice. Arista Networks confirmed in June 2026 it would not ship a software patch for KEV-listed CVE-2026-7473, citing configuration-breaking concerns, and offered only ACL mitigations instead. BOD 22-01 imposes obligations on federal agencies, not on vendors.Source: CISA KEV Catalogue
Why did CISA set federal patch deadlines before patches were available in 2026?
BOD 22-01's fixed-Deadline model assumed a patch or workaround would exist before CISA acted. In May 2026 CISA issued deadlines for Cisco SD-WAN and Exchange Server before fixes were available; the Exchange patch arrived sixteen days after the federal Deadline. BOD 26-04's next-upgrade-cycle tier is designed to avoid this.Source: event
What happens if a federal agency cannot patch a KEV vulnerability in time?
Agencies must document their remediation posture. Where no patch exists, they typically apply vendor workarounds and report the non-compliance, though BOD 22-01's text does not explicitly permit mitigation as a substitute for remediation.
Source Material