
BOD 26-04
CISA's 2026 risk-tiered patch directive replacing fixed KEV deadlines with four remediation windows.
BOD 26-04 is CISA's June 2026 directive replacing fixed KEV deadlines with risk tiers; 87 percent of new entries since then have drawn a three-day window, up from 39 percent before.
Last refreshed: 3 August 2026 · Appears in 1 active topic
What changed when CISA replaced BOD 22-01 with four risk tiers?
Timeline for BOD 26-04
Replaced fixed-deadline BOD 22-01 with risk-tiered triage on 10 June
Cybersecurity: Threats and Defences: KEV patch clocks fell to three daysRisk-tiered directive that may be reshaping KEV additions
Cybersecurity: Threats and Defences: A quiet KEV fortnight, then a 2008 bugRisk-tiered directive one fortnight in
Cybersecurity: Threats and Defences: BOD 26-04, a fortnight of triageSharePoint patch clock runs out today
Cybersecurity: Threats and DefencesProvided the 3-day top-tier risk classification for the first time in the wild
Cybersecurity: Threats and Defences: Triple CVSS-10 Ubiquiti chain hits rootBackground
BOD 26-04 is a Binding Operational Directive issued by the US Cybersecurity and Infrastructure Security Agency, compulsory for federal civilian executive branch agencies. It replaced BOD 22-01, which had assigned a flat default remediation window, with a four-dimension risk model that tiers deadlines by how dangerous a flaw is judged to be.
The directive rolls out in phases. Phase II, due around 9 August 2026, requires agencies to update their internal vulnerability-management procedures and make copies available to CISA on request; there is no public filing requirement and no mechanism for CISA to name an agency that falls short. Phase III, due around mid-December 2026, is where remediation tagging binds.
Because the directive sets no published scoring rubric for how a flaw lands in a given tier, agencies face genuine uncertainty about why any single entry drew the Deadline it did, even as the compliance burden of the tightest tier has grown sharply since June.
Patch deadlines collapsed under the new tiers
BOD 26-04 took effect on 10 June 2026, replacing BOD 22-01's fixed deadlines with a four-tier risk model assigning three-day, 14-day, 60-day or next-upgrade-cycle windows. Of the 39 flaws CISA added to its KEV catalogue between 10 June and 29 July, 34, or 87 per cent, carried a three-day Deadline or less, against 12 of 31, or 39 per cent, in the seven weeks before. Median time allowed fell from 14 days to three, mean from 9.45 to 4.41.
The rate at which CISA adds flaws did not change, holding near 0.78 entries a day either side of the directive; only the time agencies get to fix them shrank. Phase II falls due around 9 August 2026, requiring agencies to update internal vulnerability-management procedures and furnish copies to CISA on request, with no public filing and no way to name a non-compliant agency.