Skip to content
You can now search across every topic, entity and event.What's new
BOD 26-04
Legislation

BOD 26-04

CISA's 2026 risk-tiered patch directive replacing fixed KEV deadlines with four remediation windows.

BOD 26-04 is CISA's June 2026 directive replacing fixed KEV deadlines with risk tiers; 87 percent of new entries since then have drawn a three-day window, up from 39 percent before.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

What changed when CISA replaced BOD 22-01 with four risk tiers?

Timeline for BOD 26-04

#12 28 Jul

Replaced fixed-deadline BOD 22-01 with risk-tiered triage on 10 June

Cybersecurity: Threats and Defences: KEV patch clocks fell to three days
#10 14 Jul

Risk-tiered directive that may be reshaping KEV additions

Cybersecurity: Threats and Defences: A quiet KEV fortnight, then a 2008 bug
#9 4 Jul

Risk-tiered directive one fortnight in

Cybersecurity: Threats and Defences: BOD 26-04, a fortnight of triage
#9 1 Jul

SharePoint patch clock runs out today

Cybersecurity: Threats and Defences
#8 23 Jun

Provided the 3-day top-tier risk classification for the first time in the wild

Cybersecurity: Threats and Defences: Triple CVSS-10 Ubiquiti chain hits root
View full timeline →

Background

BOD 26-04 is a Binding Operational Directive issued by the US Cybersecurity and Infrastructure Security Agency, compulsory for federal civilian executive branch agencies. It replaced BOD 22-01, which had assigned a flat default remediation window, with a four-dimension risk model that tiers deadlines by how dangerous a flaw is judged to be.

The directive rolls out in phases. Phase II, due around 9 August 2026, requires agencies to update their internal vulnerability-management procedures and make copies available to CISA on request; there is no public filing requirement and no mechanism for CISA to name an agency that falls short. Phase III, due around mid-December 2026, is where remediation tagging binds.

Because the directive sets no published scoring rubric for how a flaw lands in a given tier, agencies face genuine uncertainty about why any single entry drew the Deadline it did, even as the compliance burden of the tightest tier has grown sharply since June.

Key Issues
Deadline compression

Patch deadlines collapsed under the new tiers

BOD 26-04 took effect on 10 June 2026, replacing BOD 22-01's fixed deadlines with a four-tier risk model assigning three-day, 14-day, 60-day or next-upgrade-cycle windows. Of the 39 flaws CISA added to its KEV catalogue between 10 June and 29 July, 34, or 87 per cent, carried a three-day Deadline or less, against 12 of 31, or 39 per cent, in the seven weeks before. Median time allowed fell from 14 days to three, mean from 9.45 to 4.41.

The rate at which CISA adds flaws did not change, holding near 0.78 entries a day either side of the directive; only the time agencies get to fix them shrank. Phase II falls due around 9 August 2026, requiring agencies to update internal vulnerability-management procedures and furnish copies to CISA on request, with no public filing and no way to name a non-compliant agency.

Common Questions

Reference

What does a 3-day remediation window under BOD 26-04 mean?
A 3-day window is the top tier, assigned when a KEV-listed flaw is internet-exposed, has a public exploit, and allows high post-exploitation impact. The Ubiquiti UniFi triple CVSS-10 chain was the first batch to draw this window, on 23 June 2026.Source: CISA KEV catalogue
Does BOD 26-04 apply to private sector companies?
Directly, no. BOD 26-04 applies only to US federal civilian executive branch agencies. However, its four-dimension risk-scoring model is widely used as an enterprise patch prioritisation benchmark internationally.Source: CISA BOD 26-04 scope section
Why did CISA revoke BOD 22-01?
BOD 22-01 assumed a patch always existed or was imminent. In practice, deadlines landed before patches shipped and vendors sometimes refused to fix flaws entirely. BOD 26-04 replaces the single-Deadline model with risk-tiered windows that account for these cases.Source: CISA BOD 26-04 preamble
What is CISA BOD 26-04 and how does it change patch deadlines?
BOD 26-04, issued 10 June 2026, replaced the single fixed Deadline per flaw under BOD 22-01 with a four-tier risk model assigning 3-day, 14-day, 60-day, or next-upgrade-cycle windows based on internet exposure, KEV status, exploit automation, and impact.Source: CISA BOD 26-04 directive
Is BOD 26-04 slowing down the pace of CISA KEV additions?
No. The addition rate held steady at roughly 0.78 entries a day through the 5-14 July quiet fortnight and beyond; of 39 entries added between 10 June and 29 July, 87 per cent (34) now carry a three-day-or-less Deadline, against 39 per cent before, so BOD 26-04 is reshaping Deadline severity, not the pace of KEV listing.Source: event
Source Material