Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Phase II asks agencies for paperwork

2 min read
16:08UTC

BOD 26-04's second checkpoint falls around 9 August and requires agencies only to update internal procedures and hand copies to CISA on request. No public filing exists, and the directive provides no way to name an agency that misses it.

TechnologyAssessed
Key takeaway

The August checkpoint produces internal documents only; December is the first stage with a checkable obligation.

BOD 26-04 requires federal agencies to update their internal vulnerability-management procedures and furnish copies to CISA on request, a step falling due 60 days after the directive's 10 June issuance and therefore around 9 August 1. A Binding Operational Directive is a compulsory instruction CISA may issue to federal civilian agencies; this one was issued on 10 June and revoked the fixed-deadline regime that preceded it. The directive runs in three stages. Phase I applied immediately on issuance and required agencies to keep monitoring the catalogue and continue routine hygiene scanning. Phase III lands at 180 days, around mid-December, and is where remediation tagging becomes binding.

Read the text of the August stage carefully and the enforcement question answers itself. No public compliance filing exists at this stage, and nothing in the directive provides for identifying an agency that fails it. The documents produced will circulate between an agency and CISA, on request, and nowhere else. A security chief hoping to benchmark a private estate against the federal one therefore has nothing to benchmark against until the December stage produces tagging that can actually be checked.

That conclusion has a different footing from the deadline arithmetic elsewhere in this briefing. Whether the shortening of federal patch windows reflects doctrine or the mix of products being exploited is arguable, and more months of data could settle it either way. What the August checkpoint requires comes from the instrument itself, which does not change with the next register update.

This beat told readers in its last briefing to watch whether CISA would name a non-compliant agency at this checkpoint. The directive's text carries no such mechanism, and that expectation was ours rather than the document's.

Deep Analysis

In plain English

In June, the US government's cyber-defence agency, CISA, replaced its old system of fixed patch deadlines with a new three-stage plan. The second stage, due around 9 August, asks federal agencies to update their internal policies for handling security flaws and show CISA the paperwork if asked. That's all this stage requires. It doesn't produce a public report card, and CISA has no built-in way to name an agency that falls short at this point. Anyone expecting a public reckoning here will be looking in the wrong place: the directive's actual enforcement teeth, if any, wait until its third stage, roughly mid-December.

Deep Analysis
Root Causes

Phase II is a paperwork gate by design: BOD 26-04 structures compliance in three phases, immediate KEV monitoring, a 60-day procedural update, and 180-day full remediation tagging, and only the last phase touches the remediation record CISA could use to name a lagging agency publicly.

The absence of a public compliance filing at Phase II is not a gap CISA needs to fix; it is how the directive was written from the start. A checkpoint built around internal documentation, provided to CISA only on request, structurally cannot produce the kind of public naming its predecessor's fixed deadlines made visible by omission.

What could happen next?
  • Meaning

    Phase II's due-around-9-August date will not produce a public compliance report, so absence of news at that date is not evidence of anything.

  • Opportunity

    Phase III's mid-December remediation-tagging deadline is the point where public accountability, if it comes at all under this directive, would actually surface.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

CISA· 3 Aug 2026
Read original
Causes and effects
This Event
Phase II asks agencies for paperwork
Anyone waiting for the August checkpoint to reveal which agencies are keeping pace with the shortened deadlines will get nothing until December.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.