Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Phase II asks agencies for paperwork

2 min read
12:09UTC

BOD 26-04's second checkpoint falls around 9 August and requires agencies only to update internal procedures and hand copies to CISA on request. No public filing exists, and the directive provides no way to name an agency that misses it.

TechnologyAssessed
Key takeaway

The August checkpoint produces internal documents only; December is the first stage with a checkable obligation.

BOD 26-04 requires federal agencies to update their internal vulnerability-management procedures and furnish copies to CISA on request, a step falling due 60 days after the directive's 10 June issuance and therefore around 9 August 1. A Binding Operational Directive is a compulsory instruction CISA may issue to federal civilian agencies; this one was issued on 10 June and revoked the fixed-deadline regime that preceded it. The directive runs in three stages. Phase I applied immediately on issuance and required agencies to keep monitoring the catalogue and continue routine hygiene scanning. Phase III lands at 180 days, around mid-December, and is where remediation tagging becomes binding.

Read the text of the August stage carefully and the enforcement question answers itself. No public compliance filing exists at this stage, and nothing in the directive provides for identifying an agency that fails it. The documents produced will circulate between an agency and CISA, on request, and nowhere else. A security chief hoping to benchmark a private estate against the federal one therefore has nothing to benchmark against until the December stage produces tagging that can actually be checked.

That conclusion has a different footing from the deadline arithmetic elsewhere in this briefing. Whether the shortening of federal patch windows reflects doctrine or the mix of products being exploited is arguable, and more months of data could settle it either way. What the August checkpoint requires comes from the instrument itself, which does not change with the next register update.

This beat told readers in its last briefing to watch whether CISA would name a non-compliant agency at this checkpoint. The directive's text carries no such mechanism, and that expectation was ours rather than the document's.

Deep Analysis

In plain English

In June, the US government's cyber-defence agency, CISA, replaced its old system of fixed patch deadlines with a new three-stage plan. The second stage, due around 9 August, asks federal agencies to update their internal policies for handling security flaws and show CISA the paperwork if asked. That's all this stage requires. It doesn't produce a public report card, and CISA has no built-in way to name an agency that falls short at this point. Anyone expecting a public reckoning here will be looking in the wrong place: the directive's actual enforcement teeth, if any, wait until its third stage, roughly mid-December.

Deep Analysis
Root Causes

Phase II is a paperwork gate by design: BOD 26-04 structures compliance in three phases, immediate KEV monitoring, a 60-day procedural update, and 180-day full remediation tagging, and only the last phase touches the remediation record CISA could use to name a lagging agency publicly.

The absence of a public compliance filing at Phase II is not a gap CISA needs to fix; it is how the directive was written from the start. A checkpoint built around internal documentation, provided to CISA only on request, structurally cannot produce the kind of public naming its predecessor's fixed deadlines made visible by omission.

What could happen next?
  • Meaning

    Phase II's due-around-9-August date will not produce a public compliance report, so absence of news at that date is not evidence of anything.

  • Opportunity

    Phase III's mid-December remediation-tagging deadline is the point where public accountability, if it comes at all under this directive, would actually surface.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

CISA· 3 Aug 2026
Read original
Causes and effects
This Event
Phase II asks agencies for paperwork
Anyone waiting for the August checkpoint to reveal which agencies are keeping pace with the shortened deadlines will get nothing until December.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.