Severity Daily

IT and AI security incidents, checked against the primary source

BOD 22-01 has been dead since June. Its replacement ships the deadline matrix as a screenshot, and the first compliance date passed unremarked.

THE RECORD — BOD 22-01 has been dead since June. Its replacement ships the deadline matrix as a screenshot, and the first compliance date passed unremarked.

Written by

in

If your vulnerability management policy says “patch KEV entries within 14 days,” it cites a directive that CISA revoked eleven weeks ago. BOD 26-04 replaced it on 10 June 2026, swapping one flat deadline for a risk-tiered schedule with a three-day top tier. The schedule itself is published as an image file with no alt text, the firms transcribing it disagree about what lands in that top tier, and the directive’s first compliance milestone passed on 7 August with nobody publicly checking whether agencies met it.

What happened

CISA issued Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk,” on 10 June 2026. Its revocation language is unambiguous:

“This Directive supersedes and hereby revokes BOD 19-02: Vulnerability Remediation Requirements for Internet-Accessible Systems (April 29, 2019), and BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities (Nov. 3, 2021).”

BOD 22-01 is the one the industry internalized. It created the Known Exploited Vulnerabilities catalog and set a single rule: if a flaw is on the list, federal civilian agencies patch it within roughly two weeks. Five years of vendor SLAs, audit checklists, and internal policies were written against that number. It is no longer in force.

What replaced it grades every vulnerability on four variables: whether the affected asset is publicly exposed, whether the CVE is KEV-listed, whether the exploit is automatable, and whether the technical impact is total or partial control of the system. CISA supplies three of the four through its Vulnrichment program. Agencies determine public exposure themselves — the one input nobody outside the agency grades.

The resulting deadlines fall into four bands: three days (some carrying an additional forensic obligation), 14 days, 60 days, and a formal deferral tier where the fix waits for the next scheduled system upgrade. The clock starts at whichever comes first — CISA adding the CVE to KEV, or the agency identifying it through continuous monitoring — and the deadline moves as conditions change. Take an asset off the public internet and the timeline lengthens; a KEV addition shortens it immediately.

The three-day tier carries a second requirement that is easy to miss. In the directive’s own words:

“The text ‘& forensic triage’ means that the agency must complete remediation or mitigation action within the timeline (three days) and carry out a forensic triage of the asset to assess whether the system is compromised.”

Patch it, and separately determine whether you were already owned. Both inside 72 hours.

Obligations phase in. Policy and process updates were due at 60 days — FedRAMP’s guidance names 7 August 2026. Remediation timelines and asset tagging become operative at 180 days, 7 December 2026. Scope covers federal information systems and explicitly excludes statutorily defined national security systems along with certain Department of War and Intelligence Community systems. Contractors are not directly bound, but agencies must review contracts to determine what modifications compliance requires.

Why it matters

The binding deadline schedule is a picture. Table 1 lives in Appendix A of the directive and is published only as PNG images, without alt text. There is no machine-readable version of the matrix that determines how fast every federal civilian agency must patch every vulnerability. Every analysis in circulation was produced by someone reading a screenshot.

Predictably, they do not agree. One group of firms reads the three-day tier as requiring all four conditions — publicly exposed and KEV-listed and automatable and total control. Another reads it as two separate rows, one triggered by KEV plus total control regardless of exposure, another by exposure plus automation plus total control even without a KEV listing. At least one published transcription contains a row that flatly contradicts the “meets none of the criteria” definition of the deferral tier that other firms use.

These are not shades of interpretation. They are different answers to the question of whether a given vulnerability on your estate is a three-day emergency or a 60-day ticket. We are not printing a tier table in this story, because we cannot verify one, and neither can anyone reproducing a vendor’s version.

Nobody has reported whether agencies met 7 August. The milestone passed three weeks ago. There is no GAO assessment, no inspector general finding, no compliance scorecard, and no reporting we can find on whether the policy and process requirements were satisfied across more than a hundred agencies. A binding directive with a passed deadline and no accounting is a gap, and it is the most answerable open question in this story.

The statistic driving it is not a federal number. CISA’s rationale cites falling remediation performance alongside AI compressing the window between disclosure and weaponization. The figure in circulation — 26% of KEV-catalog vulnerabilities fully remediated in 2025, down from 38% the year before — comes from the 2026 Verizon Data Breach Investigations Report, not from CISA’s own telemetry, and it measures Verizon’s contributor population of general organizations rather than federal agencies. It is a private-sector remediation statistic being used to justify a federal directive. That does not make it wrong; it makes it something other than what several write-ups imply.

The three-day tier is narrower than it sounds. CISA’s Chris Butera has offered the agency’s own counterweight: at one large agency, roughly 1% of vulnerabilities fell into the three-day window while about 60% qualified for deferral to the next system upgrade. Anyone reading “three-day patching mandate” as applying broadly has the shape wrong.

The criticism is still real. Vulnerability researcher Tod Beardsley has publicly questioned whether agencies without centralized asset inventories or automated patch orchestration can hit 72 hours at scale. Law firm Wiley Rein calls the tier “extremely aggressive,” notes it presumes a patch already exists, and raises the sharper point: the framework could be “misunderstood to establish a patching schedule that all organizations should follow.” Several practitioners have flagged that “publicly exposed” is loosely enough defined to be contested — which matters, because it is the single variable agencies grade for themselves.

What to do

  • Search your vulnerability management policy for “BOD 22-01” and for any flat 14-day KEV SLA. If either appears, it references a revoked directive. This is a documentation problem today and an audit problem later.
  • Do not copy a vendor’s tier table into your own standard. They disagree with each other. If you need the matrix, open Appendix A of the directive and read the image yourself, and have a second person confirm your reading.
  • If you sell to federal agencies or operate in FedRAMP, 7 December is the date that binds you — FedRAMP has independently tied vulnerability deviation reporting to the new model from that date, with a grace period running to 7 March 2027, after which non-compliant providers face certification consequences.
  • If you are adopting this voluntarily, decide deliberately whether “publicly exposed” is self-assessed at your organization too. It is the variable with the most room for optimism, and the one that moves deadlines the furthest.
  • Treat “patched” and “remediated” as different states in your reporting. Where a fix requires a reboot to take effect, a dashboard showing the update installed does not mean the exposure is closed.

Sourcing note

cisa.gov blocks automated retrieval, returning 403 to every direct request. The directive’s text and quotations above were obtained through a third-party proxy that returned CISA’s own page content, and were cross-checked against CISA’s GovDelivery bulletin of 10 June 2026 and fedramp.gov. Anyone relying on the quoted language for compliance purposes should confirm it against the directive page in a browser. Table 1 is image-only and we could not read it; the conflicting transcriptions described above are the reason no tier table appears in this story. CISA’s separate implementation guidance page was unreachable, so anything attributed to it elsewhere — including the widely repeated hour-by-hour forensic triage sequence — is second-hand, and at least one source indicates those steps are recommended rather than required. Sources also disagree on whether forensic triage must precede patching; the directive’s own wording describes concurrent obligations and does not obviously mandate an order. The 26% and 38% figures are Verizon’s, measuring general organizations. The “CISA strongly encourages all partners to adopt similar actions” line widely quoted as directive text appears to originate in CISA’s press release rather than the directive body. FedRAMP’s 7 August date is 58 days from issuance rather than 60, a discrepancy we could not resolve. We found no evidence of any revision, extension, or amendment to BOD 26-04 since it was issued.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *