Fortinetics
← Insights · Cross-cutting · · 8 min read

CISA BOD 26-04 retires BOD 22-01's flat KEV deadline — what it does (and doesn't) mean for defense contractors

On June 10, 2026 CISA issued BOD 26-04, replacing BOD 22-01's flat KEV deadline with a four-criteria, risk-scored remediation model — as fast as three days when all four criteria are met. Binding operational directives only bind civilian federal agencies, not the Defense Industrial Base. Here is the honest read on what changes for DoD contractors, where the KEV catalog still touches your DFARS 7012 / NIST 800-171 / CMMC obligations, and why the new model is worth adopting before any contract makes you.

Published June 10, 2026 — CISA issued Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk,” the same day. It supersedes and revokes BOD 22-01 (the 2021 Known Exploited Vulnerabilities directive) and BOD 19-02 (the 2019 internet-accessible remediation directive). This is a federal-agency directive, not a contractor rule — but because it rewires the most-cited patching baseline in government, defense contractors will hear about it secondhand. Here is the practitioner read.

For four years, “BOD 22-01” was the shorthand a lot of people reached for when they meant “the deadline to patch a known-exploited vulnerability.” It was never a rule that bound the Defense Industrial Base — Binding Operational Directives reach only Federal Civilian Executive Branch agencies — but its Known Exploited Vulnerabilities (KEV) catalog and its flat remediation deadline became a de facto reference point that crept into prime flow-downs, POA&M closure dates, and the way assessors read a flaw-remediation control narrative.

On June 10, 2026, CISA replaced it. BOD 26-04 swaps the one-size deadline for a risk-scored model. The change is worth understanding precisely, because the wrong takeaway — “CISA now requires three-day patching” — is already circulating, and it is wrong for you in two different ways.

What BOD 26-04 actually does

The directive abandons the idea that every vulnerability on the KEV list carries the same clock. Instead it scores each vulnerability against four criteria:

  • Asset exposure — is the affected asset publicly reachable (internet-accessible) rather than internal-only?
  • Exploit automation — can exploitation be fully automated, or does it require meaningful attacker effort and skill?
  • Post-exploitation impact — does a successful exploit hand the attacker full control of the system, or something more limited?
  • Active exploitation — is there evidence the vulnerability is being exploited in the real world (the signal the KEV catalog encodes)?

The more of those four a vulnerability meets, the shorter the remediation window. A vulnerability that meets all four — internet-facing, fully automatable, full-takeover, and actively exploited — must be remediated within three days, and the agency must run a forensic triage to determine whether the system was already compromised. Vulnerabilities meeting fewer criteria get progressively longer windows, and genuinely low-risk issues can be deferred to the next scheduled system upgrade.

The implementation schedule for agencies is staged: update vulnerability-management policies immediately (including a standing process for the KEV “must-patch” list), update the processes for remediating common vulnerabilities within 60 days, and meet the directive’s full remediation timelines within 180 days.

CISA framed the motivation as a response to AI compressing the window between when a vulnerability is discovered and when it is weaponized, and tied it to the AI executive order signed earlier that month. The agency cited the 2026 Verizon Data Breach Investigations Report finding that only 26% of KEV-listed vulnerabilities were fully remediated across organizations in 2025 — down from 38% the year before — with median time-to-resolution climbing to 43 days. The honest subtext is that the flat deadline was being missed at scale, and a risk-scored model lets agencies spend their limited remediation capacity where it actually reduces risk. CISA’s own analysis of one large agency found roughly 1% of vulnerabilities fell into the three-day bucket while about 60% could safely wait for the next upgrade cycle.

Why it does not bind you — and why that matters

A Binding Operational Directive is issued under 44 U.S.C. § 3553. Its authority runs to FCEB agencies and nowhere else. BOD 26-04 explicitly carves out DoD systems, National Security Systems, and Intelligence Community systems, and it has never reached private companies. CISA “encourages” the private sector to adopt the model; encouragement is not a clause.

So if you are a defense subcontractor handling Controlled Unclassified Information, your patch obligations did not change on June 10. They still come from the same three places they came from on June 9:

  • Your contract clauses. DFARS 252.204-7012 requires you to implement NIST SP 800-171 on covered systems and report cyber incidents; this directive does not touch it. The companion assessment clauses — 252.204-7019 (self-assessment posting to SPRS) and 252.204-7020 (government assessment access) — also remain in force, with CMMC (252.204-7021) layering on top through Phase 2. See DFARS 7012: the 72-hour incident reporting gap.
  • The NIST controls those clauses require. Flaw remediation (3.14.1 / SI-2) and vulnerability scanning (3.11.2 / RA-5) define your actual remediation cadence. They require you to identify, report, and correct flaws on a timeline you define and defend — not on CISA’s three-day clock.
  • Your CMMC assessment. A C3PAO assessing those controls reads your evidence, not a federal directive.

The reason this distinction matters is that the misreading cuts both ways. Treat BOD 26-04 as binding and you may over-rotate — committing in your POA&M to remediation windows you cannot consistently hit, then failing your own stated control. Ignore it entirely and you miss that the KEV catalog underneath it is already woven into your assessment surface.

Where the KEV catalog still reaches your program

The directive changed; the catalog did not. CISA’s Known Exploited Vulnerabilities catalog remains the most defensible public definition of “actively exploited,” and it shows up in places that do govern you:

In how an assessor reads SI-2 and RA-5. When a C3PAO evaluates your flaw-remediation control, “we patch on a 30-day cycle” is a weaker narrative than “we patch on a 30-day cycle, and we pull KEV-listed vulnerabilities affecting internet-facing assets forward to an expedited track.” The four-criteria model is, conveniently, a clean articulation of exactly the prioritization logic an assessor wants to see behind your evidence. Adopting it voluntarily strengthens the control narratives in your SSP.

In prime flow-downs. Tier-1 primes increasingly reference the KEV catalog directly in supplier-security addenda. A prime’s expectation that you remediate KEV-listed issues within a stated window is a contractual obligation between you and the prime, independent of any BOD. As DoD and prime security teams absorb the new risk-scored model, expect that flow-down language to drift from flat deadlines toward criteria-based ones — the same direction federal civilian agencies just moved.

In your POA&M realism. POA&M closure dates are where contractors most often over-promise. The four-criteria model gives you an external, defensible yardstick for why one open item closes in days and another in a quarter — which is precisely the kind of milestone fidelity assessors look for when they read a POA&M.

The DoD and IC angle

Binding Operational Directives don’t reach DoD or the IC, but those communities have a long history of migrating toward CISA’s vulnerability-management constructs after the fact — the KEV catalog itself became a touchstone well beyond the agencies BOD 22-01 bound. It is reasonable to expect DoD components and IC elements to fold a risk-scored prioritization model into their own internal vulnerability-management guidance over the coming cycles, and for that to surface in cleared-contractor contract language and assessor expectations downstream. That is a “watch this” signal, not a “do this now” deadline — and it is the kind of architecture-level shift worth designing toward early rather than retrofitting under contract pressure, the same way we treat the DoD Zero Trust target-level timeline.

What a contractor should actually do

Nothing on a deadline. But three things are worth doing while it is quiet:

  1. Adopt the four-criteria logic in your own remediation prioritization — not because a directive requires it, but because it is a defensible model that maps cleanly onto how an assessor reads SI-2 and RA-5, and onto how primes are likely to write flow-downs going forward.
  2. Re-read your POA&M closure dates against it. If an open item is internet-facing, automatable, full-takeover, and KEV-listed, a quarter-long closure date is hard to defend. If it is internal-only and not actively exploited, a fast deadline you cannot hit is worse than an honest longer one.
  3. Resist the over-claim. When a vendor tells you BOD 26-04 means you must now patch in three days, you are hearing marketing, not compliance. The honest position — the one we hold on every “comply faster” pitch — is that the directive changed the federal baseline, the KEV catalog still touches your obligations, and your timelines are still set by your clauses and your control narratives, not by a directive that was never yours to follow.

The broader regulatory picture this quarter is moving on several fronts at once; our Q2 2026 compliance landscape briefing tracks the changes that do carry direct contractor obligations alongside signals like this one.