Fortinetics Book a call →
Menu
Cross-cutting · · 8 min read

CISA BOD 26-04 retires BOD 22-01's flat KEV deadline — what it does (and doesn't) mean for defense contractors

On June 10, 2026 CISA issued BOD 26-04, replacing BOD 22-01's flat KEV deadline with a four-criteria, risk-scored remediation model, as fast as three days when all four criteria are met. Binding operational directives only bind civilian federal agencies, not the Defense Industrial Base. Here is the honest read on what changes for DoD contractors, where the KEV catalog still touches your DFARS 7012 / NIST 800-171 / CMMC obligations, and why the new model is worth adopting before any contract makes you.

Published June 10, 2026 — CISA issued Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk,” the same day. It supersedes and revokes BOD 22-01 (the 2021 Known Exploited Vulnerabilities directive) and BOD 19-02 (the 2019 internet-accessible remediation directive). This is a federal-agency directive, not a contractor rule, but because it rewires the most-cited patching baseline in government, defense contractors will hear about it secondhand. Here is the practitioner read.

For four years, “BOD 22-01” was the shorthand a lot of people reached for when they meant “the deadline to patch a known-exploited vulnerability.” It was never a rule that bound the Defense Industrial Base (Binding Operational Directives reach only Federal Civilian Executive Branch agencies), but its Known Exploited Vulnerabilities (KEV) catalog and its flat remediation deadline became a de facto reference point that crept into prime flow-downs, POA&M closure dates, and the way assessors read a flaw-remediation control narrative.

On June 10, 2026, CISA replaced it. BOD 26-04 swaps the one-size deadline for a risk-scored model. The change is worth understanding precisely, because the wrong takeaway (“CISA now requires three-day patching”) is already circulating, and it is wrong for you in two different ways.

What BOD 26-04 actually does

The directive abandons the idea that every vulnerability on the KEV list carries the same clock. Instead it scores each vulnerability against four criteria:

  • Asset exposure — is the affected asset publicly reachable (internet-accessible) rather than internal-only?
  • Exploit automation — can exploitation be fully automated, or does it require meaningful attacker effort and skill?
  • Post-exploitation impact — does a successful exploit hand the attacker full control of the system, or something more limited?
  • Active exploitation — is there evidence the vulnerability is being exploited in the real world (the signal the KEV catalog encodes)?

The more of those four a vulnerability meets, the shorter the remediation window. A vulnerability that meets all four (internet-facing, fully automatable, full-takeover, and actively exploited) must be remediated within three days, and the agency must run a forensic triage to determine whether the system was already compromised. Vulnerabilities meeting fewer criteria get progressively longer windows, and genuinely low-risk issues can be deferred to the next scheduled system upgrade.

The implementation schedule for agencies is staged: update vulnerability-management policies immediately (including a standing process for the KEV “must-patch” list), update the processes for remediating common vulnerabilities within 60 days, and meet the directive’s full remediation timelines within 180 days.

CISA framed the motivation as a response to AI compressing the window between when a vulnerability is discovered and when it is weaponized, and tied it to the AI executive order signed earlier that month. The agency cited the 2026 Verizon Data Breach Investigations Report finding that only 26% of KEV-listed vulnerabilities were fully remediated across organizations in 2025 (down from 38% the year before), with median time-to-resolution climbing to 43 days. The honest subtext is that the flat deadline was being missed at scale, and a risk-scored model lets agencies spend their limited remediation capacity where it actually reduces risk. CISA’s own analysis of one large agency found roughly 1% of vulnerabilities fell into the three-day bucket while about 60% could safely wait for the next upgrade cycle.

Why it does not bind you — and why that matters

A Binding Operational Directive is issued under 44 U.S.C. § 3553. Its authority runs to FCEB agencies and nowhere else. BOD 26-04 explicitly carves out DoD systems, National Security Systems, and Intelligence Community systems, and it has never reached private companies. CISA “encourages” the private sector to adopt the model; encouragement is not a clause.

So if you are a defense subcontractor handling Controlled Unclassified Information, your patch obligations did not change on June 10. They still come from the same three places they came from on June 9:

  • Your contract clauses. DFARS 252.204-7012 requires you to implement NIST SP 800-171 on covered systems and report cyber incidents; this directive does not touch it. The companion assessment clauses, 252.204-7019 (self-assessment posting to SPRS) and 252.204-7020 (government assessment access), also remain in force. CMMC (252.204-7021) has not been removed from the DFARS either, though the Phase 2 transition it was to ramp through was suspended on July 13, 2026 and only self-assessment levels can currently be designated. See DFARS 7012: the 72-hour incident reporting gap.
  • The NIST controls those clauses require. Flaw remediation (3.14.1 / SI-2) and vulnerability scanning (3.11.2 / RA-5) define your actual remediation cadence. They require you to identify, report, and correct flaws on a timeline you define and defend, not on CISA’s three-day clock.
  • Your CMMC assessment. A C3PAO assessing those controls reads your evidence, not a federal directive.

The reason this distinction matters is that the misreading cuts both ways. Treat BOD 26-04 as binding and you may over-rotate — committing in your POA&M to remediation windows you cannot consistently hit, then failing your own stated control. Ignore it entirely and you miss that the KEV catalog underneath it is already woven into your assessment surface.

Where the KEV catalog still reaches your program

The directive changed; the catalog did not. CISA’s Known Exploited Vulnerabilities catalog remains the most defensible public definition of “actively exploited,” and it shows up in places that do govern you:

In how an assessor reads SI-2 and RA-5. When a C3PAO evaluates your flaw-remediation control, “we patch on a 30-day cycle” is a weaker narrative than “we patch on a 30-day cycle, and we pull KEV-listed vulnerabilities affecting internet-facing assets forward to an expedited track.” The four-criteria model is, conveniently, a clean articulation of exactly the prioritization logic an assessor wants to see behind your evidence. Adopting it voluntarily strengthens the control narratives in your SSP.

In prime flow-downs. Tier-1 primes increasingly reference the KEV catalog directly in supplier-security addenda. A prime’s expectation that you remediate KEV-listed issues within a stated window is a contractual obligation between you and the prime, independent of any BOD. As DoD and prime security teams absorb the new risk-scored model, expect that flow-down language to drift from flat deadlines toward criteria-based ones, the same direction federal civilian agencies just moved.

In your POA&M realism. POA&M closure dates are where contractors most often over-promise. The four-criteria model gives you an external, defensible yardstick for why one open item closes in days and another in a quarter, which is precisely the kind of milestone fidelity assessors look for when they read a POA&M.

The DoD and IC angle

Binding Operational Directives don’t reach DoD or the IC, but those communities have a long history of migrating toward CISA’s vulnerability-management constructs after the fact. The KEV catalog itself became a touchstone well beyond the agencies BOD 22-01 bound. It is reasonable to expect DoD components and IC elements to fold a risk-scored prioritization model into their own internal vulnerability-management guidance over the coming cycles, and for that to surface in cleared-contractor contract language and assessor expectations downstream. That is a “watch this” signal, not a “do this now” deadline, and it is the kind of architecture-level shift worth designing toward early rather than retrofitting under contract pressure, the same way we treat the DoD Zero Trust target-level timeline.

What a contractor should actually do

Nothing on a deadline. But three things are worth doing while it is quiet:

  1. Adopt the four-criteria logic in your own remediation prioritization, not because a directive requires it, but because it is a defensible model that maps cleanly onto how an assessor reads SI-2 and RA-5, and onto how primes are likely to write flow-downs going forward.
  2. Re-read your POA&M closure dates against it. If an open item is internet-facing, automatable, full-takeover, and KEV-listed, a quarter-long closure date is hard to defend. If it is internal-only and not actively exploited, a fast deadline you cannot hit is worse than an honest longer one.
  3. Resist the over-claim. When a vendor tells you BOD 26-04 means you must now patch in three days, you are hearing marketing, not compliance. The honest position, the one we hold on every “comply faster” pitch, is that the directive changed the federal baseline, the KEV catalog still touches your obligations, and your timelines are still set by your clauses and your control narratives, not by a directive that was never yours to follow.

The broader regulatory picture this quarter is moving on several fronts at once; our Q2 2026 compliance landscape briefing tracks the changes that do carry direct contractor obligations alongside signals like this one.


Primary sources. Read the directive rather than a summary of it: CISA, BOD 26-04, “Prioritizing Security Updates Based on Risk”, and the accompanying implementation guidance. The directive it supersedes, BOD 22-01, is marked revoked on CISA’s own page — useful if you need to show someone the flat KEV deadline is gone. The catalog itself: CISA Known Exploited Vulnerabilities Catalog. Your actual obligations live in DFARS 252.204-7012 and the NIST SP 800-171 Rev 2 controls it invokes.

Frequently asked

Common questions.

Does CISA BOD 26-04 apply to defense contractors?
No. Binding Operational Directives are issued under 44 U.S.C. § 3553 and bind only Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 explicitly excludes Department of Defense systems, National Security Systems, and Intelligence Community systems, and it has never bound private companies, including the Defense Industrial Base. A defense contractor's patch obligations come from its contract clauses (DFARS 252.204-7012), the NIST SP 800-171 controls those clauses require, and CMMC assessment, not from a BOD. That said, the KEV catalog the directive is built on continues to surface inside all three of those, so the model is worth understanding.
What did BOD 26-04 actually change?
It superseded and revoked two older directives: BOD 22-01 (the November 2021 Known Exploited Vulnerabilities 'must-patch' deadline) and BOD 19-02 (2019 internet-accessible remediation timelines). In their place it sets risk-scored timelines based on four criteria: whether the vulnerability affects a publicly exposed asset, whether exploitation can be fully automated, whether it allows full system takeover, and whether there is evidence of active exploitation (KEV listing). The more criteria a vulnerability meets, the shorter the window. A vulnerability meeting all four must be remediated within three days plus a forensic triage. The KEV catalog itself was not retired; the directive 'evolves upon' it.
Does BOD 26-04 mean I now have to patch within three days?
Not as a matter of law. The three-day window binds FCEB agencies, not contractors. Be skeptical of any vendor or platform that tells you 'BOD 26-04 now requires you to patch in three days.' What governs your timelines is your DFARS 7012 / NIST SP 800-171 flaw-remediation and vulnerability-scanning controls (SI-2, RA-5), any KEV-referencing language a prime has flowed down to you, and the closure dates in your own POA&M. The directive is a useful external yardstick for what 'reasonable' prioritization looks like, not a new contractual deadline.
Where does the KEV catalog touch my CMMC or DFARS obligations?
CISA's Known Exploited Vulnerabilities catalog is the most defensible public definition of 'actively exploited.' NIST SP 800-171's flaw-remediation (3.14.1 / SI-2) and vulnerability-scanning (3.11.2 / RA-5) controls require you to remediate known vulnerabilities on a defined cadence; a C3PAO assessor reading that evidence wants to see that actively-exploited issues are prioritized over theoretical ones. Many primes' supplier-security addenda reference the KEV catalog directly for flow-down patch expectations. So the catalog is already inside your assessment surface even though the BOD that governs federal agencies is not.