BOD 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities
SupersededCISA · Binding Operational Directive · November 3, 2021
Summary
Created the KEV catalog and required agencies to fix each listed vulnerability by the due date CISA set, usually two weeks, on all agency systems including those hosted by third parties, and to update their vulnerability management procedures.
Replaced by
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Binding Operational Directive
- Number
- BOD 22-01
- Issued
- November 3, 2021
- Status
- Superseded
Replaced by a newer document or edition.
Revoked and replaced by BOD 26-04 on June 10, 2026.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.