Skip to content

BOD 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities

SupersededCISA · Binding Operational Directive · November 3, 2021

Summary

Created the KEV catalog and required agencies to fix each listed vulnerability by the due date CISA set, usually two weeks, on all agency systems including those hosted by third parties, and to update their vulnerability management procedures.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Binding Operational Directive
Number
BOD 22-01
Issued
November 3, 2021
Status
Superseded

Replaced by a newer document or edition.

Revoked and replaced by BOD 26-04 on June 10, 2026.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.