Skip to content

BOD 26-04, Prioritizing Security Updates Based on Risk

In effectCISA · Binding Operational Directive · June 10, 2026

Summary

Requires agencies to fix vulnerabilities within 3 to 60 days based on risk factors such as KEV listing and internet exposure, tag exposed assets, keep CISA scanning access, and check high-risk systems for prior compromise.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Binding Operational Directive
Number
BOD 26-04
Issued
June 10, 2026
Status
In effect

Still in force, possibly with amendments.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.