BOD 26-04, Prioritizing Security Updates Based on Risk
In effectCISA · Binding Operational Directive · June 10, 2026
Summary
Requires agencies to fix vulnerabilities within 3 to 60 days based on risk factors such as KEV listing and internet exposure, tag exposed assets, keep CISA scanning access, and check high-risk systems for prior compromise.
Replaces
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Binding Operational Directive
- Number
- BOD 26-04
- Issued
- June 10, 2026
- Status
- In effect
Still in force, possibly with amendments.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.