BOD 26-04: Implementation Guidance for Prioritizing Security Updates Based on Risk
In effectCISA · CISA guidance · June 10, 2026
Summary
Explains how agencies apply Binding Operational Directive 26-04, including how to judge the risk factors that set each remediation deadline, tag exposed assets, and report to CISA.
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- CISA guidance
- Issued
- June 10, 2026
- Status
- In effect
Still in force, possibly with amendments.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.