Skip to content

BOD 26-04: Implementation Guidance for Prioritizing Security Updates Based on Risk

In effectCISA · CISA guidance · June 10, 2026

Summary

Explains how agencies apply Binding Operational Directive 26-04, including how to judge the risk factors that set each remediation deadline, tag exposed assets, and report to CISA.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
CISA guidance
Issued
June 10, 2026
Status
In effect

Still in force, possibly with amendments.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.