ED 21-01, Mitigate SolarWinds Orion Code Compromise
RetiredCISA · Emergency Directive · December 13, 2020
Summary
After attackers planted malicious code in SolarWinds Orion software updates, required agencies to disconnect affected Orion servers immediately, look for signs of compromise, reset credentials, and rebuild and harden systems before reconnecting.
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Emergency Directive
- Number
- ED 21-01
- Issued
- December 13, 2020
- Status
- Retired
Closed by its issuer (CISA's term for a directive that has done its job).
Retired by CISA on January 8, 2026; CISA had added supplemental guidance in December 2020 and January 2021 and a supplemental direction in April 2021.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.