Security1 publisher2 min readPublished
BOD 26-04 makes remediation urgency a function of exposure, KEV status, exploit automation and technical impact. CISA publishes three of those four answers per CVE; agencies determine the fourth themselves.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Four questions with two answers each produce sixteen possible risk profiles [13], and CISA answers three of the four before an agency looks at anything. KEV status, exploit automation and technical impact are published per CVE ID through services including the Vulnrichment Program [6]. The remaining variable, whether the vulnerable asset is publicly exposed, is the agency's own determination, made against CISA's Internet Exposure Reduction Guidance [7]. One of the four inputs is owned locally [14].
Enrichment data cannot know what an agency has facing the public internet. An inventory that records an internet-facing appliance as internal moves every CVE on that appliance into a slower tier, and the mistake is invisible in the CVE feed, because the feed is correct and the asset record is not.
BOD 22-01 in 2021 pointed agencies at the Known Exploited Vulnerabilities catalog and told them to remediate aggressively [8]. 26-04 keeps that urgency for high-risk items and adds deferral of low-risk ones [9], with CISA describing the approach as focusing effort on the areas of highest risk rather than treating all vulnerabilities and systems equally [10]. A program that formally deprioritizes a CVE now does so with a compulsory directive behind it.
BOD 26-04 binds Federal Civilian Executive Branch agencies [3] and does not apply to statutorily defined national security systems or to certain systems operated by the Department of War or the Intelligence Community [4]. Nothing in it obliges a vendor, a contractor or a private enterprise. What crosses that boundary is the data: any organization can pull the same three published answers per CVE [6] and run the same tiering, without any obligation to do so.
CISA's stated reason for changing the model is that threat actors exploit unpatched vulnerabilities, and that their use of AI may further narrow the time defenders have between patch release and possible exploitation [11]. CISA frames that as a possibility rather than a confirmed measurement. The directive is aligned to OMB Circular A-130 and FISMA, and CISA has issued separate implementation guidance for agencies working through it [12].
For federal teams the deadline now comes out of four fields, three delivered by CISA and one produced by whatever the asset inventory says [14]. Inventory accuracy has become a scheduling control.
Ranked by verification strength, evidence, and original report placement.
The urgency of remediation, per the directive's Table 1: Remediation Timelines, is determined by four variables: asset exposure (is the vulnerable asset publicly exposed), KEV status (is the CVE ID on CISA's Known Exploited Vulnerabilities Catalog), exploit automation (can an adversary automate all the steps necessary to exploit), and technical impact (does an adversary gain partial or total control of the asset after exploitation).
CISA issued Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk".
A Binding Operational Directive is a compulsory direction to federal executive branch departments and agencies for safeguarding federal information and information systems under 44 U.S.C. 3552(b)(1); federal agencies are required to comply under 44 U.S.C. 3554(a)(1)(B)(ii).
The directive refers to the systems to which it applies as Federal Civilian Executive Branch systems, and to the agencies operating them as Federal Civilian Executive Branch agencies.
These directives do not apply to statutorily defined national security systems or to certain systems operated by the Department of War or the Intelligence Community.
CISA publishes answers to KEV Status, Exploit Automation, and Technical Impact for every CVE ID through services such as the Vulnrichment Program.
Publishers with included, body-backed reporting in this cluster.
1 article · September 6, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
CISA's KEV clock now runs on BOD 26-04, and your patch SLA cites the wrong directive2 publishers
security
CISA's KEV triage guidance tells agencies to collect RAM before they patch1 publisher
security
CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass4 publishers
security
Citrix called it a crash bug. It is unauthenticated RCE, and CISA gave agencies three days.7 publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary text, single voice
Everything rests on the directive itself, which is the correct document to quote for what the rule requires: the four questions, the statutory hook and the division of labour with Vulnrichment are all CISA's own wording, and the 16-profile count is arithmetic a reader can redo. What the available text lacks is Table 1, so the deadlines this story is named for sit behind a cross-reference rather than in front of us, and no second party has yet examined how the enrichment data holds up per CVE.
Nothing to measure yet
Compliance is where a directive like this gets judged, and none of it is visible. We can see that the rule is live and that it revokes BOD 19-02 and BOD 22-01; we cannot see a single agency meeting or missing a timeline under it, nor any count of CVE records carrying complete exploit-automation and technical-impact answers. Putting a number on uptake would mean inventing one.
Mostly the issuer's adjectives
CISA's framing carries weight the text does not support: the directive "evolves upon" the KEV Catalog, it "increases mission readiness", AI may narrow the window between patch and exploit. No figure accompanies any of those. The mechanics, by contrast, are stated plainly and our coverage stays on them, so the overstatement is confined to the agency's self-description rather than the scheme it describes.
Rule-writer describes own rule
The one voice in this story wrote the mandate. CISA is describing a framework it authored, and that framework routes agencies to its own enrichment feed and its own exposure guidance for three of the four answers, so the directive also functions as a case for the data services behind it. Ordinary for a mandate, and still worth naming: nobody in the file is positioned to say the enrichment is patchy or the timelines unrealistic.
Solid on text, thin on effect
On what BOD 26-04 says, this is about as firm as it gets: the issuing agency's published text, plus a count anyone can verify from four binary questions. On what it will change in federal patching, much less. The deadline table is outside the text available here, and the accuracy of CISA's per-CVE answers is the point the whole scheme turns on and the one thing no source addresses.