CYBERSECURITYTRACKER
TRACKING3,014 stories541 vuln stories
Compliance

CISA directives

Curated, operator-reviewed Binding Operational Directives (BODs) and Emergency Directives (EDs) from the Cybersecurity and Infrastructure Security Agency (CISA). Each entry, its status, and every compliance deadline is verified and sourced. Upcoming deadlines also appear on the compliance calendar.

Active
  • BOD 26-04BODActive
    Issued 2026-06-10

    Prioritizing Security Updates Based on Risk

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 2026-08-09Update vulnerability remediation processes to the risk-based tiered model (within 60 days of issuance)
    • 2026-12-07Meet the full BOD 26-04 remediation timelines in Table 1 (within 180 days of issuance)
    View on cisa.gov
  • ED 26-01EDActive
    Issued 2025-10-15

    Mitigate Vulnerabilities in F5 Devices

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 2025-10-22Apply F5 October 2025 updates to BIG-IP hardware and software appliances (F5OS, BIG-IP TMOS, BIG-IQ, BNK/CNF)
    • 2025-10-31Apply updates to all remaining in-scope F5 virtual and physical devices
    • 2025-12-03Report a full inventory of in-scope F5 products to CISA
    View on cisa.gov
  • BOD 23-01BODActive
    Issued 2022-10-03

    Improving Asset Visibility and Vulnerability Detection on Federal Networks

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 2023-04-03Initial compliance (automated 7 day asset discovery, 14 day vulnerability enumeration, CDM dashboard access)
    View on cisa.gov
Superseded, revoked, and retired
  • ED 24-02EDRetired
    Issued 2024-04-02

    Mitigating the Significant Risk from Nation-State Compromise of Microsoft Corporate Email System

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 2024-04-30Complete a cybersecurity impact analysis of exfiltrated correspondence
    • 2024-05-01Provide a status update to CISA
    View on cisa.gov
  • BOD 22-01BODSuperseded
    Issued 2021-11-03

    Reducing the Significant Risk of Known Exploited Vulnerabilities

    Superseded by BOD 26-04

    All Federal Civilian Executive Branch (FCEB) agencies

    View on cisa.gov
  • ED 21-01EDRetired
    Issued 2020-12-13

    Mitigate SolarWinds Orion Code Compromise

    All Federal Civilian Executive Branch (FCEB) agencies

    View on cisa.gov
  • ED 19-01EDRetired
    Issued 2019-01-22

    Mitigate DNS Infrastructure Tampering

    Federal executive branch agencies, excluding the Department of Defense, CIA, and ODNI

    View on cisa.gov