CISA directives
Binding Operational Directives (BODs) and Emergency Directives (EDs) from the Cybersecurity and Infrastructure Security Agency (CISA) for federal civilian agencies, checked against cisa.gov by hand. Every card links to its cisa.gov page; a deadline derived from the issued date rather than printed by CISA is labelled computed. Upcoming deadlines also appear on the compliance calendar.
Federal remediation deadline backlog
Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) due dates are federal agency deadlines and a useful planning signal for every defender. Select a bar to open its matching rows.
Last reviewed against cisa.gov: . 16 directives listed. This page lists the directives this site has verified; it is not CISA's full list.
Active
- BOD 26-04BODActiveIssued
Prioritizing Security Updates Based on Risk
All Federal Civilian Executive Branch (FCEB) agencies
Source: BOD 26-04 on cisa.govCompliance deadlines- Update vulnerability remediation processes to the risk-based tiered model (within 60 days of issuance) (computed from the issued date; not a date CISA published)
34 days ago
- Meet the full BOD 26-04 remediation timelines in Table 1 (within 180 days of issuance) (computed from the issued date; not a date CISA published)
in 86 days
- ED 26-03EDActiveIssued
Mitigate Vulnerabilities in Cisco SD-WAN Systems
All Federal Civilian Executive Branch (FCEB) agencies
Compliance deadlines- Identify all in-scope Cisco SD-WAN systems, provide the inventory to CISA, and report a summary of in-scope products (11:59 PM ET)
198 days ago
- Apply the Cisco-provided updates to all CVEs identified in the directive (5:00 PM ET)
197 days ago
- Report a detailed inventory of in-scope products and the actions taken, including artifacts collected and hunting results (11:59 PM ET)
191 days ago
- Report the actions taken to harden networks (11:59 PM ET)
184 days ago
- Complete the log-provision actions and report them to CISA (11:59 PM ET)
173 days ago
Source: ED 26-03 on cisa.govAffected CVEs - BOD 26-02BODActiveIssued
Mitigating Risk From End-of-Support Edge Devices
All Federal Civilian Executive Branch (FCEB) agencies
Source: BOD 26-02 on cisa.govCompliance deadlines- Inventory all devices on the CISA EOS Edge Device List and provide it to CISA (within 3 months of issuance) (computed from the issued date; not a date CISA published)
130 days ago
- Decommission listed EOS edge devices with an EOS date on or before this milestone, report the decommissions, and inventory devices reaching EOS within the next twelve months (within 12 months of issuance) (computed from the issued date; not a date CISA published)
in 146 days
- Decommission all identified EOS edge devices and report the decommissions to CISA (within 18 months of issuance) (computed from the issued date; not a date CISA published)
in 327 days
- Establish continuous discovery of EOS edge devices and decommission each on or before its EOS date (within 24 months of issuance) (computed from the issued date; not a date CISA published)
in 511 days
- ED 26-01EDActiveIssued
Mitigate Vulnerabilities in F5 Devices
All Federal Civilian Executive Branch (FCEB) agencies
Compliance deadlines- Apply F5 October 2025 updates to BIG-IP hardware and software appliances (F5OS, BIG-IP TMOS, BIG-IQ, BNK/CNF)
325 days ago
- Apply updates to all remaining in-scope F5 virtual and physical devices
316 days ago
- Report a full inventory of in-scope F5 products to CISA
283 days ago
Source: ED 26-01 on cisa.govAffected CVEs4 verified of about 43 CVEs in F5's October 2025 Quarterly Security Notification (K000156572); the directive covers the whole notification.
- ED 25-03EDActiveIssued
Identify and Mitigate Potential Compromise of Cisco Devices
All Federal Civilian Executive Branch (FCEB) agencies
Compliance deadlines- Submit core dumps for public-facing Cisco ASA hardware appliances and apply the latest Cisco software updates to ASA and ASAv (11:59 PM ET)
351 days ago
- Permanently disconnect ASA hardware models with an end-of-support date on or before this date
347 days ago
- Report a complete inventory of in-scope products and actions taken to CISA (11:59 PM ET)
345 days ago
- V1 Submit core dumps for the identified Firepower devices and apply the latest Cisco software updates (11:59 PM ET)
141 days ago
- V1 Hard-reset the identified devices by physically removing power
135 days ago
- V1 Report a complete inventory of Firepower 1000, 2100, 4100, 9300 and Secure Firewall series devices to CISA (11:59 PM ET)
134 days ago
Source: ED 25-03 on cisa.govAffected CVEs - ED 25-02EDActiveIssued
Mitigate Microsoft Exchange Vulnerability
All Federal Civilian Executive Branch (FCEB) agencies
Compliance deadlines- Inventory Exchange servers, disconnect servers not eligible for the April 2025 hotfix updates, and update hybrid on-premises servers (9:00 AM ET); report to CISA (5:00 PM ET)
397 days ago
Source: ED 25-02 on cisa.govAffected CVEs - BOD 25-01BODActiveIssued
Implementing Secure Practices for Cloud Services
All Federal Civilian Executive Branch (FCEB) agencies
Source: BOD 25-01 on cisa.govCompliance deadlines- Provide CISA the tenant name and owning agency for every in-scope cloud tenant
568 days ago
- Deploy all SCuBA assessment tools for in-scope cloud tenants and begin continuous reporting
505 days ago
- Implement all mandatory SCuBA policies in effect at issuance
449 days ago
- BOD 23-02BODActiveIssued
Mitigating the Risk from Internet-Exposed Management Interfaces
All Federal Civilian Executive Branch (FCEB) agencies
Source: BOD 23-02 on cisa.gov - BOD 23-01BODActiveIssued
Improving Asset Visibility and Vulnerability Detection on Federal Networks
All Federal Civilian Executive Branch (FCEB) agencies
Source: BOD 23-01 on cisa.govCompliance deadlines- Initial compliance (automated 7 day asset discovery, 14 day vulnerability enumeration, CDM dashboard access)
1258 days ago
- BOD 20-01BODActiveIssued
Develop and Publish a Vulnerability Disclosure Policy
All Federal Civilian Executive Branch (FCEB) agencies
Source: BOD 20-01 on cisa.govCompliance deadlines- Update the security contact and organization fields for every registered .gov domain (30 days)
2171 days ago
- Publish a vulnerability disclosure policy at /vulnerability-disclosure-policy on the primary .gov site and set vulnerability disclosure handling procedures (180 days)
2021 days ago
- Report metrics to CISA, then every 90 days thereafter (270 days)
1929 days ago
- All internet-accessible systems or services must be in scope of the policy (2 years)
1471 days ago
- BOD 18-02BODActiveIssued
Securing High Value Assets
All Federal Civilian Executive Branch (FCEB) agencies
Source: BOD 18-02 on cisa.govCompliance deadlines- Submit lead and backup HVA points of contact to DHS (within 7 days of issuance) (computed from the issued date; not a date CISA published)
3043 days ago
- Submit a current, prioritized High Value Asset list through HSIN (within 30 days of issuance) (computed from the issued date; not a date CISA published)
3020 days ago
Superseded, revoked, and closed
- ED 24-02EDClosed (retired by CISA)Issued
Mitigating the Significant Risk from Nation-State Compromise of Microsoft Corporate Email System
All Federal Civilian Executive Branch (FCEB) agencies
Source: ED 24-02 on cisa.govCompliance deadlines- Complete a cybersecurity impact analysis of exfiltrated correspondence
865 days ago
- Provide a status update to CISA
864 days ago
- BOD 22-01BODSupersededIssued
Reducing the Significant Risk of Known Exploited Vulnerabilities
Superseded by BOD 26-04
All Federal Civilian Executive Branch (FCEB) agencies
Source: BOD 22-01 on cisa.gov - ED 21-01EDClosed (retired by CISA)Issued
Mitigate SolarWinds Orion Code Compromise
All Federal Civilian Executive Branch (FCEB) agencies
Source: ED 21-01 on cisa.gov - BOD 19-02BODSupersededIssued
Vulnerability Remediation Requirements for Internet-Accessible Systems
Superseded by BOD 26-04
All Federal Civilian Executive Branch (FCEB) agencies
Source: BOD 19-02 on cisa.gov - ED 19-01EDClosed (retired by CISA)Issued
Mitigate DNS Infrastructure Tampering
Federal executive branch agencies, excluding the Department of Defense, CIA, and ODNI
Source: ED 19-01 on cisa.gov