Compliance
CISA directives
Curated, operator-reviewed Binding Operational Directives (BODs) and Emergency Directives (EDs) from the Cybersecurity and Infrastructure Security Agency (CISA). Each entry, its status, and every compliance deadline is verified and sourced. Upcoming deadlines also appear on the compliance calendar.
Active
- BOD 26-04BODActiveIssued 2026-06-10
Prioritizing Security Updates Based on Risk
All Federal Civilian Executive Branch (FCEB) agencies
View on cisa.govCompliance deadlines- 2026-08-09Update vulnerability remediation processes to the risk-based tiered model (within 60 days of issuance)
- 2026-12-07Meet the full BOD 26-04 remediation timelines in Table 1 (within 180 days of issuance)
- ED 26-01EDActiveIssued 2025-10-15
Mitigate Vulnerabilities in F5 Devices
All Federal Civilian Executive Branch (FCEB) agencies
View on cisa.govCompliance deadlines- 2025-10-22Apply F5 October 2025 updates to BIG-IP hardware and software appliances (F5OS, BIG-IP TMOS, BIG-IQ, BNK/CNF)
- 2025-10-31Apply updates to all remaining in-scope F5 virtual and physical devices
- 2025-12-03Report a full inventory of in-scope F5 products to CISA
- BOD 23-01BODActiveIssued 2022-10-03
Improving Asset Visibility and Vulnerability Detection on Federal Networks
All Federal Civilian Executive Branch (FCEB) agencies
View on cisa.govCompliance deadlines- 2023-04-03Initial compliance (automated 7 day asset discovery, 14 day vulnerability enumeration, CDM dashboard access)
Superseded, revoked, and retired
- ED 24-02EDRetiredIssued 2024-04-02
Mitigating the Significant Risk from Nation-State Compromise of Microsoft Corporate Email System
All Federal Civilian Executive Branch (FCEB) agencies
View on cisa.govCompliance deadlines- 2024-04-30Complete a cybersecurity impact analysis of exfiltrated correspondence
- 2024-05-01Provide a status update to CISA
- BOD 22-01BODSupersededIssued 2021-11-03
Reducing the Significant Risk of Known Exploited Vulnerabilities
Superseded by BOD 26-04
All Federal Civilian Executive Branch (FCEB) agencies
View on cisa.gov - ED 21-01EDRetiredIssued 2020-12-13
Mitigate SolarWinds Orion Code Compromise
All Federal Civilian Executive Branch (FCEB) agencies
View on cisa.gov - ED 19-01EDRetiredIssued 2019-01-22
Mitigate DNS Infrastructure Tampering
Federal executive branch agencies, excluding the Department of Defense, CIA, and ODNI
View on cisa.gov