CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Compliance

CISA directives

Binding Operational Directives (BODs) and Emergency Directives (EDs) from the Cybersecurity and Infrastructure Security Agency (CISA) for federal civilian agencies, checked against cisa.gov by hand. Every card links to its cisa.gov page; a deadline derived from the issued date rather than printed by CISA is labelled computed. Upcoming deadlines also appear on the compliance calendar.

Deadline quick view

Federal remediation deadline backlog

Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) due dates are federal agency deadlines and a useful planning signal for every defender. Select a bar to open its matching rows.

  1. OverdueCalculating
  2. Due in 0 to 7 daysCalculating
  3. Due in 8 to 14 daysCalculating
  4. Due in 15 to 30 daysCalculating

Counts use this device's current date. Calculating the backlog.

Next deadline: BOD 26-04, (in 86 days)

Last reviewed against cisa.gov: . 16 directives listed. This page lists the directives this site has verified; it is not CISA's full list.

Active

  • BOD 26-04BODActive
    Issued

    Prioritizing Security Updates Based on Risk

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 34 days ago
      Update vulnerability remediation processes to the risk-based tiered model (within 60 days of issuance) (computed from the issued date; not a date CISA published)
    • in 86 days
      Meet the full BOD 26-04 remediation timelines in Table 1 (within 180 days of issuance) (computed from the issued date; not a date CISA published)
    Source: BOD 26-04 on cisa.gov
  • ED 26-03EDActive
    Issued

    Mitigate Vulnerabilities in Cisco SD-WAN Systems

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 198 days ago
      Identify all in-scope Cisco SD-WAN systems, provide the inventory to CISA, and report a summary of in-scope products (11:59 PM ET)
    • 197 days ago
      Apply the Cisco-provided updates to all CVEs identified in the directive (5:00 PM ET)
    • 191 days ago
      Report a detailed inventory of in-scope products and the actions taken, including artifacts collected and hunting results (11:59 PM ET)
    • 184 days ago
      Report the actions taken to harden networks (11:59 PM ET)
    • 173 days ago
      Complete the log-provision actions and report them to CISA (11:59 PM ET)
    Affected CVEs
    Source: ED 26-03 on cisa.gov
  • BOD 26-02BODActive
    Issued

    Mitigating Risk From End-of-Support Edge Devices

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 130 days ago
      Inventory all devices on the CISA EOS Edge Device List and provide it to CISA (within 3 months of issuance) (computed from the issued date; not a date CISA published)
    • in 146 days
      Decommission listed EOS edge devices with an EOS date on or before this milestone, report the decommissions, and inventory devices reaching EOS within the next twelve months (within 12 months of issuance) (computed from the issued date; not a date CISA published)
    • in 327 days
      Decommission all identified EOS edge devices and report the decommissions to CISA (within 18 months of issuance) (computed from the issued date; not a date CISA published)
    • in 511 days
      Establish continuous discovery of EOS edge devices and decommission each on or before its EOS date (within 24 months of issuance) (computed from the issued date; not a date CISA published)
    Source: BOD 26-02 on cisa.gov
  • ED 26-01EDActive
    Issued

    Mitigate Vulnerabilities in F5 Devices

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 325 days ago
      Apply F5 October 2025 updates to BIG-IP hardware and software appliances (F5OS, BIG-IP TMOS, BIG-IQ, BNK/CNF)
    • 316 days ago
      Apply updates to all remaining in-scope F5 virtual and physical devices
    • 283 days ago
      Report a full inventory of in-scope F5 products to CISA
    Affected CVEs

    4 verified of about 43 CVEs in F5's October 2025 Quarterly Security Notification (K000156572); the directive covers the whole notification.

    Source: ED 26-01 on cisa.gov
  • ED 25-03EDActive
    Issued

    Identify and Mitigate Potential Compromise of Cisco Devices

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 351 days ago
      Submit core dumps for public-facing Cisco ASA hardware appliances and apply the latest Cisco software updates to ASA and ASAv (11:59 PM ET)
    • 347 days ago
      Permanently disconnect ASA hardware models with an end-of-support date on or before this date
    • 345 days ago
      Report a complete inventory of in-scope products and actions taken to CISA (11:59 PM ET)
    • 141 days ago
      V1 Submit core dumps for the identified Firepower devices and apply the latest Cisco software updates (11:59 PM ET)
    • 135 days ago
      V1 Hard-reset the identified devices by physically removing power
    • 134 days ago
      V1 Report a complete inventory of Firepower 1000, 2100, 4100, 9300 and Secure Firewall series devices to CISA (11:59 PM ET)
    Source: ED 25-03 on cisa.gov
  • ED 25-02EDActive
    Issued

    Mitigate Microsoft Exchange Vulnerability

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 397 days ago
      Inventory Exchange servers, disconnect servers not eligible for the April 2025 hotfix updates, and update hybrid on-premises servers (9:00 AM ET); report to CISA (5:00 PM ET)
    Affected CVEs
    Source: ED 25-02 on cisa.gov
  • BOD 25-01BODActive
    Issued

    Implementing Secure Practices for Cloud Services

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 568 days ago
      Provide CISA the tenant name and owning agency for every in-scope cloud tenant
    • 505 days ago
      Deploy all SCuBA assessment tools for in-scope cloud tenants and begin continuous reporting
    • 449 days ago
      Implement all mandatory SCuBA policies in effect at issuance
    Source: BOD 25-01 on cisa.gov
  • BOD 23-02BODActive
    Issued

    Mitigating the Risk from Internet-Exposed Management Interfaces

    All Federal Civilian Executive Branch (FCEB) agencies

    Source: BOD 23-02 on cisa.gov
  • BOD 23-01BODActive
    Issued

    Improving Asset Visibility and Vulnerability Detection on Federal Networks

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 1258 days ago
      Initial compliance (automated 7 day asset discovery, 14 day vulnerability enumeration, CDM dashboard access)
    Source: BOD 23-01 on cisa.gov
  • BOD 20-01BODActive
    Issued

    Develop and Publish a Vulnerability Disclosure Policy

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 2171 days ago
      Update the security contact and organization fields for every registered .gov domain (30 days)
    • 2021 days ago
      Publish a vulnerability disclosure policy at /vulnerability-disclosure-policy on the primary .gov site and set vulnerability disclosure handling procedures (180 days)
    • 1929 days ago
      Report metrics to CISA, then every 90 days thereafter (270 days)
    • 1471 days ago
      All internet-accessible systems or services must be in scope of the policy (2 years)
    Source: BOD 20-01 on cisa.gov
  • BOD 18-02BODActive
    Issued

    Securing High Value Assets

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 3043 days ago
      Submit lead and backup HVA points of contact to DHS (within 7 days of issuance) (computed from the issued date; not a date CISA published)
    • 3020 days ago
      Submit a current, prioritized High Value Asset list through HSIN (within 30 days of issuance) (computed from the issued date; not a date CISA published)
    Source: BOD 18-02 on cisa.gov

Superseded, revoked, and closed

  • ED 24-02EDClosed (retired by CISA)
    Issued

    Mitigating the Significant Risk from Nation-State Compromise of Microsoft Corporate Email System

    All Federal Civilian Executive Branch (FCEB) agencies

    Compliance deadlines
    • 865 days ago
      Complete a cybersecurity impact analysis of exfiltrated correspondence
    • 864 days ago
      Provide a status update to CISA
    Source: ED 24-02 on cisa.gov
  • BOD 22-01BODSuperseded
    Issued

    Reducing the Significant Risk of Known Exploited Vulnerabilities

    Superseded by BOD 26-04

    All Federal Civilian Executive Branch (FCEB) agencies

    Source: BOD 22-01 on cisa.gov
  • ED 21-01EDClosed (retired by CISA)
    Issued

    Mitigate SolarWinds Orion Code Compromise

    All Federal Civilian Executive Branch (FCEB) agencies

    Source: ED 21-01 on cisa.gov
  • BOD 19-02BODSuperseded
    Issued

    Vulnerability Remediation Requirements for Internet-Accessible Systems

    Superseded by BOD 26-04

    All Federal Civilian Executive Branch (FCEB) agencies

    Source: BOD 19-02 on cisa.gov
  • ED 19-01EDClosed (retired by CISA)
    Issued

    Mitigate DNS Infrastructure Tampering

    Federal executive branch agencies, excluding the Department of Defense, CIA, and ODNI

    Source: ED 19-01 on cisa.gov

Glossary