CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 386

As cited

Copy frozen at (site build).

vulnerabilities

CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive

CISA issued BOD 26-04, replacing the previous flat-deadline patching directive with a four-variable risk-based model that assigns remediation timelines ranging from three days for the highest-risk vulnerabilities to full deferral for the lowest-risk ones. The directive applies to federal civilian agencies and uses asset exposure, exploitation evidence, adversary automation capability, and technical impact severity to create a 16-tier remediation matrix. While mandatory only for federal agencies, CISA encourages private sector adoption, and the framework is expected to become an industry standard similar to its predecessor BOD 22-01.

Why it matters: Federal agencies must implement risk-based patching workflows immediately to meet the three-day remediation timeline for critical vulnerabilities, while private sector organizations should adopt the framework proactively as it becomes the de facto prioritization standard across industries.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary