
On June 10, CISA retired the directive that shaped a decade of vulnerability management. BOD 26-04 replaces the flat “every KEV on the same clock” rule with a four-variable risk model — and the framework is worth adopting whether or not a federal mandate ever touches your org.
BOD 26-04, “Prioritizing Security Updates Based on Risk,” revokes and replaces both BOD 22-01 (the November 2021 directive that made the KEV catalog a remediation mandate) and the older BOD 19-02 from 2019. The flat timeline is gone. Where 22-01 assigned every KEV-listed CVE the same window — 14 days for anything dated after 2021 — 26-04 grades each vulnerability against four factors and assigns a deadline based on the specific combination that applies.
The directive binds Federal Civilian Executive Branch agencies. It does not cover national security systems, the intelligence community, or military systems, and it is not mandatory for the private sector. But CISA explicitly encourages private adoption, and history is instructive: 22-01’s KEV catalog became the most widely used prioritization signal in the industry without ever being binding outside government. There’s little reason to expect 26-04’s model to behave differently.
| BOD 22-01 (2021–2026) | BOD 26-04 (2026–) | |
|---|---|---|
| Deadline model | Flat — 14 days for post-2021 KEVs | Graduated — 3 / 14 / 60 days, or defer |
| Primary signal | KEV membership + CVSS | Four-variable risk (KEV is one input) |
| Deferral path | None — every KEV required action | “Fix on upgrade” tier for lowest risk |
| Compromise check | Not required | Forensic triage on the top tier |
| Methodology | KEV catalog + CVSS scoring | SSVC-informed, fed by Vulnrichment |
Each vulnerability is scored on four binary questions. CISA publishes the answers to three of them — KEV status, adversary automatability, and technical impact — through its Vulnrichment program. The fourth, public exposure, is the one each organization has to answer for itself from its own asset inventory. That single requirement is where most of the operational pain lives.
Two pressures converged. The first is that traditional vulnerability management is losing. Citing the 2026 Verizon DBIR, CISA notes that only 26% of KEV-listed vulnerabilities were fully remediated by organizations in 2025 — down from 38% the year before — while the median time to fully resolve a vulnerability climbed to 43 days.
The second is AI. CISA states plainly that AI is accelerating both vulnerability discovery and weaponization, compressing the gap between disclosure and exploitation. The directive is positioned alongside the June 2026 AI Executive Order, “Promoting Advanced Artificial Intelligence Innovation and Security.” When the time-to-exploit shrinks toward hours, a 43-day median isn’t just slow — it’s a window adversaries are increasingly able to drive a truck through. A flat “patch everything eventually” mandate can’t survive that math. A model that tells you what to patch first can.
“The 60% you can defer is not the story. The 1% you can’t is — and AI is shrinking the time you have to find it.”
You don’t need a mandate to use this. The four variables are a defensible prioritization spine that maps onto any exposure-management program. The work is in answering them continuously.
Can you name which assets are publicly exposed right now? Do your tools fold KEV status and exploit automatability into prioritization, or are you still ranking by CVSS alone? If you can’t answer cleanly, that’s your first gap.
22-01 leaned on KEV + CVSS; 26-04 drops mandatory CVSS entirely in favor of SSVC-style reasoning. Ingest Vulnrichment and KEV signals and weight by exposure and impact, not severity score alone.
The top tier requires forensic triage, not just a patch. Build the detection and attribution context to answer “were we already hit?” before you need it under a three-day clock.
If your runbooks, dashboards, or contractual language cite 22-01, they now reference a revoked directive. Update them to the four-variable model before the language outlives the policy.
Sourcing: deadline tiers, variable model, and milestone dates are from CISA’s BOD 26-04 directive and its implementation guidance. Remediation rates (26% / 38%) and the 43-day median are from the 2026 Verizon DBIR as cited by CISA. The ~1% / 60%+ tiering figures come from CISA’s sample analysis at one large civilian agency, not an industry-wide measurement — treat them as illustrative of the model’s intent, not a benchmark for your environment.
Agencies must update vulnerability-management policy immediately. Within roughly 60 days (about August 2026) they must update remediation processes to the tiered model, and CISA will publish machine-level asset-tagging data requirements. Within roughly 180 days (about December 2026) they must meet the full Table 1 timelines. Private-sector teams aligning early gain a head start before any of it becomes an expectation in regulated industries or federal supply chains.
If you find ByteVanguard useful, you can support the site and help keep the analysis independent.
Support the analysis