BOD 26-04 Kills the Flat KEV Deadline — Steal the Model

Briefings

On June 10, CISA retired the directive that shaped a decade of vulnerability management. BOD 26-04 replaces the flat “every KEV on the same clock” rule with a four-variable risk model — and the framework is worth adopting whether or not a federal mandate ever touches your org.

ByteVanguard• June 2026• Policy Shift

Bottom Line BOD 22-01 told you to patch everything in the KEV on one deadline. BOD 26-04 says that was never the right question. The new model — exposure, exploitation, automatability, impact — is a sharper prioritization engine than most private programs run today. Adopt the logic now; the mandate will pull the rest of the market along behind it.

What actually changed

BOD 26-04, “Prioritizing Security Updates Based on Risk,” revokes and replaces both BOD 22-01 (the November 2021 directive that made the KEV catalog a remediation mandate) and the older BOD 19-02 from 2019. The flat timeline is gone. Where 22-01 assigned every KEV-listed CVE the same window — 14 days for anything dated after 2021 — 26-04 grades each vulnerability against four factors and assigns a deadline based on the specific combination that applies.

The directive binds Federal Civilian Executive Branch agencies. It does not cover national security systems, the intelligence community, or military systems, and it is not mandatory for the private sector. But CISA explicitly encourages private adoption, and history is instructive: 22-01’s KEV catalog became the most widely used prioritization signal in the industry without ever being binding outside government. There’s little reason to expect 26-04’s model to behave differently.

What changed at a glance
 BOD 22-01 (2021–2026)BOD 26-04 (2026–)
Deadline modelFlat — 14 days for post-2021 KEVsGraduated — 3 / 14 / 60 days, or defer
Primary signalKEV membership + CVSSFour-variable risk (KEV is one input)
Deferral pathNone — every KEV required action“Fix on upgrade” tier for lowest risk
Compromise checkNot requiredForensic triage on the top tier
MethodologyKEV catalog + CVSS scoringSSVC-informed, fed by Vulnrichment

The four variables

Each vulnerability is scored on four binary questions. CISA publishes the answers to three of them — KEV status, adversary automatability, and technical impact — through its Vulnrichment program. The fourth, public exposure, is the one each organization has to answer for itself from its own asset inventory. That single requirement is where most of the operational pain lives.

The decision model
01 · EXPOSED
Reachable from outside the network via a routable IP?
you determine
02 · IN THE KEV
Listed in CISA’s Known Exploited Vulnerabilities catalog?
CISA / Vulnrichment
03 · AUTOMATABLE
Can an adversary automate every step of exploitation?
CISA / Vulnrichment
04 · IMPACT
Total control of the system, or only partial?
CISA / Vulnrichment
↓   16 COMBINATIONS   ↓
3d + triage 3 days 14 days 60 days fix on upgrade

The five tiers

3d
top-tier deadline + forensic triage
16
variable combinations in the matrix
~1%
of instances hit the 3-day tier at one agency
60%+
qualified for deferral in that same sample
  • 3 DAYS + FORENSIC TRIAGE
    In the KEV and yields total system control. The most aggressive timeline in federal directive history — and patching alone isn’t enough. Agencies must assess whether the system is already compromised.
  • 3 DAYS
    High-risk combinations such as a publicly exposed, automatable vulnerability with total control — even when the CVE is not yet listed in the KEV.
  • 14 DAYS
    The standard accelerated window for most KEV-listed vulnerabilities and several high-risk non-KEV combinations.
  • 60 DAYS
    Lower-risk combinations — for example, non-exposed assets with automatable but partial-control flaws.
  • FIX ON SYSTEM UPGRADE
    Meets none of the four criteria. The deferral tier — and the real operational relief in the directive. These can wait for the next scheduled upgrade cycle.
Operational gotcha The timelines are dynamic, not static. Pull an asset off the public internet and its window lengthens automatically. But the moment CISA adds a CVE to the KEV, every matching asset’s clock accelerates immediately. That means compliance isn’t a quarterly scan — it’s a continuous correlation of asset exposure against a live catalog. An org that can’t see, in near real time, which of its assets are internet-facing can’t meet the graduated deadlines at all.

Why now

Two pressures converged. The first is that traditional vulnerability management is losing. Citing the 2026 Verizon DBIR, CISA notes that only 26% of KEV-listed vulnerabilities were fully remediated by organizations in 2025 — down from 38% the year before — while the median time to fully resolve a vulnerability climbed to 43 days.

The second is AI. CISA states plainly that AI is accelerating both vulnerability discovery and weaponization, compressing the gap between disclosure and exploitation. The directive is positioned alongside the June 2026 AI Executive Order, “Promoting Advanced Artificial Intelligence Innovation and Security.” When the time-to-exploit shrinks toward hours, a 43-day median isn’t just slow — it’s a window adversaries are increasingly able to drive a truck through. A flat “patch everything eventually” mandate can’t survive that math. A model that tells you what to patch first can.

“The 60% you can defer is not the story. The 1% you can’t is — and AI is shrinking the time you have to find it.”

What to do this week

You don’t need a mandate to use this. The four variables are a defensible prioritization spine that maps onto any exposure-management program. The work is in answering them continuously.

01 · Audit

Score yourself on the four variables

Can you name which assets are publicly exposed right now? Do your tools fold KEV status and exploit automatability into prioritization, or are you still ranking by CVSS alone? If you can’t answer cleanly, that’s your first gap.

02 · Re-plumb

Move off CVSS-first prioritization

22-01 leaned on KEV + CVSS; 26-04 drops mandatory CVSS entirely in favor of SSVC-style reasoning. Ingest Vulnrichment and KEV signals and weight by exposure and impact, not severity score alone.

03 · Triage muscle

Treat KEV + total control as assume-compromise

The top tier requires forensic triage, not just a patch. Build the detection and attribution context to answer “were we already hit?” before you need it under a three-day clock.

04 · Clean up

Retire your BOD 22-01 references

If your runbooks, dashboards, or contractual language cite 22-01, they now reference a revoked directive. Update them to the four-variable model before the language outlives the policy.

Sourcing: deadline tiers, variable model, and milestone dates are from CISA’s BOD 26-04 directive and its implementation guidance. Remediation rates (26% / 38%) and the 43-day median are from the 2026 Verizon DBIR as cited by CISA. The ~1% / 60%+ tiering figures come from CISA’s sample analysis at one large civilian agency, not an industry-wide measurement — treat them as illustrative of the model’s intent, not a benchmark for your environment.

Compliance clock (for federal readers)

Agencies must update vulnerability-management policy immediately. Within roughly 60 days (about August 2026) they must update remediation processes to the tiered model, and CISA will publish machine-level asset-tagging data requirements. Within roughly 180 days (about December 2026) they must meet the full Table 1 timelines. Private-sector teams aligning early gain a head start before any of it becomes an expectation in regulated industries or federal supply chains.

References

1
CISA · Directive
BOD 26-04: Prioritizing Security Updates Based on Risk — full directive text, issued June 10, 2026
cisa.gov
2
CISA · Guidance
BOD 26-04 Implementation Guidance — compliance milestones, SSVC methodology, and the four-variable FAQ
cisa.gov
3
Tenable
CISA BOD 26-04 FAQ — Robert Huber’s breakdown of the four-variable model and 16-tier remediation matrix
tenable.com
4
Verizon
2026 Data Breach Investigations Report — KEV remediation rates and median time-to-remediate
verizon.com
5
The White House
Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security, June 2026
whitehouse.gov

Support independent security analysis

If you find ByteVanguard useful, you can support the site and help keep the analysis independent.

Support the analysis
Intelligence over headlines. Signal over noise.

Stay Connected

Report Intelligence
© 2026 ByteVanguard. Built for security professionals.