Resources

BOD 26-04 Is Not a Three-Day Patch Rule: The Five Tiers Explained

Resources

BOD 26-04 Is Not a Three-Day Patch Rule: The Five Tiers Explained

Resources

BOD 26-04 Is Not a Three-Day Patch Rule: The Five Tiers Explained

The most common reading of CISA's Binding Operational Directive 26-04 is "patch everything in three days". It is wrong, and the misreading is expensive in both directions: teams either panic about volume or underestimate the evidence work.

What changed

BOD 26-04 was issued on 10 June 2026. It replaces BOD 22-01 and BOD 19-02. Where BOD 22-01 gave agencies a single deadline for anything in the Known Exploited Vulnerabilities catalogue, BOD 26-04 sorts findings into five tiers using four questions:

  • Is it publicly exposed?

  • Is it in KEV?

  • Is exploitation automatable?

  • Does it give total or only partial control?

Tier

Deadline

Typical profile

Tier 1

3 days plus forensic triage

In KEV and gives total control

Tier 2

3 days

Worst exposed, automatable combinations

Tier 3

14 days

Most KEV entries

Tier 4

60 days

Lower risk findings

Tier 5

Fix on next upgrade

Everything else

Five tiers, four questions. The deadline is only as defensible as the classification behind it.

Five tiers, four questions. The deadline is only as defensible as the classification behind it.

What the pilot showed

At the pilot agency, roughly 1% of vulnerability instances landed in the three-day tiers. More than 60% could wait for the next upgrade. The context matters: in 2025 only 26% of KEV entries were fully remediated across the federal estate, down from 38% in 2024, with a median of 43 days.

So the directive is not mainly about speed. It is about putting the right 1% on the short clock and being able to defend why the rest is not.

In plain language

Most findings get more time, not less. But you have to prove which tier each one is in, and "publicly exposed" is something you determine and evidence yourself.

The timeline

Agencies run BOD 26-04 in three phases: policy and CDM changes straight away, processes and asset tagging at 60 days, and full compliance at 180 days, which lands around 7 December 2026. December is when agencies start asking the people who run their systems for evidence rather than intent.

Who it reaches

BOD 26-04 binds federal civilian executive branch agencies. It does not legally bind contractors or MSPs. It reaches them anyway, through agency systems they operate, prime contract flow-downs that cite KEV, and the next round of RFPs.

Next step. The BOD 26-04 briefing pack covers the tiers, the clock and how the directive reaches contractors and MSPs. Get the briefing pack →

For any comments or information please reach out to info@astragar.com

Get Started Now

Know the Real Cyber Risk Behind the Data

Get Started Now

Know the Real Cyber Risk Behind the Data

Get Started Now

Know the Real Cyber Risk Behind the Data

©Astragar All rights reserved.