logo

CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive

ID: f779245b-26a6-5d75-9714-bcda05ad40f1

STIX ID: report--f779245b-26a6-5d75-9714-bcda05ad40f1

Feed Name: Security Boulevard

Date Published: 2026-06-11

Date Updated: 2026-06-12

Author: Robert Huber

...
...

Tenable's analysis explains CISA BOD 26-04, which replaces the flat KEV-based deadlines of BOD 22-01 with a four-variable (public exposure, KEV status, exploit automation, technical impact) 16-tier remediation model that assigns timelines from three days (including forensic triage for the highest-risk cases) to fix-on-system-upgrade for the lowest-risk cases; the directive forces agencies to adopt continuous asset discovery, risk-based prioritization, and forensic readiness to meet aggressive compliance deadlines and respond to an AI-accelerated threat landscape.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.