CISA BOD 26-04: What Every Federal Agency Needs to Know (Part 1)
The directive replaces static patch schedules with risk-based timelines as short as 3 calendar days. Here is what changes, what agencies need to prepare, and how cloud provider oversight must evolve.

InfusionPoints Blog
Federal agencies have entered a new era of vulnerability management. With CISA BOD 26-04, Prioritizing Security Updates Based on Risk, CISA is making clear that vulnerability management can no longer be treated as a static compliance routine. The directive moves Federal Civilian Executive Branch agencies away from one-size-fits-all remediation and toward a risk-based model focused on the vulnerabilities most likely to create real mission impact by assessing how they affect federal workloads.
Five biggest changes for agencies
1. New remediation timelines. Remediation timelines are now dynamic and can be as short as 3 calendar days. A static severity score no longer sets your deadline. Four factors do: KEV status, public exposure, automatability, and technical impact.
2. Knowing your exposure. Agencies must continuously identify internet-reachable assets. Every externally reachable asset must carry current context, and prioritization is impossible without it.
3. Vulnerability management now has a forensic layer. Forensic triage is now part of vulnerability management. For the highest-risk findings, agencies must be prepared to scope affected systems, preserve evidence, stabilize and patch, contain exposure, perform triage analysis, and decide whether escalation is required.
4. New rules demand new governance. Policies, roles, and reporting must be rebuilt around the new model. Agencies must update vulnerability management policies, assign roles and responsibilities, validate adherence, monitor the KEV catalog, continue Cyber Hygiene scanning, and automate reporting through the CDM Dashboard where possible.
5. Your cloud providers’ and third parties’ vulnerabilities are your problem too. Agencies remain accountable for third-party systems used in FedRAMP boundaries. Agencies must validate inventory, obtain directive status updates, and ensure compliance through collaborative continuous monitoring. FedRAMP Notice NTC-0014 requires cloud providers to adopt the new Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules by December 7, 2026, and states that legacy monthly scanning is insufficient.
Table 1: remediation timeline? No. Decision model.
Table 1 of the directive turns remediation into a decision model built on four data points:
- Whether the CVE is in the KEV catalog
- Whether the asset is publicly exposed
- Whether exploitation is automatable
- Whether the technical impact is partial or total control
The same CVE can land in a different response window depending on asset context. Removing public exposure can shift a system into a longer timeline, while a new KEV addition or a total-control impact can accelerate the response overnight.
Source note: This model should be read with the official CISA BOD 26-04 Implementation Guidance. Days are calendar days. Timelines are dynamic as exposure, KEV status, automatable status, or technical impact changes.
| In KEV | Publicly Exposed | Automatable | Technical Impact | Remediation Timeline |
|---|---|---|---|---|
| No | No | No | Partial | Fix on system upgrade |
| Yes | No | No | Partial | 14 days |
| No | Yes | No | Partial | 60 days |
| No | No | Yes | Partial | 60 days |
| No | No | No | Total | Fix on system upgrade |
| Yes | Yes | No | Partial | 14 days |
| Yes | No | Yes | Partial | 14 days |
| No | Yes | Yes | Partial | 14 days |
| Yes | No | No | Total | 14 days |
| No | Yes | No | Total | 14 days |
| No | No | Yes | Total | 60 days |
| Yes | Yes | Yes | Partial | 3 days |
| Yes | Yes | No | Total | 3 days + forensic triage |
| Yes | No | Yes | Total | 3 days + forensic triage |
| No | Yes | Yes | Total | 3 days |
| Yes | Yes | Yes | Total | 3 days + forensic triage |
What agencies need to comply
Applying Table 1 consistently, and defending those decisions to authorizing officials, requires several capabilities working together:
- Continuous asset awareness, so exposed systems can be identified.
- Risk-based prioritization, so vulnerabilities with the highest agency impact move first.
- Operational response workflows, so mitigation, remediation, validation, and escalation are coordinated.
- Current evidence and reporting, so decisions are visible, defensible, and feed CDM where possible.
- Security operations alignment, so high-risk findings connect to monitoring, triage, and incident response when required.
What to expect from cloud providers
BOD 26-04 changes the agency-provider conversation. Agencies should expect cloud service providers to supply current asset information, exposure context, KEV awareness, exploitability evaluation, technical impact analysis, remediation status, mitigation evidence, and coordinated reporting. A monthly scan report no longer meets the bar. The relationship needs to become more operational, more evidence-driven, and more transparent.
How InfusionPoints can help
InfusionPoints supports agencies across this entire operating model through the Continuous Trust Platform, a coordinated loop of Build, Operate, Prove, and Defend. We help agencies build secure, instrumented environments where asset tagging and exposure visibility are part of the architecture, operate vulnerability management as a continuous lifecycle aligned to BOD 26-04 timelines, prove posture with current evidence for CDM reporting, provider oversight, and authorizing officials, and defend the mission by connecting the highest-risk findings to monitoring, forensic triage, and escalation through VNSOC360 security operations.
InfusionPoints works both sides of the shared responsibility line, helping agencies get the visibility and evidence they need from FedRAMP and third-party providers ahead of the December 2026 deadline.
References
Ready to make vulnerability response decision-ready?
InfusionPoints helps agencies and providers move from static reporting to continuous vulnerability awareness, evidence, and response.