Skip to content

Menu

Network by SubjectChannelsBlogsHomeAboutContact
AI Legal Journal logo
Subscribe
Search
Close
PublishersBlogsNetwork by SubjectChannels
Subscribe

CISA Releases Binding Operational Directive on Prioritizing Security Updates Based on Risk

By Caleb Skeath, Ashden Fein, Micaela McMurrough, Ryan Burnette & Bryan Ramirez on June 18, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

On June 10, the Cybersecurity & Infrastructure Security Agency (CISA) released Binding Operational Directive (BOD) 26-04 on Prioritizing Security Updates Based on Risk and the accompanying Implementation Guidance. In releasing the BOD and Implementation Guidance, CISA noted that the documents are “part of CISA’s response to the current threat landscape” and the impact of AI on the volume of identified security vulnerabilities and compressed timelines for remediation as threat actors move quickly to exploit them. While the BOD and Implementation Guidance apply to agencies, CISA Acting Director Nick Anderson noted in the release of the documents that “CISA strongly encourages all partners to adopt similar actions in their vulnerability management policy.”

The BOD and Implementation Guidance apply to federal agency assets in a federal information system—a system used or operated by an agency or by another entity on behalf of an agency—that collects, processes, stores, transmits, disseminates, or otherwise maintains agency information. Although the BOD is directed to federal agencies, contractors that operate federal information systems should monitor agency implementation. The BOD states that it does not apply directly to contractors unless required by the governing contract, but also directs agencies to review contracts to determine what modifications may be necessary to comply with the directive. Contractors and cloud service providers therefore may see these requirements reflected in contract terms or in FedRAMP requirements in the future. The BOD requires agencies to, for example:

  • Review and update agency vulnerability management policies to include certain specified information, such as establishing a process for ongoing remediation of vulnerabilities that CISA identifies through the Known Exploited Vulnerabilities (KEV) Catalog, clear roles and responsibilities, validation and enforcement procedures, and internal tracking and reporting requirements.
  • Continue Cyber Hygiene scanning and update the agency’s exposed IPs and domain names quarterly.
  • Remediate vulnerabilities as quickly as possible, and no later than the timelines in the directive, which range from 3 to 60 days, depending on the vulnerability.
  • Implement asset management measures, including continuous identification and tagging of all agency-owned assets that can be reached from outside the agency network and using a routable IP address.

The BOD also includes proposed remediation timelines to “effectively prioritiz[e] high-risk vulnerabilities for timely action, while deferring action against low-risk vulnerabilities.”  Remediation urgency is based on the following four factors:

  • Asset Exposure: Is the vulnerable asset publicly exposed?
  • KEV Status: Is the vulnerability, as identified by a common vulnerabilities and exposures identifier (CVE ID), on CISA’s Known Exploited Vulnerabilities Catalog?
  • Exploit Automation: Is an adversary able to automate all the steps necessary to exploit the vulnerability?
  • Technical Impact: Does an adversary gain partial control or total control of the vulnerable asset after exploitation of the vulnerability?

Depending on the response to these four questions, the proposed remediation timelines are set forth in the table below from the BOD:

Table 1: Remediation Timelines

The BOD emphasizes that these timelines are dynamic as facts change, and remediation measures (such as removing a system from the internet) can shift the required timeline. Notably, the BOD states that the references to “forensic triage” indicate that the agency must also “carry out a forensic triage of the asset to assess whether the system is compromised.” On the other end of the spectrum, the “fix on system upgrade” timeline is described as remediating a vulnerability “the next time the vulnerable asset receives a scheduled major upgrade or rebuild.”

The Implementation Guidance provides additional recommended best practices for executing prompt vulnerability response, including:

  • Scoping: Within 2 hours of CISA adding a CVE to the KEV catalog, identify whether the vulnerability meets the remediation threshold in fewer than three days and requires forensic triage to assess whether the system or network infrastructure has been impacted or compromised. If so, activate the appropriate response team, scope the bounds of the potential incident, and establish out-of-band communications that do not rely on potentially compromised infrastructure.
  • Preserve and Collect Evidence: Within 2-24 hours of KEV addition, prioritize preserving and collecting volatile data, which includes any data stored in memory or existing in transit that will be lost when the computer is powered off.
  • Critical Patching and Stabilization: Within 2-24 hours of KEV addition, collect all required evidence and then apply critical available patches.
  • Contain and Control: Within 6-24 hours of KEV addition, begin containment of in-scope systems and network infrastructure, ensuring coordination with evidence containment to avoid destroying vital evidence prematurely or alerting the threat actor while documenting actions taken.
  • Triage Analysis: Within 24-48 hours of KEV addition, begin evidence analysis to identify unauthorized access to systems, accounts, or data; threat actor access or presence; lateral movement from the initial access vector; persistence mechanisms; and data staging and/or exfiltration.
  • Escalation Decision: Within 48-72 hours of KEV addition, produce a forensic triage report covering information gathered and actions taken, including an incident timeline; timeline of actions taken in response to a vulnerability notification and triage actions; technical findings; containment and mitigation efforts; and recommended next steps.
Photo of Caleb Skeath Caleb Skeath

Caleb Skeath advises clients on a broad range of privacy and data security issues, including regulatory inquiries from the Federal Trade Commission, data breach notification obligations, compliance with consumer protection laws, and state and federal laws regarding educational and financial privacy.

Read more about Caleb Skeath
Photo of Ashden Fein Ashden Fein

Ashden Fein advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance.

For cybersecurity matters, Mr. Fein counsels clients on preparing for and responding to cyber-based attacks, assessing…

Ashden Fein advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance.

For cybersecurity matters, Mr. Fein counsels clients on preparing for and responding to cyber-based attacks, assessing security controls and practices for the protection of data and systems, developing and implementing cybersecurity risk management and governance programs, and complying with federal and state regulatory requirements. Mr. Fein frequently supports clients as the lead investigator and crisis manager for global cyber and data security incidents, including data breaches involving personal data, advanced persistent threats targeting intellectual property across industries, state-sponsored theft of sensitive U.S. government information, and destructive attacks.

Additionally, Mr. Fein assists clients from across industries with leading internal investigations and responding to government inquiries related to the U.S. national security. He also advises aerospace, defense, and intelligence contractors on security compliance under U.S. national security laws and regulations including, among others, the National Industrial Security Program (NISPOM), U.S. government cybersecurity regulations, and requirements related to supply chain security.

Before joining Covington, Mr. Fein served on active duty in the U.S. Army as a Military Intelligence officer and prosecutor specializing in cybercrime and national security investigations and prosecutions — to include serving as the lead trial lawyer in the prosecution of Private Chelsea (Bradley) Manning for the unlawful disclosure of classified information to Wikileaks.

Mr. Fein currently serves as a Judge Advocate in the U.S. Army Reserve.

Read more about Ashden Fein
Show more Show less
Photo of Micaela McMurrough Micaela McMurrough
Read more about Micaela McMurrough
Photo of Ryan Burnette Ryan Burnette

Ryan Burnette advises clients on a range of issues related to government contracting. Mr. Burnette has particular experience with helping companies navigate mergers and acquisitions, FAR and DFARS compliance issues, public policy matters, government investigations, and issues involving government cost accounting and the…

Ryan Burnette advises clients on a range of issues related to government contracting. Mr. Burnette has particular experience with helping companies navigate mergers and acquisitions, FAR and DFARS compliance issues, public policy matters, government investigations, and issues involving government cost accounting and the Cost Accounting Standards.  Prior to joining Covington, Mr. Burnette served in the Office of Federal Procurement Policy in the Executive Office of the President, where he worked on government-wide contracting regulations and administrative actions affecting more than $400 billion dollars’ worth of goods and services each year.

Read more about Ryan Burnette
Show more Show less
Photo of Bryan Ramirez Bryan Ramirez

Bryan Ramirez is an associate in the firm’s San Francisco office and is a member of the Data Privacy and Cybersecurity Practice Group. He advises clients on a range of regulatory and compliance issues, including compliance with state privacy laws. Bryan also maintains…

Bryan Ramirez is an associate in the firm’s San Francisco office and is a member of the Data Privacy and Cybersecurity Practice Group. He advises clients on a range of regulatory and compliance issues, including compliance with state privacy laws. Bryan also maintains an active pro bono practice.

Read more about Bryan Ramirez
Show more Show less
  • Posted in:
    Administrative, Government
  • Blog:
    Inside Government Contracts
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

LexBlog logo
Copyright © 2026, LexBlog. All Rights Reserved.
Legal content Portal by LexBlog LexBlog Logo