CISA released Binding Operational Directive 26-04 today. As with any significant government directive, the nuances often reveal themselves only after several deep dives. Having analyzed the initial requirements, several key shifts in vulnerability management strategy are immediately apparent. Here is a breakdown of what cybersecurity practitioners need to know.

Risk-based prioritization for the KEV #

BOD 26-04 introduces an explicit prioritization framework for the CISA Known Exploited Vulnerabilities (KEV) catalog. Historically, remediation deadlines for federal civilian agencies centered around two or three weeks, but occasionally landed on one or three days. This was always a little mysterious, and a likely risk indicator (as mentioned in our paper on KEVology). Now, CISA has codified the logic: deadlines are determined by whether a target is publicly accessible and the overall attacker value of the vulnerability. This shift moves the industry closer to a true risk-based approach rather than treating all KEV entries as equally hot fires.

Standardizing on SSVC #

The directive firmly pins its triage methodology on Stakeholder-Specific Vulnerability Categorization (SSVC). While many practitioners were raised on CVSS as the definitive standard, SSVC offers a more pragmatic path for triage. No scoring system is perfect, but SSVC excels at guiding remediation decisions based on organizational context. For a deeper look at how this compares to other signals, see our research on deciphering signals from vulnerability scores.

The compressed timeline of remediation #

We are entering an era of aggressive patching. A three-day remediation window for KEVs has become the new, de facto benchmark, and 14 days represent the "fairly normal" outer limit. While achieving a three-day turnaround across massive federal infrastructures is a Herculean task, the increasingly AI-driven threat landscape demands it. As we publish this blog, exactly 31 KEVs have been posted with a three-day deadline (which you can track via the KEV Collider), but we expect this count to skyrocket as CISA leans into these new prioritizations.

Defining the digital perimeter #

There is still much to debate, particularly regarding the specific technical definitions of what "counts" as being "publicly exposed." For example, while BOD 26-04 accounts for a change in exposure status leading to a change in the deadline, does the status change when there’s a hot new firewall 0-day that makes the firewall fail open? I would hope so, but what if there’s no evidence of that vulnerability being exploited? The firewall didn’t fail, didn’t go away, but it’s arguably a lot more fragile than people thought.

This is the kind of thing that people will definitely struggle with when they interpret the interaction of vulns-du-jour. So, as always, the devil remains in the details, and how agencies interpret and defend their exposure determinations will dictate the speed and success of their compliance. You can read the full text of the directive on the CISA website.

Take action: Assess your exposure #

As the window between discovery and exploitation continues to shrink, understanding your attack surface is no longer optional. To understand why we must move faster, I highly recommend reading our Apex Agentic Adversary blog. 

To begin assessing your exposures and identifying publicly accessible assets, sign up for a runZero free trial today.

Written by todb

Tod Beardsley is VP of Security Research at runZero, where he "kicks assets and fakes frames." Prior to 2025, he was the Section Chief for the Vulnerability Response section for CSD/VM/VRC at CISA, the Cybersecurity and Infrastructure Security Agency, part of the US government, and a seasonal Travis County Election Judge in Texas. He's also a founder and CNA point of contact for AHA!. Tod spends much of his time involved in vulnerability research and coordinated vulnerability disclosure (CVD). He has over 30 years of hands-on security experience, stretching from in-band telephony switching to modern ICS/OT implementations. He has held IT ops, security, software engineering, and management positions in large organizations such as the US Government, Rapid7, 3Com, Dell, and Westinghouse, as both an offensive and defensive practitioner. Tod is a CVE Board member, has authored several research papers, and is an internationally-tolerated horror fiction expert.

More about todb

Written by Colin Dupreay

Colin is a Federal Solutions Engineer at runZero. With almost a decade of experience supporting Public Sector customers, Colin is passionate about protecting and securing our nations networks.

More about Colin Dupreay
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 5.0: Exposure management built to outpace AI-driven attacks
When you're up against AI, every minute counts. Get deep, actionable intelligence across your entire attack surface to close the gaps and hold the...
Product Videos
runZero 5.0: Platform Demo
With the new 5.0 release, runZero is giving defenders the edge they need to succeed in the AI-attack era.
runZero Perspective
BOD 26-04: A new era of prioritized remediation
A complete breakdown of CISA's BOD 26-04 directive. Learn how the shift to SSVC, risk-based KEV prioritization, and 3-day remediation impacts your...
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
runZero Hour, Ep. 32: AI-pocalypse now? Why the 2026 DBIR is actually good news
In this episode of runZero Hour, Tod Beardsley, Brianna Cluck, and Verizon's Alex Pinto broke down 2026 DBIR trends, AI threats, and runZero 5.0.
Podcasts
The shadow era AI, exploits, and cybersecurity's 90s comeback
HD Moore explains how AI is turning hacking back to the 90s, generating permanent exploit skeleton keys and breaking traditional defense.
Talks
Identifying exposures at scale with BloodHound OpenGraph
Traditional exposure management misses hidden attack paths. Learn how BloodHound and Cypher queries can uncover vulnerabilities beyond individual...
Podcasts
When is a vulnerability not a vulnerability?
Attackers care about outcomes, not CVEs. Tod Beardsley joins Distilled Security to discuss reframing risk from checklist compliance to adversary...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.