What changed
CISA Binding Operational Directive 26-04 consolidates and clarifies federal vulnerability remediation requirements. It supersedes BOD 19-02 and BOD 22-01. Agencies still care about known exploited vulnerabilities—but the directive pushes clearer, risk-based prioritization and tighter coupling to asset visibility programs.
Why primes should care
Solicitations written after BOD 26-04 will expect more than "we patch KEVs." They will expect:
- Asset and vulnerability reconciliation across scanners, EDR, CMDB, and cloud
- Coverage metrics that survive an auditor's questions
- Risk-based remediation sequencing with executive-readable dashboards
- CDM reporting alignment where applicable
The CAASM connection
You cannot prioritize what you cannot see. BOD 26-04 works with BOD 23-01's asset visibility expectations. That is why our CAASM and Vulnerability Data Reconciliation package focuses on duplicate resolution, identity conflicts, and coverage metrics before promising remediation SLAs.
Honest scoping
Week ranges for reconciliation work assume a single system or boundary. Multi-tenant or multi-bureau environments take longer. We confirm duration after we have looked at the environment—not before.
