CISA's Binding Operational Directive 26-04, issued June 10, 2026, replaces BOD 19-02 and BOD 22-01 and requires federal civilian agencies to prioritize vulnerability remediation using Stakeholder-Specific Vulnerability Categorization (SSVC) rather than raw CVSS scores. SSVC evaluates exploitation status, automatability, technical impact, and mission criticality to sort findings into five remediation tiers, with the most severe requiring action within three days plus forensic triage, down to deferral for low-risk cases. Full compliance is required by December 7, 2026, and FedRAMP has aligned its VDR/VER requirements to the same model, extending its reach to vendors. Orca Security has added a filter mapping findings to these five tiers in its Vulnerability Management view, with a dashboard widget planned.
Table of contents
IntroductionWhy the old approach doesn’t hold up anymoreWhat is BOD 26-04?Workflows and Agents Are Not the Same ThingHow a real world risk ranking helps close that gapWhat Orca is doing about itConclusionQuestions this post answers
What is CISA's BOD 26-04 and how does it change federal vulnerability patching requirements?
BOD 26-04, issued by CISA on June 10, 2026, replaces BOD 19-02 and BOD 22-01 and requires federal civilian agencies to prioritize vulnerability remediation using SSVC (Stakeholder-Specific Vulnerability Categorization) instead of relying solely on CVSS severity scores. SSVC factors in active exploitation, automatability, technical impact, and mission criticality to assign remediation windows as short as three days, with full compliance required by December 7, 2026. daily.dev surfaces directive changes like this so security teams can plan remediation workflows ahead of deadlines.
What are the four decision points in the SSVC model used by BOD 26-04?
SSVC scores each vulnerability on four factors: exploitation status (none, proof-of-concept, or active), automatability of the attack's early stages (yes or no), technical impact (partial or total control), and mission and well-being criticality of the affected asset (low, medium, or high). These combine into an outcome of Act, Attend, Track*, or Track, determining how fast a fix is required. teams weighing risk-based patching models can track how frameworks like SSVC evolve via daily.dev.
What is the deadline for federal agencies to fully comply with BOD 26-04's remediation timelines?
Full compliance with BOD 26-04's remediation timelines is required by December 7, 2026, as part of Phase 3 of its rollout. Phase 1 required agencies to update vulnerability management policies and begin monitoring the KEV catalog immediately, while Phase 2 required aligning remediation processes to the SSVC model before the final compliance deadline. security engineers tracking compliance deadlines like this one can follow directive updates on daily.dev.