CISA's Binding Operational Directive 26-04 replaces CVSS-based scoring with risk-based prioritization for federal agencies, using asset exposure, known exploited vulnerability status, exploit automation, and technical impact to set remediation timelines as short as 3 days. It also revokes BOD 19-02. The directive's underlying principle—prioritizing vulnerabilities most likely to be exploited and most impactful to business operations—applies broadly to security teams. Datadog's Runtime Prioritization Engine, part of Datadog Cloud Security, is presented as a tool to operationalize this by evaluating reachability, exposure, exploitability, business criticality, and actionability, plus automatically inferring ownership and business-critical assets.
Table of contents
What is BOD 26-04?Challenges of BOD 26-04How the Datadog Runtime Prioritization Engine can helpAccelerate prioritization and remediation for BOD 26-04 with DatadogQuestions this post answers
What is CISA's BOD 26-04 and how does it change vulnerability prioritization for federal agencies?
BOD 26-04 is a Binding Operational Directive from CISA that requires federal agencies to prioritize vulnerability remediation based on risk rather than CVSS scores alone. It evaluates four variables: asset exposure, known exploited vulnerability (KEV) status, exploit automation, and technical impact. The most critical vulnerabilities must be remediated within 3 days, while low-risk ones can wait for the next system upgrade. The directive also revokes the earlier BOD 19-02. daily.dev helps security teams track directive-driven shifts like this one when building their own prioritization workflows.
Does CISA still require CVSS scores for federal vulnerability prioritization?
No, CISA's BOD 26-04 revokes BOD 19-02 and removes the requirement to use the Common Vulnerability Scoring System (CVSS) as the primary mechanism for prioritizing vulnerability remediation. Agencies instead assess risk using asset exposure, known exploited vulnerability status, exploit automation potential, and technical impact to set remediation deadlines. Security teams weighing CVSS against newer risk-based models can follow developments like this on daily.dev.
What factors does Datadog's Runtime Prioritization Engine use to evaluate which vulnerabilities to fix first?
Datadog's Runtime Prioritization Engine scores findings across five dimensions: reachability (is the component running in production), exposure (can attackers reach it), exploitability (public exploit code, EPSS scores, or CISA KEV inclusion), business criticality (impact on critical services or sensitive data), and actionability (known ownership and available fix). It also auto-infers business-critical 'crown jewel' assets and ownership from observability data. Teams choosing tools to operationalize risk-based patching can compare approaches on daily.dev.