---
title: "How CISA’s BOD 26-04 changes vulnerability prioritization"
url: https://daily.dev/posts/how-cisa-s-bod-26-04-changes-vulnerability-prioritization-kjpzodkau
source_url: https://www.datadoghq.com/blog/cisa-bod-26-04-vulnerability-prioritization
type: article
source: "Datadog"
published: 2026-08-19T14:58:03.103Z
updated: 2026-08-20T18:47:59.405Z
tags: ["security", "devops", "compliance"]
reading_time: 6
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# How CISA’s BOD 26-04 changes vulnerability prioritization

**[Datadog](https://daily.dev/sources/datadog)** · 6 min read · 0 upvotes · 0 comments

## Summary

CISA's Binding Operational Directive 26-04 replaces CVSS-based scoring with risk-based prioritization for federal agencies, using asset exposure, known exploited vulnerability status, exploit automation, and technical impact to set remediation timelines as short as 3 days. It also revokes BOD 19-02. The directive's underlying principle—prioritizing vulnerabilities most likely to be exploited and most impactful to business operations—applies broadly to security teams. Datadog's Runtime Prioritization Engine, part of Datadog Cloud Security, is presented as a tool to operationalize this by evaluating reachability, exposure, exploitability, business criticality, and actionability, plus automatically inferring ownership and business-critical assets.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.datadoghq.com/blog/cisa-bod-26-04-vulnerability-prioritization>

## Questions this post answers

### What is CISA's BOD 26-04 and how does it change vulnerability prioritization for federal agencies?

BOD 26-04 is a Binding Operational Directive from CISA that requires federal agencies to prioritize vulnerability remediation based on risk rather than CVSS scores alone. It evaluates four variables: asset exposure, known exploited vulnerability (KEV) status, exploit automation, and technical impact. The most critical vulnerabilities must be remediated within 3 days, while low-risk ones can wait for the next system upgrade. The directive also revokes the earlier BOD 19-02.

_daily.dev helps security teams track directive-driven shifts like this one when building their own prioritization workflows._

### Does CISA still require CVSS scores for federal vulnerability prioritization?

No, CISA's BOD 26-04 revokes BOD 19-02 and removes the requirement to use the Common Vulnerability Scoring System (CVSS) as the primary mechanism for prioritizing vulnerability remediation. Agencies instead assess risk using asset exposure, known exploited vulnerability status, exploit automation potential, and technical impact to set remediation deadlines.

_Security teams weighing CVSS against newer risk-based models can follow developments like this on daily.dev._

### What factors does Datadog's Runtime Prioritization Engine use to evaluate which vulnerabilities to fix first?

Datadog's Runtime Prioritization Engine scores findings across five dimensions: reachability (is the component running in production), exposure (can attackers reach it), exploitability (public exploit code, EPSS scores, or CISA KEV inclusion), business criticality (impact on critical services or sensitive data), and actionability (known ownership and available fix). It also auto-infers business-critical 'crown jewel' assets and ownership from observability data.

_Teams choosing tools to operationalize risk-based patching can compare approaches on daily.dev._

## Similar posts on daily.dev

- [How CISA BOD 26-04 is reshaping the vulnerability remediation approach](https://daily.dev/posts/how-cisa-bod-26-04-is-reshaping-the-vulnerability-remediation-approach-flrbivlg9) · Dynatrace · 0 upvotes · 0 comments
- [Operationalize CISA BOD 26-04 with Tenable One Exposure Management](https://daily.dev/posts/operationalize-cisa-bod-26-04-with-tenable-one-exposure-management-9q5qfstuj) · Tenable Blog · 0 upvotes · 0 comments
- [CISA tells agencies to patch smarter, not harder — foreshadowing broader industry practice](https://daily.dev/posts/cisa-tells-agencies-to-patch-smarter-not-harder-foreshadowing-broader-industry-practice-abzel1zsg) · CSO Online · 0 upvotes · 0 comments
- [What is CISA BOD 26-04: Impact on vulnerability remediation](https://daily.dev/posts/what-is-cisa-bod-26-04-impact-on-vulnerability-remediation-bethgvuba) · Tenable Blog · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#devops](https://daily.dev/tags/devops), [#compliance](https://daily.dev/tags/compliance)

[View this post on daily.dev](https://daily.dev/posts/how-cisa-s-bod-26-04-changes-vulnerability-prioritization-kjpzodkau)
