CISA's Binding Operational Directive (BOD) 26-04 replaces BOD 19-02 and BOD 22-01, ending federal agencies' reliance on static CVSS scores for vulnerability prioritization. The new directive mandates a dynamic, risk-based model built on four variables: asset exposure, KEV status, exploit automation, and technical impact. Tenable One maps directly to these four variables, offering continuous asset discovery, attack surface management, and AI-powered prioritization via Tenable Hexa AI. Key data points include: removing internet exposure can shift 76.7% of CVEs to deferral tiers, 83% of actively exploited CVEs yield total system control (triggering a 3-day remediation + forensic triage requirement), and 61% of actively exploited vulnerabilities cannot be fully automated. The platform also automates CDM asset tagging for Phase 3 compliance and extends coverage to cloud and third-party environments via Tenable One Cloud Exposure.

12m read timeFrom tenable.com
Post cover image
Table of contents
Key takeawaysWhat are the implications of CISA BOD 26-04 on federal agency vulnerability management?How can Tenable help me comply with CISA BOD 26-04?How vulnerability research from Tenable helps federal agencies comply with BOD 26-04Vulnerability research from Tenable helps federal agencies address the forensic triage requirement of BOD 26-04Navigate the phased requirements of BOD 26-04 with the platform-scale automation of Tenable OneExtend governance to third-party and cloud environmentsComplying with BOD 26-04 requires the scale that Tenable One providesCISA BOD 26-04 accelerates federal agencies’ journey from vulnerability management to exposure management
39 Impressions