bodtrade-pressNewsThe Broadside3 min read

BOD 26-04 retires CVSS, clocks remediation at three days

BOD 26-04 converts federal vulnerability management from a detection exercise into an execution audit, and the passing grade is three days.


TL;DR

CISA's BOD 26-04, issued June 10, retires CVSS as the standalone vulnerability metric and mandates complete remediation within three days for the highest-risk exposures: internet-facing, KEV-listed, automatable flaws that could give an attacker full control. Federal civilian agencies and their contractors now face compliance failures measured in coordination speed, not detection coverage. The directive doesn't ask whether you can find the problem. It asks whether your organization can actually fix things when the clock starts, and that's the muscle the industry spent a decade neglecting while it perfected scoring.

BOD 26-04 isn't a scoring refinement. It's the first federal cybersecurity directive that measures compliance on execution speed rather than detection coverage. For a decade, the industry bet that better vulnerability scoring (CVSS, EPSS, SSVC) would solve the prioritization problem. CISA just told every federal agency that a perfect risk score is worthless if you can't complete the fix.

The directive tiers vulnerabilities using four risk factors: internet exposure, KEV catalog listing, exploit automation potential, and whether successful exploitation yields full system control. When a vulnerability hits all four, agencies have three calendar days: not to begin remediation, not to develop a plan, but to complete it. CISA's implementation guidance layers forensic triage on top: scope the affected assets, preserve evidence, contain the threat, analyze for compromise, and then decide whether to escalate. The practical window for routing the work to the right team collapses to hours. The Ivanti Connect Secure emergency directive in early 2024 previewed what this looks like in practice, as Federal News Network reported: agencies had to yank appliances offline immediately, perform factory resets, and rebuild configurations from scratch while remote access for thousands sat dead.

Most early vendor commentary frames BOD 26-04 as a data problem. Buy better asset discovery, faster scanning, richer context. But the numbers say otherwise. Per Verizon's 2026 DBIR, only 26% of KEV-listed vulnerabilities were fully remediated in 2025, and median time to resolution hit 43 days, against a then-standard of 15. That gap doesn't come from slow scanners. It comes from remediation tickets bouncing between security and IT operations while three teams debate who owns the host. A faster scanner can't fix an organizational bottleneck. The directive puts a stopwatch on coordination, not detection. The compliance failure most agencies will face isn't "we didn't know." It's "we couldn't get the right person to act."

BOD 26-04 quietly assumes the operational infrastructure to execute on its timelines already exists. It mostly doesn't. CISA's own guidance describes a split model: human judgment for emergency fixes, automated workflows for the long tail. But routing a vulnerability to the correct lane instantly requires asset context, ownership mapping, and threat intelligence wired into the orchestration layer, not scattered across four tools and an outdated spreadsheet. Most agencies don't have that integration today, and the directive doesn't fund it.

If you run a federal security program, your reflex will be to retune your prioritization algorithms. That's the wrong project. The directive already prioritized for you. Spend the next 90 days measuring your actual three-day close rate on top-tier vulnerabilities. Most programs are structurally built around 30-to-90-day patch cycles. The baseline failure rate for a 72-hour window is the finding you need first. Map asset ownership across every handoff between security and IT. Make KEV status an automatic input to the remediation pipeline, not a report someone reads a week later. Treat your SLA failures as diagnostic output: better to find the structural fractures yourself than have an auditor document them. BOD 26-04 isn't the last directive of its kind. It's the template for what regulators and insurers will define as defensible posture, and the clock is already running.


Published ·Deep Fathom