First BOD 26-02 update lands six months into 12-month deadline
The webinar is CISA's first formal implementation briefing since the February directive, and it follows a 76-day DHS shutdown that stalled the work.
TL;DR
CISA holds its first formal implementation update Thursday on Binding Operational Directive 26-02, which requires federal civilian agencies to inventory, update, and decommission all end-of-support edge devices within 12 months. Robert Thompson, acting associate director of threat hunting, leads the briefing roughly six months into the compliance window. A 76-day Department of Homeland Security shutdown earlier this year delayed CISA's implementation work; the decommissioning deadline hasn't changed.
BOD 26-02, issued February 5, requires FCEB agencies to identify every end-of-support edge device on their networks (firewalls, routers, VPN gateways, load balancers) report the inventory to CISA, bring what can be updated to a vendor-supported software version, and remove everything else within 12 months. The directive landed alongside a CISA-FBI-NCSC fact sheet warning that nation-state threat actors are actively exploiting unsupported edge devices as entry points into federal networks, using them to pivot past perimeter defenses. [4]
That's a six-month gap and a 76-day DHS shutdown since the directive dropped, with no formal implementation briefing until now.
Agencies have roughly six months left to finish decommissioning. The directive doesn't pause for shutdowns, and unsupported devices at the network perimeter remain the most reliable on-ramp for advanced threat actors. CISA is encouraging private-sector and state and local organizations to follow the BOD's guidance voluntarily, though the directive binds only FCEB agencies. [4] Thursday's briefing may signal how aggressively the agency expects organizations outside the federal enterprise to mirror its edge-device lifecycle requirements.
Published ·Deep Fathom