CISA just changed the rules. Is your vulnerability program ready?

Sarayut Thaneerat / Getty Images
COMMENTARY | BOD 26-04 is a mandate about process. What it implies is a mandate about intelligence.
The attacker is already inside. Not hypothetically – statistically. Nearly half of organizations that experienced a production security incident last year were breached through a vulnerability their own team had already identified. They knew it was there. They just didn’t get to it in time.
On June 10, CISA decided that “in time” now means three days. Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk rewrites how federal agencies prioritize vulnerability remediation and for defense contractors watching closely, it’s a preview of what’s coming for them next.
The directive does something deceptively simple. It tells agencies to stop treating every vulnerability as equally urgent. It establishes four criteria: whether an asset is publicly exposed; whether the vulnerability is actively exploited; whether exploitation can be automated; and whether exploitation yields full system control. It then ties remediation timelines to how many factors apply. A vulnerability that checks all four boxes must be patched within three days. Roughly 60% can be deferred entirely.
The average organization takes 55 days to patch half its critical vulnerabilities. Three days is more than a tightening of standards. It is a different game entirely.
The gap this directive is trying to close
BOD 26-04 lands in a specific threat context. The mean time to exploit known vulnerabilities has dropped to an estimated seven days, and exploitation now routinely occurs before a patch is published. Threat actor alerts increased 225% between 2024 and 2025. The fastest observed attacker breakout time from initial access to lateral movement is now 27 seconds.
What's accelerating that window is AI. Most discussion about AI and cybersecurity focuses on zero-days, which are a real concern. But the more immediate problem is what AI does to known vulnerabilities that have been disclosed but remain unpatched. WannaCry arrived 59 days after its patch. Citrix Bleed took two weeks. That window is collapsing. BOD 26-04's deferral model is being issued into a threat environment where a vulnerability assessed as non-urgent today could have a working exploit by tomorrow.
This is why the traditional model to scan, score, queue, and patch no longer works. CISA's acting director Nick Andersen put it plainly: the agency has to be willing to say some systems are less important than others, and direct limited resources toward the risks that actually matter. A critical vulnerability is not always a critical risk. Without context, severity scores are noise. The right question is “which exposures matter to us right now, given what adversaries are actively doing?”
Detection is not the gap. Prioritization and speed are.
What the directive doesn’t solve
BOD 26-04 formally applies to federal civilian Executive Branch agencies, not contractors yet, but CISA's own Implementation Guidance directs agencies to ensure appropriate remediation timelines are part of service-level agreements or that service providers establish a contractual arrangement. Contracting officers will likely incorporate these requirements into Statements of Work as agencies act on that guidance. For defense industrial base contractors, CMMC sets the floor for what must be protected. BOD 26-04 is raising the ceiling on what operational readiness actually requires.
There are also two structural limitations practitioners need to understand.
The first is the deferral problem. Deferred is not the same as resolved. The 60% of vulnerabilities the directive allows agencies to defer don’t sit in a static threat environment; exploit timelines are compressing and actor groups pivot targeting constantly. A vulnerability assessed as low-urgency in June can be actively exploited by August. Defenders also need to account for vulnerability chaining: attackers frequently combine lower-severity vulnerabilities to gain a foothold, then escalate toward critical systems. A vulnerability that would never independently trigger the three-day clock can become a critical exposure when paired with one that opens a lateral movement path.
The second is control posture drift. BOD 26-04's first criterion – whether a vulnerable asset is publicly exposed – sounds like an inventory question. It is a continuous control validation problem. Exposure state changes constantly as firewall rules drift, cloud configurations shift, and new services are stood up. A vulnerability behind a compensating control can become a three-day priority the moment that control fails silently. Most programs won’t know until the next scan.
What compliance actually requires
Consider the same vulnerability disclosure under two operating models.
A defense agency cyber team receives intelligence that a known adversary group is discussing exploitation of a newly disclosed flaw in a widely used remote access tool. Under a traditional model, the alert joins a queue: CVSS score assigned, patch cycle pending. Under a continuous exposure model, the alert is correlated immediately with vulnerability footprint, current control effectiveness, and mission dependency. The team understands what the adversary can actually do given the controls in place right now, rather than the controls documented in the last assessment. Remediation begins before the KEV catalog is updated.
A CMMC Level 2 subcontractor faces the same disclosure. A lean team, under a traditional model, lacks the context to know whether it's relevant. Under a continuous exposure model, questions about whether this is in our environment, whether we are a target profile and if adversaries are actively exploiting similar organizations have answers before anyone asks.
The difference between a managed risk and a contract-jeopardizing incident is the time between alert and a contextualized picture of what it means.
The real ask
BOD 26-04 is a mandate about process. What it implies is a mandate about intelligence.
CISA is right that prioritization is the real lever. The directive creates a risk-based framework where none existed and will force conversations that have been deferred for years. But it only holds if the intelligence running underneath it is continuous. The three-day clock requires knowing which systems match the exposure profile. The deferral model requires watching deferred vulnerabilities as the threat environment evolves. The control posture criteria require visibility that reflects what’s actually enforced now, rather than last quarter’s scan.
That is the real ask of federal agencies today, and the defense industrial base shortly. CISA just put a deadline on it.
Tim Miller, Dataminr’s Global Field CTO and Chief Cybersecurity Strategist, has nearly two decades of experience helping public sector organizations adopt and leverage emerging technologies.




