What BOD 22-01 Actually Requires: The 21-Day CISA Deadline, Who It Applies To, and What Private Companies Should Do

Retool's new app builder is where AI-generated code ships safely
Building apps with AI is easy. Getting them to production safely is another story.
Every major vulnerability story references CISA patch deadlines. Most do not explain who those deadlines actually bind. The answer matters operationally: if you are a security engineer at a private company, hospital, bank, or state agency reading about a June 1 CISA deadline, that deadline is not legally enforceable against your organization.
That does not mean you should ignore it. CISA adds CVEs to the KEV catalog only when there is confirmed evidence of active exploitation. The deadline is useful as a threat signal regardless of whether you are legally required to meet it. But understanding what the policy actually says changes how you communicate urgency internally and how you frame compliance posture to leadership.
What BOD 22-01 Actually Says
Binding Operational Directive 22-01, issued November 3, 2021, establishes three requirements for FCEB agencies:
- Maintain a current inventory of software and systems.
- Remediate every vulnerability in the CISA KEV catalog within the timeframe specified in the catalog entry. Most deadlines are 14 days for older vulnerabilities added at directive launch and 21 days for new additions. Some critical entries have been set to shorter windows.
- Report remediation status to CISA through the Continuous Diagnostics and Mitigation (CDM) program.
The directive was issued under the authority of the Federal Information Security Modernization Act (FISMA) and the Homeland Security Act. It is enforceable against FCEB agencies through OMB oversight mechanisms. It does not create legal exposure for private sector organizations.
BOD 22-01 does not specify a particular patching method. Agencies can meet the requirement through patching, applying vendor mitigations, network isolation of affected assets, or decommissioning vulnerable systems. What matters is that the vulnerability is remediated or compensating controls are in place before the due date.
Exactly Who Is and Is Not Bound
Bound by BOD 22-01:
- US Federal Civilian Executive Branch (FCEB) agencies. This means departments like DHS, HHS, Treasury, State, and their component agencies. Approximately 100 organizations total.
Not bound by BOD 22-01:
- Private sector companies, regardless of size or sector
- State, local, tribal, and territorial (SLTT) governments
- US Department of Defense components (DoD has its own directives and processes)
- Contractors to federal agencies (though contractual requirements may flow down through agreements)
- Critical infrastructure operators in the private sector (energy, water, healthcare, finance)
- Public universities and academic institutions
CISA regularly and correctly notes that it "strongly encourages" all organizations to address KEV entries. That language is deliberate: it acknowledges that the legal mandate stops at FCEB while making clear that the operational urgency extends everywhere the affected products are deployed.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
What Private Sector Organizations Should Actually Do
The KEV catalog is still the most operationally useful public vulnerability feed available, and the absence of a legal mandate does not reduce its threat intelligence value.
Use the due date as a threat signal, not a compliance deadline. When CISA sets a June 1 deadline for CVE-2026-0257 in PAN-OS, that date reflects their assessment of exploitation urgency based on threat intelligence. It is a reasonable benchmark for your own remediation timeline even if you are not a federal agency.
Cross-reference your asset inventory against the KEV catalog weekly. Any asset running software listed in the catalog is running confirmed-exploited code. That is the relevant operational fact regardless of BOD 22-01. For a free automated approach, see How to Set Up CISA KEV Alerts Without a SIEM.
Use KEV to justify patch urgency to leadership. The KEV catalog is authoritative enough to carry weight in internal communications. When you need to escalate a patch request, citing the KEV entry and its confirmed exploitation evidence is more persuasive than citing a CVSS score. Leadership that understands the KEV catalog will also understand why a 7.8 CVSS may be more urgent than a 9.8. See the CVSS vs. CISA KEV explainer for supporting material.
Prioritize KEV entries in your SLAs. Even without a legal mandate, most security programs should adopt an internal policy of addressing KEV-listed vulnerabilities affecting their environment within 30 days, with shorter windows for internet-exposed assets. That is a reasonable private-sector analog to the BOD 22-01 framework.
Common Misconceptions Cleared Up
"We missed the CISA deadline, are we liable?" If you are a private company: no legal liability to CISA for missing a KEV due date. You may have liability under cyber insurance policy conditions (some policies require patching known exploited vulnerabilities promptly), contractual SLAs with clients, or sector-specific regulations like HIPAA, PCI DSS, or NY DFS if a breach results from the unpatched vulnerability.
"Our penetration test passed, so we are fine on KEV entries." A penetration test snapshots a moment in time. KEV entries can be added between tests. An asset that passed a pentest in April may be running a KEV-listed vulnerability added in May. KEV monitoring is continuous and orthogonal to periodic testing.
"CISA's requirements apply to critical infrastructure." BOD 22-01 specifically does not apply to private critical infrastructure. CISA does issue voluntary guidance and sector-specific advisories for critical infrastructure operators through its sector risk management authority, but those are advisory rather than binding for private entities.
"If we follow NIST 800-53 or ISO 27001, we are covered." NIST 800-53 and ISO 27001 include vulnerability management controls, but neither framework mandates KEV-specific remediation timelines. Compliance with those frameworks does not automatically mean KEV entries are being addressed on the appropriate schedule.
The bottom line
BOD 22-01 binds around 100 US federal civilian agencies. Private sector organizations, state governments, DoD components, and critical infrastructure operators are not legally required to comply. The right posture for private sector organizations is to treat the KEV catalog as the most operationally reliable public list of confirmed-exploited vulnerabilities, establish internal SLAs that mirror the intent of BOD 22-01 (remediate KEV entries within 21 to 30 days), and use KEV entries as the primary signal for patch prioritization over CVSS scores alone.
Frequently asked questions
Does BOD 22-01 apply to government contractors?
BOD 22-01 directly binds FCEB agencies, not their contractors. However, contracts with federal agencies often include cybersecurity requirements through Federal Acquisition Regulation (FAR) and Defense Federal Acquisition Regulation Supplement (DFARS) clauses. Contractors handling federal data under FedRAMP authorizations or CMMC frameworks have separate and sometimes more stringent patching requirements. Review your specific contract vehicles and security control overlays rather than assuming BOD 22-01 does or does not apply.
What happens if a federal agency does not meet a BOD 22-01 deadline?
FCEB agencies that cannot remediate a KEV entry by the due date are required to report the exception to CISA and document compensating controls in place. CISA uses this data to track compliance across the federal enterprise and can escalate persistent non-compliance through OMB. There is no public enforcement history of penalty actions against individual agencies for BOD 22-01 non-compliance, but the directive is technically enforceable under FISMA.
Is there a BOD 22-01 equivalent for the Department of Defense?
The DoD operates under its own directives rather than CISA's BOD 22-01. The DoD Cyber Strategy and DISA Security Technical Implementation Guides (STIGs) govern vulnerability remediation timelines for defense components. DoD contractors face additional requirements through CMMC (Cybersecurity Maturity Model Certification) and DFARS clauses.
Can cyber insurance policies require BOD 22-01 compliance from private companies?
Cyber insurance policies increasingly include provisions requiring policyholders to patch known exploited vulnerabilities promptly. Some policies specifically reference the CISA KEV catalog as the benchmark. Failing to patch a KEV-listed vulnerability before a related breach can be grounds for claim denial. Review your specific policy language with your broker, particularly around vulnerability management and patch obligations.
How does BOD 22-01 interact with FISMA compliance?
BOD 22-01 is issued under FISMA authority and is one of several binding directives that shape FCEB agency FISMA compliance. Meeting BOD 22-01 KEV remediation requirements contributes to an agency's overall FISMA posture. Annual FISMA assessments conducted by Inspectors General include evaluation of vulnerability management programs, and persistent KEV backlog is a common finding in IG reports.
What documentation should private sector organizations maintain to demonstrate they are treating KEV entries appropriately even without a legal mandate?
Private sector organizations that want to demonstrate reasonable vulnerability management practice -- for cyber insurance underwriters, enterprise customers conducting vendor security assessments, or regulators in sectors with general duty-of-care obligations -- should maintain four artifacts. First, a written vulnerability management policy that references the CISA KEV catalog as a primary prioritization input and specifies internal remediation SLAs tiered by asset criticality and exposure. Second, a monthly log showing the KEV cross-reference run against the asset inventory, the matches found, and their remediation status. Third, documented exception records for any KEV entry not remediated within your stated SLA, including the business justification, compensating controls in place, and the revised remediation date with owner sign-off. Fourth, evidence of KEV monitoring automation -- whether a cron job, GitHub Actions workflow, or enterprise scanner KEV filter -- so you can show continuous monitoring rather than point-in-time checks. These four artifacts satisfy the documentation requirements of most cyber insurance supplemental questionnaires that ask about known exploited vulnerability management and provide defensible evidence in the event of a breach investigation involving a KEV-listed vulnerability.
Sources & references
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
Win a $2,495 Black Hat pass.
Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.
