CISA has issued a new cybersecurity directive requiring federal civilian agencies to prioritize software patching and vulnerability remediation based on risk, marking a significant shift in how the federal government addresses cyber threats.

Binding Operational Directive 26-04 replaces previous federal vulnerability management directives with a framework that focuses remediation efforts on vulnerabilities that present the greatest threat to government systems. The directive comes as federal officials warn that cybercriminals and nation-state actors continue to exploit unpatched software flaws to gain access to sensitive networks and critical infrastructure.

Under the new model, agencies must evaluate vulnerabilities using four primary factors: whether a system is publicly exposed to the internet, whether the vulnerability appears in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, whether an attack can be automated, and the level of control an attacker would gain after successful exploitation.

CISA said the approach is intended to help agencies direct resources toward the vulnerabilities most likely to be used in real-world attacks rather than treating all software flaws equally. The agency noted that advances in artificial intelligence may reduce the amount of time defenders have to respond after security patches are released.

The directive immediately requires agencies to review and update vulnerability management policies, monitor updates to the KEV Catalog, maintain participation in CISA’s Cyber Hygiene program, and improve automated vulnerability reporting through the Continuous Diagnostics and Mitigation program.

Within 60 days, agencies must revise vulnerability management processes to align with the new framework. Within 180 days, agencies must implement the directive’s remediation timelines and continuously identify and tag publicly reachable assets across their networks.

The directive also applies to federal information systems hosted in cloud environments, including FedRAMP-authorized services. Agencies remain responsible for ensuring that cloud providers and third-party service environments comply with applicable requirements.

For the insurance industry, the directive underscores the growing importance of vulnerability management as a core component of cyber risk. Known exploited vulnerabilities remain a common entry point in ransomware attacks, data breaches, and other incidents that generate cyber insurance claims.

Claims professionals investigating cyber losses frequently examine patch management records, vulnerability assessments, and security controls when determining the circumstances surrounding an event. The directive’s focus on documented remediation timelines and asset inventories reflects broader expectations across both the public and private sectors for organizations to demonstrate active cybersecurity governance.

The new directive supersedes BOD 22-01 and BOD 19-02, consolidating federal vulnerability remediation requirements into a single risk-based framework intended to improve cybersecurity resilience across government networks.