What was BOD 22-01?
CISA Binding Operational Directive 22-01 (November 2021), which created the KEV catalog and required federal agencies to fix listed CVEs by set deadlines. It was revoked on 10 June 2026 by BOD 26-04.
"Reducing the Significant Risk of Known Exploited Vulnerabilities" applied to federal civilian executive branch agencies. It set default deadlines of six months for CVEs assigned before 2021 and two weeks for all others, counted from when CISA added the CVE to the catalog, with shorter deadlines when there was grave risk.
Many security tools and policies still quote "BOD 22-01 due dates". The catalog it created continues; the deadlines now come from BOD 26-04.
Sources
Related terms
- BOD 26-04CISA Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk" (10 June 2026), which replaced BOD 22-01's flat KEV deadlines with risk-based timelines.
- KEV due dateThe dueDate field on a KEV catalog entry: the deadline by which US federal civilian agencies must apply the required action for that CVE.
- KEV catalogCISA's Known Exploited Vulnerabilities catalog: the list of CVEs with reliable evidence of exploitation in the wild, each with a required action and a due date.