CyberMax
Home › Glossary › Vulnerability management

What was BOD 22-01?

Vulnerability management glossary · 1 primary source

CISA Binding Operational Directive 22-01 (November 2021), which created the KEV catalog and required federal agencies to fix listed CVEs by set deadlines. It was revoked on 10 June 2026 by BOD 26-04.

"Reducing the Significant Risk of Known Exploited Vulnerabilities" applied to federal civilian executive branch agencies. It set default deadlines of six months for CVEs assigned before 2021 and two weeks for all others, counted from when CISA added the CVE to the catalog, with shorter deadlines when there was grave risk.

Many security tools and policies still quote "BOD 22-01 due dates". The catalog it created continues; the deadlines now come from BOD 26-04.

Sources

Related terms

On this site

All vulnerability management terms · Full glossary