What is a KEV due date?
The dueDate field on a KEV catalog entry: the deadline by which US federal civilian agencies must apply the required action for that CVE.
Under BOD 22-01 (2021) the default was two weeks after the CVE was added, or six months for CVEs assigned before 2021. BOD 26-04, issued on 10 June 2026, revoked BOD 22-01 and replaced the flat deadline with risk tiers that depend on asset exposure, KEV status, whether exploitation can be automated and technical impact; its highest tier gives three days plus forensic triage.
The due date binds federal agencies only, but private teams often reuse it as a ready-made service level: anything in KEV that faces the internet gets patched on the federal clock or faster.
What the catalog shows now
Gap between dateAdded and dueDate for the 60 most recent KEV entries (added 2026-08-26 to 2026-10-08, CISA catalog version 2026.10.08):
| Due after | Entries |
|---|---|
| 3 days | 47 |
| 14 days | 13 |
Sources
- CISA BOD 26-04: Prioritizing Security Updates Based on Risk
- CISA Known Exploited Vulnerabilities catalog
Related terms
- KEV catalogCISA's Known Exploited Vulnerabilities catalog: the list of CVEs with reliable evidence of exploitation in the wild, each with a required action and a due date.
- BOD 22-01CISA Binding Operational Directive 22-01 (November 2021), which created the KEV catalog and required federal agencies to fix listed CVEs by set deadlines. It was revoked on 10 June 2026 by BOD 26-04.
- BOD 26-04CISA Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk" (10 June 2026), which replaced BOD 22-01's flat KEV deadlines with risk-based timelines.