CyberMax
Home › Glossary › Vulnerability management

What is a KEV due date?

Vulnerability management glossary · 2 primary sources

The dueDate field on a KEV catalog entry: the deadline by which US federal civilian agencies must apply the required action for that CVE.

Under BOD 22-01 (2021) the default was two weeks after the CVE was added, or six months for CVEs assigned before 2021. BOD 26-04, issued on 10 June 2026, revoked BOD 22-01 and replaced the flat deadline with risk tiers that depend on asset exposure, KEV status, whether exploitation can be automated and technical impact; its highest tier gives three days plus forensic triage.

The due date binds federal agencies only, but private teams often reuse it as a ready-made service level: anything in KEV that faces the internet gets patched on the federal clock or faster.

What the catalog shows now

Gap between dateAdded and dueDate for the 60 most recent KEV entries (added 2026-08-26 to 2026-10-08, CISA catalog version 2026.10.08):

Due afterEntries
3 days47
14 days13

Computed from the public KEV JSON feed at build time. Browse the list on the CVE pages.

Sources

Related terms

On this site

All vulnerability management terms · Full glossary