National ยท Cybersecurity
CISA directs federal agencies to prioritize patches by risk
Binding Operational Directive 26-04 sets a risk-based patching model for civilian federal agencies, including a three-day deadline for vulnerabilities meeting three or more high-risk criteria.

CISA's BOD 26-04, issued June 10, replaces BOD 19-02 with a risk-based approach to prioritizing security updates. It is mandatory for federal civilian executive-branch agencies and offered as guidance for critical infrastructure operators.