The 72-Hour Rule: CISA Just Turned Patch Management Into a Ticking Clock
Security Boulevard, Wednesday, July 22nd, 2026
CISA's BOD 26-04 sets aggressive remediation deadlines for high-risk internet-facing vulnerabilities.
CISA's Binding Operational Directive 26-04 replaces older patching models with risk-based vulnerability remediation carrying very short deadlines for the most dangerous exposures.
The directive evaluates four factors: asset exposure, exploitation status, automation capability and technical impact.
Although formally binding only on federal agencies, the guidance will likely shape private-sector standards, litigation benchmarks and regulatory expectations.
Organizations that cannot patch immediately should deploy compensating controls and keep documented evidence of their response to demonstrate reasonable security practice.