Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 340, Issue 4IT NewsOperations

The 72-Hour Rule: CISA Just Turned Patch Management Into a Ticking Clock

Security Boulevard, Wednesday, July 22nd, 2026

CISA's BOD 26-04 sets aggressive remediation deadlines for high-risk internet-facing vulnerabilities.

CISA's Binding Operational Directive 26-04 replaces older patching models with risk-based vulnerability remediation carrying very short deadlines for the most dangerous exposures.

The directive evaluates four factors: asset exposure, exploitation status, automation capability and technical impact.

Although formally binding only on federal agencies, the guidance will likely shape private-sector standards, litigation benchmarks and regulatory expectations.

Organizations that cannot patch immediately should deploy compensating controls and keep documented evidence of their response to demonstrate reasonable security practice.

more →  ·  More from Operations →