Binding Operational Directive: Authority, Scope, and Requirements

A binding operational directive is a compulsory cybersecurity order issued by the Department of Homeland Security that requires federal civilian agencies to fix a specific threat, vulnerability, or risk within a set deadline. The statute defines it as a direction “for purposes of safeguarding Federal information and information systems from a known or reasonably suspected information security threat, vulnerability, or risk.”1Office of the Law Revision Counsel. 44 USC 3552 – Definitions Every department and agency in the Federal Civilian Executive Branch must comply.2Cybersecurity and Infrastructure Security Agency. Cybersecurity Directives National security systems and certain systems run by the Department of Defense and the Intelligence Community are outside the scope.3Cybersecurity and Infrastructure Security Agency. Binding Operational Directive 15-01

Where the Authority Comes From

The Federal Information Security Modernization Act of 2014 gives the Secretary of Homeland Security authority to develop and oversee binding operational directives. Under 44 U.S.C. § 3553, the Secretary exercises this power “in consultation with” the Director of the Office of Management and Budget, and the directives can cover incident reporting, mitigation of urgent risks, and other operational measures the Secretary or Director determines are necessary.4Office of the Law Revision Counsel. 44 US Code 3553 – Authority and Functions of the Director and the Secretary

CISA does the technical drafting and day-to-day oversight. OMB serves as a check: the Director can revise or repeal a directive that doesn’t align with broader OMB policies and guidelines.4Office of the Law Revision Counsel. 44 US Code 3553 – Authority and Functions of the Director and the Secretary Once a directive is issued, each agency head is legally required to comply, and the obligation flows down to the agency’s Chief Information Officer, who runs implementation.5Office of the Law Revision Counsel. 44 USC 3554 – Federal Agency Responsibilities

Who Must Comply and Who Is Excluded

The Federal Civilian Executive Branch is broad. It covers most non-military departments and independent regulatory agencies that manage domestic government functions.2Cybersecurity and Infrastructure Security Agency. Cybersecurity Directives

Directives do not apply to statutorily defined national security systems or to certain systems operated by the Department of Defense and the Intelligence Community.3Cybersecurity and Infrastructure Security Agency. Binding Operational Directive 15-01 National security systems include those involved in intelligence activities, military command and control, weapons systems, and information classified under executive order or statute.1Office of the Law Revision Counsel. 44 USC 3552 – Definitions Those systems are governed by separate classified standards. If an agency operates both types, only the civilian systems are covered.

Compliance obligations also reach some private entities that hold federal data. Cloud service providers with FedRAMP authorization must implement the actions in BOD 22-01, including tracking listed vulnerabilities in their Plan of Action and Milestones.6FedRAMP. FedRAMP BOD 22-01 Guidance A proposed Federal Acquisition Regulation rule, FAR Case 2021-019, would formally require other contractors running federal information systems on non-cloud infrastructure to comply with BODs and Emergency Directives. Under the proposal, contracting officers would identify applicable directives at award, and later directives could be added by contract modification.7Federal Register. Federal Acquisition Regulation – Standardizing Cybersecurity Requirements for Unclassified Federal Information Systems Until that rule is finalized, contractor obligations depend on the specific terms of their contracts.

How BODs Differ From Emergency Directives

CISA also issues Emergency Directives, which target threats requiring an even faster response. By statute, Emergency Directives exist “to rapidly mitigate emerging threats” and are limited to the shortest time necessary.8Cybersecurity and Infrastructure Security Agency. CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity A standard binding operational directive typically gives agencies weeks or months. An Emergency Directive compresses that window because the threat is being actively exploited or poses an imminent danger. Agency heads must follow both under 44 U.S.C. § 3554.5Office of the Law Revision Counsel. 44 USC 3554 – Federal Agency Responsibilities

What a Directive Actually Requires

The most visible product of these directives is CISA’s Known Exploited Vulnerabilities catalog, the KEV. Created by BOD 22-01, the KEV is a running list of software vulnerabilities that attackers have already used in real-world incidents. As of mid-2025 it contained over 1,550 entries.9Cybersecurity and Infrastructure Security Agency. Known Exploited Vulnerabilities Catalog Every time CISA adds an entry, agencies are on the clock to fix it.

BOD 22-01 sets default remediation windows based on when a vulnerability was first cataloged. Vulnerabilities with a CVE identifier assigned before 2021 get six months. Everything else must be fixed within two weeks.10Cybersecurity and Infrastructure Security Agency. BOD 22-01 – Reducing the Significant Risk of Known Exploited Vulnerabilities Those timelines can shift in cases of “grave risk to the Federal Enterprise,” but the baseline expectation is aggressive.

Individual directives can set their own deadlines. BOD 25-01, which requires agencies to implement secure configuration baselines for cloud services like Microsoft 365, set a single compliance date of June 20, 2025 for all listed configuration policies.11Cybersecurity and Infrastructure Security Agency. BOD 25-01 – Implementing Secure Practices for Cloud Services Required Configurations The most recent, BOD 26-02, addresses risks from end-of-support edge devices and was issued in February 2026.2Cybersecurity and Infrastructure Security Agency. Cybersecurity Directives

Some directives target the plumbing that makes remediation possible in the first place. BOD 23-01 requires agencies to run automated asset discovery across their networks every seven days and to enumerate vulnerabilities on those assets every fourteen days. These are continuous cycles, not one-time obligations, and they exist because you can’t patch what you don’t know you have.

What Happens if an Agency Misses the Deadline

CISA does not issue waivers or exceptions for actions required under its directives.10Cybersecurity and Infrastructure Security Agency. BOD 22-01 – Reducing the Significant Risk of Known Exploited Vulnerabilities If an agency cannot remediate a vulnerable system in time, it must remove that asset from its network. Disconnect first, fix later. Agencies must also set up their own internal validation and enforcement procedures so tracking doesn’t rest solely on CISA.

The directives themselves don’t spell out fines or sanctions for agencies that miss deadlines. Federal agencies aren’t penalized the way private companies might be. The consequences are structural and reputational. Disconnection of a system that supports a critical government function is expensive and draws leadership attention. OMB layers on budget pressure: agencies must show alignment with cybersecurity priorities in their resource requests, and poor Inspector General ratings can trigger targeted engagement sessions where OMB scrutinizes an agency’s security spending and progress.12The White House. M-25-04 Fiscal Year 2025 Guidance on Federal Information Security and Privacy Management Requirements

Each agency’s Inspector General runs an independent annual evaluation of the information security program under FISMA, and those evaluations explicitly test compliance with specific BODs. For fiscal year 2025, the IG metrics incorporated BOD 23-01 for hardware asset management; BODs 18-02, 19-02, 22-01, and 23-01 for vulnerability remediation; and BOD 18-01 for data protection.13Cybersecurity and Infrastructure Security Agency. Final FY 2025 IG FISMA Reporting Metrics OMB publishes portions of agency performance data publicly. In fiscal year 2023 it released a Federal Cybersecurity Progress Report on performance.gov with individual agency summaries covering CIO ratings, independent IG assessments, and incident counts broken down by attack type.14The White House. Federal Information Security Modernization Act of 2014 Annual Report to Congress – Fiscal Year 2023 Agencies that consistently perform poorly are visible to Congress, the press, and the public.