BOD 19-02: Vulnerability Remediation Deadlines and BOD 22-01 Overlap

Binding Operational Directive 19-02 requires every federal civilian agency to remediate critical vulnerabilities on internet-facing systems within 15 calendar days of detection and high-severity vulnerabilities within 30 calendar days. CISA issued the directive on April 29, 2019, and it remains in force. It shortened the older 30-day critical window in half and, for the first time, pulled high-severity flaws into scope.1Cybersecurity and Infrastructure Security Agency. BOD 19-02 Vulnerability Remediation Requirements for Internet-Accessible Systems

Who Has to Follow It

BOD 19-02 binds all Federal Civilian Executive Branch departments and agencies covered by the Federal Information Security Modernization Act. The obligation follows the system, not the operator: if a contractor or third party runs a federal information system on an agency’s behalf, the patching requirement still sits with the agency.1Cybersecurity and Infrastructure Security Agency. BOD 19-02 Vulnerability Remediation Requirements for Internet-Accessible Systems

National security systems are excluded, along with certain systems operated by the Department of Defense and the Intelligence Community. The definition in 44 U.S.C. § 3552 captures systems tied to intelligence activities, national-security cryptology, military command and control, and equipment integral to weapons systems.2U.S. Government Publishing Office. 44 USC 3552 – Definitions State and local governments and private-sector organizations are not bound by the directive, though CISA encourages them to adopt similar practices.

How the Clock Starts

The remediation window begins the moment CISA’s Cyber Hygiene scanning service detects a qualifying vulnerability on an internet-facing asset. Cyber Hygiene is a no-cost, continuous scanning service that CISA runs against participating agencies, and it is the primary trigger for BOD 19-02 timelines.

Severity comes from the Common Vulnerability Scoring System. As of June 2022, CISA uses the newest available CVSS version for each finding: CVSSv3.1 when it exists, then CVSSv3.0, and CVSSv2.0 only as a fallback. On the standard scale, a score of 9.0 to 10.0 is critical and 7.0 to 8.9 is high. Those two tiers are the ones the directive covers.1Cybersecurity and Infrastructure Security Agency. BOD 19-02 Vulnerability Remediation Requirements for Internet-Accessible Systems

For the clock to run accurately, CISA has to be able to see the assets. Agencies must keep CISA’s scanning IP addresses off any firewall or intrusion-prevention block lists, and they must notify CISA of changes to their internet-accessible IP space, including newly acquired addresses, within five working days.

The Two Deadlines

  • Critical vulnerabilities (CVSS 9.0–10.0): remediate within 15 calendar days of initial detection.
  • High vulnerabilities (CVSS 7.0–8.9): remediate within 30 calendar days of initial detection.

Both windows are measured in calendar days. Weekends and holidays count. A critical flaw first detected on the Friday before a long weekend carries the same 15-day due date as one detected on a Monday morning.1Cybersecurity and Infrastructure Security Agency. BOD 19-02 Vulnerability Remediation Requirements for Internet-Accessible Systems

If an Agency Misses a Deadline

When a deadline passes with a vulnerability still open, CISA sends the agency a partially pre-populated remediation plan covering every overdue finding. The agency has three working days to complete and return it. For each overdue vulnerability, the plan requires:

  • the remediation constraints that prevented on-time patching;
  • any interim mitigations in place to reduce risk while the flaw remains open; and
  • an estimated completion date.

CISA’s guidance acknowledges that networks vary and that dependencies can make fast patching impractical. What it demands is transparency: name the constraint, describe what you are doing in the meantime, and commit to a date.1Cybersecurity and Infrastructure Security Agency. BOD 19-02 Vulnerability Remediation Requirements for Internet-Accessible Systems

Continued slippage or non-response gets escalated to senior agency leadership, including the Chief Information Officer, Chief Information Security Officer, and Senior Accountable Official for Risk Management. CISA also reports cross-agency compliance trends to the Office of Management and Budget every month, and Cyber Hygiene reports plus a Federal Enterprise scorecard let agencies see how they compare with one another.

How It Interacts With BOD 22-01 and the KEV Catalog

BOD 19-02 was not replaced by the Known Exploited Vulnerabilities directive. In November 2021, CISA issued BOD 22-01, which created the KEV catalog: a continuously updated list of vulnerabilities that attackers are actively exploiting. BOD 22-01 enhances BOD 19-02; it does not supersede it.3Cybersecurity and Infrastructure Security Agency. BOD 22-01 Reducing the Significant Risk of Known Exploited Vulnerabilities

The triggers differ. BOD 19-02 applies whenever Cyber Hygiene scanning finds a critical or high vulnerability on an internet-facing system, whether or not anyone is exploiting it. BOD 22-01 applies when a vulnerability lands on the KEV catalog because evidence of active exploitation exists. Its default deadlines are two weeks for CVEs assigned after 2021 and six months for older ones, and CISA can shorten them further when the risk warrants.

When a single vulnerability falls under both directives, the earlier deadline governs. A critical flaw that also appears on the KEV catalog will often carry a BOD 22-01 due date near or inside the 15-day BOD 19-02 window, so treating the two as one prioritization workflow tends to work better than running them as parallel compliance exercises.