Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Staying Secure at Eventsno-cost Cyber ServicesCybersecurity Awareness MonthKEV CatalogReport A Cyber Issue 

Cybersecurity & Infrastructure Security Agency logo America’s Cyber Security Defense Agency National Coordinator For Critical Infrastructure Security and ResilienceCybersecurity & Infrastructure Security Agency logo America’s Cyber Security Defense Agency National Coordinator For Critical Infrastructure Security and Resilience
CISA Logo

Search

 

America's Cyber Defense Agency
 
  • Topics
    Cybersecurity Best Practices
    Cyber Threats and Response
    Critical Infrastructure Security and Resilience
    Election Security
    Emergency Communications
    Industrial Control Systems
    Information and Communications Technology Supply Chain Security
    Partnerships and Collaboration
    Physical Security
    Risk Management
    How can we help?
    GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutivesHigh-Risk Communities
  • Spotlight
  • Resources & Tools
    All Resources & Tools
    Services
    Programs
    Resources
    Training
    Groups
  • News & Events
    Directives
    News
    Events
    Cybersecurity Alerts & Advisories
    Request a CISA Speaker
    Congressional Testimony
    CISA Conferences
    CISA Live!
  • Careers
    Benefits & Perks
    Hiring and Recruitment
    New Employee Orientation & Onboarding
    Students & Recent Graduates
    Veteran and Military Spouses
  • About
    Divisions & Offices
    Regions
    Leadership
    Doing Business with CISA
    Site Links
    CISA GitHub
    CISA Central
    Contact Us
    Subscribe
    Transparency and Accountability
    Policies & Plans

Staying Secure at Eventsno-cost Cyber ServicesCybersecurity Awareness MonthKEV CatalogReport A Cyber Issue 

Breadcrumb
  1. Home
  2. News & Events
  3. Cybersecurity Directives
Share:
Opens in a new window Opens in a new window Opens in a new window
A blue background with cyber code

Cybersecurity Directives

News & Events

  • Directives
  • News
  • Events
  • Cybersecurity Alerts & Advisories
  • Request a CISA Speaker
  • Congressional Testimony
  • CISA Conferences
  • CISA Live!

Overview

The Cybersecurity and Infrastructure Security Agency (CISA) develops and oversees the implementation of “Binding Operational Directives (BODs)” and “Emergency Directives (EDs),” which require action on the part of certain federal agencies in the civilian Executive Branch.

Recent Emergency Directives

View All Emergency Directives

V1: ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices

This V1 supersedes the required actions in Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices and applies to any agency running affected products. V1 expands on the original ED 25-03 requirements with required actions three, four, and six.

Supplemental Direction ED 25-03: Core Dump and Hunt Instructions

CISA issued Emergency Directive (ED) 25-03 in response to an ongoing exploitation campaign by a sophisticated threat actor which targets Cisco Adaptive Security Appliances (ASA) via web services. This guidance helps entities check the status of their Cisco devices.

V1: ED 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems

This V1 supersedes the required actions in Emergency Directive (ED) 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems and applies to any federal agency running affected products. This V1 includes updated and new required actions and an additional reporting requirement.
View All Emergency Directives

Recent Binding Operational Directives

View All Binding Operational Directives

BOD 26-04: Prioritizing Security Updates Based on Risk

This Directive supersedes and hereby revokes BOD 19-02 and BOD 22-01. BOD 26-04: Prioritizing Security Updates Based on Risk, consolidates and clarifies vulnerability remediation guidelines for federal agencies addressing cybersecurity vulnerabilities.

BOD 26-04: Implementation Guidance for Prioritizing Security Updates Based on Risk

This implementation guidance establishes forensic triage steps for agencies to execute prompt vulnerability response actions aligning with BOD 26-04 requirements.

BOD 26-02: Mitigating Risk From End-of-Support Edge Devices

This Binding Operational Directive, developed in coordination with OMB, implements OMB policy on phasing out unsupported information systems and information system components.
View All Binding Operational Directives

Federal Civilian Executive Branch Agencies List

FCEB Agencies Illustration

Federal agencies are required to comply with DHS-developed directives.

These directives do not apply to statutorily defined “national security systems” nor to certain systems operated by the Department of Defense or the Intelligence Community.

View all agencies

Emergency Directives. Closures.

CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity

This is just another example of CISA advancing federal cyber resilience and building a stronger, safer digital infrastructure for America's future.

read press release
Return to top
  • Topics
  • Spotlight
  • Resources & Tools
  • News & Events
  • Careers
  • About
Cybersecurity & Infrastructure Security Agency
  • Facebook
  • X
  • LinkedIn
  • YouTube
  • Instagram
  • RSS
CISA Central 1-844-Say-CISA contact@cisa.dhs.gov
DHS Seal
CISA.gov
An official website of the U.S. Department of Homeland Security
  • About CISA
  • Budget and Performance
  • DHS.gov
  • FOIA Requests
  • No FEAR Act
  • Office of Inspector General
  • Privacy Policy
  • Subscribe
  • The White House
  • USA.gov
  • Website Feedback