Cybersecurity Directives
Overview
The Cybersecurity and Infrastructure Security Agency (CISA) develops and oversees the implementation of “Binding Operational Directives (BODs)” and “Emergency Directives (EDs),” which require action on the part of certain federal agencies in the civilian Executive Branch.
Recent Emergency Directives
View All Emergency DirectivesV1: ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices
This V1 supersedes the required actions in Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices and applies to any agency running affected products. V1 expands on the original ED 25-03 requirements with required actions three, four, and six.
Supplemental Direction ED 25-03: Core Dump and Hunt Instructions
CISA issued Emergency Directive (ED) 25-03 in response to an ongoing exploitation campaign by a sophisticated threat actor which targets Cisco Adaptive Security Appliances (ASA) via web services. This guidance helps entities check the status of their Cisco devices.
V1: ED 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems
This V1 supersedes the required actions in Emergency Directive (ED) 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems and applies to any federal agency running affected products. This V1 includes updated and new required actions and an additional reporting requirement.
Recent Binding Operational Directives
View All Binding Operational DirectivesBOD 26-04: Prioritizing Security Updates Based on Risk
This Directive supersedes and hereby revokes BOD 19-02 and BOD 22-01.
BOD 26-04: Prioritizing Security Updates Based on Risk, consolidates and clarifies vulnerability remediation guidelines for federal agencies addressing cybersecurity vulnerabilities.
BOD 26-04: Implementation Guidance for Prioritizing Security Updates Based on Risk
This implementation guidance establishes forensic triage steps for agencies to execute prompt vulnerability response actions aligning with BOD 26-04 requirements.
BOD 26-02: Mitigating Risk From End-of-Support Edge Devices
This Binding Operational Directive, developed in coordination with OMB, implements OMB policy on phasing out unsupported information systems and information system components.
Federal Civilian Executive Branch Agencies List

Federal agencies are required to comply with DHS-developed directives.
These directives do not apply to statutorily defined “national security systems” nor to certain systems operated by the Department of Defense or the Intelligence Community.
CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity
This is just another example of CISA advancing federal cyber resilience and building a stronger, safer digital infrastructure for America's future.
