BOD 22-01

CISA BOD 22-01 for companies that are not federal

Updated 2026-08-28

Binding Operational Directive 22-01 orders federal agencies to remediate KEV entries by a due date. Private companies are not bound — but the catalog is still the right patch list. Here is how to use it without pretending you are an agency.

What the directive actually is

BOD 22-01 requires FCEB agencies to remediate vulnerabilities in CISA’s Known Exploited catalog within the due date on each entry. It created a public, living list so agencies would stop arguing about CVSS while ransomware groups reused the same bugs.

Private companies like to cite BOD 22-01 in security reviews because it sounds like a requirement. It is not, unless you are the agency or a contract says so. Citing it anyway is fine if you mean: “we treat KEV like they must.”

A sane private-sector policy in four lines

One: ingest KEV (JSON feed or a watchtower). Two: match to what you run and what you subscribe to — including identity and cloud parents. Three: KEV matches are P1 until you can say “vendor patched / we do not run it / compensating control.” Four: keep evidence. Auditors like dates more than vibes.

You do not need CISA’s federal due date as your SLA. You need a clock you own. Same-day awareness, next-business-day decision is enough for most SaaS-only shops. Appliance-heavy shops should be faster.

Where ZeroDayTracker fits

We are not a GRC tool and we do not attest BOD 22-01. We match KEV to a SaaS catalog and give you the required action text CISA already published. That is the awareness layer. Your IR plan is still yours.

Questions

Does BOD 22-01 apply to my startup?

No. It directs federal civilian executive branch agencies. Contractors may see it in flow-down language. Everyone else can still use the KEV catalog as a priority list.

All guides · SaaS KEV tracker

Watch the SaaS that holds your data.

Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.

Start watching — freePricing