BOD 22-01
CISA BOD 22-01 for companies that are not federal
Updated 2026-08-28
Binding Operational Directive 22-01 orders federal agencies to remediate KEV entries by a due date. Private companies are not bound — but the catalog is still the right patch list. Here is how to use it without pretending you are an agency.
What the directive actually is
BOD 22-01 requires FCEB agencies to remediate vulnerabilities in CISA’s Known Exploited catalog within the due date on each entry. It created a public, living list so agencies would stop arguing about CVSS while ransomware groups reused the same bugs.
Private companies like to cite BOD 22-01 in security reviews because it sounds like a requirement. It is not, unless you are the agency or a contract says so. Citing it anyway is fine if you mean: “we treat KEV like they must.”
A sane private-sector policy in four lines
One: ingest KEV (JSON feed or a watchtower). Two: match to what you run and what you subscribe to — including identity and cloud parents. Three: KEV matches are P1 until you can say “vendor patched / we do not run it / compensating control.” Four: keep evidence. Auditors like dates more than vibes.
You do not need CISA’s federal due date as your SLA. You need a clock you own. Same-day awareness, next-business-day decision is enough for most SaaS-only shops. Appliance-heavy shops should be faster.
Where ZeroDayTracker fits
We are not a GRC tool and we do not attest BOD 22-01. We match KEV to a SaaS catalog and give you the required action text CISA already published. That is the awareness layer. Your IR plan is still yours.
Questions
Does BOD 22-01 apply to my startup?
No. It directs federal civilian executive branch agencies. Contractors may see it in flow-down language. Everyone else can still use the KEV catalog as a priority list.
Watch the SaaS that holds your data.
Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.