CISA BOD 26-04
CISA BOD 26-04What Is CISA BOD 26-04?
CISA BOD 26-04 is a binding operational directive issued by the Cybersecurity and Infrastructure Security Agency. It sets mandatory requirements for how federal civilian executive branch agencies manage software security risks across their environments.
The directive builds on years of executive-level pressure to modernize federal cybersecurity posture. It is one of the most operationally specific directives CISA has issued, moving beyond general guidance toward concrete, measurable actions that agencies must take on defined timelines.
BOD 26-04 reflects a broader federal shift: treating software supply chain integrity as a national security matter, not simply an IT concern.
What BOD 26-04 Requires of Federal Civilian Agencies
CISA BOD 26-04 places direct obligations on federal civilian agencies in several areas. Agencies must:
- Identify and inventory all software running in their environments
- Validate that software providers have submitted self-attestation forms confirming secure development practices
- Track and remediate vulnerabilities appearing in the CISA Known Exploited Vulnerabilities catalog within required timeframes
- Maintain visibility into third-party software components, including open-source dependencies
How BOD 26-04 Connects to Known Exploited Vulnerabilities and SBOM Attestation
One of the most significant elements of CISA BOD 26-04 is its direct linkage to the CISA Known Exploited Vulnerabilities catalog. This catalog lists vulnerabilities that are actively being exploited in the wild. Agencies are required to remediate any KEV-listed vulnerabilities present in their software stack on an accelerated timeline.
This connection is deliberate. By anchoring remediation obligations to real-world exploitation data rather than theoretical risk scores, CISA pushes agencies to prioritize based on actual threat activity.
BOD 26-04 also formalizes the role of SBOM attestation in the federal procurement and operations cycle. Vendors must provide self-attestation confirming their software was built following secure development practices outlined in NIST SP 800-218 and the NIST Secure Software Development Framework.
- Attestation forms must be submitted to CISA through a designated secure portal
- Third-party assessments may be required for critical software categories
- Agencies are responsible for collecting and tracking attestation status across their vendor portfolio
BOD 26-04 Compliance for Containerized Federal Workloads
Containerized environments present specific challenges under CISA BOD 26-04. Containers often bundle dozens of open-source packages, each of which may carry its own vulnerability profile. Agencies running containerized workloads must ensure that the images deployed across their infrastructure meet the same software security compliance standards as any other software asset.
This means container images must be scanned for Known Exploited Vulnerabilities. It also means agencies need SBOM data covering the contents of those images, not just the application layer.
For federal teams managing Kubernetes clusters or container platforms, BOD 26-04 reinforces the need to adopt continuous scanning practices rather than point-in-time assessments. Static snapshots are not sufficient when exploitation timelines are measured in days. Container security as part of FedRAMP compliance strategy becomes inseparable from meeting BOD 26-04 obligations in practice. See how this connects to broader FedRAMP compliance container security requirements.
What BOD 26-04 Means for Software Vendors Selling to Federal Agencies
For any software vendor with federal civilian agency customers, CISA BOD 26-04 creates direct go-to-market implications. Agencies are now required to obtain attestation before deploying or continuing to use software products. Vendors who cannot provide compliant attestation documentation risk having their products deprioritized or removed.
Practically, this means vendors should:
- Complete the CISA self-attestation form and maintain updated submissions as software versions change
- Produce and deliver SBOM documentation in a machine-readable format upon request
- Establish internal processes to monitor KEV listings and patch affected components rapidly
- Align development practices with NIST SP 800-218 to support accurate attestation claims
FAQs
Which agencies must comply with CISA BOD 26-04?
CISA BOD 26-04 applies to all federal civilian executive branch agencies. This includes cabinet departments, independent agencies, and other entities within the executive branch. It does not directly apply to the Department of Defense or intelligence community agencies, though those bodies often adopt parallel requirements through their own regulatory frameworks.
How long does BOD 26-04 give agencies to remediate critical vulnerabilities?
BOD 26-04 ties remediation timelines to the CISA Known Exploited Vulnerabilities catalog. Agencies typically have 14 days to remediate KEV-listed vulnerabilities classified as critical and 30 days for high-severity findings. Exact timelines may vary based on directive updates, so agencies should monitor CISA guidance continuously.
Does BOD 26-04 apply to commercial software used by federal agencies?
Yes. BOD 26-04 applies to commercial off-the-shelf software, open-source tools, and custom-developed applications used within federal civilian environments. Vendors providing any of these software categories to covered agencies must submit self-attestation forms and comply with the secure development practice requirements outlined in the directive.
How does BOD 26-04 differ from previous CISA binding operational directives?
Earlier binding operational directives often focused on network-level controls, patch timelines, or specific technology configurations. BOD 26-04 is more expansive, targeting the entire software supply chain. It introduces vendor attestation obligations, SBOM requirements, and a direct integration with the Known Exploited Vulnerabilities catalog as a living compliance benchmark.
Can non-US vendors be affected by CISA BOD 26-04 requirements?
Yes. Any vendor whose software is deployed by a federal civilian agency must meet BOD 26-04 requirements regardless of where the vendor is headquartered. Non-US companies selling into the federal market must submit attestation documentation and maintain compliant development practices, making this a global software security compliance concern.






