CISA Binding Operational Directive
A CISA Binding Operational Directive is a compulsory instruction issued to federal executive branch departments and agencies to help safeguard their information systems. These directives require agencies to take specific security actions, such as addressing known vulnerabilities or securing cloud environments. They are mandatory for the federal civilian agencies they cover rather than optional guidance.
A Binding Operational Directive is a compulsory direction issued by CISA to federal, executive branch departments and agencies for purposes of safeguarding federal information and information systems. Individual directives establish specific required actions and timelines; examples in the evidence include BOD 22-01, which established a CISA-managed catalog of known exploited vulnerabilities carrying significant risk to the federal enterprise, BOD 25-01, which requires federal civilian agencies to identify specific cloud tenants, implement assessment tools, and align cloud environments to secure practices, and BOD 26-04 concerning prioritizing security updates based on risk. Some directives are developed in coordination with OMB and implement OMB policy. Note that these directives apply to covered federal agencies and are distinct from advisory guidance; their applicability, scope, and compliance obligations are defined by CISA and, where relevant, OMB.
Why it matters
CISA Binding Operational Directives are legally compulsory for the federal civilian executive branch agencies they cover, which makes them a clear signal of what the U.S. government considers urgent and material cybersecurity risk. While they do not directly bind private-sector organizations, they often set a de facto standard that regulators, customers, and insurers look to when judging what reasonable security practice looks like. Directives such as BOD 22-01, which established a CISA-managed catalog of known exploited vulnerabilities carrying significant risk to the federal enterprise, have become widely referenced beyond their mandatory audience as a prioritization tool for vulnerability management.
Who it's relevant to
Inside BOD
Common questions
Answers to the questions practitioners most commonly ask about BOD.