Skip to main content
Category: Regulatory & Legal Obligations

CISA Binding Operational Directive

Also known as: BOD, Binding Operational Directive, CISA BOD
Simply put

A CISA Binding Operational Directive is a compulsory instruction issued to federal executive branch departments and agencies to help safeguard their information systems. These directives require agencies to take specific security actions, such as addressing known vulnerabilities or securing cloud environments. They are mandatory for the federal civilian agencies they cover rather than optional guidance.

Formal definition

A Binding Operational Directive is a compulsory direction issued by CISA to federal, executive branch departments and agencies for purposes of safeguarding federal information and information systems. Individual directives establish specific required actions and timelines; examples in the evidence include BOD 22-01, which established a CISA-managed catalog of known exploited vulnerabilities carrying significant risk to the federal enterprise, BOD 25-01, which requires federal civilian agencies to identify specific cloud tenants, implement assessment tools, and align cloud environments to secure practices, and BOD 26-04 concerning prioritizing security updates based on risk. Some directives are developed in coordination with OMB and implement OMB policy. Note that these directives apply to covered federal agencies and are distinct from advisory guidance; their applicability, scope, and compliance obligations are defined by CISA and, where relevant, OMB.

Why it matters

CISA Binding Operational Directives are legally compulsory for the federal civilian executive branch agencies they cover, which makes them a clear signal of what the U.S. government considers urgent and material cybersecurity risk. While they do not directly bind private-sector organizations, they often set a de facto standard that regulators, customers, and insurers look to when judging what reasonable security practice looks like. Directives such as BOD 22-01, which established a CISA-managed catalog of known exploited vulnerabilities carrying significant risk to the federal enterprise, have become widely referenced beyond their mandatory audience as a prioritization tool for vulnerability management.

Who it's relevant to

Federal civilian agency security leaders
For the federal executive branch departments and agencies these directives cover, compliance is mandatory rather than optional. Security leaders in these organizations must track directive-specific required actions and timelines, such as those in BOD 25-01 for cloud environments, and coordinate the internal work to meet them. Note that even where a virtual or fractional CISO advises such an organization, legal and organizational accountability for meeting directive obligations typically remains with the agency and its officers.
Virtual and fractional CISOs advising regulated or federal-adjacent clients
A vCISO or fractional CISO whose clients contract with, sell to, or support federal agencies may need to understand relevant directives even though private organizations are not directly bound by them. In these engagements the security leader generally advises on how directive-driven expectations, such as the known exploited vulnerabilities catalog established under BOD 22-01, can inform a client's own risk prioritization. The value of this work depends on defined scope, organizational maturity, and access to the stakeholders responsible for acting on the guidance.
Governance, risk, and compliance stakeholders
Executives and GRC teams may reference BODs as an authoritative view of urgent federal cybersecurity risk when shaping internal policy or benchmarking practices. It is important not to overstate their reach: directives apply to covered federal agencies and are distinct from advisory guidance, so treating them as universally binding or as a substitute for applicable regulations and frameworks would be a mistake an expert would correct.

Inside BOD

Compulsory Directive for Federal Civilian Agencies
A CISA Binding Operational Directive (BOD) is a compulsory instruction issued by the Cybersecurity and Infrastructure Security Agency that directs federal civilian executive branch agencies to take specified actions to safeguard information and information systems. Its binding nature applies to those in-scope agencies rather than to private-sector organizations.
Statutory Basis
BODs derive their authority from federal law governing information security responsibilities. This statutory foundation is what distinguishes a directive from voluntary guidance, though the specific scope and enforcement mechanisms depend on the governing legislation and how CISA is empowered to act.
Specified Required Actions
A directive typically enumerates concrete actions agencies must complete, such as remediating identified vulnerabilities, adopting particular security controls, or reporting on specified conditions. The particular requirements vary by directive and are defined within each individual BOD.
Timelines and Deadlines
Directives generally establish timeframes within which agencies must act and may include reporting obligations. Exact deadlines and reporting cadences are specified per directive and can vary.
Scope of Applicability
BODs generally apply to federal civilian executive branch agencies and typically exclude national security systems and systems operated by the Department of Defense and the Intelligence Community. Applicability boundaries should be confirmed against the text of each specific directive.

Common questions

Answers to the questions practitioners most commonly ask about BOD.

Does a CISA Binding Operational Directive apply to my private company?
Generally, no. CISA Binding Operational Directives are compulsory directions issued to federal executive branch agencies, not to private sector organizations. A common mistake is assuming these directives carry legal force over commercial entities. That said, many private organizations voluntarily treat the technical guidance within a directive, such as timelines for remediating known exploited vulnerabilities, as a useful benchmark. A virtual CISO may reference this material as a reference point when advising a client, but doing so is a governance choice rather than a compliance obligation.
If we follow a Binding Operational Directive, are we compliant with federal cybersecurity requirements?
Following the technical practices described in a directive does not by itself establish compliance with any particular federal requirement, nor does it constitute certification of any kind. A directive addresses specific operational actions rather than a comprehensive compliance program. Conflating adherence to a single directive with broad regulatory compliance is a distinction an experienced practitioner would insist on correcting. The value of aligning to directive guidance depends on how it fits into a client's overall risk and governance approach.
How can a virtual CISO help our organization use directive guidance without being a covered agency?
In many engagements, a virtual CISO reviews the practices described in a directive and advises on whether adopting similar measures fits the client's risk profile, maturity, and resources. The vCISO typically provides strategy and prioritization guidance rather than performing the hands-on remediation work, which usually falls to internal teams or contracted operational providers. The client organization retains accountability for deciding whether and how to act on any such recommendation.
Who is responsible for actually executing the technical actions a directive describes?
Execution of operational tasks such as patching, vulnerability remediation, or configuration changes generally falls outside the typical scope of a virtual CISO engagement unless explicitly contracted. A vCISO more commonly advises on prioritization, sets expectations, and helps establish accountability structures, while the client's operational staff or service providers carry out the work. Clarifying this scope boundary early helps avoid the misconception that the vCISO performs hands-on implementation.
How should we prioritize actions when adopting directive-style guidance voluntarily?
Prioritization in many engagements depends on the client's risk exposure, existing security maturity, available resources, and stakeholder cooperation. A virtual CISO can help map directive-derived practices against the organization's broader risk register and governance framework, so that voluntary adoption reflects business risk rather than a mechanical checklist. The effectiveness of this exercise depends heavily on access to relevant stakeholders and accurate visibility into the environment.
Does aligning to directive guidance guarantee we will prevent a breach?
No engagement or guidance can guarantee breach prevention. Directive practices are intended to reduce specific risks, such as exposure to known exploited vulnerabilities, but outcomes vary and no set of measures eliminates risk entirely. A virtual CISO advises and directs the effort, yet legal and organizational accountability for security decisions typically remains with the client organization and its officers. Realistic value depends on defined scope, organizational maturity, and sustained client cooperation.

Common misconceptions

A CISA Binding Operational Directive is legally binding on private companies and must be treated as a compliance mandate by all organizations.
BODs are compulsory for in-scope federal civilian executive branch agencies, not for private-sector organizations. Private companies may choose to reference directives as useful signals of prioritized threats, but doing so is voluntary and does not create a legal obligation for them.
A Binding Operational Directive is the same thing as a framework or standard like NIST CSF or ISO 27001.
A BOD is a directive requiring specific actions within defined timelines for covered agencies, whereas frameworks and standards are voluntary, structured sets of practices organizations adopt to guide programs. They serve different purposes and should not be treated as interchangeable.
Complying with a Binding Operational Directive guarantees an agency is secure or breach-proof.
A directive addresses specific prioritized actions and does not guarantee a comprehensive security posture or prevention of breaches. Meeting a directive's requirements is one input into an overall risk program, and residual risk and accountability for security decisions remain with the organization.

Best practices

Confirm applicability first by reviewing the specific directive's scope to determine whether your organization is a covered federal civilian agency or whether the directive is merely informational for your context.
Read the actual text of each directive rather than relying on summaries, since required actions, timelines, and reporting obligations are defined per directive and vary.
Map the directive's required actions to internal owners and existing controls, and track remediation against the stated deadlines to demonstrate progress and support any required reporting.
For private-sector or non-covered organizations, treat directives as optional threat-prioritization signals that can inform risk decisions rather than as compliance mandates, and document the rationale for any actions taken.
Preserve the distinction between advising on directive-related actions and holding accountability for them, keeping formal accountability for security decisions with the client organization and its officers unless a contract specifies otherwise.
Where a virtual or fractional security leader is engaged, define in the scope of work whether support covers directive tracking and readiness versus hands-on remediation execution, since operational tasks are typically out of scope unless explicitly contracted.