Binding Operational Directives: what federal agencies must do (and what everyone else should copy)
Binding Operational Directives are CISA's compulsory orders to federal civilian agencies. They don't legally bind contractors or private operators — but smart ones treat them as the federal baseline anyway, because agency customers and auditors do.
The directives that matter most
- BOD 22-01 — remediate Known Exploited Vulnerabilities (the KEV catalog) within CISA's deadlines. This is the big one: it turned the KEV catalog into a de facto national patching standard.
- BOD 23-01 — maintain asset inventories and run vulnerability disclosure programs. “Know what you have” as a federal mandate.
- Email and web security directives — DMARC, HTTPS, and related hygiene for federal domains.
Why contractors copy them
Two forces: agency contracts increasingly flow down KEV-remediation expectations, and assessors for programs like CMMC and FedRAMP look for the same hygiene. If you're patching KEVs on BOD timelines, you're ahead of most commercial peers — and it's cheap compared to most security spending.
Where consultants fit
Agencies use contractors to stand up the underlying programs: continuous vulnerability management, asset discovery tooling, and reporting pipelines. See our directory filtered to federal-stage firms.
Get quotes from verified firms
One brief, matched firms, competing quotes — free.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.