RVA CYBER Security briefing

Vulnerability management

CISA’s New Vulnerability Clock

The three-day deadline is real. “Critical equals three days” is not.

RVA Cyber 5-minute read

The change: CISA now uses exposure, evidence of exploitation, exploit automation, and technical impact to set federal remediation deadlines. The resulting clocks are 3, 14, or 60 calendar days—or the next major system upgrade.

Stop treating severity as the deadline

CISA’s new three-day tier does not apply to every vulnerability labeled Critical. It applies to the most dangerous combinations of real-world exploitation, public exposure, automated attack potential, and system impact.

Likewise, CISA no longer provides a simple “High gets this many days, Medium gets that many” schedule in its current federal directive. A Medium-rated vulnerability that attackers are exploiting may outrank a theoretical Critical vulnerability that is isolated and difficult to weaponize.

On June 10, 2026, the Cybersecurity and Infrastructure Security Agency issued Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk. The directive replaces the earlier federal model that emphasized broad CVSS severity and fixed Known Exploited Vulnerabilities deadlines.

The philosophy is simple: patch the vulnerabilities most likely to become damaging incidents first. CISA describes the approach as “patch smarter, not harder.”

The new clocks are 3, 14, and 60 days

BOD 26-04 produces four operational outcomes. All stated deadlines are calendar days.

3

days

Highest-risk combinations. Some also require forensic triage to determine whether the affected system was already compromised.

14

days

Elevated-risk vulnerabilities, including many Known Exploited Vulnerabilities and dangerous publicly exposed flaws.

60

days

Lower-risk findings that still have meaningful exposure or automation characteristics.

Upgrade

scheduled cycle

The lowest-risk combinations may wait until the asset’s next scheduled major upgrade or rebuild.

The deadline starts when CISA adds the vulnerability to the Known Exploited Vulnerabilities catalog or the agency identifies it on an asset, as applicable. The calculation can change when the facts change—for example, when a system becomes publicly exposed or CISA adds the vulnerability to the catalog.

Four questions replace the Critical/High shorthand

The new model asks four binary questions about each vulnerability instance:

  1. 1

    Is the asset publicly exposed?

    An internet-reachable vulnerable service gives an attacker a direct path and shortens the defensive window.

  2. 2

    Is the vulnerability in CISA’s KEV catalog?

    A Known Exploited Vulnerability has evidence of exploitation in the wild. That is stronger evidence of urgency than a theoretical severity score alone.

  3. 3

    Can an adversary automate exploitation?

    Automation lets attackers scan and compromise vulnerable systems at scale, accelerating exposure from days to hours.

  4. 4

    Is the technical impact total or partial?

    Total control carries more urgency than a limited effect. CISA publishes decision data through its Vulnrichment project.

The full 16-row decision matrix is also available in the CERT/CC implementation of CISA’s response model.

Three days is the top tier—not a synonym for Critical

A vulnerability can reach the three-day tier through several paths. Examples include:

A practical private-sector policy

BOD 26-04 is binding on Federal Civilian Executive Branch agencies. It is not a universal legal deadline for every private company. Still, it provides a useful operating benchmark because the risk factors apply everywhere.

Organizations that need simple service-level labels can translate the CISA outcomes into internal language:

Urgent3 calendar days
High14 calendar days
Medium60 calendar days
LowNext major upgrade or rebuild

Important: This translation is an internal policy suggestion, not CISA’s official Critical/High/Medium/Low mapping. The four-factor decision should always override the label when it produces a faster deadline.

A defensible program should also document compensating controls and exceptions. Removing public exposure, isolating a service, or disabling vulnerable functionality can reduce immediate risk, but the organization should still record ownership, the final remediation action, and the evidence used to close the finding.

The operational takeaway

The headline is not “all Critical vulnerabilities now have three days.” The better headline is that CISA has moved from severity-driven queues to evidence-driven response.

That means vulnerability teams need more than scanner scores. They need accurate asset inventories, internet-exposure data, KEV monitoring, exploitability intelligence, clear ownership, and the ability to launch forensic triage quickly. Without that context, a three-day policy becomes an arbitrary race. With it, the deadline focuses attention on the small set of vulnerabilities most likely to become incidents.

Sources