CISA's Binding Operational Directive 19-02 requires federal civilian agencies to fix critical vulnerabilities on their internet-accessible systems within 15 calendar days of initial detection, and high vulnerabilities within 30 days. If an agency can't meet a deadline, it has to submit a remediation plan. Your company isn't bound by the directive, but its core ideas are worth copying: put internet-facing systems on a shorter clock, start that clock at first detection, scan your own perimeter from the outside, require a written plan whenever a deadline slips, and make overdue findings visible to leadership.

This post explains what the directive requires and how to adapt each idea to a smaller organization.

What is CISA's BOD 19-02?

A binding operational directive is a compulsory instruction from the Department of Homeland Security to federal executive branch agencies. The Cybersecurity and Infrastructure Security Agency (CISA), part of DHS, issued BOD 19-02, "Vulnerability Remediation Requirements for Internet-Accessible Systems," on April 29, 2019.

It replaced BOD 15-01, issued in May 2015, which gave agencies 30 days to fix critical vulnerabilities on internet-facing systems. BOD 19-02 halved that window, added a deadline for high-severity findings and changed when the clock starts.

The findings come from CISA's Cyber Hygiene vulnerability scanning. CISA scans each agency's internet-accessible addresses from the outside, sends weekly reports, and automatically rescans previously detected vulnerabilities to confirm whether they've been fixed.

What the directive requires agencies to do

  • Keep the scanner's access open. Agencies must not block Cyber Hygiene scans, and must tell CISA within five working days of any change to their internet-accessible IP addresses.
  • Fix critical vulnerabilities within 15 calendar days of initial detection.
  • Fix high vulnerabilities within 30 calendar days of initial detection.
  • Return a remediation plan when a deadline is missed. CISA sends a partially completed plan listing the overdue findings, and the agency has three working days to return it with the constraints preventing remediation, interim mitigations, and an estimated completion date.

How CISA follows up

The directive doesn't rely on reports alone. CISA engages agency security and IT leadership when deadlines are missed, and sends the Office of Management and Budget regular reports on trends and persistent problems across agencies. Missed deadlines become visible to people who control budgets.

BOD 15-01 vs. BOD 19-02 at a glance

BOD 15-01 (2015) BOD 19-02 (2019)
Severities covered Critical Critical and high
Critical deadline 30 days 15 calendar days
High deadline None 30 calendar days
Clock starts When the weekly Cyber Hygiene report is issued At initial detection
If missed Justification with planned steps and a timeframe Remediation plan returned within 3 working days

Why did CISA shorten the deadlines?

The directive's stated reason is that the time between the discovery of a vulnerability and its exploitation keeps shrinking. Internet-accessible systems are the first place that matters, because anyone can reach them and automated scanning for known weaknesses is cheap.

That logic applies just as much to a 300-person company as to a federal agency. Your web servers, remote access gateways and email services face the same internet. With the move to remote work this year, many organizations have also put more services online, so the list of systems that fit this category has probably grown.

Lesson 1: Set shorter remediation deadlines for internet-facing systems

Many companies run a single remediation target for everything, such as "patch within 30 days." That treats an unpatched file server deep inside the network the same as the login page of your customer portal.

BOD 19-02 scopes its tightest deadlines to exposure. You can do the same by combining severity with whether a system is reachable from the internet. Here's one way to lay it out as a starting point:

Severity Internet-facing Internal only
Critical 15 days 30 days
High 30 days 60 days
Medium 90 days 90 days or next maintenance cycle
Low Next maintenance cycle Next maintenance cycle

The numbers aren't a standard. Pick targets your teams can actually meet, get them approved by leadership, and then measure against them. A deadline that's missed every month teaches everyone to ignore it.

Severity scores alone won't tell you everything. A high-severity finding on a system that holds customer data may deserve the critical clock. Write down the conditions that move a finding up a tier, so the decision isn't made case by case under pressure.

Lesson 2: Measure remediation time from first detection

This is the quietest change in BOD 19-02 and one of the most useful. Under BOD 15-01, the 30 days ran from when the weekly report was issued. BOD 19-02 measures from when CISA's scanning first detected the vulnerability.

In a lot of companies, the clock starts much later. It might start when someone reviews the scan report, when a ticket is created, or when the ticket reaches the right team. Each handoff adds days that nobody counts, so the reported time to fix looks better than the real exposure.

To measure from first detection:

  • Record a first-seen date for every finding, tied to the specific asset, and never overwrite it.
  • Don't reset the clock when a finding disappears for one scan because a host was offline, then reappears.
  • Report age from first detection, not from ticket creation. If both dates are available, the gap between them tells you how slow your handoffs are.

Most scanning tools keep a first-seen date already. The work is making sure your tickets and reports use it.

Lesson 3: Scan your external perimeter regularly

The directive works because CISA looks at agencies the way an outsider would. It scans from the internet, and it only sees what is actually exposed. That view often differs from what internal teams believe is exposed.

You can build the same view for your own organization:

  1. List your internet-facing assets. Include your public IP ranges, DNS records, hosted services and cloud workloads with public addresses.
  2. Keep the list current. The directive's five-working-day notification rule exists because unknown addresses don't get scanned. Make "update the external asset list" part of your change process.
  3. Scan externally on a regular cadence. Weekly is a reasonable target for most small and mid-sized organizations.
  4. Compare what you find with what you expected. A forgotten test server or an open management port is often more urgent than any single CVE.

CISA also offers Cyber Hygiene scanning at no cost to certain organizations outside the federal government, such as state and local governments and critical infrastructure organizations. If your organization might qualify, CISA can confirm eligibility. The Federal Trade Commission published a short overview of the service for businesses in December 2019.

Lesson 4: Require a remediation plan when you miss a deadline

Deadlines slip. A vendor hasn't released a fix, the only maintenance window is next month, or the change would break a system nobody has tested. BOD 19-02 doesn't pretend otherwise. It asks for a short, structured plan, and it asks for it quickly.

A remediation plan for your company needs the same three elements:

  • Constraints. Why the finding can't be fixed on time, stated specifically.
  • Interim mitigations. What you're doing to reduce the risk now, such as restricting access, disabling a vulnerable feature or adding monitoring.
  • Estimated completion date. A real date, with a named owner.

Keep the turnaround short. Three working days is a good benchmark. It stops a missed deadline from drifting for weeks before anyone writes anything down.

Treat the plan as a temporary record with an end date, not as a permanent exception. When the estimated completion date passes, the finding comes back up for review.

Lesson 5: Report overdue vulnerabilities to leadership

CISA escalates to agency leadership and reports trends to OMB. The equivalent in a private company is a regular report of overdue findings to whoever owns IT budget and risk decisions.

A monthly summary is usually enough. Show the number of critical and high findings past their deadline, how long they've been open and which have an approved remediation plan. When the same systems or teams appear month after month, that's a resourcing problem, and leadership is the right audience for it.

What not to copy from the federal model

BOD 19-02 is narrow on purpose. It covers internet-accessible systems as seen from CISA's scanners, and it doesn't address internal networks, workstations or applications behind a login. Your program still needs internal and authenticated scanning to cover those.

It also relies on severity ratings as scored by the scanning process. For your own program, add context the scanner doesn't have, such as what the system does and what data it holds.

Frequently asked questions

Does BOD 19-02 apply to private companies?

No. It applies to federal civilian executive branch agencies. If you operate systems on behalf of a federal agency, check your contract and the agency's own requirements, but the directive itself doesn't bind private organizations.

What counts as "remediated" under the directive?

A finding is closed when CISA's follow-up scanning no longer detects it. Rescanning is automatic, so fixes are verified by the same external scans that found the problem. That could mean a patch, a configuration change or taking the service off the internet.

Is a 15-day deadline realistic for a small IT team?

For internet-facing critical findings, usually yes, because the number of such systems is small. It gets harder when the deadline covers every server. Scope the shortest clock to your most exposed systems, and make sure you have a tested way to apply emergency fixes outside the normal monthly cycle.

Should we use calendar days or business days?

The directive uses calendar days, and that's the simpler choice. Attackers don't pause for weekends, and calendar days avoid arguments about holidays when you calculate whether a deadline was met.

Key takeaways

  • BOD 19-02 gives federal agencies 15 calendar days for critical and 30 for high vulnerabilities on internet-accessible systems, counted from initial detection.
  • Give your own internet-facing systems a shorter remediation clock than internal ones.
  • Store a first-seen date for every finding and measure age from it.
  • Scan your perimeter from the outside at least weekly, and keep your list of public addresses current.
  • When a deadline slips, require a written plan within a few days with constraints, interim mitigations and a completion date.
  • Report overdue findings to leadership every month so resourcing gaps get addressed.