BOD 22-01 and the Federal Remediation Mandate

The CISA Binding Operational Directive that requires federal civilian agencies to remediate KEV-listed vulnerabilities by an assigned due date.

Why It Matters

BOD 22-01 is what gives KEV listing teeth for federal agencies specifically — it converts "this is being actively exploited" into a binding, dated remediation requirement rather than a advisory recommendation.

Application to Application Security

Relevant to any team building or maintaining software used by U.S. federal civilian agencies — a KEV-listed CVE in your software's dependency chain can create a compliance deadline for your federal customers, not just a security concern.

Relation to Software Development

For a vendor or contractor, this means dependency CVE monitoring against the KEV catalog specifically (not just CVSS-based scanning generally) is a practical requirement, not just good practice.

How Strata Surfaces This

This page explains the mandate conceptually; it is not a compliance-tracking tool, and CISA's own catalog and directive text are the authoritative source for current due dates on any specific entry.

Developer guidance

If your software is used by federal civilian agencies, monitor your dependency chain against the KEV catalog specifically, not just general CVE feeds, since that's the list your federal customers are bound to.

Management guidance

A federal customer asking about KEV remediation timelines is asking about a binding compliance obligation on their side — treat it with the urgency of a contractual deadline, not a routine security question.

Related Standards
BOD 22-01
CISAKnown Exploited Vulnerabilities CatalogSource ↗