CISA retires ten Emergency Directives for FCEB agencies
Public Sector Action
Summary
Hide ▲
Show ▼
CISA retired ten Emergency Directives, ending a major set of federal cybersecurity remediation requirements for Federal Civilian Executive Branch (FCEB) agencies. The agency said the directives were either fully implemented or now covered by BOD 22-01 and the KEV catalog. CISA said the retirement is the highest number it has closed at one time, marking a notable federal cybersecurity milestone.
Related Happenings
CISA BOD 26-04 SharePoint remediation deadline
Public Sector Action
H score77
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector ActionAbout this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
Pentagon suspends CMMC phase two for 60-day review
Public Sector Action
H score24
First: 14.07.2026 09:37
Last: 14.07.2026 09:37
Sources 1
About this happening:
The Pentagon suspended CMMC phase two and opened a 60-day review, delaying new certification requirements for defense contractors and subcontractors. The pause...
Pentagon suspends CMMC phase two for 60-day review
Public Sector ActionAbout this happening: The Pentagon suspended CMMC phase two and opened a 60-day review, delaying new certification requirements for defense contractors and subcontractors. The pause...
CISA KEV directive for Joomla extension flaws
Public Sector Action
H score36
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA KEV directive for Joomla extension flaws
Public Sector ActionAbout this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA BOD 26-04 three-day remediation directive
Public Sector Action
H score36
First: 24.06.2026 17:35
Last: 24.06.2026 17:35
Sources 1
About this happening:
CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
CISA BOD 26-04 three-day remediation directive
Public Sector ActionAbout this happening: CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
Timeline
-
08.01.2026 14:00 3 articles · 6mo ago
CISA retires ten FCEB Emergency Directives
Legal Policy Action UpdateCISA retired ten Emergency Directives affecting Federal Civilian Executive Branch (FCEB) agencies after determining the required actions had been implemented or were now covered by Binding Operational Directive (BOD) 22-01 and the Known Exploited Vulnerabilities (KEV) catalog. The closed directives included ED 19-01, ED 20-02, ED 20-03, ED 20-04, ED 21-01, ED 21-02, ED 21-03, ED 21-04, ED 22-03, and ED 24-02, spanning remediation guidance for Windows, SolarWinds Orion, Microsoft Exchange On-Premises, Pulse Connect Secure, VMware, and the Microsoft Corporate Email System.
Show sources
- CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity — www.cisa.gov — 08.01.2026 14:00
- CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024 — thehackernews.com — 09.01.2026 11:11
- CISA Closes Ten Emergency Directives After Federal Cyber Reviews — www.infosecurity-magazine.com — 12.01.2026 18:45