CISA retires ten Emergency Directives for FCEB agencies
Public Sector Action
Summary
Hide ▲
Show ▼
CISA retired ten Emergency Directives, ending a major set of federal cybersecurity remediation requirements for Federal Civilian Executive Branch (FCEB) agencies. The agency said the directives were either fully implemented or now covered by BOD 22-01 and the KEV catalog. CISA said the retirement is the highest number it has closed at one time, marking a notable federal cybersecurity milestone.
Related Happenings
CISA revises CIRCIA town hall schedule
Public Sector Action
First: 26.05.2026 15:00
Last: 26.05.2026 15:00
Sources 1
About this happening:
CISA **revised the schedule** for **virtual town halls** on the **CIRCIA rulemaking**, reopening stakeholder engagement on a cybersecurity reporting rule that will affect **critic...
CISA revises CIRCIA town hall schedule
Public Sector ActionAbout this happening: CISA **revised the schedule** for **virtual town halls** on the **CIRCIA rulemaking**, reopening stakeholder engagement on a cybersecurity reporting rule that will affect **critic...
CISA launches KEV Nomination Form
Public Sector Action
First: 21.05.2026 15:00
Last: 21.05.2026 15:00
Sources 1
About this happening:
CISA launched a **new Nomination Form** for the **KEV catalog**, giving **researchers, vendors, and industry partners** a direct way to report **known exploited vulnerabilities**....
CISA launches KEV Nomination Form
Public Sector ActionAbout this happening: CISA launched a **new Nomination Form** for the **KEV catalog**, giving **researchers, vendors, and industry partners** a direct way to report **known exploited vulnerabilities**....
CISA KEV order for Copy Fail on federal Linux devices
Public Sector Action
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
**CISA** added **Copy Fail** to the **Known Exploited Vulnerabilities (KEV) Catalog**, making the Linux flaw a federal remediation priority. The agency ordered **federal agencies*...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector ActionAbout this happening: **CISA** added **Copy Fail** to the **Known Exploited Vulnerabilities (KEV) Catalog**, making the Linux flaw a federal remediation priority. The agency ordered **federal agencies*...
CISA releases CI Fortify guidance for critical infrastructure resilience
Public Sector Action
First: 05.05.2026 15:00
Last: 05.05.2026 15:00
Sources 1
About this happening:
CISA released CI Fortify, guidance for critical infrastructure operators across sectors to help keep essential services running during cyberattack or crisis conditions. The framew...
CISA releases CI Fortify guidance for critical infrastructure resilience
Public Sector ActionAbout this happening: CISA released CI Fortify, guidance for critical infrastructure operators across sectors to help keep essential services running during cyberattack or crisis conditions. The framew...
Latest development: 06.05.2026 16:15
CISA launched CI Fortify on Tuesday as a planning framework for critical infrastructure operators in water, energy, transportation and communications to prepare for cyber disruption by disconnecting OT systems from third-party and business networks, maintaining essential services in degraded communications conditions, and recovering compromised systems through backups, component replacement, or a transition to manual operations.
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector Action
First: 03.05.2026 09:26
Last: 03.05.2026 09:26
Sources 1
About this happening:
CISA added **CVE-2026-31431** to its **KEV catalog**, putting **Federal Civilian Executive Branch (FCEB)** agencies on notice to remediate an actively exploited Linux privilege-es...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector ActionAbout this happening: CISA added **CVE-2026-31431** to its **KEV catalog**, putting **Federal Civilian Executive Branch (FCEB)** agencies on notice to remediate an actively exploited Linux privilege-es...
Timeline
-
08.01.2026 14:00 3 articles · 4mo ago
CISA retires ten FCEB Emergency Directives
Legal Policy Action UpdateCISA retired ten Emergency Directives affecting Federal Civilian Executive Branch (FCEB) agencies after determining the required actions had been implemented or were now covered by Binding Operational Directive (BOD) 22-01 and the Known Exploited Vulnerabilities (KEV) catalog. The closed directives included ED 19-01, ED 20-02, ED 20-03, ED 20-04, ED 21-01, ED 21-02, ED 21-03, ED 21-04, ED 22-03, and ED 24-02, spanning remediation guidance for Windows, SolarWinds Orion, Microsoft Exchange On-Premises, Pulse Connect Secure, VMware, and the Microsoft Corporate Email System.
Show sources
- CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity — www.cisa.gov — 08.01.2026 14:00
- CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024 — thehackernews.com — 09.01.2026 11:11
- CISA Closes Ten Emergency Directives After Federal Cyber Reviews — www.infosecurity-magazine.com — 12.01.2026 18:45