10 emergency directives were withdrawn as CISA declares them redundant


  • CISA withdrew ten emergency directives citing successful implementation or redundancy under BOD 22-01
  • BOD 22-01 mandates agencies to remediate known exploited vulnerabilities (KEVs) within strict deadlines
  • This marks the largest simultaneous ED retirement, reinforcing CISA’s Secure by Design principles

The US Cybersecurity and Infrastructure Security Agency (CISA) withdrew ten emergency directives (ED) it issued between 2019 and 2024, saying they achieved their purpose and are no longer needed.

In a brief notice published on its website, CISA said the EDs have either been successfully implemented or are now covered by Binding Operational Directive (BOD) 22-01, making them redundant.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top