Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DHS’s 15-day patch rule was a 2019 federal directive, not a current universal deadline. Under Binding Operational Directive 19-02 (BOD 19-02), covered federal civilian agencies had to remediate critical vulnerabilities on internet-accessible systems within 15 days of their initial detection; high-severity vulnerabilities had a 30-day window. CISA announced a newer risk-based directive, BOD 26-04, on June 10, 2026, so the 15-day rule is best understood as historical context.

What BOD 19-02 required

Issued by the Department of Homeland Security in April 2019, BOD 19-02 set remediation deadlines for vulnerabilities found by cyber-hygiene scanning on internet-accessible systems belonging to federal civilian executive-branch agencies.

Finding severity Deadline under BOD 19-02 Clock trigger
Critical 15 days Initial detection
High 30 days Initial detection

The clock began when a vulnerability was initially detected, not when an agency received the scan report. The directive and its timing are described in SecurityWeek’s May 1, 2019 account.

Which systems and agencies were covered?

BOD 19-02 applied to federal civilian executive-branch agencies and their internet-accessible systems. CISA’s directive index says federal agencies are required to comply with DHS-developed directives, while identifying exclusions for statutorily defined national-security systems and certain systems operated by the Department of Defense or the Intelligence Community. See CISA’s Cybersecurity Directives index.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It was not a general law imposing the same deadline on private companies, state governments, or every computer system. Its scope was federal and specifically concerned systems reachable from the internet.

What happened if an agency could not meet a deadline?

An agency that could not remediate a vulnerability on time had three working days to submit a remediation plan. The plan had to explain the constraints, describe mitigations, and provide an estimated completion date. This was a reporting and planning requirement; it did not convert the original remediation deadline into an automatic extension.

Why DHS shortened the critical deadline

BOD 19-02 replaced BOD 15-01, which had allowed 30 days for critical vulnerabilities and did not establish the same high-vulnerability deadline. DHS focused on internet-exposed flaws because attackers may exploit them before an agency’s ordinary patch cycle catches up. In its 2019 statement, DHS said the directive would advance remediation requirements and reduce the attack surface and risk to federal information systems; the statement is reproduced in SecurityWeek’s report.

What the reported results show

DHS and a congressional hearing record reported improvements after the directives, but the figures measure different things over different periods and should not be treated as one continuous data series.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reported result What it measures Source and period
11 days Median time for federal agencies to patch critical vulnerabilities DHS, FY 2019; CISA Congressional Budget Justification
More than 57% decrease Open critical and high vulnerabilities after BOD 19-02 DHS, FY 2019–2021 Annual Performance Report; DHS report
149 days to 20 days Average federal-agency patch time for critical vulnerabilities Figures cited in a 2020 congressional hearing record; U.S. Government Publishing Office record

The median in the FY 2019 figure is not directly comparable to the average reported in the hearing record. The reduction in open vulnerabilities is a separate measure from time to patch.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is the 15-day rule still current?

Not as the latest CISA directive. On June 10, 2026, CISA announced BOD 26-04, titled “Prioritizing Security Updates Based on Risk,” and said it harmonizes and improves BOD 19-02 and BOD 22-01. The announcement is available from CISA’s BOD 26-04 bulletin. Therefore, BOD 19-02’s 15-day deadline should not be presented as the current rule without consulting BOD 26-04’s operative requirements.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.