DHS’s 15-day patch rule was a 2019 federal directive, not a current universal deadline. Under Binding Operational Directive 19-02 (BOD 19-02), covered federal civilian agencies had to remediate critical vulnerabilities on internet-accessible systems within 15 days of their initial detection; high-severity vulnerabilities had a 30-day window. CISA announced a newer risk-based directive, BOD 26-04, on June 10, 2026, so the 15-day rule is best understood as historical context.
What BOD 19-02 required
Issued by the Department of Homeland Security in April 2019, BOD 19-02 set remediation deadlines for vulnerabilities found by cyber-hygiene scanning on internet-accessible systems belonging to federal civilian executive-branch agencies.
| Finding severity | Deadline under BOD 19-02 | Clock trigger |
|---|---|---|
| Critical | 15 days | Initial detection |
| High | 30 days | Initial detection |
The clock began when a vulnerability was initially detected, not when an agency received the scan report. The directive and its timing are described in SecurityWeek’s May 1, 2019 account.
Which systems and agencies were covered?
BOD 19-02 applied to federal civilian executive-branch agencies and their internet-accessible systems. CISA’s directive index says federal agencies are required to comply with DHS-developed directives, while identifying exclusions for statutorily defined national-security systems and certain systems operated by the Department of Defense or the Intelligence Community. See CISA’s Cybersecurity Directives index.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
It was not a general law imposing the same deadline on private companies, state governments, or every computer system. Its scope was federal and specifically concerned systems reachable from the internet.
What happened if an agency could not meet a deadline?
An agency that could not remediate a vulnerability on time had three working days to submit a remediation plan. The plan had to explain the constraints, describe mitigations, and provide an estimated completion date. This was a reporting and planning requirement; it did not convert the original remediation deadline into an automatic extension.
Rank #2
Why DHS shortened the critical deadline
BOD 19-02 replaced BOD 15-01, which had allowed 30 days for critical vulnerabilities and did not establish the same high-vulnerability deadline. DHS focused on internet-exposed flaws because attackers may exploit them before an agency’s ordinary patch cycle catches up. In its 2019 statement, DHS said the directive would advance remediation requirements and reduce the attack surface and risk to federal information systems; the statement is reproduced in SecurityWeek’s report.
What the reported results show
DHS and a congressional hearing record reported improvements after the directives, but the figures measure different things over different periods and should not be treated as one continuous data series.
Rank #3
| Reported result | What it measures | Source and period |
|---|---|---|
| 11 days | Median time for federal agencies to patch critical vulnerabilities | DHS, FY 2019; CISA Congressional Budget Justification |
| More than 57% decrease | Open critical and high vulnerabilities after BOD 19-02 | DHS, FY 2019–2021 Annual Performance Report; DHS report |
| 149 days to 20 days | Average federal-agency patch time for critical vulnerabilities | Figures cited in a 2020 congressional hearing record; U.S. Government Publishing Office record |
The median in the FY 2019 figure is not directly comparable to the average reported in the hearing record. The reduction in open vulnerabilities is a separate measure from time to patch.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is the 15-day rule still current?
Not as the latest CISA directive. On June 10, 2026, CISA announced BOD 26-04, titled “Prioritizing Security Updates Based on Risk,” and said it harmonizes and improves BOD 19-02 and BOD 22-01. The announcement is available from CISA’s BOD 26-04 bulletin. Therefore, BOD 19-02’s 15-day deadline should not be presented as the current rule without consulting BOD 26-04’s operative requirements.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

