Skip to content
    Back to Regulatory Radar
    ImportantNew RegulationOctober 3, 2022

    CISA Issues Binding Operational Directive 23-01: Vulnerability Scanning Requirements

    CISA published Binding Operational Directive (BOD) 23-01, 'Improving Asset Visibility and Vulnerability Detection on Federal Networks,' requiring federal civilian executive branch (FCEB) agencies to perform automated asset discovery every 7 days and vulnerability enumeration on all discovered assets every 14 days. Agencies were required to initiate automated asset discovery by April 3, 2023, and begin reporting vulnerability enumeration results to CISA's Continuous Diagnostics and Mitigation (CDM) dashboard. While directly binding only on federal agencies, the directive set a de facto industry benchmark for vulnerability management programs.

    NIST CSFHITRUSTSOC 2DefenseSaaSHealthcare

    Key Analytics

    October 3, 2022
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    3
    Frameworks Affected

    Impact Analysis

    Defense contractors and federal suppliers faced downstream pressure to align their vulnerability management cadences with BOD 23-01 timelines. SOC 2 and HITRUST assessors began referencing BOD 23-01's 7/14-day scanning cadences as reasonable benchmarks. Organizations supporting federal contracts needed to demonstrate vulnerability scanning capabilities that met or exceeded these timelines. The directive also accelerated adoption of continuous vulnerability scanning over periodic scan-and-patch approaches.

    Recommended Actions

    • Implement automated asset discovery scanning on a 7-day cycle or more frequently
    • Configure vulnerability enumeration to run against all discovered assets every 14 days
    • Establish automated reporting of vulnerability enumeration results to your security operations team

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate60-130 hours
    Key Workstreams
    • Tighten discovery and enumeration cadence to the 7 and 14-day benchmark
    • Close scanning coverage gaps on unmanaged and cloud assets
    • Automate reporting of enumeration results to security operations

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 60-130 hours
    Start cold under pressureSignificant · 150-320 hours

    Roughly 90 to 190 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events