← Back

Wire · regulatory

The 72-Hour Rule: CISA Just Turned Patch Management Into a Ticking Clock

Published

22 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

United States

Source

Read at securityboulevard.com

Verified

Fusion42 · 22 July 2026 · Fusion42 review

CISA's Binding Operational Directive 26-04 mandates remediation of high-risk, publicly exposed vulnerabilities within 72 hours, replacing older 15-30 day timelines and establishing a litigation-grade benchmark for "reasonable" cybersecurity response based on exploitability, automation potential, and technical impact.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

You now have 72 hours to patch internet-facing vulnerabilities CISA flags as exploitable and automatable, or a regulator, court, or insurer will use that deadline as evidence of negligence. This is not a federal-only rule—it's the new standard of "reasonable" for every company handling customer data or critical infrastructure.

Coverage

1 source · 22 Jul 2026

Related on Wire

Topics

Cybersecuritycisa-bod-26-04patch-managementvulnerability-remediationcybersecurity-complianceai-exploitationlitigation-risk