Wire · regulatory
The 72-Hour Rule: CISA Just Turned Patch Management Into a Ticking Clock
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 22 July 2026 · Fusion42 review
CISA's Binding Operational Directive 26-04 mandates remediation of high-risk, publicly exposed vulnerabilities within 72 hours, replacing older 15-30 day timelines and establishing a litigation-grade benchmark for "reasonable" cybersecurity response based on exploitability, automation potential, and technical impact.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
You now have 72 hours to patch internet-facing vulnerabilities CISA flags as exploitable and automatable, or a regulator, court, or insurer will use that deadline as evidence of negligence. This is not a federal-only rule—it's the new standard of "reasonable" for every company handling customer data or critical infrastructure.
◆ Coverage
1 source · 22 Jul 2026
◆ Related on Wire
◆ Topics