KNOWLEDGE CENTER
What is CISA BOD 26-02?
Public sector agencies are facing a growing challenge at the edge: devices running software thatΒ isΒ no longer supported, no longer patched, and increasingly targeted by attackers. These assets often underpin mission-critical operations, yetΒ theyβre among the hardest to inventory, assess, and modernize.
TheΒ guidanceΒ in CISA BOD 26-02Β on end-of-support (EoS) and end-of-life (EoL) software, particularly for internet-exposed and operational edge devices, reflects this reality. The guidance reinforces what many agencies already know: unsupported edge software is both a technical issue and aΒ missionΒ readiness risk.Β
CISAβs BOD 26-02 Five Step TimelineΒ
CISAβs BOD 26-02 sets a compliance clock providing agencies with a timeline to complete a series of concrete stepsΒ by certain dates:Β
- Feb 5, 2026: Apply safe vendor-supported updates.
- May 5, 2026: Inventory and reportΒ on edge devices that appear on CISAβs EOS list.
- Feb 5, 2027: DecommissionΒ devices that have reached EOS.
- Aug. 5, 2027: Replace remaining EOSΒ edgeΒ devicesΒ with vendor-supported equipment.
- Feb.Β 5,Β 2028:Β Operationalize continuous discovery and EOS trackingΒ ofΒ edge devices.Β
The Risk of Unsupported Edge Software Is a Decision ProblemΒ
Edge devices like firewalls, VPN appliances, load balancers, and other network-connected infrastructure often sit outside traditional endpoint and server management workflows. When these devices reach the end of support, they stop receiving security updates, even as new vulnerabilities continue toΒ emerge.Β
CISA has consistently emphasized the risks associated with unsupported software. Once a product is no longer supported by the vendor, organizations lose access to security patches, technical support, and validated mitigation guidance.Β In many cases, newly disclosed vulnerabilities cannot be remediated at all.Β This leaves agencies exposed at the network edge.Β
For most public sector teams, the challenge lies on the decision-making side with operational and budget constraints:Β
- Where do unsupported assets exist today?
- Which unsupported systems are externally exposed or operate at the network edge?
- Which ones meaningfully impact mission operations?
- Which risks require immediate action, and which require planning, funding, or compensating controls?Β
Without shared, trusted context, these decisions are slow, fragmented, and difficult to justify.Β
Staying Ahead of Guidance Rather Than Chasing ItΒ
The focus of CISA BOD 26-02 on end-of-support edge devices reflects the reality of todayβs threat landscape. Attackers are targeting outdated infrastructure. Because of this, agencies are expected to bothΒ identifyΒ these risks andΒ demonstrateΒ how decisions are being made to manage them.
Want to Learn More About Nucleus and BOD 26-02?
See how Nucleus employs automated End of Life and End of Support operating system tracking.