CISA issued Binding Operational Directive 26-02 on February 5, 2026, compelling all Federal Civilian Executive Branch agencies to identify, report, and phase out edge devices that no longer receive security updates from their manufacturers.
The directive responds to what CISA describes as widespread exploitation campaigns by advanced threat actors who target end of support network equipment as pivot points into federal information systems. Devices covered include firewalls, VPN concentrators, routers, load balancers, and other internet facing infrastructure running software their vendors have ceased patching.
Agencies face an immediate requirement to update any vendor supported edge devices currently running end of support software. Within three months of issuance, they must submit a complete inventory of devices appearing on CISA’s End of Support Edge Device List. By August 5, 2027, all unsupported edge devices must be updated or replaced regardless of list inclusion. By February 5, 2028, agencies must demonstrate continuous identification mechanisms ensuring only supported devices operate in production.
While BOD 26-02 applies only to federal agencies, CISA, FBI, and the UK National Cyber Security Centre jointly urged all organizations to adopt the same lifecycle management practices. The directive reflects a broader recognition that perimeter device vulnerabilities have become a preferred initial access vector for both nation state and criminal threat actors.