Beyond CVSS: What CISA's BOD 26-04 Reveals About the Future of Risk Management
For nearly two decades, cybersecurity programs have been built around a deceptively simple question:
How severe is the vulnerability?
The answer was typically found in a Common Vulnerability Scoring System (CVSS) score.
Organizations built remediation programs around critical, high, medium, and low rankings. Compliance frameworks adopted the model. Dashboards filled with vulnerability counts. Success was measured by how many findings could be patched within prescribed timelines.
But there has always been a problem.
A vulnerability is not a risk.
And a high-severity vulnerability does not necessarily represent a high-priority threat.
With the release of Cybersecurity and Infrastructure Security Agency (CISA)'s Binding Operational Directives (BOD) 26-04, federal cybersecurity policy has officially shifted from severity-based prioritization to exposure-based decision-making. Instead of focusing solely on the characteristics of a vulnerability, organizations must now consider:
- Whether an asset is exposed
- Whether exploitation is occurring in the wild
- Whether exploitation can be automated
- The potential operational and business impact
- The likelihood of compromise
This may sound like a technical policy adjustment. In reality, it signals the industry's transition toward Continuous Threat Exposure Management (CTEM) — a framework built around understanding and reducing real-world cyber exposure rather than simply counting vulnerabilities.
The Evolution of Cybersecurity Thinking
BOD 26-04 did not emerge in isolation.
Over the past several years, CISA's directives have steadily advanced cybersecurity maturity:
- Know what is being exploited.
- Know what assets you have.
- Understand which exposures matter most.
This progression mirrors the core principles of CTEM. The goal is no longer to identify every vulnerability. The goal is to continuously discover, prioritize, validate, and reduce the exposures most likely to impact the business.
The challenge facing organizations today is not a lack of information. It's deciding what deserves attention.
Security teams have accumulated more vulnerability data, more threat intelligence feeds, more dashboards, and more alerts than ever before. Yet many still struggle to answer a simple question:
What should we do first?

From Vulnerability Management to Exposure Management
One of the most important implications of BOD 26-04 is the recognition that risk is dynamic.
One of the core principles of CTEM is that risk is constantly changing.
A vulnerability that appears low risk today can quickly become a priority if a new exploit is released, threat actors begin targeting it, or a system becomes exposed to the internet. The vulnerability itself may not have changed, but the organization's exposure has.
That's why CTEM focuses not just on finding vulnerabilities, but on continuously assessing which exposures pose the greatest risk at any given time.
Rather than viewing vulnerabilities as isolated findings, CTEM evaluates risk through the lens of attack paths, exploitability, business context, asset criticality, and operational impact.
The question is no longer:
"How severe is this vulnerability?"
The question becomes:
"Given our current threat environment, attack surface, and business priorities, how dangerous is this exposure right now?"
The Rise of Explainable Risk
Perhaps the most overlooked aspect of BOD 26-04 is its requirement that organizations justify prioritization decisions.
It is no longer enough to point to a score.
Organizations must explain why a vulnerability received a particular remediation timeline and demonstrate the contextual factors that informed the decision.
This is another area where CTEM becomes essential.
Exposure management is not simply about identifying risk. It is about creating a repeatable and explainable process for prioritizing and reducing risk.
In many ways, this mirrors a broader trend occurring across technology and business.
As AI becomes embedded in decision-making systems, leaders are increasingly expected to answer:
- Why was this decision made?
- Why this customer?
- Why this investment?
- Why this security response?
- Why this risk?
The future belongs to organizations that can combine intelligence with explainability.
The Bigger Lesson
The most important takeaway from BOD 26-04 is not that CVSS is obsolete.
Cybersecurity is moving from vulnerability management to exposure management. From static scoring to continuous prioritization and from reporting findings to driving decisions.
This is why CTEM is rapidly becoming the operating model for modern cybersecurity programs.
The organizations that thrive will not be those with the most dashboards, alerts, or vulnerability reports.
They will be those who can continuously determine:
What matters most, what represents the greatest risk, and what action should happen next.
That is the promise of CTEM.
And it is the real lesson behind CISA's BOD 26-04.
Source: BOD 26-04: Implementation Guidance for Prioritizing Security Updates Based on Risk