The United States Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 26-02, titled Mitigating Risk From End-of-Support Edge Devices, to address vulnerabilities associated with network edge devices that are no longer supported by their original vendors. The directive applies to Federal Civilian Executive Branch agencies and compels them to strengthen lifecycle management and remove unsupported hardware and software that could be exploited by threat actors. Edge devices, such as firewalls, routers, switches, wireless access points, load balancers, IoT edge devices, and network security appliances have all been identified as presenting disproportionate risks when they reach the end-of-life stage, because they no longer receive security updates, patches, or firmware maintenance.
The directive sets a structured timeline for remediation and risk reduction. Immediately upon issuance, agencies must update vendor-supported devices running end-of-support (EOS) software to a supported version wherever this can be done without impairing mission-critical functionality. Within three months, agencies are required to inventory all EOS edge devices and report that inventory to CISA. This inventory process leverages an initial list provided by CISA of devices that are already EOS or soon to become EOS, including product names, versions, and end-of-support dates. Over the next 12 months, agencies must decommission all devices on CISA’s EOS edge device list that have already passed their support deadlines and replace them with vendor-supported alternatives capable of receiving security updates. Agencies are also required to inventory all other edge devices that are EOS or will become EOS within the next year and report these to CISA. By 18 months, all identified EOS edge devices must be removed from agency networks and replaced with supported hardware and software. The directive further mandates that within 24 months, agencies must establish a process for continuous discovery and lifecycle management of edge devices. This process must maintain an up-to-date inventory of devices approaching end of support and ensure they are decommissioned before their support ends. The ultimate objective is to ensure that unsupported technology does not persist on federal networks beyond its safe operational period, thereby reducing the attack surface available to cyber threat actors.
Although the requirements in the directive legally bind only U.S. federal civilian agencies, CISA and partners including the FBI and the U.K. National Cyber Security Centre (NCSC) encourage private sector organizations to adopt similar practices. Unsupported edge devices represent significant security liabilities because they often lack vendor-issued patches for known vulnerabilities and are frequently targeted in exploitation campaigns. The guidance in this directive aligns with broader U.S. cybersecurity policy, including expectations for improved asset management and risk reduction under Zero Trust and lifecycle management frameworks. It is advisable for other organizations to issue similar policies.