The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has taken a major step to strengthen the security of federal networksby issuing a new binding operational directive. The directive requires government agencies to identify and remove network edge devices that are no longer supported by their manufacturers and have stopped receiving security updates.

CISA warns that such devices, which are at the end of their lifecycle (End of Support – EOS), constitute one of the most dangerous "blind spots" for cyber defense, as they remain active within critical infrastructures without being protected by new patches.
Why EOS devices are considered so dangerous
Unsupported network devices – such as routers, firewalls, and switches – leave federal systems exposed to modern exploits that exploit newly discovered security vulnerabilities.
See also: CISA adds SolarWinds WHD vulnerability to KEV List
According to CISA, the threat is immediate and ongoing. As it notes, organizations that continue to use EOS edge devices face “disproportionate and unacceptable risks.” The agency says it is already aware of extensive campaigns by advanced threat actors who are systematically targeting such equipment.
The problem is that these devices no longer receive official updates from the manufacturer, which means that even if a critical vulnerability, there is no way to fix it.

What does the new BOD 26-02 directive provide?
The new Binding Operational Directive 26-02 obliges federal agencies to disable hardware and software that has reached EOS status, in order to prevent its exploitation by cybercriminals or state-sponsored groups.
The directive is not limited to the disposal of old devices, but requires a comprehensive equipment lifecycle management strategy.
See also: CISA: VMware vCenter vulnerability in KEV Catalog
Compliance timeline: From inventory to replacement
CISA sets clear deadlines:
- Immediate action for devices that are still supported by vendors but running EOS software, where updates are available.
- Within three months, services must complete an inventory of all devices included in the CISA EOS list.
- Organizations have 12 months to deactivate devices that had already reached end of support before the directive was issued.
- Within 18 months, all EOS edge devices must be replaced with equipment that is actively supported and receives security updates.
- Finally, within 24 months, continuous discovery and monitoring processes must be created to promptly identify devices approaching the end of support.
Although it concerns the US, the message is global
Although the requirements of BOD 26-02 directly apply only to FCEB services, CISA calls on all organizations, public and private, to follow the same practices.
See also: CISA withdraws 10 Emergency Directives
The reality is that attacks on edge devices have increased dramatically, as they are the "gateway" to corporate networks and often remain neglected for years.

Previous CISA initiatives and the war on ransomware
This is not the first time CISA has taken action. In June 2023, it issued BOD 23-02, requiring federal agencies to secure misconfigured or internet-exposed management interfaces.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In addition, the service has announced a Ransomware Vulnerability Warning Pilot (RVWP), through which it notifies critical infrastructures when vulnerable devices are detected on their networks.
Lifecycle management as a new priority
The new CISA guidance clearly shows that cybersecurity is not just about antivirus and firewalls, but also about the proper management of the equipment itself. “Old” devices without support are today one of the easiest targets for large-scale attacks.
The message is clear: if a device is not updated, it should not be on the network.
Source: www.bleepingcomputer.com
