HomeSecurityCISA considers new 3-day deadline to remediate critical vulnerabilities

CISA considers new 3-day deadline to remediate critical vulnerabilities

Experts have mixed reactions to a report that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is considering reducing the window of time in which government agencies must address critical vulnerabilities from two weeks to just three days. The current 14-day window applies to high-severity vulnerabilities from 2021 onwards that are listed as known to be exploitable on CISA’s List of Known Exploitable Vulnerabilities (KEV).

See also: CISA: cPanel & WHM Vulnerability in KEV Catalog

CISA

According to a Reuters report citing two anonymous sources, this could be reduced to 72 hours amid growing concern that artificial intelligence models like Anthropic’s Claude Mythos (which, according to a recent report, CISA does not yet have access to) will speed up attackers’ ability to discover and exploit more serious vulnerabilities. This potential reduction remains an unconfirmed point of discussion, and no timeline has been proposed for introducing a change.

But in a sign that any change will carry weight, decision-makers involved include Nick Andersen, the acting head of the Cybersecurity and Infrastructure Security Agency, and Sean Cairncross, the U.S. national cybersecurity director, Reuters reported. Current CISA requirements Current CISA remediation deadlines depend on the severity of a vulnerability, which is influenced by a number of factors.

The most urgent category, zero-day vulnerabilities — vulnerabilities known to be exploitable but for which no patch is available — are covered by Urgent Directives that require remediation within 24 to 72 hours. Next are the 14-day KEV List vulnerabilities under the Binding Operational Directives (BOD 22-01). In addition to being actively exploitable, a vulnerability in this category must have a CVE identifier and an available patch or workaround.

Underscoring the urgency, threat intelligence platform VulnCheck recently reported that 29% of KEV-level vulnerabilities in 2025 showed evidence of exploitation on or before the day the CVE was published. Critical vulnerabilities that are not known to be actively exploited, on the other hand, are categorized under BOD 19-02, which allows for a remediation timeline of between 15 and 30 days, depending on the CVSS score.

See also: CISA adds Linux vulnerability to KEV List

CISA considers new 3-day deadline to remediate critical vulnerabilities

Moving to 72-hour remediation would mark a huge shift in workload for security teams within U.S. government agencies. It could also set a new standard for best practice in the private sector. The question is whether implementing patches or remediation within three days is a practical goal. A CISA spokesperson declined to comment on the Reuters report, but security experts were more forthcoming, with most believing the idea is simply an acknowledgement that modern vulnerability management is evolving.

One source of concern was that a three-day timeframe would leave little time for meaningful testing, which is usually a time-consuming and complex process that ensures that a patch, fix, or workaround will not cause problems in the systems around it.

Adam Arellano, field CTO at security firm API Harness, said that moving to a three-day window for remediation was only possible if agencies had the processes and technology needed to achieve it.

A three-day recovery timeline is entirely feasible,” Arellano said. “The process is not inherently complex, but it has become complex over time, especially in government environments that have been slow to adopt modern technologies. With the right systems in place, this can be a simplified and manageable process.” For Arellano, the change in the repair window is inevitable.

See also: CISA: ConnectWise and Windows vulnerabilities in the KEV Catalog

CISA considers new 3-day deadline to remediate critical vulnerabilities

The window between discovering a vulnerability and exploiting it is shrinking to minutes and could soon be virtually instantaneous,” he said. “The ability to respond almost instantly will be critical.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS