The Cybersecurity and Infrastructure Security Agency (CISA) has announced the retirement of ten Emergency Directives issued between 2019 and 2024, representing the largest single batch of retired directives in the agency’s history.
This milestone reflects CISA’s successful efforts to mitigate urgent threats to Federal Civilian Executive Branch (FCEB) agencies and to establish more sustainable, long-term cybersecurity practices across the federal enterprise.
Strategic Consolidation and Evolution
The retirement of these directives follows a comprehensive review concluding that the required actions have been successfully implemented or consolidated under Binding Operational Directive (BOD) 22-01, which addresses the significant risk posed by known exploited vulnerabilities.
This strategic consolidation demonstrates CISA’s commitment to streamlining federal cybersecurity operations while maintaining rigorous protection standards.
Seven directives tied to specific Common Vulnerabilities and Exposures (CVEs) have been formally closed because those vulnerabilities are now included in CISA’s Known Exploited Vulnerabilities (KEV) catalog.
The remaining three directives, ED 1901, ED 2101, and ED 2402, achieved their primary objectives, with requirements that no longer align with current risk postures and practices that have rendered them obsolete.
The closed directives addressed critical vulnerabilities across multiple platforms, including: DNS infrastructure tampering; Windows vulnerabilities from the 2020 and 2021 Patch Tuesdays; the SolarWinds Orion compromise; Microsoft Exchange on-premises vulnerabilities; Pulse Connect Secure issues; Windows Print Spooler service vulnerabilities; VMware vulnerabilities; and the nation-state compromise of Microsoft corporate email systems.
CISA Acting Director Madhu Gottumukkala emphasized the agency’s operational commitment, stating that the closure reflects collaborative efforts across the federal enterprise to eliminate persistent threats and counter emerging risks.
Moving forward, CISA continues advancing Secure by Design principles, prioritizing transparency, configurability, and interoperability to strengthen defenses across diverse federal environments.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyber Press as a Preferred Source in Google.