CISA Retires Ten Emergency Directives Following Milestone Achievement
The Cybersecurity and Infrastructure Security Agency (CISA) has announced the retirement of ten Emergency Directives as of Thu, Jan 8, 2026. These directives, issued between 2019 and 2024, have been retired following the successful implementation of…
The Cybersecurity and Infrastructure Security Agency (CISA) has announced the retirement of ten Emergency Directives as of Thu, Jan 8, 2026. These directives, issued between 2019 and 2024, have been retired following the successful implementation of required security measures across federal systems.
Emergency Directives are urgent orders intended to address emerging threats to Federal Civilian Executive Branch (FCEB) agencies swiftly. The retirement of these directives signifies advancements in federal cybersecurity efforts and the integration of these security measures into existing regulatory frameworks, such as the Binding Operational Directive (BOD) 22-01.
Among the ten retired directives, seven were related to specific vulnerabilities that are now included in CISA's Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities encompassed issues such as Windows vulnerabilities, Netlogon elevation-of-privilege problems, and VMware security concerns.
Three additional directives addressed incidents involving SolarWinds and Microsoft Exchange vulnerabilities. These directives were closed after CISA confirmed that the objectives had been met and practices had evolved beyond the original requirements.
The Cybersecurity and Infrastructure Security Agency (CISA) has announced the retirement of ten Emergency Directives as of Thu, Jan 8, 2026.
According to CISA Acting Director Madhu Gottumukkala, the closure of these directives underscores the agency's commitment to federal cybersecurity collaboration.
The following directives have been retired:
ED 19-01 : Mitigate DNS Infrastructure Tampering ED 20-02 : Mitigate Windows Vulnerabilities from January 2020 Patch Tuesday ED 20-03 : Mitigate Windows DNS Server Vulnerability from July 2020 Patch Tuesday ED 20-04 : Mitigate Netlogon Elevation of Privilege Vulnerability from August 2020 Patch Tuesday ED 21-01 : Mitigate SolarWinds Orion Code Compromise ED 21-02 : Mitigate Microsoft Exchange On-Premises Product Vulnerabilities ED 21-03 : Mitigate Pulse Connect Secure Product Vulnerabilities ED 21-04 : Mitigate Windows Print Spooler Service Vulnerability ED 22-03 : Mitigate VMware Vulnerabilities ED 24-02 : Mitigating the Significant Risk from Nation-State Compromise of Microsoft Corporate Email System
These protective measures are now part of CISA's ongoing security programs, which support federal cybersecurity governance while maintaining protection against critical threats. CISA continues to develop “Secure by Design” principles, emphasizing transparency, configurability, and cross-system compatibility across federal infrastructure. The agency remains poised to issue new Emergency Directives as required by evolving threats.
Based on reporting by Cyber Security News.
