Overview
Note the rename
The CISA BOD 22-01 was relaunched as the CISA KEV (Known Exploited Vulnerabilities) list in 2022. You will see references to both CISA BOD & CISA KEV in Nucleus documentation and platform depending on if you are a federal customer or commercial client.
On November 3, 2021, the Cybersecurity and Infrastructure Security Agency (CISA), a branch of the U.S. Department of Homeland Security (DHS), released Binding Operational Directive (BOD) 22-01. Cybersecurity directives from CISA are infrequent, the last being issued on September 2, 2020, and they tend to be at a rather high level. BOD 22-01 is different, because it instructs agencies to remediate a specific list of vulnerabilities, and it attaches strict deadlines. Importantly, this directive is a requirement, and not simply guidance or a recommended best practice.
The target for this BOD is government organizations. However, it is not at all uncommon for private industry to adopt government standards once they become aware of them. Organizations with significant government contracts in their book of business would do well to comply and be able to prove compliance upon demand. Fortunately, Nucleus simplifies compliance with CISA BOD 22-01.
Where to find and how to use
CISA BOD 22-01 results can be found, associated with specific CVEs, on the Vulnerability Intelligence tab of the detail view on any vulnerability or compliance finding.
View CISA KEV status on a finding:
Navigate to Global Dashboard > Project > Explore > Vulnerabilities to view the Active Vulnerabilities page.
Click on any vulnerability to open the detail view.
Select the Vulnerability Intelligence tab.
Look for the CISA KEV field, which displays:
KEV Status: Whether the CVE is on the CISA Known Exploited Vulnerabilities list
Due Date: The CISA-mandated remediation deadline (if applicable)

Filter by CISA KEV status:
Navigate to Explore > Vulnerabilities.
Click the Filter button to open the query builder.
Add a filter condition: CISA KEV Vulnerability = Yes.
Apply the filter to view only vulnerabilities on the CISA KEV list.
Additionally, CISA BOD 22-01 can be used as criteria for triggering automation rules that create downstream events like Finding Processing and Notifications.
Create automation rules using CISA KEV:
Navigate to Automation.
Create a new rule with trigger criteria based on CISA KEV Vulnerability = Yes.
Configure downstream actions such as:
Auto-assign to specific teams
Set due dates based on CISA deadlines
Send notifications to stakeholders
Adjust finding priority or severity
NOTE: When evaluating CISA Known Exploited Vulnerabilities (KEV) status across Findings, Nucleus currently only checks the primary CVE in each finding’s vulnerability intelligence record. If a finding contains multiple CVEs, only the first (primary) CVE determines whether the finding is marked as KEV-true.