The new CISA BOD 26-04 shifts the focus from simply patching vulnerabilities to actively identifying and replacing internet-facing edge devices that are at or beyond vendor support. The directive requires federal agencies to inventory these assets, identify end-of-life/end-of-support (EOL/EOS) systems, assess risk, and develop replacement plans because unsupported edge devices represent a disproportionately high risk to federal networks.
Eclypsium’s Hardware Supply Chain protection capabilities align closely with those requirements in several ways:
1. Discovering and Inventorying Edge Assets
A main challenge in BOD 26-04 is knowing exactly which internet-facing devices exist across the environment. Eclypsium provides asset discovery and inventory across network infrastructure, servers, appliances, and other critical systems, helping organizations establish the authoritative inventory needed to identify devices covered by the directive. Eclypsium’s platform specifically includes inventory and asset visibility capabilities.
2. Identifying Unsupported and End-of-Life Devices
BOD 26-04 requires agencies to find devices that are no longer receiving vendor security updates. Eclypsium can identify hardware and firmware versions, correlate them against vendor lifecycle information, and highlight systems running obsolete or unsupported software and firmware. This allows security teams to quickly determine which assets fall within the directive’s scope.
3. Prioritizing Risk Based on Real Exposure
The directive is fundamentally risk-driven. Rather than treating all assets equally, agencies must focus on publicly accessible edge infrastructure that creates outsized risk. Eclypsium helps prioritize remediation by combining:
- Asset criticality
- Internet exposure
- Firmware and hardware vulnerabilities
- Known exploited vulnerabilities (KEVs)
- Device lifecycle status
This enables organizations to distinguish between devices that merely need updates and those that require replacement.
4. Supporting Replacement Planning
Because BOD 26-04 often requires replacing devices rather than patching them, organizations need accurate data for procurement and migration planning. Eclypsium’s asset inventory provides:
- Device models and versions
- Ownership and deployment information
- Lifecycle status
- Exposure and risk context
This helps teams build the replacement roadmaps and business cases required by the directive.
5. Continuous Monitoring After Initial Compliance
The directive is not a one-time exercise. New devices can age into EOS status, and newly discovered vulnerabilities can increase risk. Eclypsium continuously monitors assets and firmware posture so organizations can maintain compliance and avoid accumulating unsupported infrastructure in the future.
Summary
Eclypsium helps organizations comply with CISA BOD 26-04 by discovering internet-facing infrastructure, identifying end-of-support hardware and firmware, prioritizing risk based on exposure and exploitability, and providing the asset intelligence needed to plan and execute device replacement programs.
For federal customers, the strongest linkage is typically: asset visibility → lifecycle awareness → risk-based prioritization → replacement planning, which maps directly to the intent of the directive.
Related Resources
- Take a tour of the Eclypsium Platform
- Learn more about our Public Sector Solutions
- Explore our Regulatory Compliance Offerings
