
CISA Orders Federal Agencies to Replace End-of-Life Edge Networking Gear
CISA's Binding Operational Directive 26-02 requires Federal Civilian Executive Branch agencies to identify and decommission end-of-life edge devices (routers, firewalls, switches) that no longer receive updates. Agencies must inventory EOS devices within 3 months, decommission EOS gear within 12 months, and replace identified devices within 18 months with vendor-supported equipment, with continuous discovery inventories to be in place within 24 months. The mandate aims to reduce exposure to exploits targeting outdated edge devices; it applies to FCEB agencies, with encouragement for others to follow.