- What: CISA issues new directive on end-of-life devices
- Impact: Federal agencies must replace unsupported edge devices
The new CISA BOD 26-04 shifts the focus from simply patching vulnerabilities to actively identifying and replacing internet-facing edge devices that are at or beyond vendor support. The directive requires federal agencies to inventory these assets, identify end-of-life/end-of-support (EOL/EOS) systems, assess risk, and develop replacement plans because unsupported edge devices represent a disproportionately high risk to federal networks. Eclypsium’s Hardware Supply Chain protection capabilities align closely with those requirements in several ways: 1. Discovering and Inventorying Edge Assets A main challenge in BOD 26-04 is knowing exactly which internet-facing devices exist across the environment. Eclypsium provides asset discovery and inventory across network infrastructure, servers, appliances, and other critical systems, helping organizations establish the authoritative inventory needed to identify devices covered by the directive. Eclypsium’s platform specifically includes inventory and asset visibility capabilities. 2. Identifying Unsupported and End-of-Life Devices BOD 26-04 requires agencies to find devices that are no longer receiving vendor security updates. Eclypsium can identify hardware and firmware versions, correlate them against vendor lifecycle information, and highlight systems running obsolete or unsupported software and firmware. This allows security teams to quickly determine which assets fall within the directive’s scope. 3. Prioritizing Risk Based on Real Exposure The directive is fundamentally risk-driven. Rather than treating all assets equally, agencies must focus on publicly accessible edge infrastructure that creates outsized risk. Eclypsium helps prioritize remediation by combining: Asset criticality Internet exposure Firmware and hardware vulnerabilities Known exploited vulnerabilities (KEVs) Device lifecycle status This enables organizations to distinguish between devices that merely need updates and those that require replacement. 4. Supporting Replacement Planning Because BOD 26-04 often requires replacing devices rather than patching them, organizations need accurate data for procurement and migration planning. Eclypsium’s asset inventory provides: Device models and versions Ownership and deployment information Lifecycle status Exposure and risk context This helps teams build the replacement roadmaps and business cases required by the directive. 5. Continuous Monitoring After Initial Compliance The directive is not a one-time exercise. New devices can age into EOS status, and newly discovered vulnerabilities can increase risk. Eclypsium continuously monitors assets and firmware posture so organizations can maintain compliance and avoid accumulating unsupported infrastructure in the future. Summary Eclypsium helps organizations comply with CISA BOD 26-04 by discovering internet-facing infrastructure, identifying end-of-support hardware and firmware, prioritizing risk based on exposure and exploitability, and providing the asset intelligence needed to plan and execute device replacement programs. For federal customers, the strongest linkage is typically: asset visibility → lifecycle awareness → risk-based prioritization → replacement planning, which maps directly to the intent of the directive. Related Resources Take a tour of the Eclypsium Platform Learn more about our Public Sector Solutions Explore our Regulatory Compliance Offerings The post CISA BOD-26-04: What it Means and How Eclypsium Can Help appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise .