eosl.ai
Compliance guide

CISA BOD 26-02: end-of-support edge devices must go — here’s how to find yours

On February 5, 2026 CISA ordered US federal civilian agencies to identify and remove end-of-support edge devices — firewalls, routers, switches, wireless access points and security appliances that no longer get vendor security updates. The reference list CISA built for it is not public. The vendor bulletins it's built from are — and that's what EOSL.ai tracks, per part number, with a source link on every date.

The deadlines

DateMilestoneWhat agencies must do
Feb 5, 2026Directive issuedImmediately: update any supported edge device still running EOS software to a vendor-supported version.
May 5, 2026+3 monthsInventory all devices on the CISA EOS Edge Device List; report to CISA. (Passed — agencies are now in the decommission phases.)
Feb 5, 2027+12 monthsDecommission listed devices whose EOS date has passed; replace with vendor-supported gear. Report to CISA.
Aug 5, 2027+18 monthsDecommission ALL EOS edge devices — on CISA’s list or not.
Feb 5, 2028+24 monthsContinuous discovery running; devices decommissioned on or before the day they reach EOS.
Who this binds. FCEB agencies only — the directive states it "applies to FCEB agencies, not contractors," though agencies may modify contracts to comply; OT devices and FedRAMP-authorized cloud services are out of scope. CISA shares the device list with state/local governments and critical-infrastructure partners. For everyone else it is fast becoming the benchmark auditors and boards reach for: if the US government won't run EOS edge gear, "why do we?" is the next question in your risk review.

CISA's definitions — the exact scope

End of Support (EOS)

"Hardware devices, firmware, and software versions that no longer receive timely, supported updates from the original equipment manufacturer, including patches for CVEs, security updates, software fixes (hotfixes), and defects." Note it covers firmware and software, not just boxes — a supported device on an EOS software train counts (see tracked OS trains).

Edge devices

"All technology devices that reside on the boundary of an agency's network and are accessible from the public internet" — load balancers, firewalls, routers, switches, wireless access points, network security appliances, IoT edge and SDN devices. The directive adds that EOS devices "should not reside anywhere on federal networks."

What the tracked data shows for in-scope device classes

EOSL.ai tracks 1,408 edge-class products (7,159 part numbers) across 15 vendors. Of those: 701 fully past vendor support, 47 mixed (some part numbers past), and 97 with support ending within the directive's 12-month lookahead window. This is not CISA's list — it is the public, vendor-source-backed record the same facts come from.

All unsupported hardware → · Ending within 18 months →

Running the directive's workflow with free tools

1 · Identify (the 3-month task)

Paste your edge-device part numbers into the bulk checker — exact-SKU status, source bulletin, the Fleet Timeline chart, and a BOD 26-02 scope flag on every in-scope row (also in Stack Monitor and its CSV export). Scope is derived from public vendor data — it never claims presence on CISA's non-public list.

2 · The 12-month lookahead inventory

The directive makes "EOS or EOS within 12 months" a recurring inventory unit. Subscribe to the EOSL calendars (90-day alarms) and Stack Monitor keeps your list in your browser — nothing uploads.

3 · Evidence

Every date links to the vendor bulletin, every record carries a last-verified date, and "Copy lifecycle evidence" on any model page produces the citable record for your report.

4 · Continuous (the 24-month bar)

The change ledger and RSS catch new bulletins and moved dates weekly; watch any current model and it flags the day the vendor announces EOL.

BOD 26-02 — questions

What is CISA BOD 26-02?

A Binding Operational Directive issued by the US Cybersecurity and Infrastructure Security Agency on February 5, 2026, requiring Federal Civilian Executive Branch (FCEB) agencies to identify and remove end-of-support (EOS) edge devices — firewalls, routers, switches, wireless access points, VPN and security appliances and similar internet-facing gear that no longer receives vendor security updates.

Who does BOD 26-02 apply to?

It is legally binding on FCEB agencies only — not on private companies, and per the directive text not directly on contractors, though agencies "may need to modify contracts to comply." CISA shares the supporting EOS Edge Device List with state, local, tribal and territorial governments and critical-infrastructure partners, and the directive is widely treated as the de facto lifecycle benchmark beyond government.

What are the BOD 26-02 deadlines?

From the February 5, 2026 issuance: immediately update supported edge devices running EOS software; within 3 months (May 5, 2026) inventory devices on CISA's EOS Edge Device List; within 12 months (February 5, 2027) decommission listed devices whose EOS date has passed by then; within 18 months (August 5, 2027) decommission ALL EOS edge devices; within 24 months (February 5, 2028) run continuous discovery and decommission devices before they reach EOS.

Is the CISA EOS Edge Device List public?

No. CISA provides it to federal agencies and shares it with SLTT and critical-infrastructure partners; it is not published openly. The list contains IT product name, version and end-of-support date — the same category of vendor-published facts EOSL.ai tracks publicly with a source link on every date.

How does CISA define "end of support"?

Per the directive: "Hardware devices, firmware, and software versions that no longer receive timely, supported updates from the original equipment manufacturer, including patches for CVEs, security updates, software fixes (hotfixes), and defects."

How do I identify EOS edge devices without access to CISA's list?

Work from the vendors' own end-of-life bulletins. Paste your edge-device part numbers into the EOSL.ai bulk checker for source-linked EOS status per exact SKU, subscribe to the EOSL calendars for the 12-month-lookahead inventory the directive requires on an ongoing basis, and use the change ledger to catch dates that move.

Source: CISA Binding Operational Directive 26-02 (read in full Aug 2026). EOSL.ai is independent and not affiliated with or endorsed by CISA; this page summarizes the directive and links the primary source — verify requirements against the directive itself.