KEV Remediation Deadline Calculator
Work out the real working time on a CISA KEV remediation deadline — calendar days, working days after weekends and SG/MY public holidays, weekend due dates.
KEV Remediation Deadline Calculator
CISA's directive states that KEV remediation windows are counted in calendar days — weekends and public holidays included. Enter the date a vulnerability was added and its due date (or window length) to see the working time you actually have. Everything is computed in your browser; this tool never contacts cisa.gov.
—
How to Use the KEV Deadline Calculator
Enter the date added
Type the date the vulnerability was added to the CISA KEV catalogue. It is the "Date Added" column in the catalogue entry and the start of the remediation clock.
Give the deadline
Enter the catalogue's due date, or switch to "Window length" and pick the number of days — 3, 14 or 21 are the common ones. The window is measured in calendar days.
Choose your region
Leave it on "Weekends only", or select Singapore or Malaysia to also exclude local public holidays and see your team's real working time.
Read the working time
The verdict names the working days you actually have, flags weekend deadlines, and shows the days remaining from today. Copy the link to share the exact scenario.
The Three-Day Clock and Why the Weekday Matters
The clock that arrived before the directive
For most of its life, the CISA Known Exploited Vulnerabilities catalogue — the KEV — ran on a comfortable rhythm. Under Binding Operational Directive 22-01, issued in November 2021, United States federal civilian agencies were given roughly two to three weeks to remediate most listed flaws, a median window that sat around 21 days. That number is what many teams still picture when they think of a "KEV deadline," and it is now badly out of date. By the middle of 2026 the median had collapsed to just three days. The paperwork that gets the credit — Binding Operational Directive 26-04, which formally superseded 22-01 — only landed in June 2026, but the operational change had already happened. The first three-day deadline appeared in the catalogue on 27 January 2026, and the old 21-day window was quietly retired on 5 March 2026, months before the new directive was signed. Teams waiting for an announcement to change their process were already behind.
"The directive that gets the credit arrived in June 2026. The three-day clock had been running since January."
Why the day of the week now decides your deadline
The shift matters because of a single line most people miss. CISA's directive is explicit: "Days are calendar days." The clock does not pause for weekends, and it does not pause for public holidays. When the window was 21 days, that hardly mattered — a weekend or two was lost in the noise. At three days, it is decisive. A vulnerability added to the catalogue on a Thursday with a three-day window is due on Sunday, which means the only working day inside the window is Friday. Added on a Friday, the window spans Saturday and Sunday and lands on Monday — again a single working day. From RECATOOLS analysis of the July 2026 catalogue, ten of thirty-two recent three-day clocks contained exactly one working day, and roughly a third of three-day deadlines fell on a weekend. The weekday a vulnerability is published now quietly decides how much real time a team gets, which is exactly what this calculator makes visible.
There is a regional dimension too. For a security team in Singapore or Malaysia, a deadline that already loses a weekend can lose another day to a public holiday — a three-day clock that opens the day before Hari Raya or Chinese New Year can contain no working days at all. Because the directive counts calendar days, those holidays do not extend the deadline; they simply compress the working time available to respond. The optional Singapore and Malaysia holiday sets in this tool exist to make that real working time visible, so a team can see at a glance whether a deadline that looks like three days is, in practice, an afternoon. The deadlines themselves remain CISA's to set and publish; this tool only does the arithmetic the directive implies, so you can plan staffing and escalation around the working time you actually have rather than the calendar figure that hides it.
10 Facts About KEV Remediation Deadlines
CISA's directive states plainly that KEV windows are calendar days — weekends and holidays are counted.
The median remediation window collapsed from 21 days to 3 between October 2025 and July 2026. (RECATOOLS analysis of the CISA KEV catalogue, v2026.07.27)
21 of the 25 July 2026 KEV additions were given a three-day window. (RECATOOLS analysis)
Of 32 recent three-day clocks, 10 (31%) contained exactly one working day. (RECATOOLS analysis)
34% of three-day deadlines landed on a Saturday or Sunday. (RECATOOLS analysis)
8 of 25 July 2026 additions (32%) came from edge or perimeter vendors. (RECATOOLS analysis)
BOD 26-04 binds US federal civilian agencies — not private firms, though it is the de-facto industry benchmark.
A CVE added on a Thursday with a three-day window leaves exactly one working day: Friday.
Two CVEs added the same day can carry different deadlines — the catalogue sets each due date individually.
This calculator runs entirely in your browser and never contacts cisa.gov — nothing you enter is sent anywhere.
Frequently Asked Questions
- The Known Exploited Vulnerabilities catalogue is a list, maintained by the US Cybersecurity and Infrastructure Security Agency (CISA), of software flaws that are confirmed to be exploited in the wild. Each entry names the CVE, the vendor and product, the date it was added, and a remediation due date. Because everything on it is actually being attacked, it is widely used well beyond government as a prioritisation list for patching.
- The binding operational directive behind the KEV — BOD 22-01, and from June 2026 its successor BOD 26-04 — legally binds US federal civilian executive-branch agencies. Private companies, and organisations outside the United States, are not legally required to meet the dates. In practice, though, the catalogue has become an industry benchmark: if a flaw is being exploited widely enough for CISA to list it, most security teams treat the due date as a sensible target regardless of whether it binds them.
- Calendar days. The directive states explicitly that "Days are calendar days," so weekends and public holidays are included in the count and do not extend the deadline. That distinction barely mattered when windows were around 21 days, but with three-day windows now common it is decisive — the working time inside a window can be a fraction of the calendar figure. This tool shows both so you can plan around the working days you really have.
- When every KEV entry shared the same fixed window, the due date told you nothing extra. Now that windows vary — three days for the most urgent, longer for others — the length of the window is itself a message about how seriously CISA views the flaw. A three-day clock signals active, high-impact exploitation. Reading the window length alongside the CVSS score gives a fuller picture of urgency than either does alone.
- The deadline does not pause. If a vendor has not shipped a fix, the directive expects agencies to apply mitigations — configuration changes, network isolation, disabling the affected feature, or, if nothing else works, taking the product out of service — by the due date. The remediation clock is about reducing risk by the deadline, not solely about installing a patch, so "no patch yet" is not an extension.
- Because CISA assigns each entry its own due date rather than applying one fixed window to everything. Two vulnerabilities added on the same day can be given different windows depending on how CISA weighs the threat, so one might be due in three days and another in three weeks. Always read the due date on the specific catalogue entry; do not assume every item added on a given day shares a deadline. This tool lets you enter either the due date or the window directly.
- Enormously, once windows are short. Because the count is in calendar days, a three-day window that opens on a Thursday or Friday spends most of its length on the weekend and leaves a single working day. The same three-day window opening on a Monday gives three working days. So the publication weekday, entirely outside your control, can triple or third your real response time. Seeing that at a glance is the main reason this calculator exists.
- No. The calculator never makes a request to cisa.gov or any third-party host from your browser, so your IP address and the details of what you are checking are never exposed to an outside server. You type the dates in yourself, and all the arithmetic runs locally. This is a deliberate design choice: the page works offline and adds no external dependency or data leak.
- Weekends are always excluded from the working-day count. Public holidays are excluded only when you select a region — Singapore or Malaysia — from the working-time dropdown. Those holiday sets are a vendored snapshot: Singapore uses the Ministry of Manpower's gazetted national holidays, and Malaysia uses the federal national holidays, which individual states may add to. They are a planning aid; for anything binding, verify the specific date against the official gazette.
- No. This is an independent planning aid built by RECATOOLS, not affiliated with or endorsed by CISA. The authoritative source for any deadline is the KEV catalogue entry itself, and CISA's published due date always takes precedence over anything computed here. Use this calculator to understand the working time a deadline implies and to plan around it, then confirm the date against the official catalogue.
Related News
You may be interested in these recent stories from our newsroom.
No related news yet for this tool. Our editorial team publishes new pieces every week.
Browse all news →Pick up where you left off
Stored only in this browser — never sent to our servers.