BOD 26-04: The Federal Printer Directive Private Industry Will Inherit
On December 7, every federal civilian agency has to account for the printers on its network. The directive binds government. It will not stop there, and the organizations that move before their auditor does will spend a fraction of what the ones who wait spend.
In June, CISA issued Binding Operational Directive 26-04. Buried in a document about prioritizing security updates based on risk is an instruction that changes how one specific device class gets treated: every federal civilian agency has to put every printer on its security asset map. Including the printers sitting on private internal addresses. Compliance deadline, December 7, 2026.
The directive binds federal civilian agencies. It does not bind your bank, your dealership group, your hospital, or your school district.
Not yet.
What the directive actually requires
Three provisions matter for anyone who runs a print fleet.
Complete enumeration. Networked devices that originate or transmit data have to appear in the agency's asset inventory. Multifunction printers are not exempt because they are leased, because Facilities owns the contract, or because they only appear in the print-management vendor's billing report.
Private addresses are explicitly in scope. This is the provision that does the work. For twenty years the operating assumption on print fleets has been that a device on a private internal address is not really exposed, so it does not really need to be inventoried, so nobody really needs to know what it transmits. The directive removes that reasoning at the federal level.
Short remediation clocks. Fix windows run as short as three days for the highest-risk findings. That is not a timeline you meet by discovering your fleet after the finding lands.
The assumption that just stopped working
Ask a competent IT director why the MFP fleet is not in the risk assessment and you will get a version of the same answer: it is behind the firewall, it does not have a public IP, and it is a copier.
That answer was never about the device. It was about the traffic. A multifunction printer configured for scan-to-email is not a copier. It is an unattended, unauthenticated document-transmission endpoint that anyone in the building can walk up to, and that relays regulated data through the mail system in the clear.
The private address never protected the document. It protected the assumption that nobody had to look.
Two well-documented cases show what happens when someone does. The PaperCut print-management flaw (CVE-2023-27350) drew a joint CISA and FBI advisory after confirmed real-world exploitation. Xerox VersaLink devices shipped with a credential pass-back weakness (CVE-2024-12510 and CVE-2024-12511) that let an attacker on the same network recover the login credentials stored inside the device, credentials that on most fleets are a domain service account with reach into file shares and directory services. Neither of those attacks needed the printer to be internet-facing.
Federal rules do not stay federal
This is the part worth internalizing, because it is a pattern and not a prediction.
When CISA published its Known Exploited Vulnerabilities catalog in 2021, it was a federal instrument aimed at federal agencies. Today it is the benchmark commercial auditors and third-party risk teams reference by default. Nobody passed a law making that happen. The catalog was simply the most credible published list, so the private sector adopted it.
The same propagation is already underway here. FedRAMP aligned to BOD 26-04 within weeks of its release. That is the second domino, and it moves the requirement from agencies to the vendors who sell to agencies.
The third domino is the one that reaches everyone else: security auditors and cyber-insurance underwriters. Audit firms build their testing procedures from published federal frameworks because that is where defensible criteria come from. Underwriters build questionnaires the same way, and they update them after losses. Both groups will start tracking MFP traffic as a vulnerability and flagging it, and both move on annual cycles, which puts the practical arrival somewhere in 2027.
If your renewal questionnaire next year contains a question about multifunction-device transmission that this year's did not, that is this directive arriving.
The rules you already answer to
Here is what makes the timeline shorter than it looks. Unencrypted scan-to-email is not waiting on a new rule to become a finding. It is already written up under language on the books today.
- GLBA and the FTC Safeguards Rule. 16 CFR 314.4(d) requires encryption of customer information in transit. The 2026 examiner read is no longer satisfied by a policy attestation. It expects evidence of encryption on device-originated traffic.
- HIPAA. 45 CFR 164.312(e)(1) is a transmission-security standard. A scanned chart note leaving an MFP in plaintext is transmission, and it is electronic protected health information.
- FERPA. Student records scanned at a school district office move through the same unencrypted path as everything else.
- PCI DSS, NIST 800-171, ITAR. Each contains transmission-protection requirements that a plaintext scan does not satisfy.
The gap has never been the regulation. The gap has been that nobody scoped the device class, so nobody tested the path. BOD 26-04 is the document that makes the device class impossible to leave out of scope.
The email system is where the damage lives
The printer is the entry point. It is not where the loss happens.
Compromised business email is the most financially destructive category of cyberattack aimed at organizations, with roughly $3 billion in reported United States losses in 2025 alone according to the FBI Internet Crime Complaint Center. Every scan-to-email job drops another unencrypted attachment into an inbox, then a sent folder, then an archive, then a backup, where it stays.
Run the arithmetic on your own fleet. A modest deployment of forty devices, at roughly forty scans per device per day, across 250 working days, is 400,000 plaintext transmissions of regulated data per year that nobody can currently attest to. Every one of those documents is still sitting in the mail system.
Ask the question that actually matters: how many terabytes of scanned documents live in your mail system right now, and who could enumerate them? On most networks the honest answer is that nobody knows. One phished mailbox exposes years of scans at once.
What the wait costs
Pick your regulator, or pick your plaintiff.
- $53,088 per violation, per day. FTC Safeguards civil penalty, 2025-adjusted.
- $10.22 million average cost of a United States data breach. IBM, 2025.
- 1,822 data-breach class actions filed in 2025, roughly triple the 2022 count. Duane Morris, 2026.
- December 7, 2026. The federal deadline. Flow-down follows.
What to do in the next hundred days
None of this requires waiting for your auditor to ask. Five steps, and the first four cost nothing but time.
- Inventory the fleet. Count of devices, brands, firmware versions, locations. If the only place this list exists is a vendor billing report, it does not count as an asset inventory.
- Confirm whether scan-to-email is enabled and whether it relays plaintext through your mail server. On most fleets it is, and it does, because that is the default configuration.
- Identify what actually gets scanned. Medical records, financial and account documents, contracts, driver licenses, student records. This determines which rule you are answering to.
- Check whether the fleet appears in your risk analysis as a transmission endpoint. If it does not, that is the gap, stated in the language your examiner will use.
- Close the path. Encrypted transport with a per-document audit trail and no residual copy left in a mailbox. The point is to be able to produce evidence rather than an assurance.
Steps one through four produce a one-page summary of exactly where you stand. That summary is worth having whether or not you ever do anything about step five.
Why we are publishing this now
Because the useful time to say something is before it is obvious.
Botdoc has been building secure digital transport since long before printers were on anyone's regulatory radar, and we filed a patent on the SecureMFP approach in January 2026, months ahead of this directive. That is not a credential we are waving around. It is the reason we can describe what is coming with some confidence: we have been working the transport problem for years, and the print fleet is the last place in most organizations where regulated data still moves in the clear by default.
Between now and 2027 a lot of vendors will explain why this is overblown, and then a lot of the same vendors will explain that they have always covered it. Read the publication dates. This one is September 2, 2026, the citations are primary sources, and every claim in it can be checked.
Talking about this live on September 9
I am joining Josh Koronich and Adam Crowell of KPA for a LinkedIn Live session, "Scan, Copy, Breach: Why the Feds Are Sounding the Alarm on Office Printers", on Wednesday, September 9 at 1:00 PM Eastern. It is a practical hour: what the directive says, what to check on your own fleet, and how to close the gap without a rip-and-replace. Registration is free and open here, and KPA's announcement post has the details.
Sources: CISA Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk (June 10, 2026); CISA and FBI Joint Advisory AA23-131A (PaperCut, CVE-2023-27350); Rapid7, Xerox VersaLink pass-back vulnerabilities (CVE-2024-12510, CVE-2024-12511); FBI IC3 2025 Internet Crime Report; FedRAMP response to BOD 26-04; FTC civil penalty adjustments (90 FR, January 2025); IBM Cost of a Data Breach Report 2025; Duane Morris Data Breach Class Action Review 2026; 16 CFR 314.4(d); 45 CFR 164.312(e)(1).
BOD 26-04 binds federal civilian executive branch agencies. Statements about future auditor and insurer behavior describe how prior federal frameworks have propagated into commercial practice. This is not legal or compliance advice.
Scan, Copy, Breach: Why the Feds Are Sounding the Alarm on Office Printers
Karl Falk joins Josh Koronich and Adam Crowell of KPA for a practical hour on BOD 26-04: what the directive requires, what to check on your own fleet, and how to close the gap without replacing hardware. Wednesday, September 9, 1:00 PM Eastern. Free to attend.
Register for the session