Skip to main content
Emergency Directive Response: Your Action Plan for CISA ED 25-03FedRAMP Program
5 min readFor Cloud Service Providers (DoD/FedRAMP)

Emergency Directive Response: Your Action Plan for CISA ED 25-03

When CISA issues an emergency directive, your response time is measured in days, not weeks. FedRAMP's directive regarding CISA V1: ED 25-03 requires cloud service providers to identify and mitigate potential compromises of specific Cisco devices, with final reporting due by 5:00 PM ET April 29, 2026. This is a live incident requiring coordinated action across your technical teams, compliance function, and agency customer base.

This checklist translates the directive's requirements into actionable steps with clear completion criteria. If you're a FedRAMP authorized provider, you're in scope regardless of impact level.

Prerequisites

Before you begin, confirm you have:

  • Access to your FedRAMP Security Inbox (the response form link was sent there, not published publicly)
  • Current network topology documentation showing all devices within your FedRAMP boundary
  • Incident response team availability for potential compromise investigation
  • Contact information for all agency Authorizing Officials or ISSOs who hold authorizations for your offering
  • Write access to your FedRAMP repository's Incident Response folder

What good looks like: You can assemble your response team within two hours and identify the correct agency points of contact without searching email archives.

Emergency Directive Response Checklist

1. Review CISA V1: Emergency Directive 25-03

Read the full directive to understand affected systems and required actions. Don't rely on summaries.

Done when: Your technical lead and compliance lead have both read the directive and understand which Cisco device series are in scope: Firepower 1000, 2100, 4100, 9300 series and Secure Firewall 200, 1200, 3100, 4200, and 6100 series.

What good looks like: Your team can explain why these specific models matter and what vulnerabilities (CVE-2025-20333 and CVE-2025-20362) are being addressed.

2. Identify All In-Scope Cisco Devices

Inventory every public-facing Cisco device from the affected series within your FedRAMP boundary. Use automated discovery tools, but validate against your system security plan and network diagrams.

Done when: You have a complete list with device model, serial number, software version, and location within your boundary. If you find zero in-scope devices, document this finding and skip to Step 8.

What good looks like: Your inventory matches what your 3PAO would find during an assessment. No surprises.

3. Collect Logs from Affected Systems

Follow CISA's Supplemental Direction ED 25-03: Core Dump and Hunt Instructions to collect artifacts before you make configuration changes.

Done when: You've captured core dumps and relevant logs in a forensically sound manner, preserving chain of custody.

What good looks like: Your artifacts are timestamped, stored in a secure location separate from production systems, and documented with collection methodology.

4. Evaluate for Indicators of Compromise

Use CISA's FIRESTARTER Backdoor Malware Analysis Report and available threat intelligence to hunt for compromise indicators on each identified device.

Done when: You've completed analysis on all in-scope devices and documented findings. If you detect compromise or anomalous behavior, immediately follow FedRAMP Incident Communication Procedures (which includes notifying CISA and agency customers).

What good looks like: Your analysis is documented well enough that an independent assessor could validate your methodology. You're not just running automated scans, you're actively hunting based on known indicators.

5. Apply Required Updates by April 24, 2026

If no compromise indicators are present, patch all identified CVEs. This includes software updates for CVE-2025-20333 and CVE-2025-20362, plus the persistence-specific patch referenced in CISA's instructions.

Done when: All devices show the updated software version and you've verified patch installation through device console access, not just management interface reports.

What good looks like: You've tested patches in a non-production environment first (if time permits), documented the patch window, and confirmed no service degradation post-patch.

6. Perform Hard Reset by April 29, 2026

Physically unplug each device's power supply. A software reboot won't expunge the malware. This is a physical action.

Done when: Each device has been power-cycled via physical disconnection, brought back online, and verified operational.

What good looks like: You've coordinated the power cycle with agency customers to minimize impact, documented the exact time of reset for each device, and confirmed service restoration.

7. Upload Supplemental Information and Notify Customers

Create a spreadsheet (CSV or XLSX format) named ED-25-03-V1-Response-[FRID] containing affected system types, actions taken, results, and any additional context. Upload to your FedRAMP repository's Incident Response folder. Email all agency Authorizing Officials or ISSOs.

Done when: File is uploaded, all agency points of contact have received notification emails, and you've received acknowledgment from each agency.

What good looks like: Your summary is clear enough that an agency ISSO who wasn't involved can understand your response without follow-up questions.

8. Complete FedRAMP Response Form by 5:00 PM ET April 29, 2026

Submit the form sent to your FedRAMP Security Inbox. This is required even if you identified zero in-scope devices.

Done when: You receive confirmation of form submission before the deadline.

What good looks like: You submitted 24 hours early to account for technical issues.

Common Mistakes

Treating this as optional if you have zero affected devices. Step 8 is mandatory regardless. FedRAMP needs to know you reviewed the directive.

Relying solely on asset management databases. Shadow IT and undocumented devices exist. Cross-reference multiple sources.

Rebooting instead of physically power-cycling. The directive explicitly states a reboot isn't sufficient. You must physically disconnect power.

Notifying FedRAMP but forgetting agency customers. Both are required. Your agency points of contact need to know what you found and what you did.

Waiting until April 28 to start. You have evaluation, patching, coordination, and physical access requirements. Budget time for complications.

Next Steps

After you've submitted your response:

  • Document lessons learned. How quickly could you inventory devices? Where were gaps in your asset management?
  • Review your incident response plan. This directive exposed your real-world response capability. Update procedures based on what actually happened.
  • Assess your threat intelligence integration. Could you easily access CISA reports and apply indicators to your environment? If not, fix that gap.
  • Brief your continuous monitoring program. Add these device types to enhanced monitoring if you're retaining them in your boundary.

Emergency directives test whether your compliance program is documentation theater or operational reality. The providers who respond fastest aren't the ones with the most polished SSPs, they're the ones who know their environments cold and maintain current contact lists. If this directive caught you flat-footed, use it as a forcing function to close the gap between what your security plan says and what your team can actually execute under pressure.

You Might Also Like