Cybersecuritydive
CISA Discontinues Key Cybersecurity Assessments for Critical Infrastructure
Article Content
The Cybersecurity and Infrastructure Security Agency (CISA) has announced the discontinuation of six free cybersecurity assessments aimed at critical infrastructure operators, citing workload concerns. The assessments being scrapped include Cyber Resilience Reviews and Ransomware Risk Assessments, which provided vital insights into organizations' vulnerabilities. This decision comes as CISA faces staffing challenges, having lost about one-third of its workforce since the beginning of the second Trump administration. CISA will redirect organizations to its Cross-Sector Cybersecurity Performance Goals (CPGs) for resilience improvements, although these may not offer the same level of personalized support. The move raises concerns about the ability of infrastructure operators to effectively manage and mitigate cyber risks without CISA's direct assistance. The agency's acting executive assistant director emphasized the need to reduce redundancy in assessments. The changes were communicated to CISA staff during an internal meeting on August 25, 2026.
Key Points: • CISA is discontinuing six free cybersecurity assessments for critical infrastructure. • The decision is driven by workload issues and a significant workforce reduction. • Organizations will be directed to CISA's Cross-Sector Cybersecurity Performance Goals for guidance.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.