The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the retirement of six free, hands-on cybersecurity assessment services that were previously offered to critical infrastructure organizations. The decision, effective September 7, 2026, will end direct support from CISA's regional staff for these programs. The agency cited a need to reduce redundancy and streamline its offerings, directing organizations instead toward self-service questionnaires and its Cybersecurity Performance Goals (CPGs). The move has drawn concern from some industry experts, who worry that under-resourced entities in sectors like healthcare and water utilities will lose a valuable, no-cost resource for improving their security posture, particularly as CISA prepares to enforce new incident reporting mandates.
CISA is discontinuing regional staff support for the following six assessment programs:
Previously, these programs involved CISA advisors working directly with organizations to facilitate in-depth evaluations, often using the Cyber Security Evaluation Tool (CSET). This process provided tailored reports and actionable recommendations. Going forward, organizations will be guided to use CISA's self-service tools and the cross-sector Cybersecurity Performance Goals (CPGs) to conduct their own evaluations.
Chris Butera, acting executive assistant director of CISA's Cybersecurity Division, stated the goal is to "reduce redundancy" and improve the efficiency of the agency's services.
The primary entities affected are U.S. critical infrastructure operators. This includes a wide range of public and private sector organizations, with a significant impact on smaller or under-funded entities that lack the budget for commercial security consulting services. Key sectors that have historically relied on these free assessments include:
The retirement of these hands-on services creates a potential guidance and support gap for the very organizations CISA is tasked with protecting. While self-service tools are valuable, they lack the interactive, expert-led facilitation that many resource-constrained organizations found beneficial. The hands-on assessments provided not just a report, but a collaborative process that helped teams understand their specific risks and prioritize improvements.
This decision is particularly notable given two external factors:
With the retirement of these services, critical infrastructure operators should take the following steps:
CISA confirms the retirement of six free cybersecurity assessment services for critical infrastructure.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.