CISA Retires Six Critical Infrastructure Assessments

CISA Retires Six Free Cybersecurity Assessment Services

INFORMATIONAL
September 7, 2026
4m read
Policy and ComplianceRegulatorySecurity Operations

Related Entities

Products & Tech

Cyber Security Evaluation Tool (CSET)

Other

U.S. Critical Infrastructure OperatorsCyber Incident Reporting for Critical Infrastructure Act (CIRCIA)

Full Report

Executive Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the retirement of six free, hands-on cybersecurity assessment services that were previously offered to critical infrastructure organizations. The decision, effective September 7, 2026, will end direct support from CISA's regional staff for these programs. The agency cited a need to reduce redundancy and streamline its offerings, directing organizations instead toward self-service questionnaires and its Cybersecurity Performance Goals (CPGs). The move has drawn concern from some industry experts, who worry that under-resourced entities in sectors like healthcare and water utilities will lose a valuable, no-cost resource for improving their security posture, particularly as CISA prepares to enforce new incident reporting mandates.


Regulatory Details

CISA is discontinuing regional staff support for the following six assessment programs:

  • Cyber Resilience Review (CRR)
  • Ransomware Readiness Assessment (RRA)
  • Incident Management Review (IMR)
  • External Dependencies Management Assessment (EDMA)
  • Cyber Infrastructure Survey (CIS)
  • Cyber Resilience Essentials survey

Previously, these programs involved CISA advisors working directly with organizations to facilitate in-depth evaluations, often using the Cyber Security Evaluation Tool (CSET). This process provided tailored reports and actionable recommendations. Going forward, organizations will be guided to use CISA's self-service tools and the cross-sector Cybersecurity Performance Goals (CPGs) to conduct their own evaluations.

Chris Butera, acting executive assistant director of CISA's Cybersecurity Division, stated the goal is to "reduce redundancy" and improve the efficiency of the agency's services.

Affected Organizations

The primary entities affected are U.S. critical infrastructure operators. This includes a wide range of public and private sector organizations, with a significant impact on smaller or under-funded entities that lack the budget for commercial security consulting services. Key sectors that have historically relied on these free assessments include:

  • Water and Wastewater Systems
  • Healthcare and Public Health
  • Energy
  • Transportation Systems
  • State, Local, Tribal, and Territorial (SLTT) governments

Impact Assessment

The retirement of these hands-on services creates a potential guidance and support gap for the very organizations CISA is tasked with protecting. While self-service tools are valuable, they lack the interactive, expert-led facilitation that many resource-constrained organizations found beneficial. The hands-on assessments provided not just a report, but a collaborative process that helped teams understand their specific risks and prioritize improvements.

This decision is particularly notable given two external factors:

  1. Workforce Pressures: The move is reportedly linked to workload pressures and a significant reduction in CISA's workforce, which may have made the labor-intensive assessments unsustainable at scale.
  2. CIRCIA Implementation: CISA is in the final stages of rulemaking for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). This act will impose strict, mandatory reporting deadlines on these same critical infrastructure entities. Critics argue that removing a key tool for improving security posture just before increasing compliance burdens is counter-intuitive and could leave many organizations less prepared to meet the new requirements.

Compliance Guidance

With the retirement of these services, critical infrastructure operators should take the following steps:

  1. Leverage CPGs: Familiarize yourself with CISA's Cybersecurity Performance Goals. These are designed to be a prioritized subset of security practices that can help organizations make the most impactful improvements. Use the associated self-assessment questionnaire as a starting point.
  2. Utilize CSET: The Cyber Security Evaluation Tool (CSET) remains available for download and use. Organizations can still run the tool independently to conduct a detailed assessment against various standards, though they will lack the CISA facilitator.
  3. Seek Community and ISAC Support: Engage with your sector-specific Information Sharing and Analysis Center (ISAC). These groups often provide resources, tools, and peer support that can help fill the gap left by the retired CISA services.
  4. Prepare for CIRCIA: Proactively begin aligning your incident response plans and capabilities with the expected requirements of CIRCIA. This includes identifying what constitutes a reportable incident, defining roles and responsibilities, and practicing response procedures.
  5. Budget for External Assessments: For organizations that relied heavily on the free CISA assessments, it may be necessary to budget for periodic third-party security assessments to maintain an objective view of their security posture.

Timeline of Events

1
September 7, 2026
CISA confirms the retirement of six free cybersecurity assessment services for critical infrastructure.
2
September 7, 2026
This article was published

Timeline of Events

1
September 7, 2026

CISA confirms the retirement of six free cybersecurity assessment services for critical infrastructure.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

CISAPolicyComplianceCritical InfrastructureCIRCIAGovernment

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.