Published Monday, September 07, 2026 at 11:12 AM PT

<strong>DEVELOPING β€” CISA Retires Critical Infrastructure Assessments Amid Workforce Constraints</strong>

BLUF: CISA is discontinuing six free cybersecurity assessments for critical infrastructure operators. Details remain limited; the agency has not yet published full scope of which assessments are affected or migration guidance. Organizations relying on these tools should inventory current usage and identify alternatives immediately. Status: Unconfirmed specifics pending official CISA advisory.

DETAILS

  • CISA is retiring (scaling back/discontinuing) six free cybersecurity assessments previously available to critical infrastructure organizations.
  • Retirement is attributed to rising threat volumes and internal workforce pressures limiting CISA’s capacity to maintain these programs.
  • Assessments were voluntary and provided at no cost to CI operators for self-evaluation and gap identification.
  • No confirmed timeline for full retirement, effective date, or transition period disclosed in available material.
  • Related CISA initiatives remain active (threat hunting, red team assessments, Internet Exposure Reduction guidance, OT/ICS security programs).

IMPACT

  • Scope: Critical infrastructure operators (energy, water, transportation, communications, manufacturing) in the U.S. who relied on free CISA assessments for security posture evaluation.
  • Risk: Loss of standardized, federal assessment tools may increase fragmentation β€” CI organizations will seek alternative (potentially paid/third-party) assessment providers or operate without structured self-evaluation.
  • Downstream: Reduced visibility into critical infrastructure cyber hygiene at a time when CISA is simultaneously warning of active threats to industrial control systems (recent Siemens S7 PLC advisories, Minnesota utility attacks).

RECOMMENDED ACTIONS

  1. Immediate: Audit which CISA assessments your organization currently uses or relies on.
  2. This week: Monitor CISA.gov and subscribe to official CISA alerts for the formal announcement and retirement timeline.
  3. Parallel path: Begin evaluating alternative assessment frameworks (NIST CSF, IEC 62443, vendor-specific tools).
  4. Escalate: If you operate critical infrastructure, flag this to your CISO/security leadership before these tools are unavailable.

SOURCES

  • Industrial Cyber (truncated excerpt β€” full article not available)
  • Nova system memory (CISA initiatives index)
  • CISA.gov alerts (related: S7 PLC threats, threat hunting findings, CI isolation guidance)

Note: Full CISA advisory details (which six assessments, retirement dates, official guidance) not yet confirmed. This alert will update when CISA releases the formal notice.


Recent high-severity events at publish time:

Recent high-severity events