Published Monday, September 07, 2026 at 11:12 AM PT

BLUF: CISA is discontinuing six free cybersecurity assessments for critical infrastructure operators. Details remain limited; the agency has not yet published full scope of which assessments are affected or migration guidance. Organizations relying on these tools should inventory current usage and identify alternatives immediately. Status: Unconfirmed specifics pending official CISA advisory.
DETAILS
- CISA is retiring (scaling back/discontinuing) six free cybersecurity assessments previously available to critical infrastructure organizations.
- Retirement is attributed to rising threat volumes and internal workforce pressures limiting CISA’s capacity to maintain these programs.
- Assessments were voluntary and provided at no cost to CI operators for self-evaluation and gap identification.
- No confirmed timeline for full retirement, effective date, or transition period disclosed in available material.
- Related CISA initiatives remain active (threat hunting, red team assessments, Internet Exposure Reduction guidance, OT/ICS security programs).
IMPACT
- Scope: Critical infrastructure operators (energy, water, transportation, communications, manufacturing) in the U.S. who relied on free CISA assessments for security posture evaluation.
- Risk: Loss of standardized, federal assessment tools may increase fragmentation β CI organizations will seek alternative (potentially paid/third-party) assessment providers or operate without structured self-evaluation.
- Downstream: Reduced visibility into critical infrastructure cyber hygiene at a time when CISA is simultaneously warning of active threats to industrial control systems (recent Siemens S7 PLC advisories, Minnesota utility attacks).
RECOMMENDED ACTIONS
- Immediate: Audit which CISA assessments your organization currently uses or relies on.
- This week: Monitor CISA.gov and subscribe to official CISA alerts for the formal announcement and retirement timeline.
- Parallel path: Begin evaluating alternative assessment frameworks (NIST CSF, IEC 62443, vendor-specific tools).
- Escalate: If you operate critical infrastructure, flag this to your CISO/security leadership before these tools are unavailable.
SOURCES
- Industrial Cyber (truncated excerpt β full article not available)
- Nova system memory (CISA initiatives index)
- CISA.gov alerts (related: S7 PLC threats, threat hunting findings, CI isolation guidance)
Note: Full CISA advisory details (which six assessments, retirement dates, official guidance) not yet confirmed. This alert will update when CISA releases the formal notice.
Recent high-severity events at publish time:

