CISA retires six cybersecurity assessment programmes for critical infrastructure

The US Cybersecurity and Infrastructure Security Agency is ending regional support for six free cybersecurity assessment programmes as it seeks to streamline its services amid workforce pressures.

CISA retires six cybersecurity assessment programmes for critical infrastructure

The US Cybersecurity and Infrastructure Security Agency (CISA) is scaling back six free cybersecurity assessment programmes that have provided hands-on support to organisations operating critical infrastructure.

The programmes affected are Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys.

CISA said the decision is intended to reduce duplication between its assessment services and streamline the agency’s cybersecurity support.

The programmes provided direct assistance to critical infrastructure operators. CISA regional advisers worked with organisations to assess vulnerabilities, identify weaknesses and develop recommendations to improve cybersecurity and resilience. The assessments could also use tools such as the Cyber Security Evaluation Tool (CSET).

CISA will instead direct organisations towards its cross-sector Cybersecurity Performance Goals (CPGs). These include a questionnaire designed to help organisations identify areas where security improvements may be needed.

The change comes as CISA faces pressure on its workforce. The agency supports cybersecurity and resilience across sectors including energy, communications, transportation, healthcare and financial services. According to Cybersecurity Dive, CISA has lost roughly one-third of its workforce since the beginning of the second Trump administration.

CISA has presented the decision as an effort to improve efficiency. Chris Butera, acting executive assistant director of CISA’s Cybersecurity Division, said the agency routinely reviews its services and tools and retires programmes when needed.

The change also reduces the amount of direct, tailored support available to critical infrastructure operators. Under the previous programmes, CISA specialists could work directly with organisations and provide recommendations based on their specific environments.

The new approach places more responsibility on organisations to assess their own systems, interpret the results and decide which security improvements to prioritise. This could create additional challenges for smaller operators that have fewer cybersecurity staff and resources.

Go to Top