The Cybersecurity and Infrastructure Security Agency is ending six free cybersecurity assessments previously offered to critical infrastructure owners and operators through its regional staff. The discontinued services include Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments, and Cyber Infrastructure Surveys. CISA said it is retiring the assessments to reduce redundancy and will instead direct organizations toward its Cross-Sector Cybersecurity Performance Goals.
The assessments provided organizations with direct assistance from CISA personnel in evaluating areas such as operational resilience, ransomware preparedness, incident response, supply-chain dependencies, and cybersecurity controls. Critics of the decision argue that the Cybersecurity Performance Goals do not provide the same individualized assessment and guidance, raising concerns that smaller critical-infrastructure operators may have difficulty obtaining comparable assistance at an affordable cost.
Why it matters: Many critical-infrastructure organizations, particularly smaller utilities and local operators, have limited cybersecurity personnel and depend on federal assistance to identify weaknesses and prioritize improvements. Reducing access to hands-on assessments could make it more difficult for these organizations to evaluate their resilience against ransomware, supply-chain compromises, and other cyber threats.
Source: Cybersecurity Dive
Author: Eric Geller
Published: September 1, 2026