← Back to articles

CISA Is Scaling Back Free Cyber Assessments. What Critical Infrastructure Operators Need to Do Next.

Updated September 12, 2026

CISA Is Scaling Back Free Cyber Assessments. What Critical Infrastructure Operators Need to Do Next.

A resilient organization building layered cybersecurity protection as federal assessment support changes

The federal cybersecurity safety net is changing.

According to a September 1, 2026 report from Cybersecurity Dive, updated September 3, CISA is scaling back six free, hands-on cybersecurity assessment services previously available to critical infrastructure operators.

CISA has provided valuable guidance, tools, and education to organizations across the country. Its public resources remain useful. But the reported reduction in facilitated assessment support does not reduce the cyber risk facing the organizations that operate essential services.

It changes who must take ownership of understanding, documenting, and managing that risk.

For critical infrastructure operators: and for municipalities, state agencies, healthcare organizations, manufacturers, utilities, government contractors, and other operationally important businesses: the message is straightforward:

A framework can guide your journey. It cannot drive the vehicle for you.

What Changed According to Cybersecurity Dive?

According to Cybersecurity Dive, CISA regional staff will no longer perform six reported assessment services:

  1. Cyber Resilience Reviews
  2. Cyber Resilience Essentials surveys
  3. Ransomware Readiness Assessments
  4. Incident Management Reviews
  5. External Dependencies Management Assessments
  6. Cyber Infrastructure Surveys

These services provided more than a questionnaire. They involved interaction with CISA advisers, structured discussions, use of CISA’s Cyber Security Evaluation Tool, and reports that helped organizations identify potential improvements.

The CISA Cyber Resilience Review page remains available as archived content. CISA’s archived description explains that the CRR was an interview-based assessment focused on operational resilience, cybersecurity practices, and the ability to continue critical services during stress or crisis.

CISA reportedly plans to direct organizations toward its Cross-Sector Cybersecurity Performance Goals, or CPGs.

That is an important resource: but CPGs should not be described as providing the same facilitated, interactive experience as the retired or scaled-back assessments.

What Remains Available From CISA?

CISA’s Cross-Sector Cybersecurity Performance Goals 2.0 provide a voluntary baseline of high-impact cybersecurity practices.

The CPGs are designed for organizations of all sizes, including small and organizations. They help leaders prioritize foundational actions that can reduce common cyber risks.

CPG 2.0 also aligns with the NIST Cybersecurity Framework 2.0, including its increased emphasis on governance, accountability, oversight, and risk management.

That governance focus matters. Cybersecurity is not solely an IT concern. It affects service delivery, financial performance, legal obligations, public trust, safety, and strategic goals.

CISA’s Cyber Security Evaluation Tool, or CSET®, also remains a useful resource. CISA describes CSET as a systematic, disciplined, and repeatable way to evaluate an organization’s security posture across information technology and industrial control environments.

CPGs and CSET can be valuable starting points:

  • CPGs help organizations determine which high-impact practices deserve attention.
  • CSET helps organizations perform a structured self-evaluation against recognized standards and recommendations.

Neither automatically creates an accountable owner, a funded remediation plan, reliable evidence, continuous monitoring, tested backups, or incident readiness.

Why a Checklist Is Not a Cybersecurity Program

Consider a vehicle inspection.

A checklist may confirm that the tires, brakes, lights, and fluids were reviewed. That is useful. But the checklist does not repair a worn brake pad, replace a failed tire, train the driver, monitor the vehicle during a trip, or guarantee that the vehicle will arrive safely.

Cybersecurity works the same way.

Answering assessment questions is only the beginning. Organizations must still:

  • Confirm which assets, systems, data, and identities they actually operate.
  • Determine whether identified controls are implemented consistently.
  • Collect evidence that controls are working.
  • Remediate weaknesses according to business risk.
  • Monitor systems and identities continuously.
  • Manage third-party and external dependencies.
  • Test backups and recovery procedures.
  • Rehearse incident response with executives and operations teams.
  • Reassess the environment as technology and threats change.

A completed questionnaire may tell you that a castle has a gate, walls, and watchtowers. It does not tell you whether the gate closes, whether the guards are watching, whether the walls have gaps, or how quickly the kingdom can recover after an attack.

That is the assessment-to-action gap.

A cybersecurity checklist compared with a continuously managed security program

Why It Matters

1. Cyber risk can interrupt operations

For a municipality, an attack may disrupt public services, permitting, emergency coordination, or payment systems.

For a healthcare organization, it may affect scheduling, patient access, clinical workflows, or sensitive information.

For a manufacturer or utility, it may interfere with production, distribution, safety, or operational technology.

The business impact is not limited to lost files. It can include downtime, delayed revenue, emergency expenses, contractual disputes, regulatory scrutiny, and damaged trust.

2. Responsibility remains with the organization

A CISA resource, framework, or self-assessment can inform decisions. It does not transfer accountability away from the organization’s leadership.

CEOs, CFOs, CIOs, COOs, general counsel, boards, municipal leaders, and agency executives need visibility into material cyber risks and the steps being taken to address them.

3. Cybersecurity affects EBITDA and strategic goals

Cybersecurity investments compete for limited resources. The strongest business case connects security improvements to outcomes leadership already cares about:

  • Protecting revenue and service continuity.
  • Reducing avoidable operational disruption.
  • Supporting customer and government contracts.
  • Preparing for regulatory or contractual reviews.
  • Improving board-level visibility.
  • Supporting informed cyber insurance discussions.
  • Protecting enterprise value and EBITDA.

No cybersecurity program can guarantee compliance, insurance coverage, security, or prevention of every incident. But a documented, risk-based program can help leadership make better decisions and demonstrate responsible preparation.

What Organizations Should Do Next

1. Assign an accountable executive owner

Name the person responsible for coordinating cyber risk decisions. That may be a CIO, COO, technology leader, risk executive, or another senior owner.

The owner should have authority to escalate risk, coordinate departments, and track remediation.

2. Build an accurate inventory

Document:

  • Hardware, applications, cloud services, and identities.
  • Critical data and business processes.
  • Internet-facing systems.
  • Backup and recovery dependencies.
  • Vendors, managed service providers, and external partners.
  • Information technology and operational technology connections.

You cannot protect what you cannot see.

3. Use CPG 2.0 and CSET as a baseline

Use the CPGs to prioritize high-impact practices. Use CSET to conduct a structured self-evaluation.

Treat the results as a starting point: not as proof that the program is complete.

4. Map requirements that apply to your organization

Depending on your environment, map identified gaps to relevant expectations such as:

  • NIST Cybersecurity Framework and NIST publications.
  • CIS Controls.
  • CMMC requirements for applicable contractors.
  • HIPAA Security Rule obligations.
  • NY DFS Part 500 requirements for covered financial institutions.
  • Sector-specific requirements and contractual commitments.

A framework map is most useful when it connects to evidence, owners, due dates, and measurable remediation.

5. Prioritize remediation

Rank gaps by potential business impact, exploitability, exposure, and recovery difficulty.

Do not attempt to fix everything at once. Focus first on weaknesses that could materially affect operations, privileged access, critical data, external exposure, or recovery.

6. Add continuous monitoring and validation

Risk changes after every new application, employee, vendor, cloud configuration, and business initiative.

Organizations should consider continuous monitoring, vulnerability management, identity reviews, adversarial testing, and recurring control validation.

7. Test recovery and response

Backups are not a recovery strategy until they have been restored and validated.

Incident response plans are not ready until the people responsible for using them have practiced. Include executives, legal counsel, communications, IT, operations, and key vendors in appropriate exercises.

8. Document and review quarterly

Maintain evidence of decisions, remediation, testing, training, incidents, exceptions, and executive review.

A quarterly review helps ensure that cyber risk remains connected to current business priorities rather than becoming a once-a-year compliance exercise.

How We Deliver It

PROACTIVE RISK helps organizations fill the gap between identifying cyber risk and acting on it.

As an independent cybersecurity and risk-management partner, we support organizations with services that can be aligned to their environment, priorities, and applicable requirements. Proactive Risk is not CISA and does not represent CISA. Our services are not endorsed by CISA.

Our capabilities include:

  • CyberAdvisor™ / vCISO: Fractional cybersecurity leadership, executive guidance, governance, risk prioritization, and board-level reporting.
  • MEASURERISK™: Gap assessments, evidence collection, policy development, and compliance support across NIST, CMMC, HIPAA, NY DFS 500, and other frameworks.
  • CATSCAN®: Proactive adversarial penetration testing and security validation, including IT, cloud, web applications, wireless, and selected ICS/OT environments.
  • MANAGEIT™ / MSOC: 24/7 managed detection and response, monitoring, endpoint protection, Microsoft 365 administration, and incident containment support.
  • RISKWatch™: Third-party and external dependency risk management.
  • PhishIT™: Security awareness and phishing-resilience training.
  • CyberTrain™: Incident response rehearsal and practical cyber exercises.

A complimentary Risk Briefing / Cyber & Business Risk Review can help identify meaningful gaps and prioritize next steps. It does not guarantee compliance, certification, regulatory approval, security, insurance coverage, or prevention of an incident.

The 8 Layers of Protection

A resilient program should address eight connected layers:

  1. Governance: Accountability, policies, oversight, and risk decisions.
  2. Risk and asset visibility: Knowing what exists, what matters, and what is exposed.
  3. Identity and access: Strong authentication, least privilege, and access reviews.
  4. Secure configuration and vulnerability management: Reducing exploitable weaknesses and configuration drift.
  5. Data resilience and backups: Protecting critical information and testing recovery.
  6. Human behavior: Training employees to recognize and report threats.
  7. Detection and response: Monitoring continuously and acting quickly when something changes.
  8. Validation and continuous improvement: Testing, measuring, documenting, and improving over time.
Eight connected layers of cybersecurity protection supporting organizational resilience

How Proactive Risk Helps Secure the Future of Your Strategic Goals

CISA’s public resources remain valuable. The CPGs and CSET can help organizations establish direction and conduct a disciplined baseline review.

But the responsibility for cyber risk does not end with a completed questionnaire.

Organizations must convert findings into accountable action: funded remediation, operational improvements, evidence, monitoring, recovery testing, and executive visibility.

For organizations in Morris County, across New Jersey, and throughout the Northeast, that work is closely connected to the businesses and communities they serve. A cyber event can affect more than technology. It can affect payroll, public services, patients, customers, contracts, employees, and strategic growth.

The practical takeaway is this:

Use CISA’s tools. Use the CPGs to prioritize. Use CSET to evaluate. Then build the people, process, technology, and accountability required to manage risk continuously.

PROACTIVE RISK Intelligence-Led Cybersecurity & Risk Management ANTICIPATE. DEFEND. PREVAIL. Secure the Future of Your Strategic Goals.

36 First Avenue, Suite 203, Denville, NJ 07834 973-298-1160 proactiverisk.com

For daily breach updates and breach-notification considerations, visit the Breach Intelligence Hub.