CISA just abolished 6 key cybersecurity assessments. Cybercriminals didn't get the memo.
Updated: Sep 3

This week, CISA confirmed it's retiring six of its free assessment services for critical infrastructure operators — Cyber Resilience Reviews, Ransomware Risk Assessments, Incident Management Reviews, External Dependencies Management Assessments, Cyber Infrastructure Surveys, and Cyber Resilience Essentials surveys. The agency says it's cutting "redundancy." Critics call it a retreat driven by CISA losing roughly a third of its workforce.
Here's the uncomfortable truth: the assessments disappearing doesn't mean the risk does.
The controls, capabilities, and resilience these assessments were designed to measure, like incident response readiness, supply chain risk management, ransomware containment, resilience under crisis, still need to exist. Attackers aren't going to pause because the government stopped checking.
What this really means for agencies and infrastructure operators:
This isn't just a service cut. It's a cost shift. Work that used to be centralized, standardized, and free through CISA now falls on individual agencies and operators to fund, staff, and execute themselves - at exactly the moment when adversaries are using AI to move faster, scale further, and attack with more sophistication than ever.
CISA is pointing organizations to its Cross-Sector Cybersecurity Performance Goals as a substitute. But as one former CISA official put it: CPGs tell you where to focus. The assessments told you where you actually stood. Losing that visibility, right as threats accelerate, is a gap every security leader should be planning for now not after an incident forces the question.
The bottom line: the federal safety net just got thinner. Organizations that assume "no assessment" means "no exposure" are the ones that will find out the hard way.
Is your organization ready to own this gap? Let's talk about closing it before someone else finds it first.
📎 Source: Cybersecurity Dive
.jpg)



Comments