The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is scaling back six free cybersecurity assessments for critical infrastructure organizations, according to Cybersecurity Dive, ending regional staff support for Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys. The agency said it is retiring the legacy questionnaire assessments to reduce redundancy for CISA and organizations requesting them.
The move comes as the nation’s lead cybersecurity agency faces growing workload pressures and has lost roughly one-third of its workforce since the beginning of the second administration of President Donald Trump.
The assessments previously involved CISA regional advisers working directly with infrastructure operators and using the agency’s Cyber Security Evaluation Tool to generate reports with recommended security improvements. CISA said it will instead direct operators to its cross-sector Cybersecurity Performance Goals, which include a questionnaire designed to help organizations identify resilience improvements.
“CISA routinely evaluates our services and tools to make necessary changes to improve,” Chris Butera, the acting executive assistant director of CISA’s Cybersecurity Division, said in a statement. “To reduce redundancy for CISA and organizations requesting an assessment, CISA is retiring some legacy questionnaire assessments.”
James Harrell, the acting assistant director of CISA’s Integrated Operations Division, which houses the agency’s field staff, told division employees during an Aug. 25 meeting that they were expected to stop performing the assessments.
“My apologies to those I told to leverage these free resources recently,” Denis Calderone, CTO at Suzu Labs, wrote in an emailed statement. “We’ve been pointing to those who lacked the bigger budgets to the CISA’s assessment programs. All six programs are gone now. The replacement is a self-service questionnaire that the people who built the original tools say doesn’t do the same job.”
He noted that the timing stinks. “CISA is weeks away from finalizing CIRCIA, which will require critical infrastructure operators to report cyber incidents within 72 hours and ransomware payments within 24 hours, and this comes just as they take away the testing tools. But, to be fair, we don’t really know how widely adopted these programs were in the first place. The scope is huge with 50,000 small water utilities alone; we doubt that CISA’s regional staff was ever going to reach all of them, and there’s no public data showing how many operators actually used the assessments or what the measurable impact was.”
Highlighting that CSET is open source and older versions on GitHub still include all six retired assessment modules, Calderone mentioned that “CSET measures where you actually stand against specific security standards. The CPGs that CISA is pointing everyone toward are a prioritization framework that helps you figure out where to focus. They’re complementary tools, not interchangeable ones. Use CSET to diagnose your current state, then use the CPGs to prioritize what to fix first. What you won’t get anymore is a CISA regional adviser helping you interpret the results, but using both tools together is still better than using either one alone.”
He added that “Several states are also stepping up direct cybersecurity support for local operators. And if you’re a water utility, keep an eye on Project Watershed 250. It just launched in Texas with free vulnerability assessments and red-teaming, and it’s supposed to expand nationally.”
John Strand, owner at Black Hills Information Security, wrote in a statement that “Right now, our critical infrastructure is under attack at a level we simply have not seen before. Water systems, energy, telecommunications, municipalities, and other critical infrastructure are actively being targeted. CISA itself warned in July about ongoing Iranian-affiliated attacks against operational technology and PLCs across multiple U.S. critical infrastructure sectors. And this is the moment we decide to start cutting the programs designed to help these organizations defend themselves?”
“CISA is eliminating six free cybersecurity assessment programs used by critical infrastructure organizations, including ransomware readiness, cyber resilience, incident management, and infrastructure assessments,” according to Strand. “Many of the organizations relying on these programs are exactly the organizations that do not have the money or personnel to replace them with commercial services. This is crazy.”
He added that “We should be dramatically increasing the resources available to critical infrastructure organizations right now. We should be expanding free assessments, threat intelligence, training, and technical assistance, especially for small municipalities, rural hospitals, water systems, and utilities that simply cannot afford large cybersecurity programs. Instead, we’re pulling resources away from them while the attacks are increasing.”

