CISA Ends Six Free Cybersecurity Assessment Programs
The Cybersecurity and Infrastructure Security Agency (CISA) has discontinued six free cybersecurity assessment programs, sparking concerns among experts about the impact on smaller organizations' security readiness.

The Cybersecurity and Infrastructure Security Agency (CISA) has ceased offering six specific types of free cybersecurity assessments that were previously available to organizations. These evaluations, which included services like ransomware readiness assessments and incident management reviews, helped entities gauge their security posture and preparedness for cyber threats.
The decision has prompted concern from experts who worry that smaller organizations may lose crucial resources for identifying and addressing vulnerabilities. The scaling back of these programs is seen by some as a reflection of the agency's ongoing workforce challenges and resource limitations.
CISA states that it is not abandoning these efforts entirely. The agency has introduced a single, standardized questionnaire, the "Cross-Sector Cybersecurity Performance Goals 2.0 assessment," intended to replace the six older evaluations with a streamlined process. This aims to improve data quality and reduce administrative burdens for assessed organizations.
"This reflects an agency working with a fraction of its former capacity after major workforce cuts, and having to make hard calls about where its remaining staff can add the most value," said Dave Bailey, vice president of consulting solutions and strategy. CISA maintains it will continue to provide other no-cost, voluntary services, such as threat information sharing and technical expertise.
Despite CISA's assurances, some experts express apprehension that the new process may not fully replicate the hands-on expertise and independent validation that the discontinued programs provided, particularly for organizations with limited internal cybersecurity resources.