Summary:
CISA’s retirement of six cybersecurity assessment services highlights an important distinction between assessment and governance. External assessments can identify ransomware readiness gaps, resilience weaknesses, incident-management problems, and third-party dependencies, but they cannot own the resulting risk. This article examines why critical-infrastructure operators need internal governance systems that convert findings into ownership, remediation, evidence, validation, and ongoing monitoring—and why external assurance should strengthen governance rather than become a dependency.
For years, critical-infrastructure organizations have been able to turn to the federal government for something many smaller operators struggle to obtain on their own: structured, hands-on cybersecurity assessments.
That is changing.
The Cybersecurity and Infrastructure Security Agency is retiring six free assessment services previously delivered with assistance from its regional personnel. The affected programs examined cyber resilience, ransomware readiness, incident management, external dependencies, cybersecurity controls, and related capabilities. (Utility Dive)
The immediate concern is understandable.
Water utilities, hospitals, local governments, and other critical-infrastructure operators may lose access to expertise they cannot easily replace.
But there is another governance question buried inside the decision:
What happens when an organization’s ability to understand its cyber risk depends upon someone else continuing to assess it?
That question extends well beyond CISA.
Auditors leave.
Consultants change.
Insurance requirements evolve.
Regulators revise their examination programs.
Security vendors disappear.
Government programs end.
A mature cybersecurity governance system must survive all of them.
What CISA Is Changing
CISA confirmed that regional personnel will no longer perform six assessments:
- Cyber Resilience Reviews
- Cyber Resilience Essentials surveys
- Ransomware Readiness Assessments
- Incident Management Reviews
- External Dependencies Management Assessments
- Cyber Infrastructure Surveys
These were not simply downloadable questionnaires.
CISA regional advisers worked directly with critical-infrastructure organizations, using the agency’s Cyber Security Evaluation Tool to help evaluate security practices and generate reports identifying areas for improvement. (Utility Dive)
The assessments covered consequential questions.
Can the organization continue operating during a cyber crisis?
Can it contain ransomware while maintaining critical services?
Can it detect, analyze, and contain an intrusion?
Does it understand external dependencies and supply-chain exposure?
Are appropriate cybersecurity controls operating?
Those are not peripheral security concerns.
They are fundamental resilience and governance questions.
CISA says it is retiring what it describes as legacy questionnaire assessments to reduce redundancy. The agency plans to direct organizations toward its Cross-Sector Cybersecurity Performance Goals, or CPGs, which provide prioritized cybersecurity practices and assessment capabilities. (Utility Dive)
CISA has also characterized related changes to its assessment information collections as part of a strategic consolidation and migration of questionnaire capabilities. (Justia)
That distinction is important. This should not be portrayed simply as CISA abandoning critical-infrastructure cybersecurity assessments altogether.
But something consequential is disappearing:
the human assistance surrounding these particular assessments.
And for organizations with limited cybersecurity resources, that may matter considerably.
An Assessment Is Not Governance
There is a larger lesson here.
Organizations routinely confuse cybersecurity assessment with cybersecurity governance.
They are not the same thing.
An assessment asks:
Where are we weak?
Governance asks:
What are we going to do about it?
An assessment can identify that ransomware recovery capabilities are inadequate.
Governance determines who owns the deficiency, whether remediation will be funded, how quickly it must occur, whether an exception is justified, who can accept the residual risk, and how leadership knows the problem was actually corrected.
An assessment can identify a dangerous external dependency.
Governance determines whether that dependency remains acceptable.
An assessment can identify an incident-response weakness.
Governance determines who must correct it and who is accountable if it remains unresolved.
That creates a critical distinction:
Assessment capability is not governance capability.
Organizations need both.
The External-Assurance Dependency
The end of these CISA services exposes another kind of third-party dependency—one organizations may not even recognize as a dependency.
External assurance itself can become a dependency.
Consider an organization that receives periodic cybersecurity assessments from CISA.
The findings help management prioritize investments.
The assessment helps reveal blind spots.
Leadership uses the report to understand the organization’s security posture.
Perhaps the findings are presented to the board.
That can be extremely valuable.
But what happens when the assessment disappears?
If leadership suddenly loses visibility into ransomware readiness, external dependencies, incident-management maturity, or resilience because the external assessor is no longer available, the organization has discovered something important about its governance model.
Its risk visibility was partially outsourced.
That is not inherently wrong.
External expertise is valuable precisely because independent perspectives can identify conditions internal teams overlook.
The problem occurs when external assurance becomes the organization’s primary mechanism for understanding its own risk.
Critical Infrastructure Makes the Problem Harder
This matters particularly for critical infrastructure because many operators are small.
A rural water utility does not have the cybersecurity resources of a multinational bank.
A community hospital may have to divide limited technology resources among clinical systems, infrastructure, privacy, cybersecurity, regulatory requirements, and daily operational support.
A local government may be defending decades of technology with a cybersecurity team that can be counted on one hand—if it has a dedicated cybersecurity team at all.
That is why free federal assistance matters.
Former officials and industry representatives have warned that comparable private-sector assessments may be financially difficult for some organizations to obtain. (Utility Dive)
The solution cannot simply be:
Hire a consultant.
For some organizations, that may be appropriate.
For others, it may not be financially sustainable.
The more durable question is how critical-infrastructure operators develop an internal governance capability proportionate to their resources and risk.
From Assessment to Assurance
A cybersecurity assessment should be the beginning of a governance process, not its endpoint.
The lifecycle should look more like this:
Assessment → Finding → Ownership → Risk Decision → Remediation → Evidence → Validation → Monitoring
The assessment identifies the condition.
Someone must own it.
Leadership must determine its significance.
Remediation must be assigned and funded.
Evidence must demonstrate what was changed.
Someone must validate whether the change actually addressed the finding.
And the organization must continue monitoring the underlying risk.
If the process stops at the assessment report, the organization has documented risk.
It has not necessarily governed it.
The Repeat-Finding Test
There is a simple way executives and boards can evaluate whether assessments are functioning as governance tools.
Look at repeat findings.
If the same material weakness appears repeatedly across assessments, audits, penetration tests, insurance questionnaires, regulatory examinations, or internal reviews, leadership should stop treating it merely as a cybersecurity finding.
A repeat finding is governance evidence.
It may indicate that ownership is unclear.
Funding may be inadequate.
Remediation may not be enforced.
Exceptions may remain open indefinitely.
Management reporting may obscure aging risk.
Or leadership may have implicitly accepted a risk without anyone possessing explicit authority to accept it.
The assessment cannot solve those problems.
Governance must.
What Leadership Should Do Now
Organizations that have relied upon these CISA assessments should not respond by simply finding another questionnaire.
They should determine exactly what capability is being lost.
Was CISA providing technical expertise?
Independent challenge?
Benchmarking?
Facilitated discussions?
Executive credibility?
Prioritization?
Documentation?
Access to someone who could ask questions internal personnel were not asking?
Those functions may require different replacements.
A self-assessment can replace a questionnaire.
It cannot necessarily replace independent challenge.
A framework can identify expected practices.
It cannot determine whether management is rationalizing a weakness.
An automated tool can collect information.
It cannot automatically establish whether leadership is accepting risk knowingly and appropriately.
The first step is therefore not replacement.
It is dependency identification.
Questions Every Executive Should Ask
- Which parts of our cybersecurity risk visibility currently depend upon external assessments?
- If those assessments stopped tomorrow, which risks would become harder for leadership to see?
- Do assessment findings have named owners, remediation deadlines, escalation requirements, and documented closure evidence?
- Who has authority to accept a material finding that cannot be remediated?
- Are recurring findings reported to executive leadership and the board differently from newly discovered weaknesses?
- Can we independently evaluate ransomware readiness, incident management, external dependencies, and operational resilience?
- What independent assurance do we require to challenge our internal assessment of cyber risk?
These questions matter whether the assessment comes from CISA, an auditor, a consultant, an insurer, or an internal cybersecurity team.
Governance Takeaway
The retirement of six CISA assessment services deserves attention, particularly for smaller critical-infrastructure operators that benefited from direct assistance.
But organizations should resist drawing the wrong lesson.
The lesson is not that every organization must reproduce CISA’s assessment capabilities internally.
Nor is it that external assessment has become less important.
Independent assessment remains essential precisely because organizations can become accustomed to their own weaknesses.
The lesson is that external assessment must feed an internal governance system capable of surviving without the assessor.
Critical-infrastructure operators should know their important assets.
They should understand their dependencies.
They should know whether they can withstand ransomware.
They should know whether they can detect and manage an incident.
They should know which material weaknesses remain unresolved and who has accepted the resulting risk.
And leadership should be able to produce evidence supporting those conclusions.
CISA can provide guidance.
An auditor can provide findings.
A consultant can provide expertise.
A framework can provide structure.
But none of them can own the organization’s risk.
If the assessment goes away, the governance cannot go with it.


