CISA: certification rules delay patches; voter DBs targeted

CISA released its 2026 Election Infrastructure Security Plan warning certification rules can block timely patches and that voter registration databases have been targeted by foreign actors.

The Cybersecurity and Infrastructure Security Agency released its 2026 Election Infrastructure Security Plan after Homeland Security Secretary Markwayne Mullin directed the agency to develop it in July. The plan outlines cyber and physical threats to election systems and lists no-cost services CISA offers to state and local election officials. CISA noted more than 10,000 local jurisdictions manage U.S. elections and that state and local officials bear primary responsibility for protecting election infrastructure.

CISA found that election software can contain vulnerabilities that need prompt fixes, but said certification rules can prevent vendors from releasing patches and stop system owners from applying updates quickly. The agency identified three core problems: vulnerability management constrained by outdated certification regimes, inconsistent vendor transparency about flaws and patch status, and weak cybersecurity in many state, local, tribal and territorial networks that host election systems.

Many election offices struggle with basic cyber hygiene and remediation, CISA said. Election systems are often connected to general enterprise networks, which can allow attackers who compromise email accounts or workstations to move laterally into voting systems. To address that risk, the plan recommends aligning patch management with certification requirements so security updates can be applied in real time without jeopardizing certification. The plan recommends the use of paper ballots and manual post-election audits.

Voter registration databases have been targeted by foreign actors, the plan says. CISA states hackers have attempted to breach voter registration systems in all 50 states, with confirmed success in at least 20. To protect those databases, the agency prioritizes multi-factor authentication, continuous network monitoring, limiting user access to required permissions, retaining critical logs for at least one year, and isolating public online registration and lookup tools from the master database.

The plan flags insider risk across permanent staff, seasonal workers, volunteers, contractors and vendors. CISA said temporary and volunteer personnel may not undergo the same vetting as full-time staff. Malicious insiders could alter voter rolls, ballot definitions, tabulation settings or reporting, while careless insiders could fall for phishing, insert unauthorized removable media or mishandle equipment. The agency recommends formalizing practices such as bipartisan two-person ballot handling, counting observers and chain-of-custody procedures into a documented insider threat program.

On physical security, CISA reviewed open-source reporting and found 96 of 107 election-related incidents tracked since January 2022 were bomb threats. For coordination during the 2026 election cycle, the agency is supporting a no-cost information-sharing platform for fusion centers and state and local election officials to enable near real-time communication with peers and federal partners. The plan notes a similar model was deployed during the FIFA World Cup 2026.

CISA listed free services available to election offices, including vulnerability and web application scanning, continuous penetration testing, risk and vulnerability assessments, decoy systems and canary tokens for intrusion detection. The plan urges election officials to press vendors to assign CVE identifiers to flaws, report incidents promptly, notify customers if source code is leaked or stolen, and supply a software bill of materials with each product. The document frames the federal role as providing tools and guidance while reaffirming state and local officials retain primary responsibility for protecting elections.

Articles by this author