CISA Releases 2026 Election Infrastructure Security Plan
CISA has published a 13-page Election Infrastructure Security Plan 40 days before the November 2026 midterms, offering guidance against cyber and physical

CISA released its Election Infrastructure Security Plan on September 24, 2026, providing guidance to mitigate cyber and physical threats ahead of the November midterm elections. The 13-page document outlines risks to election infrastructure, which includes physical assets like polling places and digital systems such as voter registration databases and voting machines.
The plan emphasizes leveraging collaborative partnerships, robust cyber defenses, and ongoing threat intelligence. It warns of specific dangers including software vulnerabilities, hacks of voter registration databases, insider threats, and physical security incidents like bomb threats. CISA stated, "By leveraging collaborative partnerships, robust cyber defenses, and ongoing threat intelligence, the plan ensures that all stakeholders are prepared to address evolving risks."
Context and Challenges
CISA’s own assessments show that state, local, tribal, and territorial election offices frequently struggle with basic cybersecurity hygiene and vulnerability remediation. This is partly due to outdated certification processes and inconsistent transparency from election system vendors. Threat actors have attempted to breach Statewide Voter Registration Databases in all 50 states, with confirmed success in at least 20 states over the last decade.
Election infrastructure is often accessible from general enterprise networks, allowing malicious actors to gain access via known vulnerabilities and move laterally. The agency advocates for harmonizing patch management and certification requirements to allow real-time cybersecurity updates. It also recommends the use of paper ballots for verification.
To secure voter databases, CISA urges officials to implement multifactor authentication for all access, using phishing-resistant methods for privileged accounts where possible. Continuous network monitoring and comprehensive audit trails are also advised. The plan highlights insider risks from the large temporary workforce used during elections. Mitigation includes handling ballots in bipartisan teams, allowing observers during counting, and maintaining chain-of-custody procedures.
CISA Support and Limitations
CISA offers a suite of no-cost, voluntary cybersecurity services to election officials. These services include:
However, the agency's capacity has been reduced. In 2025, as part of cost-saving efforts, CISA terminated federally funded activities supporting the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC). The EI-ISAC was not mentioned in the new plan. Security experts have warned that these cuts impacted the agency’s efforts to secure critical election infrastructure.
The Trump administration cut approximately 1,000 employees from CISA and slashed $10 million from two cybersecurity initiatives, including one dedicated to helping state and local election officials. CISA has also gone the entirety of Trump’s second term without a Senate-confirmed director, cycling through a series of acting leaders.
Official Reactions and Criticisms
Election officials from both parties have criticized the plan's timing and scope, calling it inadequate and belated. They said the administration gutted the agency’s election security work last year, forcing states to pay for private services. Homeland Security Secretary Markwayne Mullin had originally promised to release the plan by mid-August.
Nevada’s Democratic Secretary of State Cisco Aguilar said, "For them to come in five weeks before the election, yeah, nice effort." He added he would have liked more federal funding for cybersecurity rather than Nevada taxpayers covering the cost. Minnesota Secretary of State Scott Simon expects to spend roughly $250,000 on private vendors for penetration testing.
Shenna Bellows, the Democratic secretary of state in Maine, said communications with CISA had been sporadic and irregular, to say the least. She noted that trust with federal officials had been broken with the cuts and called for restored intelligence briefings on foreign adversary threats. In contrast, Kris Warner, the Republican secretary of state in West Virginia, said some of CISA’s no-cost assistance, like website reviews, had been continual throughout the Trump administration.
Election officials are urged to prioritize voter registration database security by implementing multifactor authentication for all access and to leverage CISA’s no-cost services such as vulnerability scanning and tabletop exercises.





