Policy · 6h ago

CISA Flags Certification Barriers in Election Patching

CISA published its 2026 Election Infrastructure Security Plan, laying out cyber and physical threats to election systems and the services it offers to state, local, tribal, and territorial officials. The plan also says more than 10,000 local jurisdictions run elections while primary responsibility for protection sits with those local operators.

Its key warning is procedural: election software can need a fix, but certification rules can slow vendors from releasing patches and stop system owners from applying them quickly. CISA says that delay is compounded by uneven vendor transparency and weak vulnerability-remediation capacity in many SLTT networks, so a known flaw can stay live long after a fix exists.

For readers running certified or regulated systems, the exposure is not just the bug but the approval path around it. If patching depends on a certification gate, the longest-lived risk may be the period between disclosure and the moment a signed update is actually allowed into production.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-09-25

Editions