Policy · 6h ago
CISA published its 2026 Election Infrastructure Security Plan, laying out cyber and physical threats to election systems and the services it offers to state, local, tribal, and territorial officials. The plan also says more than 10,000 local jurisdictions run elections while primary responsibility for protection sits with those local operators.
Its key warning is procedural: election software can need a fix, but certification rules can slow vendors from releasing patches and stop system owners from applying them quickly. CISA says that delay is compounded by uneven vendor transparency and weak vulnerability-remediation capacity in many SLTT networks, so a known flaw can stay live long after a fix exists.
For readers running certified or regulated systems, the exposure is not just the bug but the approval path around it. If patching depends on a certification gate, the longest-lived risk may be the period between disclosure and the moment a signed update is actually allowed into production.
2 sources covering this story
CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July.
CISA Unveils Election Security Plan Ahead of 2026 Midterms
The CISA plan provides guidance and resources for election officials to secure systems such as voter registration databases and voting machines
Part of the PlainSec briefing for 2026-09-25