Opportunity

Federal Register #1670-0035

CISA Information Collection Request for Vulnerability Assessments of Critical Infrastructure

Buyer

Cybersecurity and Infrastructure Security Agency, Department of Homeland Security

Posted

August 11, 2026

Respond By

September 10, 2026

Identifier

1670-0035

NAICS

541512, 541519

This opportunity involves the Cybersecurity and Infrastructure Security Agency (CISA), under the Department of Homeland Security, seeking public comment on its ongoing information collection for vulnerability assessments of critical infrastructure. - Government Buyer: - U.S. Department of Homeland Security (DHS) - Cybersecurity and Infrastructure Security Agency (CISA) - Purpose: - Extension of information collection activities for voluntary vulnerability assessments - Focused on state, local, tribal, territorial governments, and private sector organizations - Products/Services Requested: - Voluntary, web-based security and resiliency assessments - Collection of data on security posture, business alignment, and dependencies - Use of automated electronic questionnaires and assessment tools - Notable Requirements: - No specific OEMs or vendors are involved; this is not a procurement of products - Participation is voluntary - Recent transition of cyber-centric questionnaires to a separate system, reducing respondent burden and cost - Data supports planning, risk identification, mitigation, and grant determinations - Estimated annual burden: 1,100 respondents, 7,150.5 hours total - Assessments conducted by CISA Protective Security Advisors and Cybersecurity Advisors

Description

The Infrastructure Security Division within the Cybersecurity and Infrastructure Security Agency (CISA) is submitting an information collection request to the Office of Management and Budget for review and clearance. This request is an extension of a previously cleared information collection related to vulnerability assessments, with an expiration date of November 30, 2026. The assessments are voluntary, web-based evaluations of critical infrastructure entities' security posture, used to determine protective and resilience measures. The data collected supports planning, risk identification, mitigation, and decision-making processes for critical infrastructure security and resilience.

View original listing