Opportunity
Federal Register #1670-0035
CISA Information Collection Request for Vulnerability Assessments of Critical Infrastructure
Buyer
Cybersecurity and Infrastructure Security Agency, Department of Homeland Security
Posted
August 11, 2026
Respond By
September 10, 2026
Identifier
1670-0035
NAICS
541512, 541519
This opportunity involves the Cybersecurity and Infrastructure Security Agency (CISA), under the Department of Homeland Security, seeking public comment on its ongoing information collection for vulnerability assessments of critical infrastructure. - Government Buyer: - U.S. Department of Homeland Security (DHS) - Cybersecurity and Infrastructure Security Agency (CISA) - Purpose: - Extension of information collection activities for voluntary vulnerability assessments - Focused on state, local, tribal, territorial governments, and private sector organizations - Products/Services Requested: - Voluntary, web-based security and resiliency assessments - Collection of data on security posture, business alignment, and dependencies - Use of automated electronic questionnaires and assessment tools - Notable Requirements: - No specific OEMs or vendors are involved; this is not a procurement of products - Participation is voluntary - Recent transition of cyber-centric questionnaires to a separate system, reducing respondent burden and cost - Data supports planning, risk identification, mitigation, and grant determinations - Estimated annual burden: 1,100 respondents, 7,150.5 hours total - Assessments conducted by CISA Protective Security Advisors and Cybersecurity Advisors
Description
The Infrastructure Security Division within the Cybersecurity and Infrastructure Security Agency (CISA) is submitting an information collection request to the Office of Management and Budget for review and clearance. This request is an extension of a previously cleared information collection related to vulnerability assessments, with an expiration date of November 30, 2026. The assessments are voluntary, web-based evaluations of critical infrastructure entities' security posture, used to determine protective and resilience measures. The data collected supports planning, risk identification, mitigation, and decision-making processes for critical infrastructure security and resilience.