Federal News
CISA Ends Mobile App Vetting Program
March 22, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) terminated its Mobile App Vetting (MAV) program in June 2025, which previously provided federal agencies with a standardized mobile application security assessment framework. This termination shifts responsibility to federal agencies and contractors to self-regulate mobile app security by adopting recognized cybersecurity frameworks, implementing continuous monitoring, and maintaining transparency to demonstrate compliance and manage risk. The absence of a centralized vetting program raises concerns about increased cybersecurity vulnerabilities in federal mobile applications, emphasizing the need for procurement professionals to incorporate rigorous security requirements and verification processes in upcoming contracts.
- Federal agencies must now require contractors to align mobile app security practices with established frameworks such as those from the National Institute of Standards and Technology (NIST).
- Procurement officers should update solicitation language to mandate continuous security monitoring and transparency from vendors to mitigate risks previously managed by MAV.
- Industry stakeholders can leverage this shift by offering enhanced mobile app security services and solutions that comply with federal cybersecurity expectations.
- Organizations should be aware that the discontinuation of MAV signals a broader trend toward decentralized cybersecurity responsibility, requiring proactive risk management in contract execution and compliance verification.
The retirement of the MAV Program marks the beginning of an era where industry leaders must set the standards in mobile app security themselves.
— Subho Halder
Shutting down MAV "sends the wrong signal" at a time when threats against federal systems and private companies are growing.
— Rep. Andrew Garbarino
Agencies
Cybersecurity and Infrastructure Security Agency, Department of Homeland Security, House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection, National Institute of Standards and Technology
Vendors
Appknox, Spotify, DoorDash, Nextdoor
Locations
Sources
- Q&A: Mobile app security after MAV - Digital Journal · Digital Journal · Mar 22