# What the plan is
Agency (CISA) issued a 13-page Election Infrastructure Security Plan for 2026. The document maps the pieces of election infrastructure — voting and processing facilities, voter-registration systems, tabulation systems, and voting hardware — then describes cyber and physical threats officials may face during the midterms and how to respond.
# Threats the plan highlights
# Concrete protections and operational guidance
The plan emphasizes paper ballots and manual post-election audits. It advises jurisdictions to use paper ballots that can be reviewed for transparency and auditability and to conduct post-election manual audits to verify system performance and catch errors before certifying results.
CISA also provides a list of no-cost services election officials can request:
- Risk & Vulnerability Assessments (RVAs): comprehensive evaluations of an entity's security posture that cover internal and external systems, authentication, network architecture, and exploitable pathways, resulting in actionable mitigation steps.
- Vulnerability Scanning: continuous monitoring of internet-accessible network assets (public static IPv4 addresses) with weekly reporting and ad-hoc alerts for urgent issues such as known exploited vulnerabilities.
- Access to CISA's regional directors, designated as Election Security Advisors, to coordinate support across states.
- Use of fusion centers as channels for sharing threat intelligence and risk-assessment data across levels of government.
# How the plan is meant to be used
CISA frames the plan as a playbook election officials can use voluntarily to harden operations against both cyber and physical risks. Services are presented as free and optional, designed to help jurisdictions identify weaknesses and follow through with prioritized mitigation steps.
# Context and criticism included in the document
The article notes a political context: the plan's release follows criticism of CISA's earlier activities. A 2023 House GOP report alleged the agency had expanded into activities labeled as domestic surveillance and content moderation. The new plan is described in the document as a pivot toward election infrastructure protection under the current administration.
# Timing and rollout
The plan was released roughly 40 days before the November midterms. The article states the plan was obtained by The Federalist and will be implemented in full, according to DHS messaging.
# What this means for election officials and the public
Election offices that engage CISA can receive technical assessments and continuous scanning at no cost, access regional advisors, and integrate threat reports via fusion centers. For jurisdictions that lack dedicated cybersecurity staff or budget, these services could fill gaps in monitoring and vulnerability identification. The plan recommends simple, concrete audits and paper-based workflows that increase transparency in close or contested contests.
# Bottom line