Security2 publishers2 min readPublished
Certification rules slow election-system patching, CISA's 2026 security plan says
CISA's 2026 election security plan names outdated certification rules as one of three problems in how election system flaws get fixed. The attack path it describes starts at a compromised office inbox or workstation and moves laterally into those systems.
The Watch · Security desk

What happened
- Homeland Security Secretary Markwayne Mullin tasked CISA in July with the 2026 Election Infrastructure Security Plan, which covers cyber and physical threats and CISA's free services.
- The plan says structural constraints in the certification ecosystem limit vendors' ability to release patches and keep election offices from applying them quickly.
- CISA says election infrastructure is often reachable from general enterprise networks, so an attacker who compromises office email or a workstation can move laterally.
- CISA says hackers have tried to breach voter registration systems in all 50 states and were confirmed to have succeeded in at least 20.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Ordinary office IT sets the exposure of certified election systems: a phished inbox is a documented route to machines whose fixes certification slows.
- decision Until patching and certification are aligned as CISA recommends, an official holding a security update has to weigh installing it against the system's certification status.
- constraint Local officials' leverage over vendors is persuasion: the plan asks them to encourage CVE IDs, SBOMs and prompt notice of stolen source code.
CISA's proposed fix is to align patch management with certification requirements, so security updates can be applied in real time without affecting a system's certification [7]. SecurityWeek's account of the plan does not say who would change those requirements or when [7].
Certification is one of three problems the plan names. The other two are inconsistent vendor transparency about vulnerabilities and patch status, and the cybersecurity immaturity of many state, local, tribal and territorial networks that host election systems [6]. CISA's own assessments show those election offices often struggle with basic cyber hygiene and vulnerability remediation [4].
So the plan supports a structural explanation for part of the gap. I think it holds for certified election systems that lag on vendor fixes. It explains less about the first step of the intrusion CISA describes, a compromise of office email or a workstation on the general enterprise network [5]. Remediation there is the local work CISA's assessments say offices struggle with [4].
For the count, CISA recommends paper ballots and manual post-election audits [8]. A hand audit does not depend on the tabulator's patch level [8].
The voter registration figures cover reports from the past decade, and CISA calls registration databases attractive targets for foreign adversaries [10]. Its controls for those databases start with multi-factor authentication, anomaly monitoring and access limited to what each user's job needs [11]. Critical logs are kept for at least a year, and the public online registration and lookup tools are walled off from the master database [11].
Seasonal workers and volunteer poll workers may not get the vetting permanent staff do [15]. CISA says a malicious insider could make unauthorized changes to voter registration databases, ballot definitions, tabulation settings or results reporting [15]. Of 107 election-related security incidents tracked in open-source reporting since January 2022, 96 were bomb threats [13], about 90 percent [14].
More than 10,000 local jurisdictions run US elections, and state and local officials hold primary responsibility for protecting the infrastructure [12]. CISA's part is free help: vulnerability and web application scanning, continuous penetration testing, risk and vulnerability assessments, and decoy systems and canary tokens for spotting intrusions [17]. For the 2026 cycle it is also supporting a no-cost information-sharing platform for fusion centers and state and local election officials [16].
What to watch
- A change to certification rules that lets vendors ship security updates without putting a system's certification at risk, the alignment CISA recommends.
- Election software vendors assigning CVE IDs to flaws and shipping SBOMs, as the plan asks officials to request.
- Any confirmed intrusion into a voter registration database during the 2026 cycle, on top of the at least 20 states CISA counts.