When Election Certification Gets in the Way of a Security Patch
Certification is supposed to establish trust in election technology. CISA now warns that the same process can make a security update harder to release and slower to install.
The agency’s new 2026 Election Infrastructure Security Plan says structural constraints in certification can limit a vendor’s ability to issue patches and prevent system owners from applying them quickly. That turns a familiar patch-management problem into a governance problem: changing the certified system may reduce one security risk while creating compliance or operational uncertainty.
A passed test is not permanent evidence of safety
CISA’s plan calls for patch management and certification requirements to be aligned so security updates can be applied in real time without invalidating certification. It also asks vendors to disclose vulnerabilities and patch status consistently, obtain CVE identifiers, report incidents and provide a software bill of materials with every product.
The recommendation recognises a basic limit of assurance. Certification evaluates a defined product, configuration and point in time. New vulnerabilities, leaked source code and changes in attacker capability arrive afterwards. If the process treats every security update as a threat to certification, the trusted baseline can become an obstacle to removing a known flaw.
Enterprise compromise can become election compromise
CISA says election infrastructure is often reachable from ordinary enterprise networks. An attacker who compromises email, a workstation or an administrative account may be able to move laterally towards registration, reporting or support systems even when the voting equipment itself is not directly exposed to the internet.
The agency says its assessments show that state, local, tribal and territorial election offices frequently struggle with basic cyber hygiene and vulnerability remediation. It highlights outdated certification regimes, inconsistent vendor transparency and uneven security maturity in the networks that host election functions.
Voter registration remains a high-value target
The plan says hackers have attempted to breach voter-registration systems in all 50 states and succeeded in at least 20. This is a historical risk statement, not evidence that an attacker has altered the 2026 vote.
CISA recommends multi-factor authentication, least privilege, anomaly detection, at least one year of critical log retention and separation between public registration or lookup services and the master database. The defensive objective is resilience as well as prevention: an office should be able to detect an unauthorised change, reconstruct it and recover a trusted record.
Paper provides an independent evidence path
The plan recommends paper ballots and manual post-election audits. This is not an argument that paper cannot be mishandled. It is an architectural response to digital uncertainty. A voter-verifiable physical record gives officials an evidence source that does not depend on the same software stack used to cast, tabulate or report results.
Formal chain-of-custody and bipartisan two-person procedures also address insider risk. CISA’s definition spans permanent staff, temporary workers, volunteers, contractors and vendors. Careless insiders may introduce removable media or fall for phishing, while malicious insiders may attempt unauthorised changes to registration, ballot definitions, tabulation or reporting.
Free services only help if offices can use them
CISA’s plan lists voluntary, no-cost support including vulnerability scanning, web-application scanning, risk and vulnerability assessments, continuous penetration testing, exercises, information sharing and defensive decoys. The agency also identifies its ten regional directors as election-security advisers for the 2026 cycle.
What authorities and suppliers should do
- Define an emergency patch route before the next vulnerability. Assign who can approve, test, document and deploy a security update without losing the assurance that certification was meant to provide.
- Separate public services from authoritative records. Registration and lookup portals should not provide a direct path to the master database.
- Retain evidence for at least a year. Protect identity, administrative, database and network logs from the same accounts that operate the system.
- Demand vendor transparency. Contracts should require vulnerability disclosure, fixed-version guidance, incident reporting, component inventories and support timelines.
- Test the paper trail. Manual audit procedures, chain of custody and reconciliation must work under realistic staffing and time pressure.
- Treat ordinary office IT as part of election security. Email, endpoints, remote support and identity infrastructure can become the first stage of a lateral movement path.
BlackTree recently analysed CISA’s guidance on cyber decoys and canary tokens. Those controls can improve detection, but they do not replace patching, segmentation, independent records or a tested recovery process.
Sources
- CISA, 2026 Election Infrastructure Security Plan: Securing the Next 250, published 24 September 2026. CISA provides no publication time.
- US Department of Homeland Security, release announcement, published 24 September 2026. No publication time is provided.
- SecurityWeek, CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks, published 25 September 2026 at 08:39 ET.


