CISA

Cybersecurity and Infrastructure Security Agency (USA)

US-Behörde für Cyber- und Infrastruktursicherheit

CISA is the civilian cybersecurity agency of the USA, located within the Department of Homeland Security. It protects critical infrastructure, coordinates national incident handling and operates the globally noted Known Exploited Vulnerabilities catalogue (KEV). It is also the governmental sponsor of the CVE programme.

History & facts. CISA was created in 2018 as a standalone agency and quickly became a central voice of civilian cyber defence — with services such as the KEV catalogue, which not only lists vulnerabilities but sets binding patch deadlines for federal agencies. Since early 2025, however, the agency has lost around a third of its workforce through downsizing, and further budget and staff cuts are on the table for the following years. Outlook & recommendation. The developments at CISA — like the near-shutdown of the CVE programme in 2025 — show how vulnerable globally used, state-funded security infrastructure is to budget cycles. In practice this means not relying on a single source: the KEV catalogue remains valuable but should be combined with EPSS, vendor advisories and European sources such as the EUVD.
CISA — Cybersecurity and Infrastructure Security Agency (USA)