
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
Democrats on the House Homeland Security Committee have introduced legislation to require the Cybersecurity and Infrastructure Security Agency to produce an assessment of agency’s ability to carry out its mission with current staffing levels and resources.
Summary
“As cyber threats grow more sophisticated and technologies like artificial intelligence and quantum computing reshape the threat landscape, Congress needs a clear accounting of whether CISA has the workforce, skills, and resources required to keep Americans safe and enable mission delivery. This legislation will identify critical gaps and give Congress concrete information to address them,” Rep. James Walkinshaw (D-VA) said in a Sept.
21 release on the bill. Walkinshaw introduced the CISA Force Structure Assessment Act on Sept. 21.
The bill is co-sponsored by House Homeland Security ranking member Bennie Thompson (D-MS) and cyber subcommittee Chairwoman Delia Ramirez (D-IL). The bill tasks the CISA Director with producing a “force structure assessment” on the ability of the agency to carry out its mission and to produce recommendations for the House and Senate Homeland Security Committees to address gaps. CISA was tasked with producing a force assessment in the fiscal 2021 National Defense Authorization Act .
That assessment required CISA to evaluate its capabilities and identify gaps where the agency needs more resources and was a priority for former Rep. Jim Langevin (D-RI), who as a significant voice on Capitol Hill for cybersecurity issues. Langevin was a member of the Cyberspace Solarium Commission, which advocated for the 2021 NDAA review and a number of other provisions in the major defense policy law to strengthen CISA.
Walkinshaw’s bill builds on the NDAA provision by outlining requirements for CISA to provide information on the “resources and total number of personnel necessary to carry out the mission of CISA, including an assessment of whether all personnel have the needed training and accredited, industry-recognized certifications for existing work roles,” according to the bill text. The legislation would require the CISA Director to provide details on the number of personnel and resources needed to carry out specific responsibilities, including securing federal information systems, support for state and local governments and risks associated with emerging technologies. The bill also requires CISA to assess the workforce and resources the agency needs to provide support for critical infrastructure and operational technology systems, perform threat hunting and engage with international partners, as a part of the force structure assessment.
CISA would be required to consult with critical infrastructure owners and operators, federal partners, state and local governments and information-sharing organizations when producing the assessment, according to the bill text. The legislation comes as Democrats have raised concerns over CISA’s workforce reductions since the beginning of the second Trump administration. Walkinshaw led an Aug.
20 letter urging the Government Accountability Office to produce a report on CISA’s workforce cuts since January 2025. Thompson said in a statement, “After Trump has spent the past two years targeting and slashing CISA’s workforce, we need the agency to assess if it has right personnel in place to fulfill its mission.” CISA provided details to Thompson in January on the agency’s workforce numbers from Jan. 20, 2025 to Dec.
13, 2025. The chart showed the number of employees dropped from 3,387 employees to 2,389 individuals in the first year of the second Trump administration. CISA announced a hiring spree in June to bring on 329 employees and give out 180 job offers by the end of June.
CISA Acting Director Nick Andersen provided an update on a Sept. 9 fireside chat at the Billington Cybersecurity Summit.
KazaSec's take
AI-related security incidents are a genuinely new category — prompt injection, model manipulation, and data leakage through an LLM integration don't map cleanly onto traditional application security testing, and are worth assessing deliberately rather than assuming existing controls already cover them.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.