Developer docs
API playgroundTry for free, no card

Search company profiles

Cybersecurity and Infrastructure Security Agency

Full company profile

uuid0000rm8

Namestring
Cybersecurity and Infrastructure Security Agency
Legal namestring
Cybersecurity and Infrastructure Security Agency
Websiteurl
cisa.gov
Company typeenum
Public
Founded yearint
2018
Descriptiontext

The Cybersecurity and Infrastructure Security Agency (CISA) is the U.S. federal government's operational cybersecurity defense agency and national coordinator for critical infrastructure security and resilience, operating as a component of the Department of Homeland Security. Established in 2018 by replacing the National Protection and Programs Directorate, CISA serves federal civilian executive branch agencies, approximately 19,000 state/local/tribal/territorial (SLTT) governments, 16 critical infrastructure sectors, and educational institutions through free cybersecurity services including vulnerability scanning, assessments, training, tabletop exercises, and incident response coordination.

CISA's technology platform spans several interconnected systems: the Known Exploited Vulnerabilities (KEV) Catalog for vulnerability prioritization, the Continuous Diagnostics and Mitigation (CDM) Program providing dashboards for federal civilian networks, the Joint Cyber Defense Collaborative (JCDC) for public-private threat sharing, the CISA Gateway for integrated federal agency authentication and tools, and the StopRansomware.gov portal. The agency also operates the CIRCIA cyber incident reporting framework and publishes Binding Operational Directives (BODs) that mandate federal agency actions, including BOD 26-04 establishing 3-day remediation deadlines for critical vulnerabilities.

CISA's business model is fundamentally different from commercial cybersecurity vendors: it operates as a federally funded agency with an approximately $2.8 billion annual operating budget sourced through congressional appropriations, with all services provided free to eligible organizations. The agency employs a multi-channel go-to-market including ten regional offices, regulatory enforcement via BODs, community coordination through JCDC, and a $100 million planned Cyber Technology Services contract. Revenue is concentrated from a single source (U.S. Congress) rather than commercial customers, with non-appropriated funding streams including the $1 billion State and Local Cybersecurity Grant Program administered jointly with FEMA.

Short descriptiontext

CISA is the U.S. federal government's cybersecurity defense agency within DHS, providing no-cost cybersecurity services, vulnerability management, and incident response coordination to federal civilian agencies, 19,000+ SLTT governments, and 16 critical infrastructure sectors. Operates with an approximately $2.8 billion annual congressional budget and statutory authority to issue binding cybersecurity directives.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1,001–5,000
akta.pro rankint
HeadquartersWashington, United States
HQ citystring
Washington
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices4 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
federal cybersecurity services, critical infrastructure protection, vulnerability management, incident response coordination, cyber threat intelligence
Industry4 codes
1Critical Infrastructure Protection (CIP) & NERC-CIP Compliance
CodeHDADAJACPrimaryYes
2Security Governance, Risk & Compliance (GRC) Advisory
CodeBPAKADAGPrimaryNo
3Security Systems Monitoring & Dispatch (SOC/Remote Guarding)
CodeIMAIAEAFPrimaryNo
4Industrial & Critical Infrastructure Guarding (Utilities, Plants, Data Centers)
CodeBPAKAAADPrimaryNo
NAICS code3 codes
  • Regulation and Administration of Communications, Electric, Gas, and Other Utilities92613
  • Security Systems Services (except Locksmiths)561621
  • Justice, Public Order, and Safety Activities922
SIC code2 codes
  • Services-Computer Programming, Data Processing, Etc.7370
  • Communications Services, Nec4899
Product category
Government Cybersecurity Services
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model2 records
1Congressional Appropriations
TypeManaged Services
Description

CISA operates as a federal government agency funded through annual congressional appropriations managed by the Department of Homeland Security. FY2024 budget approximately $2.8 billion annual operating budget managed by Acting CFO Elizabeth Jackson.

cisa.gov
2State and Local Cybersecurity Grant Program
TypeLicensing Royalties
Description

$1 billion federal initiative jointly administered with FEMA providing funding to state, local, and territorial governments for cybersecurity posture improvements. Reauthorized through 2033 via PILLAR Act but pending new funding allocation.

govtech.com
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels5 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales
Pricing details1 tier
1Free cybersecurity services for eligible government and critical infrastructure entities
ModelFreemiumBilling cadenceAnnual
Notes

No-cost Cyber Services available to federal civilian agencies, SLTT governments, and critical infrastructure operators. Includes vulnerability scanning, assessments, training, and incident response support.

cisa.gov
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

The Cybersecurity and Infrastructure Security Agency (CISA) is the operational lead for federal cybersecurity and the national coordinator for critical infrastructure security and resilience. It provides cyber defense capabilities, vulnerability management, threat intelligence sharing, risk assessments, incident response support, and emergency communications services to federal civilian executive branch agencies, state/local/tribal/territorial governments, and critical infrastructure owners and operators.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • 30,000+ cyber incidents triaged governmentwide in 2025
+3 more records
Product overview1 text field

CISA operates as America's cyber defense agency offering a portfolio of interconnected cybersecurity products and services. The core offerings include StopRansomware.gov as the public-facing ransomware resource portal, the Joint Cyber Defense Collaborative (JCDC) for public-private threat sharing, and the CISA Services Catalog providing access to assessments, tools, and training. CISA Gateway provides integrated data tools for federal agencies, while the CDM Program offers dynamic cybersecurity tools and dashboards. Supporting resources include the KEV Catalog for vulnerability prioritization, over 100 CISA Tabletop Exercise Packages for stakeholder exercises, and the CIRCIA reporting framework for critical infrastructure incident reporting. These products work together to provide end-to-end cyber defense capabilities spanning prevention, detection, response, and recovery.

Product and service9 records
1StopRansomware.gov
CategoryCybersecurity Resource Portal
Description

A whole-of-government online resource hub consolidating ransomware defense guidance, alerts, and response resources for organizations and businesses.

2Joint Cyber Defense Collaborative (JCDC)
CategoryPublic-Private Partnership Platform
Description

A public-private cyber defense collaborative that enables proactive planning, information sharing, and joint cyber incident response between CISA, federal partners, and private sector companies across the cyber ecosystem.

3CISA Services Catalog
CategoryGovernment Service Catalog
Description

A centralized catalog documenting the cybersecurity and infrastructure security services CISA offers at no cost to federal civilian agencies, state/local/tribal/territorial governments, and critical infrastructure partners.

4CISA Tabletop Exercise Packages (CTEP)
CategoryTraining and Exercise Service
Description

A set of self-contained, ready-to-use tabletop exercise packages that organizations can run internally to test and strengthen their cybersecurity and infrastructure resilience plans.

5Continuous Diagnostics and Mitigation (CDM) Program
CategoryContinuous Monitoring Program
Description

A federal program providing federal civilian agencies with automated continuous diagnostics, vulnerability identification, and risk-prioritization capabilities to strengthen network security posture.

6Known Exploited Vulnerabilities (KEV) Catalog
CategoryVulnerability Intelligence Catalog
Description

An authoritative, curated catalog of vulnerabilities for which there is evidence of active exploitation, serving as the basis for remediation requirements on federal civilian agencies under Binding Operational Directive 22-01.

7CISA Cybersecurity Advisories and Alerts
CategoryThreat Intelligence Publications
Description

Timely threat intelligence products including advisories, alerts, malware analyses, and joint cybersecurity advisories disseminated to government and industry partners.

8CIRCIA Cyber Incident Reporting Portal
CategoryCyber Incident Reporting Program
Description

A regulatory reporting program under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) through which covered critical infrastructure entities report covered cyber incidents to CISA.

9Emergency Communications Services
CategoryEmergency Communications Program
Description

Programs supporting emergency communications interoperability, priority services, and 911/Next Generation 911 capabilities for federal, state, local, tribal, and territorial partners.

Scale indicator8 records

Each record includes

Type, Value, Description, Source

Partnership9 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-24
Description

White House executive order directing CISA to work with NIST on post-quantum cryptography migration (2030 key establishment, 2031 digital signatures) and State Department on promoting NIST-standardized PQC algorithms globally.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-09
Description

Partnership with Center for Internet Security to operate MS-ISAC providing threat intelligence and incident response to approximately 19,000 SLTT government organizations. MS-ISAC membership defunded under Trump administration but restoration legislation (Guaranteeing Universal Access to Cybersecurity Act) proposed with $50 million annual authorization.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-02
Description

Under Trump AI executive order, CISA coordinating with NSA and Treasury Department to establish AI cybersecurity clearinghouse for vulnerability scanning and remediation coordination across critical infrastructure.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-05-13
Description

CISA and G7 partners issued joint guidance on AI software supply chain security promoting SBOM standards for AI systems to enhance transparency and cyber resilience.

5Five Eyes Alliance (CISA, NCSC-UK, ASD-ACSC, CCCS, NCSC-NZ)
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-05-01
Description

Joint advisory on agentic AI security with Five Eyes cybersecurity agencies warning that autonomous AI systems expand attack surfaces and recommending careful deployment with human oversight and zero trust principles.

letsdatascience.com
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-04-29
Description

Joint guidance 'Adapting Zero Trust Principles to Operational Technology' developed with four federal partner agencies to help OT owners integrate zero trust security amid growing cyber threats from Volt Typhoon and other actors.

7Joint Cyber Defense Collaborative (JCDC) Partners
Strategic tierCoreTypeStrategic or Co-development Partner
Description

JCDC unifies cyber defenders from government agencies, industry partners, and international organizations worldwide. Includes major technology companies, critical infrastructure operators, and allied nation cybersecurity agencies for synchronized cyber defense planning and response.

cisa.gov
8OMB and Federal Agencies (TIC 3.0 Initiative)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

CISA collaborating with OMB on Trusted Internet Connections (TIC) 3.0 Initiative providing zero trust architecture guidance for federal civilian agencies migrating from legacy perimeter-based security models.

cisa.gov
9Federal Civilian Agencies (Cyber Technology Services)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

CISA planning $100 million Cyber Technology Services contract to support threat-hunting operations and cybersecurity capabilities, primarily based in Arlington, Virginia, anticipated award late 2027.

govconwire.com
Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

The NSA is the U.S. intelligence agency responsible for signals intelligence and information security, including the cybersecurity mission that overlaps with CISA. While NSA focuses on foreign signals intelligence and offensive operations, CISA leads defensive coordination across federal and critical infrastructure, making them complementary sister agencies within the broader U.S. national cyber mission.

TypeDirect peer
Description

The NCSC is the UK's national technical authority for cyber security, providing incident response, threat intelligence, and guidance to government and critical infrastructure, paralleling CISA's mandate. The two agencies co-issue Five Eyes advisories on agentic AI and supply chain security, making them the most direct international functional equivalent.

TypeDirect peer
Description

ACSC, part of the Australian Signals Directorate, leads Australia's national cyber defense and partners with CISA under the Five Eyes alliance. It serves a similar coordinating function for federal agencies and critical infrastructure in Australia, making it a direct international peer.

TypeDirect peer
Description

The CCCS is Canada's national cyber authority under the Communications Security Establishment, providing unified cyber defense for government and critical infrastructure. It is a Five Eyes partner with CISA and serves as Canada's functional equivalent, with comparable incident response, advisories, and threat-sharing missions.

5Germany's BSI (Bundesamt für Sicherheit in der Informationstechnik)
TypeDirect peer
Description

Germany's federal cybersecurity authority provides national cyber defense coordination, certification (BSI standards), and critical infrastructure protection analogous to CISA. As a major EU member-state cyber agency, BSI is a direct international peer in mandate and scope.

TypeBroad incumbent
Description

The FBI Cyber Division leads U.S. domestic cyber criminal investigations and co-authored the #StopRansomware Guide with CISA. It is a complementary law-enforcement peer that partners with CISA on incident response but operates under different authorities (criminal investigation vs. civilian defense).

7European Union Agency for Cybersecurity (ENISA)
TypeDirect peer
Description

ENISA is the EU's dedicated cybersecurity agency coordinating cyber defense across member states, analogous to CISA at the supranational level. It supports NIS2 implementation, cert frameworks, and pan-EU cyber exercises, paralleling CISA's role for the United States.

TypeDirect peer
Description

CSA is Singapore's national cybersecurity authority, coordinating cyber defense for government and critical infrastructure sectors. As a small advanced-economy peer, CSA is a direct international equivalent in mandate and operational scope.

9New Zealand National Cyber Security Centre (NCSC-NZ)
TypeDirect peer
Description

NCSC-NZ is part of the Government Communications Security Bureau and serves as New Zealand's lead agency for cyber defense, collaborating with CISA as a Five Eyes partner on shared advisories including the agentic AI joint guidance.

TypeOthers
Description

CIS is a nonprofit partner that operates the MS-ISAC for CISA, providing threat intelligence and incident response to ~19,000 SLTT organizations. It is a core operational partner rather than a competitor, but its closest functional analog to the services CISA provides to state and local governments.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers5 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment6 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

Integration1 record

Each record includes

Title, Type, Description, Source

AI capability9 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature5 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles12 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
Compliance1 record

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment2 records

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Cybersecurity and Infrastructure Security Agency

Government Cybersecurity Servicescisa.gov

CISA is the U.S. federal government's cybersecurity defense agency within DHS, providing no-cost cybersecurity services, vulnerability management, and incident response coordination to federal civilian agencies, 19,000+ SLTT governments, and 16 critical infrastructure sectors. Operates with an approximately $2.8 billion annual congressional budget and statutory authority to issue binding cybersecurity directives.

What Cybersecurity and Infrastructure Security Agency does

The Cybersecurity and Infrastructure Security Agency (CISA) is the U.S. federal government's operational cybersecurity defense agency and national coordinator for critical infrastructure security and resilience, operating as a component of the Department of Homeland Security. Established in 2018 by replacing the National Protection and Programs Directorate, CISA serves federal civilian executive branch agencies, approximately 19,000 state/local/tribal/territorial (SLTT) governments, 16 critical infrastructure sectors, and educational institutions through free cybersecurity services including vulnerability scanning, assessments, training, tabletop exercises, and incident response coordination.

CISA's technology platform spans several interconnected systems: the Known Exploited Vulnerabilities (KEV) Catalog for vulnerability prioritization, the Continuous Diagnostics and Mitigation (CDM) Program providing dashboards for federal civilian networks, the Joint Cyber Defense Collaborative (JCDC) for public-private threat sharing, the CISA Gateway for integrated federal agency authentication and tools, and the StopRansomware.gov portal. The agency also operates the CIRCIA cyber incident reporting framework and publishes Binding Operational Directives (BODs) that mandate federal agency actions, including BOD 26-04 establishing 3-day remediation deadlines for critical vulnerabilities.

CISA's business model is fundamentally different from commercial cybersecurity vendors: it operates as a federally funded agency with an approximately $2.8 billion annual operating budget sourced through congressional appropriations, with all services provided free to eligible organizations. The agency employs a multi-channel go-to-market including ten regional offices, regulatory enforcement via BODs, community coordination through JCDC, and a $100 million planned Cyber Technology Services contract. Revenue is concentrated from a single source (U.S. Congress) rather than commercial customers, with non-appropriated funding streams including the $1 billion State and Local Cybersecurity Grant Program administered jointly with FEMA.

Cybersecurity and Infrastructure Security Agency firmographics

Firmographics
Name
Cybersecurity and Infrastructure Security Agency
Legal name
Cybersecurity and Infrastructure Security Agency
Website
https://cisa.gov
Company type
Public
Founded year
2018
Operating status
Operating
Headcount range
1,001–5,000 employees
Short description
CISA is the U.S. federal government's cybersecurity defense agency within DHS, providing no-cost cybersecurity services, vulnerability management, and incident response coordination to federal civilian agencies, 19,000+ SLTT governments, and 16 critical infrastructure sectors. Operates with an approximately $2.8 billion annual congressional budget and statutory authority to issue binding cybersecurity directives.
Ownership category
akta.pro rank

Cybersecurity and Infrastructure Security Agency industry classification

Industry
Product category
Government Cybersecurity Services
NAICS
Regulation and Administration of Communications, Electric, Gas, and Other Utilities (92613), Security Systems Services (except Locksmiths) (561621), Justice, Public Order, and Safety Activities (922)
SIC
Services-Computer Programming, Data Processing, Etc. (7370), Communications Services, Nec (4899)
akta.pro primary industry
Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC)
akta.pro secondary industries
Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG), Security Systems Monitoring & Dispatch (SOC/Remote Guarding) (IMAIAEAF), Industrial & Critical Infrastructure Guarding (Utilities, Plants, Data Centers) (BPAKAAAD)

Keywords

  • Federal cybersecurity services
  • Critical infrastructure protection
  • Vulnerability management
  • Incident response coordination
  • Cyber threat intelligence

Where Cybersecurity and Infrastructure Security Agency is headquartered

Location

Headquarters

HQ city
Washington
HQ country
United States
HQ region
North America

Offices4 records

Markets served

Cybersecurity and Infrastructure Security Agency business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales

Revenue model

  1. Congressional Appropriations: CISA operates as a federal government agency funded through annual congressional appropriations managed by the Department of Homeland Security. FY2024 budget approximately $2.8 billion annual operating budget managed by Acting CFO Elizabeth Jackson.
  2. State and Local Cybersecurity Grant Program: $1 billion federal initiative jointly administered with FEMA providing funding to state, local, and territorial governments for cybersecurity posture improvements. Reauthorized through 2033 via PILLAR Act but pending new funding allocation.

Pricing tiers

ModelBillingPrice
FreemiumAnnualFree cybersecurity services for eligible government and critical infrastructure entities

Go-to-market motion3 records

Distribution channels5 records

Marketing channels7 records

Cybersecurity and Infrastructure Security Agency product offering

Product offering

Core offering

The Cybersecurity and Infrastructure Security Agency (CISA) is the operational lead for federal cybersecurity and the national coordinator for critical infrastructure security and resilience. It provides cyber defense capabilities, vulnerability management, threat intelligence sharing, risk assessments, incident response support, and emergency communications services to federal civilian executive branch agencies, state/local/tribal/territorial governments, and critical infrastructure owners and operators.

Product overview

CISA operates as America's cyber defense agency offering a portfolio of interconnected cybersecurity products and services. The core offerings include StopRansomware.gov as the public-facing ransomware resource portal, the Joint Cyber Defense Collaborative (JCDC) for public-private threat sharing, and the CISA Services Catalog providing access to assessments, tools, and training. CISA Gateway provides integrated data tools for federal agencies, while the CDM Program offers dynamic cybersecurity tools and dashboards. Supporting resources include the KEV Catalog for vulnerability prioritization, over 100 CISA Tabletop Exercise Packages for stakeholder exercises, and the CIRCIA reporting framework for critical infrastructure incident reporting. These products work together to provide end-to-end cyber defense capabilities spanning prevention, detection, response, and recovery.

Differentiator

Problem solved

Functional benefit

Products and services

  • StopRansomware.gov A whole-of-government online resource hub consolidating ransomware defense guidance, alerts, and response resources for organizations and businesses.
  • Joint Cyber Defense Collaborative (JCDC) A public-private cyber defense collaborative that enables proactive planning, information sharing, and joint cyber incident response between CISA, federal partners, and private sector companies across the cyber ecosystem.
  • CISA Services Catalog A centralized catalog documenting the cybersecurity and infrastructure security services CISA offers at no cost to federal civilian agencies, state/local/tribal/territorial governments, and critical infrastructure partners.
  • CISA Tabletop Exercise Packages (CTEP) A set of self-contained, ready-to-use tabletop exercise packages that organizations can run internally to test and strengthen their cybersecurity and infrastructure resilience plans.
  • Continuous Diagnostics and Mitigation (CDM) Program A federal program providing federal civilian agencies with automated continuous diagnostics, vulnerability identification, and risk-prioritization capabilities to strengthen network security posture.
  • Known Exploited Vulnerabilities (KEV) Catalog An authoritative, curated catalog of vulnerabilities for which there is evidence of active exploitation, serving as the basis for remediation requirements on federal civilian agencies under Binding Operational Directive 22-01.
  • CISA Cybersecurity Advisories and Alerts Timely threat intelligence products including advisories, alerts, malware analyses, and joint cybersecurity advisories disseminated to government and industry partners.
  • CIRCIA Cyber Incident Reporting Portal A regulatory reporting program under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) through which covered critical infrastructure entities report covered cyber incidents to CISA.
  • Emergency Communications Services Programs supporting emergency communications interoperability, priority services, and 911/Next Generation 911 capabilities for federal, state, local, tribal, and territorial partners.

Quantifiable outcome

  • 30,000+ cyber incidents triaged governmentwide in 2025
  • +3 more outcomes

Companies that use Cybersecurity and Infrastructure Security Agency

Customer profile

Named customers5 records

Segments6 records

Ideal customer profiles3 records

Cybersecurity and Infrastructure Security Agency technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Integration1 record

AI capability9 records

Feature5 records

Cybersecurity and Infrastructure Security Agency partnerships and signals

Strategic signal

Partnerships

Nine partnerships are on record, tiered core.

  • NIST and State DepartmentcoreStrategic or Co-development Partner · 24 June 2026White House executive order directing CISA to work with NIST on post-quantum cryptography migration (2030 key establishment, 2031 digital signatures) and State Department on promoting NIST-standardized PQC algorithms globally.
  • Center for Internet Security (CIS)coreStrategic or Co-development Partner · 9 June 2026Partnership with Center for Internet Security to operate MS-ISAC providing threat intelligence and incident response to approximately 19,000 SLTT government organizations. MS-ISAC membership defunded under Trump administration but restoration legislation (Guaranteeing Universal Access to Cybersecurity Act) proposed with $50 million annual authorization.
  • NSA and Treasury Department (AI Cybersecurity Clearinghouse)coreStrategic or Co-development Partner · 2 June 2026Under Trump AI executive order, CISA coordinating with NSA and Treasury Department to establish AI cybersecurity clearinghouse for vulnerability scanning and remediation coordination across critical infrastructure.
  • G7 PartnerscoreStrategic or Co-development Partner · 13 May 2026CISA and G7 partners issued joint guidance on AI software supply chain security promoting SBOM standards for AI systems to enhance transparency and cyber resilience.
  • Five Eyes Alliance (CISA, NCSC-UK, ASD-ACSC, CCCS, NCSC-NZ)coreStrategic or Co-development Partner · 1 May 2026Joint advisory on agentic AI security with Five Eyes cybersecurity agencies warning that autonomous AI systems expand attack surfaces and recommending careful deployment with human oversight and zero trust principles.
  • Department of War, Department of Energy, FBI, Department of StatecoreStrategic or Co-development Partner · 29 April 2026Joint guidance 'Adapting Zero Trust Principles to Operational Technology' developed with four federal partner agencies to help OT owners integrate zero trust security amid growing cyber threats from Volt Typhoon and other actors.
  • Joint Cyber Defense Collaborative (JCDC) PartnerscoreStrategic or Co-development PartnerJCDC unifies cyber defenders from government agencies, industry partners, and international organizations worldwide. Includes major technology companies, critical infrastructure operators, and allied nation cybersecurity agencies for synchronized cyber defense planning and response.
  • OMB and Federal Agencies (TIC 3.0 Initiative)coreStrategic or Co-development PartnerCISA collaborating with OMB on Trusted Internet Connections (TIC) 3.0 Initiative providing zero trust architecture guidance for federal civilian agencies migrating from legacy perimeter-based security models.
  • Federal Civilian Agencies (Cyber Technology Services)coreStrategic or Co-development PartnerCISA planning $100 million Cyber Technology Services contract to support threat-hunting operations and cybersecurity capabilities, primarily based in Arlington, Virginia, anticipated award late 2027.

Scale indicators8 records

Recent moves6 records

Expansion highlights6 records

Cybersecurity and Infrastructure Security Agency competitors and assessment

Company assessment

Broad incumbents

  • National Security Agency (NSA): The NSA is the U.S. intelligence agency responsible for signals intelligence and information security, including the cybersecurity mission that overlaps with CISA. While NSA focuses on foreign signals intelligence and offensive operations, CISA leads defensive coordination across federal and critical infrastructure, making them complementary sister agencies within the broader U.S. national cyber mission.
  • FBI Cyber Division: The FBI Cyber Division leads U.S. domestic cyber criminal investigations and co-authored the #StopRansomware Guide with CISA. It is a complementary law-enforcement peer that partners with CISA on incident response but operates under different authorities (criminal investigation vs. civilian defense).

Direct peers

  • UK National Cyber Security Centre (NCSC): The NCSC is the UK's national technical authority for cyber security, providing incident response, threat intelligence, and guidance to government and critical infrastructure, paralleling CISA's mandate. The two agencies co-issue Five Eyes advisories on agentic AI and supply chain security, making them the most direct international functional equivalent.
  • Australian Cyber Security Centre (ASD/ACSC): ACSC, part of the Australian Signals Directorate, leads Australia's national cyber defense and partners with CISA under the Five Eyes alliance. It serves a similar coordinating function for federal agencies and critical infrastructure in Australia, making it a direct international peer.
  • Canadian Centre for Cyber Security (CCCS): The CCCS is Canada's national cyber authority under the Communications Security Establishment, providing unified cyber defense for government and critical infrastructure. It is a Five Eyes partner with CISA and serves as Canada's functional equivalent, with comparable incident response, advisories, and threat-sharing missions.
  • Germany's BSI (Bundesamt für Sicherheit in der Informationstechnik): Germany's federal cybersecurity authority provides national cyber defense coordination, certification (BSI standards), and critical infrastructure protection analogous to CISA. As a major EU member-state cyber agency, BSI is a direct international peer in mandate and scope.
  • European Union Agency for Cybersecurity (ENISA): ENISA is the EU's dedicated cybersecurity agency coordinating cyber defense across member states, analogous to CISA at the supranational level. It supports NIS2 implementation, cert frameworks, and pan-EU cyber exercises, paralleling CISA's role for the United States.
  • Cybersecurity Agency of Singapore (CSA): CSA is Singapore's national cybersecurity authority, coordinating cyber defense for government and critical infrastructure sectors. As a small advanced-economy peer, CSA is a direct international equivalent in mandate and operational scope.
  • New Zealand National Cyber Security Centre (NCSC-NZ): NCSC-NZ is part of the Government Communications Security Bureau and serves as New Zealand's lead agency for cyber defense, collaborating with CISA as a Five Eyes partner on shared advisories including the agentic AI joint guidance.

Others

  • Center for Internet Security (CIS): CIS is a nonprofit partner that operates the MS-ISAC for CISA, providing threat intelligence and incident response to ~19,000 SLTT organizations. It is a core operational partner rather than a competitor, but its closest functional analog to the services CISA provides to state and local governments.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks6 records

Key highlights6 records

Customer concentration

Cybersecurity and Infrastructure Security Agency social profiles

Digital presence

Cybersecurity and Infrastructure Security Agency compliance and trust

Trust signal

Compliance1 record

Cybersecurity and Infrastructure Security Agency financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Cybersecurity and Infrastructure Security Agency leadership team

Management profile

Number of profiles

Profiles12 records

Cybersecurity and Infrastructure Security Agency funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Cybersecurity and Infrastructure Security Agency M&A and investment

M&A and investment

M&A

Investments2 records

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Cybersecurity and Infrastructure Security Agency

What does Cybersecurity and Infrastructure Security Agency do?

The Cybersecurity and Infrastructure Security Agency (CISA) is the operational lead for federal cybersecurity and the national coordinator for critical infrastructure security and resilience. It provides cyber defense capabilities, vulnerability management, threat intelligence sharing, risk assessments, incident response support, and emergency communications services to federal civilian executive branch agencies, state/local/tribal/territorial governments, and critical infrastructure owners and operators.

Is Cybersecurity and Infrastructure Security Agency a public or private company?

Cybersecurity and Infrastructure Security Agency is a public company. It is classified as state government owned and is currently operating.

When was Cybersecurity and Infrastructure Security Agency founded?

Cybersecurity and Infrastructure Security Agency was founded in 2018. It employs 1,001 to 5,000 people.

Where is Cybersecurity and Infrastructure Security Agency based?

Cybersecurity and Infrastructure Security Agency is headquartered in Washington, United States, in the North America region.

How does Cybersecurity and Infrastructure Security Agency make money?

Two revenue lines are on record. Congressional Appropriations are the primary driver. The others are state and Local Cybersecurity Grant Program.

Who are Cybersecurity and Infrastructure Security Agency's main competitors?

Broad incumbents on record are National Security Agency (NSA) and FBI Cyber Division. Direct peers are UK National Cyber Security Centre (NCSC), Australian Cyber Security Centre (ASD/ACSC), Canadian Centre for Cyber Security (CCCS), Germany's BSI (Bundesamt für Sicherheit in der Informationstechnik), European Union Agency for Cybersecurity (ENISA), Cybersecurity Agency of Singapore (CSA) and New Zealand National Cyber Security Centre (NCSC-NZ). Center for Internet Security (CIS) is listed as an others.

Does Cybersecurity and Infrastructure Security Agency have an API?

No public API is recorded for Cybersecurity and Infrastructure Security Agency.

What industry is Cybersecurity and Infrastructure Security Agency in?

Cybersecurity and Infrastructure Security Agency's product category is Government Cybersecurity Services. Its primary akta.pro industry code is HDADAJAC, Critical Infrastructure Protection (CIP) & NERC-CIP Compliance, with a secondary code of BPAKADAG, Security Governance, Risk & Compliance (GRC) Advisory. Its NAICS code is 92613 and its SIC code is 7370.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
Medical BuyerUS Senate passes HCCR ActThe Senate passed the Health Care Cybersecurity and Resilience Act on Sept. 30 by unanimous consent. The bipartisan bill improves coordination between HHS and the Cybersecurity and Infrastructure Security Agency to strengthen healthcare cyberattack responses and requires the HHS Secretary to develop a cybersecurity incident response plan.GovtechCybersecurity Awareness Month Puts Basic Defenses on DisplayCISA and the National Cybersecurity Alliance launched Cybersecurity Awareness Month with the theme 'Securing the Next 250,' urging basic defenses like strong passwords and multi-factor authentication. A survey of 5,000 adults found 46% use dictionary words as passwords and 80% use AI tools without security training. The campaign runs through October, emphasizing consistent application of basic protections.Law360Agencies Warn Of Chinese AI Cos. Targeting US ModelsThe Cybersecurity & Infrastructure Security Agency, National Security Administration, and FBI released a report warning that Chinese AI companies are extracting proprietary capabilities from U.S. AI models through a process called distillation. The agencies issued the warning to alert the public and industry about the threat.MintChina Vs Philippines Escalates After Viral Clip Of Philippines' Defence Secy Ridiculing BeijingThe US National Security Agency, Cybersecurity and Infrastructure Security Agency, and FBI issued a Cybersecurity Advisory accusing six Chinese companies of industrial-scale distillation campaigns against American AI firms since late 2024. Chinese Foreign Ministry spokesperson Mao Ning urged the US not to make unfounded accusations against China.The Record from Recorded Future NewsLawmakers call for investigation into impact of CISA staffing cutsMembers of Congress have requested a Government Accountability Office investigation into the impact of staffing cuts at the Cybersecurity and Infrastructure Security Agency (CISA). Lawmakers express concern that the loss of nearly one-third of CISA's workforce, combined with proposed budget reductions, hinders the agency's ability to protect critical infrastructure against evolving cyber threats. Industry leaders and state officials report reduced responsiveness from CISA, raising alarms about national security ahead of the November election.ScworldReport calls for AI sector to be designated critical infrastructureA report by Americans for Responsible Innovation urges the U.S. government to designate the artificial intelligence sector as critical infrastructure to address growing cybersecurity vulnerabilities. The proposal recommends that the Cybersecurity and Infrastructure Security Agency (CISA) lead these efforts, arguing that AI systems are interdependent with other vital sectors and susceptible to cascading failures from attacks.CyberScoopThe push to designate AI as the next critical infrastructure sectorA report by Americans for Responsible Innovation urges the U.S. federal government to designate the artificial intelligence sector as critical infrastructure, proposing the Cybersecurity and Infrastructure Security Agency (CISA) as the lead coordinator. The designation aims to unlock federal cybersecurity resources and address vulnerabilities in AI supply chains that are heavily concentrated in the United States. Experts warn that without such oversight, disruptions to AI systems could have outsized economic consequences given their integration into national security and public services.CisaCISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational StandardsThe Cybersecurity and Infrastructure Security Agency (CISA) released the Logging Reference Architecture, a guidance document for federal civilian executive branch agencies to establish effective logging and visibility standards. Developed in collaboration with the Office of Management and Budget (OMB) and the CISO Council, this framework supports compliance with OMB Memorandum M-26-14 by providing operational checklists and strategies for continuous monitoring and threat response. Federal agencies are required to submit their Agency Logging Plans based on this guidance by November 18, 2026.ScworldCritical vulnerability in Ray framework allows remote code executionThe Cybersecurity and Infrastructure Security Agency (CISA) has issued a mandate requiring US federal agencies to patch a critical remote code execution vulnerability in the open-source Ray framework within three days. The flaw, tracked as CVE-2025-62593 with a CVSS score of 9.4, allows attackers to bypass security checks via Firefox and Safari browsers to execute arbitrary shell code on vulnerable systems. Version 2.52.0 of Ray addresses this issue, which is currently being actively exploited in the wild.ScworldCISA explores single contract for cybersecurity software purchasesThe Cybersecurity and Infrastructure Security Agency (CISA) is exploring a single contract to consolidate its cybersecurity software purchases, potentially managing the $600 million annual spend through an external contractor. Working with the General Services Administration, CISA aims to streamline procurement processes and transition from its current Continuous Diagnostics and Mitigation program to a new Cyber Product List. The agency issued a sources sought notice on August 12 to evaluate acquisition approaches for this initiative.