Senator Mark Warner (D-Va.), vice chairman of the Senate Intelligence Committee, has sent a formal letter to acting CISA Director Nick Andersen demanding detailed organizational charts and workforce data, warning that Trump administration personnel reductions have left the Cybersecurity and Infrastructure Security Agency ill-equipped to support state and local governments heading into the November midterm elections. The full letter and context were first reported by Nextgov/FCW.
Warner's letter—sent around June 16, 2026, with a response deadline of June 26—requests three sets of organizational charts: one reflecting CISA's structure as of January 2025, one from October 2025, and one showing its current configuration. The senator also asked for comprehensive vacancy data and records of state and local cyber support requests and response times dating back to 2023. The goal, plainly stated, is to determine whether workforce attrition has degraded the agency's ability to perform its core mission in the months leading up to a consequential national election. That data trail, if produced, would give Congress a before-and-after picture of how deeply the reductions cut.
The numbers behind Warner's concern are stark. Across CISA's ten regional offices, five directors are currently serving in acting capacities. That proportion—half of the agency's regional leadership in temporary status—raises questions about institutional continuity and decision-making authority at the local level. Regional directors are the primary liaisons between federal cyber resources and the state, local, tribal, and territorial governments that depend on CISA for threat intelligence, incident response coordination, and election security support. Acting officials, by nature, may lack the authority or tenure to execute the same scope of programmatic commitments as confirmed counterparts.
Personnel losses at CISA came through multiple channels: layoffs, early retirements, voluntary and involuntary transfers, and the elimination of specific programs. Warner's letter does not focus on any single mechanism but treats the cumulative effect as a structural concern. The agency has acknowledged the gaps to some degree—CISA has approximately 330 planned hires in progress, with roughly 180 job offers expected to be extended by the end of June 2026. Whether that hiring pace will close the capability gap before Election Day remains an open question.
The Budget Picture
The workforce pressure does not exist in isolation. The Trump administration's proposed FY2027 budget would cut CISA's funding by more than $700 million compared to recent baseline levels. The House Appropriations Committee approved $2.35 billion for the agency in FY2027—a figure that is $253 million below FY2026 enacted levels and $135 million below even the administration's own initial budget request. That last detail is notable: Congress is proposing to fund CISA at a level that undershoots what the executive branch asked for, amplifying the financial constraint on an already strained organization.
Among the specific programs affected, the Multi-State Information Sharing and Analysis Center—known as MS-ISAC—has had its CISA funding eliminated. MS-ISAC serves as a centralized threat intelligence hub for state and local governments, providing 24/7 security operations support, alerts, and incident response coordination to entities that cannot afford to staff these functions independently. Smaller municipalities, rural counties, and under-resourced school districts that previously relied on MS-ISAC services through CISA grants are now navigating without that federal backstop.
Warner has introduced legislation—the Guaranteeing Universal Access to Cybersecurity Act—intended to restore MS-ISAC funding. The bill's name signals its intent: universalizing access means restoring services to the governments least positioned to replace them through other means. At this writing, the bill's legislative trajectory has not been publicly confirmed beyond its introduction.
What It Means for Contractors
For firms operating in the federal cybersecurity market, the situation at CISA creates both near-term turbulence and longer-term opportunity questions worth tracking closely.
On the near term: contractors holding current task orders for CISA regional support, training, or outreach programs should assess whether the personnel reductions and program cuts affect their scope of work, period of performance, or the government's capacity to provide contracting officer oversight. When agency program offices run lean, contract administration slows—approvals stall, modifications take longer, and invoicing cycles stretch. Firms should proactively communicate with their CORs and contracting officers to understand the operational status of their active programs.
The MS-ISAC defunding is a direct signal for managed security service providers and threat intelligence firms that built revenue around state and local government engagements supported by CISA grants. Those contracts may not be renewable under the current funding structure. Firms in this space should evaluate whether Warner's legislation gains traction and plan for scenarios in which federal funding for state and local cyber programs remains constrained through FY2027.
The planned hiring surge—180 offers by June's end, 330 total—suggests CISA intends to rebuild capacity, but the composition of that hiring matters. If the agency is back-filling program management and administrative roles, that does not necessarily translate to restored technical capacity or reconstituted regional teams. Contractors that can deliver surge capacity in incident response, vulnerability management, or election infrastructure support may find near-term demand as CISA works to cover capability gaps with external resources.
Longer range, the budget trajectory warrants attention from any firm whose pipeline includes CISA recompetes or new awards in FY2027. A $2.35 billion ceiling—already below both the administration's request and the prior year—constrains the total addressable contract value available at the agency. Firms building five-year business development plans around CISA growth should model a constrained baseline rather than assuming pre-2025 funding levels will return.
Finally, the midterm election security dimension carries its own implications. CISA's election security program provides direct support to state and local election officials. With half the regional director slots in acting status and MS-ISAC funding gone, that support structure is thinner than it was in the last comparable election cycle. Contractors with election security, physical security, or cybersecurity assessment capabilities may face compressed but real procurement windows if state governments seek to offset the reduced federal support through their own contract vehicles.
Warner's June 26 deadline gives CISA little room. The agency's response—or lack thereof—will signal how openly leadership engages with congressional oversight on workforce and capacity questions. Contractors and industry observers should watch that exchange closely.