CISA's free cybersecurity services: scanning, exercises, and assessments at $0
The best-kept secret in federal cybersecurity: CISA gives away real services for free to federal agencies, state/local/tribal governments, and critical-infrastructure organizations. Use them before you write a consulting check.
What's actually free
- Cyber Hygiene vulnerability scanning — CISA scans your internet-facing systems and sends you weekly reports. This is the same visibility consultants charge five figures to stand up.
- Tabletop exercise packages (CTEP) — facilitated scenarios for ransomware, insider threat, and more, with all materials included.
- Assessments — CISA's protective security advisors conduct infrastructure surveys and resilience reviews at no cost to eligible organizations.
- The CPGs and KEV catalog — the guidance itself, always free, and genuinely usable as a self-assessment.
What the free tier doesn't cover
Remediation labor, 24/7 monitoring, and program management are yours to fund — CISA finds the problems; you (or your contractor) fix them. That's exactly where the firms in our directory earn their fees: turning a free CISA scan report into a remediated, monitored program.
The honest sequencing
Enroll in Cyber Hygiene → run the CPG self-assessment → take our readiness quiz → then get scoped quotes only for the gaps you can't close internally. Skipping the free step is how organizations buy assessments twice.
Get quotes from verified firms
One brief, matched firms, competing quotes — free.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.