CISA Election Report
Open in Drive → CISA Election Report - FINAL.pdf
What it is
A technical summary of CISA's 2019–2024 election security work: source-code and binary analysis of election software conducted with Idaho National Laboratory under the Critical Product Evaluation program, penetration testing of state, local, tribal and territorial networks, and incident response. Findings are that election software contains the ordinary spectrum of vulnerabilities; that certification regimes block timely patching, with some regimes requiring no patches for months before an election; and that SLTT networks lack basic segmentation, with assessors gaining full network control within hours or days in multiple cases. Cites Halderman's ImageCast X barcode analysis from Curling v. Raffensperger. Mitigation recommendations: harmonize patch and certification rules, use human-readable paper ballots, and conduct post-election manual audits before certification.
Why it matters
Written for this release and unclassified, but it cuts against the speech rather than for it. Its recommendations — paper ballots, manual audits — are the mainstream election-security consensus, not a case for the claims Trump made. Most usefully, it declines to endorse the Puerto Rico work: it states that ODNI commissioned a forensic examination of Dominion devices from Mojave Research, and that while CISA reviewed the report, the agency had no access to the devices and could not perform its own examination. That is the agency holding the pen refusing to vouch for the administration's centerpiece hardware finding.