CISA isn't audited alone — and its mission is a two-decade High-Risk area.

Cybersecurity and Infrastructure Security Agency · Department of Homeland Security

CISA receives no standalone financial-statement audit opinion. Its books are consolidated into the Department of Homeland Security's statements, which have earned an unmodified (clean) opinion every year for over a decade — the record that covers CISA's money. Its own mission is a different oversight story: protecting Federal information systems and the Nation's cyber critical infrastructure has been on GAO's High-Risk List since 1997. That is the burning platform, stated from the public record.

How the audit record maps

CISA is a DHS component; it does not file separate audited financial statements. The clean-opinion streak shown here is the DHS consolidated streak, reconciled to the Department monitor.

The oversight record

    Why this monitor

    An agency built to secure the Nation's information systems ought to be able to trace its own money to the source. CISA's accounts already ride inside a set of statements that earn a clean opinion — the discipline exists at the Department level. This monitor makes the same demand at the bureau level: every figure resolves to a published document and recomputes against the budget's own arithmetic — each appropriation to CISA's published net discretionary subtotal, to the dollar. The favorable finding (the clean opinion) and the unfavorable one (the adverse opinion on internal control, material weaknesses rising three to five) are both reported here — not just the flattering one.

    Sources are linked at each node. The clean-opinion record is the DHS OIG independent auditor's report on the DHS consolidated statements (which include CISA); the High-Risk designation is drawn from GAO's own High-Risk List and reports.

    See something to improve, want to request a change, or have a question? Leave a note — this monitor is built in public and we iterate live.