Senior officials at NIST said significant workforce and budget reductions are forcing the agency to narrow and reprioritize work tied to national security and cybersecurity, including mandates related to AI, cybersecurity, and post-quantum encryption. NIST’s Information Technology Laboratory reported losing roughly 89 staff over the past year (within a headcount of 289), amid broader agency reductions of 700+ positions, and warned that additional congressional cuts (including a proposed $13M reduction to NIST’s labs program) could further constrain technical programs such as cryptographic testing and validation used for federal procurement and joint validation efforts with the Canadian Centre for Cybersecurity.
On Capitol Hill, House Homeland Security Committee Democrats pressed CISA Acting Director Madhu Gottumukkala on major workforce reductions—reported as about one-third of the agency’s employees departing over the past 12 months—and whether the agency can sustain its mission under current funding and staffing levels. Gottumukkala defended the reductions as part of a “mission-first” effort to eliminate duplication and align work to statutory authorities, while also signaling targeted hiring for key roles but declining to provide lawmakers a clear vacancy count or a definitive answer on whether recently appropriated DHS funding is sufficient for CISA to execute its responsibilities.

See the reporting duties and controls this puts on the clock.
8 events from the most recent confirmed update back to the earliest known activity.
NIST officials said the agency entered 2026 with reduced staffing and budget pressure, forcing it to narrow and reprioritize work across cybersecurity, AI, and post-quantum cryptography efforts.
At a House Homeland Security Committee hearing, Democrats questioned Acting Director Madhu Gottumukkala about major workforce reductions, DHS-directed reassignments, and CISA's ability to meet its mission amid reported staff losses.
NIST recently completed testing of its first post-quantum cryptographic module as part of the U.S. government's transition to quantum-resistant encryption.
By early 2026, NIST reported reducing its cryptographic validation backlog from nearly two years in 2020 to about six months, though officials said staffing losses were limiting further gains.
A staffing chart entered into the congressional record showed 65 involuntary reassignments at CISA, and lawmakers said some staff were placed on administrative leave amid an ongoing investigation tied to a failed polygraph incident.
Since President Trump took office, both CISA and NIST's Information Technology Laboratory have experienced significant personnel losses, with CISA later recording 998 departures during that period.
NIST officials said the agency's cryptographic testing and validation backlog reached nearly two years in 2020, reflecting the labor-intensive nature of its review process.
CISA's reported attempt to reassign CIO Bob Costello was later reversed, becoming one of several internal personnel incidents raised by lawmakers.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberscoop.com
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.