databreaches.net 5 Oct 2026, 22:55 UTC

CISA Tightens Retention Bonus Rules as Staff Loss Risks Grow

THE Cybersecurity and Infrastructure Security Agency (CISA) will continue offering the Cybersecurity Retention Incentive (CRI) to help retain skilled technical staff, but eligibility rules are being tightened. Under revised criteria that tie eligibility to specific job series and performance ratings, fewer employees will qualify for the incentive.

The change follows widescale resignations last year and comes as the Office of Personnel Management cap(s) higher performance ratings government‑wide, raising concerns about further staff losses.

CISA plans to keep the CRI programme going through fiscal year 2027, with the policy signed in July by acting CISA Director Nick Andersen and reported by Federal News Network. The incentive can boost an eligible employee’s pay by up to 25% of base salary, aimed at addressing retention issues and high vacancy rates across CISA’s cybersecurity workforce.

The article notes that the revised criteria may reduce the pool of eligible staff, which could complicate efforts to sustain critical cyber capabilities within the agency.

Evidence for the changes comes from the cited policy and coverage by Federal News Network, but the piece does not provide granular figures on current qualification rates or exact job series affected. The report presents the agency’s stated intention to maintain incentives while acknowledging potential risks to retention if more personnel fall outside the tightened criteria. No specific exploitation or incident is discussed; this is a policy update and its anticipated impact on staffing.

View full article

Article by CyberSIXT