
Twenty-five years later, most retrospectives on September 11, 2001, focus on airports, skylines, and war. Overlooked is a stranger fact: September 11, 2001, was itself an election day. New York City was in the middle of a mayoral primary when the towers fell — and the scramble to figure out what to do about that, followed two decades later by a slow-motion unwinding, traces the entire arc of how “election security” became a matter of national security law rather than just good election administration.
A primary interrupted

Polls in New York City opened at 6 a.m. on September 11, 2001, for Democratic and Republican mayoral primaries. By mid-morning, city and state officials were making an improvised legal call nobody had rehearsed: can an election just be stopped? Board of Elections commissioners phoned a state judge, who verbally authorized closing the polls; Governor George Pataki acted that morning to cancel the vote; and two days later the state legislature passed emergency legislation rescheduling the primary for September 25, with a runoff on October 11. Votes already cast on the 11th were preserved and counted once voting resumed.
“September 11 had already supplied the statute.”
It worked, but only because New York happened to have old emergency-postponement statutes on the books and officials willing to improvise under a court order issued over the phone. That improvisation eventually found its way into federal law. The 2022 Electoral Count Reform Act, passed mainly to close loopholes exposed by the 2020 election, also rewrote the rule governing what happens when a state “fails to make a choice” on Election Day. The old 1845-era version was vague enough that partisans floated using it to justify appointing electors after the fact. ECRA closed that loophole — but preserved a narrow exception letting a state extend its voting period under pre-existing state law in the case of “force majeure events that are extraordinary and catastrophic.” In the legislative record explaining that clause, Congress named the qualifying circumstances explicitly: catastrophic natural disasters, and terrorist attacks.
Congress worries about itself

The more consequential post-9/11 anxiety wasn’t about polling places — it was about Congress surviving to certify elections at all. Contemporaneous congressional testimony from the commission’s own executive director noted that the fourth hijacked plane, United Flight 93, was likely headed for Washington, with the Capitol or the White House as its probable target. That near-miss produced the Continuity of Government Commission, a bipartisan project of the American Enterprise Institute and the Brookings Institution launched in 2002 and co-chaired by Presidents Carter and Ford as honorary chairs. Its central finding was alarming in its own right: because House vacancies can only be filled through special elections, and those typically take months to organize, a mass-casualty attack on the Capitol could leave the House unable to reach a quorum — and therefore unable to certify a presidential election or confirm a new vice president — for the better part of a year.
“The core continuity gap 9/11 exposed is, on paper, still open today.”
The commission recommended a constitutional amendment allowing temporary emergency appointments to the House until special elections could be held. Congress never passed it. A revived version of the commission met again in 2021–2022, citing the pandemic and other recent developments, and issued the same recommendation. It remains unadopted, which means the core continuity gap 9/11 exposed is, on paper, still open today.
The Patriot Act’s quiet contribution: a legal category called “critical infrastructure”

The most durable 9/11 legacy in election security isn’t a specific election law at all — it’s a piece of legal plumbing. The USA PATRIOT Act, passed weeks after the attacks, formally defined “critical infrastructure” as systems and assets so vital that their incapacity would have a debilitating national impact. That definition, designed with power grids, water systems, and financial networks in mind, sat unused for elections for fifteen years.
“The 2016–2017 crisis supplied the political will; September 11 had already supplied the statute.”
Then, on January 6, 2017 — in the final two weeks of the Obama administration, and in direct response to intelligence findings on Russian interference in the 2016 election — Homeland Security Secretary Jeh Johnson invoked that Patriot Act–era authority to designate the nation’s election systems, including voter registration databases, voting machines, and tabulation infrastructure, as a critical infrastructure subsector under the Department of Homeland Security. Johnson was careful to frame it as assistance, not control, stressing that the move amounted to neither a federal takeover nor new regulation of how states run their elections, and would simply let DHS prioritize cybersecurity help to states that requested it. State election officials, jealous of their constitutional authority over elections, were divided; the National Association of Secretaries of State called the move “legally and historically unprecedented,” while some secretaries welcomed the access to federal cybersecurity resources it unlocked.
The point is structural: without the critical-infrastructure category the Patriot Act created, there would have been no legal hook for the federal government to treat election systems as a national-security concern in the first place. The 2016–2017 crisis supplied the political will; September 11 had already supplied the statute.
DHS, and later CISA, inherit the job
“Election security inherited that architecture almost by accident.”
The designation also plugged elections into an institutional architecture built specifically because of 9/11. The Department of Homeland Security itself is a 2002–2003 creation of the attacks, merging twenty-two agencies to close the information-sharing and coordination gaps the 9/11 Commission identified. Under DHS’s coordination, a newly formed government council of federal and state election officials voted in February 2018 to stand up the Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC) — a threat-sharing network for state and local election offices, operated by the nonprofit Center for Internet Security and modeled on the same “share information up and down levels of government” doctrine that fusion centers and the National Counterterrorism Center embodied after 9/11, just aimed at ransomware and foreign disinformation instead of hijackers. That November, Congress formally elevated DHS’s cyber wing into a standalone agency, the Cybersecurity and Infrastructure Security Agency (CISA), which inherited the election security portfolio and the EI-ISAC partnership going forward.

That system was credited with real results. In 2024, CISA and the EI-ISAC used their information-sharing pipeline and a real-time operations center to warn officials of a coordinated wave of more than 100 Russian-linked bomb threats against polling places, helping limit disruption on Election Day.
Full circle: the infrastructure meets its own crisis

That is what makes 2025 and 2026 a genuinely new chapter rather than a footnote. Since President Trump’s second term began, CISA has undergone the kind of upheaval election officials say they haven’t seen since the agency’s creation. Seventeen CISA election-security staffers were placed on administrative leave in February 2025; the agency froze election-security activities pending an internal review whose findings were never made public; it ended federal funding and support for the EI-ISAC and its cooperative arrangement with the broader Multi-State ISAC; and agency-wide staffing fell from roughly 3,400 to about 2,500, with the administration’s fiscal-year 2026 budget request proposing further cuts to around 2,649 positions.
The effects surfaced concretely. In summer 2025, a cyberattack defaced Arizona’s statewide candidate portal with images tied to Iranian leadership following U.S. military strikes in the region. In a subsequent letter to Homeland Security Secretary Kristi Noem, members of Congress argued it was troubling that Arizona officials, in responding to the breach, “did not feel it could rely on CISA for rapid, coordinated support.” In November 2025, for the first time in years, CISA did not stand up its Election Day situation room. And the agency still lacks a Senate-confirmed director, after the nomination of Sean Plankey stalled amid bipartisan concern — a vacancy tangled up with President Trump’s ongoing criticism of Chris Krebs, the CISA director he fired in 2020 for calling that year’s election “the most secure in American history.”
“State officials had no clear sense of whether they could rely on CISA heading into the 2026 midterms.”
Minnesota Secretary of State Steve Simon, a Democrat and former president of the National Association of Secretaries of State, said in late 2025 that state officials had no clear sense of whether they could rely on CISA heading into the 2026 midterms. CISA’s public affairs office has said the agency remains “laser-focused on securing America’s critical infrastructure” and ready to help if asked, without detailing staffing or plans for the midterms.
“America’s understanding of what it means to protect an election was never built from scratch.”
The through-line
None of this — the DHS org chart, the critical-infrastructure statute, the EI-ISAC’s information pipes, even the unresolved question of what happens to Congress after a mass-casualty attack on the Capitol — was written with ballots in mind. It was written in the shock of a single morning in 2001, aimed at hijackers and sleeper cells. Election security inherited that architecture almost by accident, first through a legal category sitting idle for fifteen years, then through an institution built to fight terrorism that gradually absorbed cybersecurity as its mission, then through a threat-sharing doctrine invented for counterterrorism and repurposed for foreign election interference.

That inheritance is now being tested in real time, twenty-five years on, not by a foreign attack but by a domestic political fight over whether the infrastructure should exist in its current form at all. Whatever happens to CISA before November 2026, the deeper story of the last quarter-century is that America’s understanding of what it means to protect an election was never built from scratch. It was retrofitted, piece by piece, off the scaffolding 9/11 left behind.
Sources consulted: New York City Campaign Finance Board records; the Rainey Center; EveryCRSReport (Congressional Research Service); the Continuity of Government Commission (AEI/Brookings) and Senate Judiciary testimony; DHS statements and U.S. Election Assistance Commission materials on the January 2017 critical infrastructure designation; The Hill; reporting from Votebeat, the Center for Democracy and Technology, the Brennan Center for Justice, CBS News, and OPB on CISA’s 2025–2026 restructuring; and correspondence from Sens. Padilla, Kelly, and Morelle to DHS/CISA leadership.

Leave a comment