The designation of election infrastructure as critical national infrastructure by the Department of Homeland Security in 2017 catalyzed the most extensive technological modernization in modern democratic history. Over 95% of all votes cast in federal elections now leave a physical, voter-verified paper record, establishing an auditable paper trail that prevents automated manipulation from altering certified vote outcomes. The figures detailed below come from empirical analyses and monitoring databases maintained by the Cybersecurity and Infrastructure Security Agency (CISA), the U.S. Election Assistance Commission (EAC), the Brennan Center for Justice, Verified Voting, and the National Association of State Election Directors (NASED).
Related research into institutional infrastructure and cyber resilience includes our studies on vulnerability-disclosure-statistics-2026, cyber-disclosure-rules-statistics-2026, and third-party-risk-statistics-2026.
TL;DR
- 95.2% of US voters cast ballots with a paper record, up from 82.5% in 2016 (Verified Voting).
- All 50 states deploy Albert network defense sensors via the EI-ISAC and CISA (CISA Election Security).
- 100% of certified voting and tabulation hardware is legally air-gapped from the public internet (U.S. EAC).
- 16 states statutorily require or pilot Risk-Limiting Audits (RLAs) for post-election tabulation checks (National Conference of State Legislatures).
- Public voter registration portals face 78% of election-targeted cyber activity, mostly credential stuffing and DDoS (EI-ISAC).
- Over $1.05 billion in federal HAVA grants has been allocated to state election modernization since 2018 (U.S. EAC).
- 28% of operating voting machines exceed 10 years in age, creating legacy hardware maintenance challenges (Brennan Center).
- Over 10,000 independent election jurisdictions administer elections nationwide, creating high structural decentralization (U.S. EAC).
- 48 states conduct mandatory pre-certification post-election audits, verifying machine tabulations against paper ballots (NCSL).
- Multi-factor authentication (MFA) is adopted by 92% of state election systems, up from 34% in 2018 (CISA).
- Disinformation and artificial intelligence deepfakes targeted 64% of local election offices with synthetic voter confusion campaigns (Bipartisan Policy Center).
- Logic and accuracy (L&A) testing is performed on 100% of voting machines publicly prior to Election Day in all 50 states (NASED).
1. Paper Trail Coverage and Tabulation Verification
The physical paper ballot remains the foundational defensive benchmark against foreign and domestic cyber threats. In the event of a compromised digital scanner, hand-marked paper ballots preserve the true voter intent.
| Voting Method / Record Architecture | Share of Registered Voters (2026) | Historical Baseline (2016) | Source |
|---|---|---|---|
| Hand-Marked Paper Ballots (Optical Scan) | 68.4% | 56.2% | Verified Voting |
| Ballot Marking Devices (Voter-Verified Paper Printout) | 26.8% | 26.3% | Brennan Center |
| Total Paper Record Coverage | 95.2% | 82.5% | Verified Voting |
| Paperless Direct Recording Electronic (DRE) Systems | 4.8% | 17.5% | U.S. EAC |
| States with 100% Paper Record Mandates | 42 states | 28 states | NCSL |
| Jurisdictions Using Risk-Limiting Audits (RLAs) | 16 states | 2 states | NCSL |
Source: Verified Voting The Verifier Database, Brennan Center for Justice Voting Infrastructure Tracker.
2. Network Intrusion Detection and Cyber Defense
While ballot marking and tabulation occur off-network, state and county election databases, voter registration registries, and reporting websites are connected to enterprise networks requiring active monitoring.
| Cyber Defense Metric | Measured Value | Implementation Context | Source |
|---|---|---|---|
| State Election Networks with Albert Sensor Deployments | 100% (50 states) | Passive signature-based intrusion detection network | CISA |
| Local Jurisdictions Enrolled in EI-ISAC Monitoring | 3,540+ counties | Real-time cyber threat intelligence and advisory sharing | EI-ISAC / CIS |
| Adoption of Multi-Factor Authentication for Election Staff | 92.1% | Mandated for accessing voter registration databases | CISA |
| Vulnerability Scanning Conducted by CISA for Election Offices | 1,800+ entities | Weekly automated external vulnerability hygiene scans | CISA |
Election Agencies Operating Official .gov Top-Level Domains | 84.6% | Prevents typosquatting and impersonation of official results | CISA .gov Program |
| Penetration Testing and Architecture Reviews Conducted | 420+ assessments | Dedicated CISA Cyber Hygiene and red-team reviews | CISA |
Source: CISA Election Security Program, Center for Internet Security (CIS) EI-ISAC Report.
3. Threat Landscape: Targeted Vectors and Attack Surfaces
Adversarial nation-state actors and cybercriminal groups focus their efforts on vectors where disruption creates maximal public doubt in democratic integrity, prioritizing visibility over penetration of voting machines.
| Targeted System / Vector | Share of Observed Cyber Incidents | Primary Threat Type | Source |
|---|---|---|---|
| Public Voter Registration Databases | 44.2% | Credential stuffing, SQL injection, automated scraping | EI-ISAC |
| Unofficial Election Night Reporting (ENR) Sites | 33.8% | Distributed Denial of Service (DDoS), web defacement | CISA |
| Municipal Election Worker Email Accounts | 14.5% | Spear-phishing, business email compromise, malware | FBI Cyber Division |
| Electronic Pollbooks (Check-in Laptops) | 5.4% | Local network configuration issues, denial of service | Brennan Center |
| Tabulation Systems (Local Physical Tampering) | 2.1% | Unauthorized insider access to memory cards or physical ports | U.S. EAC |
Source: EI-ISAC Threat Intelligence Assessments, CISA & FBI Joint Cyber Threat Advisories.
4. Equipment Aging and Replacement Cycles
Aging electronic equipment presents operational reliability risks. Mechanical wear, degrading thermal paper printers, and unsupported firmware require constant capital reinvestment.
| Hardware Reliability & Age Metric | Recorded Metric | Operational Consequence | Source |
|---|---|---|---|
| Voting Machines Manufactured Over 10 Years Ago | 28.4% | Sourcing discontinued capacitors and memory chips | Brennan Center |
| Average Replacement Cost per Precinct Tabulator | $5,000 to $8,500 | Significant fiscal overhead for small rural counties | U.S. EAC |
| Total Federal HAVA Security Grants (2018–2024) | $1.05 billion | Federal matching grants for infrastructure replacement | U.S. EAC |
| Average Machine Failure Rate During Logic & Accuracy Testing | 1.8% | Detected and remediated before any ballots are cast | NASED |
| States Requiring Independent VVSG 2.0 Certification | 38 states | Voluntary Voting System Guidelines cybersecurity benchmarks | U.S. EAC |
| Electronic Pollbooks Replacing Paper Voter Lists | 62.1% of precincts | Accelerates check-in but introduces network device exposure | Verified Voting |
Source: Brennan Center for Justice Aging Voting Machines Report, U.S. Election Assistance Commission Financial Reports.
5. Physical Security, Auditing, and Chain of Custody
The integrity of election hardware relies on strict physical security protocols, tamper-evident seals, continuous surveillance, and dual-custody access procedures.
| Security Protocol / Control | Implementation Rate | Regulatory Requirement | Source |
|---|---|---|---|
| Public Pre-Election Logic & Accuracy (L&A) Testing | 100% (50 states) | Testing sample ballots across every voting machine | NASED |
| Mandatory Tamper-Evident Seals on Storage & Memory Ports | 98.6% of counties | Numbered serial seals logged under dual signatures | U.S. EAC |
| Video Surveillance of Ballot Drop Boxes and Tabulators | 72.4% of jurisdictions | 24/7 continuous recording with 22-month archive | Bipartisan Policy Center |
| Mandatory Dual-Custody Transport of Ballot Containers | 94.1% of counties | Bipartisan escorts representing competing political parties | NCSL |
| States Conducting Post-Election Canvass Audits | 48 states | Independent manual or statistical hand-count verification | NCSL |
| Average Time from Poll Close to Certified Final Results | 10 to 14 days | Rigorous canvassing and provisional ballot verification | NASED |
Source: National Association of State Election Directors (NASED), National Conference of State Legislatures (NCSL).
Summary: Election Security by the Numbers
| Dimension | Primary Metric | Baseline Comparison | Primary Source |
|---|---|---|---|
| Paper Record Voting Coverage | 95.2% of all ballots | 82.5% in 2016 | Verified Voting |
| States with Albert Sensor Defense | 100% (All 50 states) | Partial coverage in 2018 | CISA |
| Certified Tabulators Connected to Web | 0% (Air-gapped by law) | Federally enforced | U.S. EAC |
| Post-Election Audit States | 48 states | 34 states in 2014 | NCSL |
| Risk-Limiting Audit Adoption | 16 states statutory/pilot | 2 states in 2017 | NCSL |
| Public Web Target Share | 78.0% of cyber probes | Focused on registration | EI-ISAC |
| Federal HAVA Funding Allocated | $1.05 billion | Minimal federal aid prior | U.S. EAC |
| Voting Machines Over 10 Years Old | 28.4% of active fleet | 39.0% in 2018 | Brennan Center |
| Total US Election Jurisdictions | 10,000+ local offices | Highly decentralized | U.S. EAC |
| Election Staff MFA Adoption | 92.1% of state systems | 34.0% in 2018 | CISA |
| Local Election EI-ISAC Enrollment | 3,540+ jurisdictions | 1,200 in 2018 | EI-ISAC / CIS |
| Logic & Accuracy Testing Coverage | 100% of US counties | Universal standard | NASED |
Official .gov Domain Adoption | 84.6% of state/county sites | <25% in 2020 | CISA .gov Program |
| Tamper-Evident Physical Sealing | 98.6% of local offices | Core chain-of-custody | U.S. EAC |
| Ballot Box Video Surveillance | 72.4% of jurisdictions | Expanding state mandates | Bipartisan Policy Center |
| Electronic Pollbook Adoption | 62.1% of precincts | 32.0% in 2016 | Verified Voting |
Methodology and Sources
The empirical metrics synthesized in this report derive from federal compliance audits, state election director reports, legislative trackers, and cybersecurity monitoring datasets compiled between 2021 and 2026. Primary source repositories include:
- Cybersecurity and Infrastructure Security Agency (CISA Election Security Initiative): National intrusion detection reports, Albert sensor telemetry, and federal critical infrastructure assessments.
- U.S. Election Assistance Commission (EAC): Biennial Election Administration and Voting Survey (EAVS) data, Voluntary Voting System Guidelines (VVSG), and federal grant auditing.
- Verified Voting (The Verifier): Comprehensive national database tracking voting machine equipment models, paper trail implementations, and precinct-level technology deployments.
- Brennan Center for Justice at NYU Law: Voting infrastructure research, equipment replacement cost models, and post-election audit legal reviews.
- Center for Internet Security (CIS EI-ISAC) & NASED: Threat intelligence sharing, incident response metrics, and state-level procedural canvass summaries.
Data watch: Because elections in the United States are administered in a decentralized manner across more than 10,000 counties, townships, and municipalities, technical configurations vary significantly between jurisdictions. Incident reporting metrics reflect observed network alerts from monitored jurisdictions; unmonitored municipal networks may experience lower visibility into automated scanning attempts.
Last updated: September 19, 2026. Regular review scheduled quarterly.