Ballot Box or Black Box? Grading America's Voting Infrastructure Four Years After 2020
The debate over election security in the United States has become so thoroughly politicized that it is now genuinely difficult to assess the underlying technical reality. One political coalition insists that American elections are irredeemably compromised. Another responds that they are the most secure in the world. Both claims are, in their absolute forms, misleading — and the gap between them has made it harder, not easier, for states to do the unglamorous administrative work of actually improving their systems.
VIS News examined publicly available security assessments, federal funding disbursements, academic evaluations, and reporting from election security organizations to produce a state-by-state accounting of where things actually stand. What follows is an evidence-based evaluation, organized by performance tier, that attempts to separate political rhetoric from operational reality.
The Baseline: What Good Election Security Actually Looks Like
Before assessing individual states, it is worth establishing what election security experts — a community that includes cybersecurity professionals, academic researchers, and officials from the Cybersecurity and Infrastructure Security Agency (CISA) — identify as the core components of a well-secured voting system.
The consensus framework includes: paper-based voting records that provide an auditable trail independent of any software system; routine post-election audits, ideally risk-limiting audits (RLAs) that use statistical methods to verify outcomes with high confidence; voting equipment that is not connected to the internet; regular cybersecurity assessments of election management systems; and robust voter registration database security.
Not every state meets all of these standards. Several fall short on multiple dimensions. And the reasons for those shortfalls vary considerably — some are resource-driven, some are political, and some reflect genuine disagreements among security professionals about best practices.
Tier One: States That Have Made Substantive Progress
Georgia presents one of the more complex cases in the national picture. The state became the epicenter of post-2020 election controversy, yet its technical infrastructure has undergone significant scrutiny and, by most expert assessments, meaningful improvement. Georgia moved to a new ballot-marking device system that produces a paper record for every vote cast and has conducted risk-limiting audits of statewide elections. Its voter registration database has received repeated federal security assessments. Critics note that the ballot-marking devices introduce their own security considerations, and debates about their implementation remain active among security researchers.
Colorado is consistently cited by election security experts as the national model. The state uses hand-marked paper ballots statewide, conducts rigorous risk-limiting audits after every election, and has built a culture of election administration transparency that includes routine public testing of equipment and open-source audit tools. Colorado's secretary of state office has proactively engaged with CISA and academic researchers in ways that few other states have matched.
Virginia has made steady, if less celebrated, progress. The state decertified the last of its paperless electronic voting machines in 2017 and has since standardized on optical scan systems with paper ballots. Post-election audits have become routine, and the state has invested in cybersecurity training for local election officials — a frequently overlooked dimension of election security, given that most operational vulnerabilities exist at the county level rather than in statewide systems.
Michigan and Pennsylvania, both of which faced intense scrutiny following 2020, have made documented infrastructure investments using federal Help America Vote Act funds and subsequent congressional appropriations. Michigan completed a comprehensive audit of its voter registration system and has expanded its post-election audit program. Pennsylvania's situation is more complicated, given ongoing disagreements between the state legislature and the executive branch over election administration rules, but the technical infrastructure in most counties has been updated.
Tier Two: States With Uneven Progress
Wisconsin has updated much of its voting equipment since 2020 but has faced persistent legislative interference in election administration that security experts say creates operational risks independent of the hardware. Disputes over the authority of the Wisconsin Elections Commission have created administrative uncertainty that, while not a direct security vulnerability, complicates consistent implementation of security protocols across the state's 72 counties.
Arizona presents a paradox: the state's voting systems survived one of the most extensive post-election reviews ever conducted — the so-called Cyber Ninjas audit of 2021, which despite its partisan origins, found no evidence of systemic fraud — yet the political fallout from that review has made routine election administration more contentious and resource-intensive than in comparable states. The state has paper ballots and conducts audits, but the administrative environment created by sustained political conflict has strained local election offices.
North Carolina has improved its voter registration security and updated equipment in most counties, but remains one of several Southern states where the patchwork of county-level election administration — with 100 counties running effectively independent operations — creates security consistency challenges that state-level investment alone cannot fully address.
Texas, despite its size and resources, has been slow to implement risk-limiting audits and continues to use a variety of voting equipment across its 254 counties, some of which is aging and difficult to secure. The state's decentralized administration model, while consistent with its broader governance philosophy, creates significant cybersecurity coordination challenges.
Tier Three: States With Significant Remaining Vulnerabilities
Louisiana and Mississippi stand out for continued use of direct-recording electronic (DRE) voting machines that produce no paper record. Security experts have identified paperless DREs as the single greatest technical vulnerability in American election infrastructure, since they provide no independent means of verifying that recorded votes match voter intent. Both states have been slow to fund replacements, and neither has implemented meaningful post-election audit programs.
Indiana and Kansas have made limited progress on audit implementation and retain aging equipment in numerous counties. Federal funding that could have accelerated modernization has in some cases gone unspent due to administrative and legislative delays.
New Hampshire, despite its national political prominence as an early primary state, uses hand-marked paper ballots in most jurisdictions but has resisted implementing risk-limiting audits, relying instead on less statistically rigorous manual recount procedures.
The Federal Funding Gap
Congress appropriated $380 million for election security improvements through the Help America Vote Act in 2018 and an additional $425 million in 2020. Security experts and election administrators widely describe these figures as insufficient for the scale of infrastructure modernization required — particularly given the decentralized nature of American election administration, which puts primary responsibility on thousands of county and municipal offices with widely varying technical capacity.
Requests for sustained federal funding have stalled repeatedly in Congress, caught in the same partisan crossfire that has made election administration a culture war battlefield rather than a bipartisan administrative challenge. The result is a patchwork of improvements driven largely by the initiative of individual state and county officials, rather than a coherent national security strategy.
Partisanship as Infrastructure Problem
Perhaps the most consistent finding across this evaluation is that partisan conflict over election administration has itself become a security vulnerability. When election officials spend their time and resources responding to unfounded fraud claims, defending against legislative interference, or navigating politically motivated audits, they have less capacity to do the routine technical work — equipment testing, cybersecurity training, database maintenance — that actually determines whether systems are secure.
This dynamic cuts across party lines in ways that challenge simple narratives. Some Republican-led states have made genuine security investments while others have allowed political disputes to crowd out technical work. Some Democratic-led states have led on best practices while others have underinvested in rural and lower-income jurisdictions where resources are scarce.
The honest conclusion is that American election security is improving in some places, stagnating in others, and everywhere complicated by a political environment that has made the straightforward administrative task of running reliable elections into a proxy war for deeper conflicts about democratic legitimacy itself. Voters deserve a clearer accounting of where their states actually stand — and a political class willing to provide one.