The Cybersecurity and Infrastructure Security Agency (CISA) is resourced to support a broad national strategy of layered deterrence by identifying systemically important entities and supporting in the mitigation of risks to national critical functions. This report documents systemic risks, cyber risks in software supply chains, past and ongoing analytical support to CISA, current limitations, and also outlines a path for future work.