IC Oversight & Policy — 2026-09-25

DHS Inspector General Finds 86 Percent of Federal Agencies Failed to Meet CISA Cloud Security Directives

BLUFCISA's inability to enforce its own binding directives renders federal cloud security standards aspirational until Congress attaches statutory penalties or budget consequences to noncompliance.

A DHS Office of Inspector General report published Sunday found that 88 of 102 federal civilian executive branch agencies, or 86%, failed to implement all mandatory Secure Cloud Business Applications (SCuBA) policies by the June 2025 deadline set under Binding Operational Directive 25-01 1. As of February, compliance had not improved, with 78 of 102 agencies still non-compliant 12. The IG identified specific unmet baselines, including blocking outdated authentication methods, enforcing multifactor authentication, and protecting sensitive personally identifiable information 23. The report attributed the shortfall to CISA's lack of authority to require full and timely implementation of its directives, and stated CISA did not respond to the findings 2.

Analysis
The problem is structural, not agency-specific: CISA can issue binding directives but lacks authority to compel compliance, leaving enforcement to voluntary self-reporting with no penalty attached, and the drop from 86% to 76% noncompliance between June and February shows remediation moving too slowly to close exposure windows tied to authentication and PII protections. Sourcing rests on a single DHS OIG report, with CyberScoop's initial treatment repackaged by Federal News Network and SC World without independent findings. The same decline may instead reflect agencies converging toward compliance under existing voluntary mechanisms, cutting against the enforcement-gap thesis. Congress, not CISA, holds the lever: statutory authority or budget conditioning. No such action has followed the report.
4 sources
  1. CISA Enhanced Cloud Security for Federal Information but Lacks Authority to Enforce Implementation of All Necessary Protective Actions - DHS Office of Inspector General
  2. Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack - CyberScoop
  3. Federal agencies fail to meet cloud security directive deadline - SC World
  4. IG report finds government cyber directives lack teeth - Federal News Network

View in full brief →

UNCLASSIFIED // OPEN SOURCE