GAO Urged OMB to Update Federal Cybersecurity Guidance
Federal agencies struggle to inventory networked devices, leaving infrastructure exposed to potential compromise.
Updated on Oct. 5, 2026 in Cybersecurity

Live Poll
Should federal agencies face stricter requirements for tracking and securing their networked devices?
The Government Accountability Office has recommended that the Office of Management and Budget modernize its cybersecurity guidance for networked hardware. A recent report found that only seven of 22 evaluated civilian agencies successfully met all federal inventory data requirements.
Why it matters
Comprehensive device inventories are critical for securing federal networks against unauthorized access, such as the July 2026 password compromises affecting water-sector controllers. The findings highlight persistent technical and resource gaps that hinder the government's ability to maintain a clear security posture.
Of the 22 civilian agencies audited, only seven fulfilled all eight mandatory inventory data points mandated by OMB memos M-24-04 and M-25-04. Meanwhile, 15 agencies maintained initial device inventories by September 2026, including the discovery of 160 previously unknown IoT assets at HUD.
The players
Government Accountability Office
The non-partisan legislative branch agency that provides auditing, evaluation, and investigative services for the United States Congress.
Office of Management and Budget
The executive office responsible for implementing government-wide policy and budgetary standards, including cybersecurity compliance mandates.
Department of Housing and Urban Development
A federal agency that identified 160 previously unreported IoT devices during the GAO inventory assessment.
The details
Agencies identified these assets using automated management systems and inventory tools designed to map networked devices. The process is governed by OMB memos requiring agencies to track eight specific data categories for every connected device. However, entities like the Department of Justice attributed delays in maintenance to high staff turnover, while others cited competing institutional priorities.
Timeline
December 2024: Three agencies established initial device inventories.
July 2026: Threat actors compromised internet-exposed water-sector controllers.
September 2026: Fifteen agencies maintained initial device inventories.
October 2026: The GAO published its formal evaluation report.
January 2027: The Department of the Interior expects to finish its initial inventory.
The Tech Race
This audit assesses 22 civilian agencies covered by the Chief Financial Officers Act to determine their adherence to mandatory security inventory standards. It highlights a widening gap between high-performing agencies and those struggling to meet foundational cybersecurity requirements.
The visibility into federal network devices is directly linked to the security of critical infrastructure, including water systems that citizens rely on daily. The pace of remediation depends on individual agency capacity, with departments like the Interior aiming for inventory completion by January 2027.
The takeaway
Effective cybersecurity begins with a complete inventory, yet the majority of assessed agencies still lack full visibility into their connected assets. Watch for the Department of the Interior's inventory progress in early 2027 to gauge whether federal agencies can overcome the staffing and resource bottlenecks currently stalling compliance.
Further reading
For more on how government agencies manage systemic vulnerabilities, see Cybersecurity.
Source note: This article includes information reported by Executive Gov.
Live Poll
Should federal agencies face stricter requirements for tracking and securing their networked devices?









