DHS Watchdog: Most Civilian Agencies Missed CISA’s Cloud Security Order, and CISA Cannot Make Them Comply

Table of Contents

The Department of Homeland Security Office of Inspector General says most federal civilian agencies missed the cloud-security rules CISA told them to finish last summer, and that CISA has no legal power to make them finish. Report OIG-26-30, issued around September 21 and covered by CyberScoop on September 23, looked at Binding Operational Directive 25-01.

CISA issued BOD 25-01 on December 17, 2024. It ordered Federal Civilian Executive Branch agencies to inventory named cloud tenants, deploy assessment tools, and align those environments to Secure Cloud Business Applications baselines. The full-implementation deadline was June 2025. SCuBA was built after the 2020 SolarWinds compromise as a set of configuration baselines and assessment tools for business cloud apps, not as a new law.

The IG found that 88 of 102 agencies, 86 percent, had not implemented every mandatory SCuBA policy by that June deadline. Compliance did not catch up. As of February 2026, 78 of 102 agencies, 76 percent, were still short of full implementation.

Earlier checkpoints failed too. Forty of 102 agencies missed the February 21, 2025 cutoff for a complete cloud-tenant inventory. Fifty-three had not deployed the required assessment tools across applicable cloud environments by April 25, 2025.

What the missed baselines actually are

The report names three examples of baselines agencies did not turn on: blocking outdated authentication methods, enforcing multifactor authentication, and a policy to protect sensitive and personally identifiable information. The IG said those settings “could mitigate vulnerabilities and threats from affecting the cloud business applications.”

That is not an exotic control set. Legacy authentication and missing MFA are how cloud tenants get walked into. A missing PII-handling policy is a records problem as well as a security problem, because federal systems hold benefit files, immigration records, and personnel data that state breach statutes would treat as notice triggers if a contractor held them.

The IG’s risk sentence is the one CyberScoop led with: noncompliant agencies “may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat.” Later in the report: “Without defined enforcement oversight of SCuBA policy compliance, the Federal cloud security posture across the Federal enterprise is weakened. When agencies do not adopt required configurations or meet implementation deadlines, their cloud environments remain exposed to preventable threats.”

Binding, except when it is not

BODs are written as mandatory for civilian agencies. The IG says the statute does not give CISA, through DHS, the authority to require full and timely implementation. CISA’s job, in the IG’s words, is limited to developing policies, assisting agencies, and reporting on how well they follow them.

CISA did not respond to the report, the IG wrote. It also did not answer CyberScoop’s request for comment. That silence matters less than the structural point. A directive that cannot be enforced is a reporting exercise with a deadline attached. The June 2025 date passed. Three-quarters of the enterprise was still out eight months later.

Then-CISA Director Jen Easterly, when the directive went out, said threat actors were targeting cloud environments and that the required actions were a step toward a more defensible civilian enterprise. She also urged private organizations to adopt the same baselines. The IG audit is about the federal side of that ask.

What contractors and state partners should read into it

Agencies that share tenants with vendors, or that push citizen data into SaaS the agency does not fully configure, are the practical exposure. If the agency never blocked legacy authentication or never turned on MFA for the tenant, the vendor’s own SOC report does not close the gap. FEDRAMP authorization of a product is not the same as the agency applying the SCuBA baseline to its tenant.

State and local governments that take CISA services, and critical-infrastructure operators that were told to copy the baselines, should treat OIG-26-30 as a status check on the federal model, not as a reason to skip the controls. The controls the IG flagged are the ones a reasonable program already has: inventory of cloud tenants, assessment tooling, MFA, retirement of legacy auth, and a written rule for sensitive data.

The open policy question is whether Congress gives DHS a consequence for a missed BOD, or whether OMB and agency inspectors general become the only enforcement path. Until that changes, “binding” describes the document, not the outcome. The numbers in OIG-26-30 are the outcome: 88 agencies short in June 2025, 78 still short in February 2026.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.