Federal Agencies Missed Cloud Security Deadlines

A government watchdog report found that most federal agencies failed to meet mandated cloud security standards by June 2025.

Updated on Sept. 24, 2026 in Law Enforcement

Federal Agencies Missed Cloud Security Deadlines

Live Poll

Should federal agencies face stricter enforcement for failing to meet mandated cybersecurity security standards?

By the June 2025 deadline, 86% of federal agencies failed to implement mandatory Secure Cloud Business Applications (SCuBA) policies. This oversight was highlighted in a September 2026 report from the Department of Homeland Security Inspector General.

Why it matters

The findings underscore significant challenges in federal cybersecurity compliance, with agencies often struggling due to limited resources and the technical complexity of modernizing cloud environments. The report also identified a structural hurdle in the current oversight framework.

The DHS IG report confirmed that 86% of federal agencies missed the mandatory SCuBA policy deadline. While CISA facilitated over 80 engagements with 1,000 participants, it currently lacks the legal authority to force compliance with these directives.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is responsible for protecting the nation's critical infrastructure against cyber threats.

DHS IG

The Department of Homeland Security Inspector General provides independent oversight and audits of the department's programs and operations.

The details

Although CISA released configuration baselines for Microsoft 365 and saw 130,000 downloads of its SCuBA assessment tools, enforcement remains ineffective. The Inspector General determined that CISA cannot mandate compliance under existing legislation, as previous attempts to pass FISMA reform bills in the Senate have stalled.

Timeline

  1. The SolarWinds cyber hack occurred in 2020.

  2. A FISMA reform bill was passed by a Senate committee in 2023.

  3. CISA issued a binding operational directive in 2024.

  4. The deadline for SCuBA policy implementation was June 2025.

  5. The DHS IG report was released in September 2026.

Legal Context

The current oversight struggle stems from the limitations of FISMA 2014, which grants the Department of Homeland Security power to issue directives without providing CISA the authority to enforce them. This gap has led to persistent compliance failures despite ongoing administrative guidance.

The failure to implement secure cloud configurations leaves federal systems—and the sensitive public data they contain—more vulnerable to potential cyber intrusions. This ongoing compliance gap necessitates increased vigilance regarding how government agencies secure digital infrastructure.

The takeaway

The gap between cybersecurity policy mandates and actual implementation highlights a critical need for legislative reform to empower oversight agencies. Without stronger enforcement authority, federal agencies remain susceptible to technical lapses that threaten infrastructure integrity.

Further reading

For more information on national security protocols, visit the Law Enforcement section.

Source note: This article includes information reported by Federal News Network.

Live Poll

Should federal agencies face stricter enforcement for failing to meet mandated cybersecurity security standards?