GAO Urged OMB to Update Device Cybersecurity Guidance

A new federal report shows most civilian agencies struggle to maintain accurate inventories of networked devices.

Updated on Oct. 5, 2026 in Cybersecurity

Bold flat-color editorial illustration of minimalist vertical prisms, representing server cabinet infrastructure for federal cybersecurity guidance.
The Government Accountability Office has recommended the Office of Management and Budget modernize its cybersecurity guidance following an evaluation of civilian agency network inventories. AI Illustration. Upload story photo >

Live Poll

Should federal agencies face stricter requirements for tracking and securing their networked devices?

The Government Accountability Office has recommended that the Office of Management and Budget modernize its cybersecurity guidance for networked devices following an evaluation of 22 civilian agencies. The review found inconsistent compliance with data requirements, noting that only seven agencies currently meet all federal inventory standards.

Why it matters

Accurate device inventories are essential for securing federal networks against intrusions, such as the July 2026 breach of water-sector controllers. Gaps in visibility leave government infrastructure vulnerable to exploitation by threat actors.

Agencies were assessed against eight specific data requirements defined in OMB memos M-24-04 and M-25-04. The Department of Housing and Urban Development notably discovered 160 previously unreported IoT devices during its asset management review.

The players

Government Accountability Office

This federal agency provides auditing, evaluation, and investigative services for the United States Congress.

Office of Management and Budget

This cabinet-level office oversees the implementation of the President's vision across the executive branch and manages federal agency performance.

Department of Housing and Urban Development

This federal department is responsible for national policy and programs that address America's housing needs and improve communities.

Department of the Interior

This federal executive department manages and conserves most federal land and natural resources.

The details

While 15 agencies had established initial device inventories by September 2026, many cited resource limitations, competing priorities, and staff turnover as major obstacles. The GAO report highlights that no agency reported using waivers for devices failing to meet established National Institute of Standards and Technology benchmarks.

Timeline

  1. December 2024: Three agencies held initial device inventories.

  2. July 2026: Threat actors compromised internet-exposed water-sector controllers.

  3. September 2026: Fifteen agencies had established initial inventories.

  4. October 2026: The GAO published the formal evaluation report.

  5. January 2027: The Department of the Interior expects to finalize its initial inventory.

The Tech Race

This evaluation highlights the growing difficulty of managing the modern attack surface as federal agencies integrate more IoT devices into their networks. It marks a shift from legacy inventory models toward the more rigorous, real-time tracking required to defend against sophisticated threat actors.

For citizens, these inventory gaps mean that sensitive government systems managing critical infrastructure could remain exposed to unauthorized access. Improved compliance will likely result in more secure public services and reduced risk of service disruptions caused by cyberattacks.

The takeaway

Maintaining a comprehensive inventory is the foundational step of any effective cybersecurity posture for large-scale organizations. Agencies that prioritize asset visibility are better equipped to identify and mitigate vulnerabilities before they are exploited.

What happens next

The Department of the Interior is scheduled to complete its initial agency-wide device inventory by January 2027.

Further reading

For more information on the evolving standards for protecting government networks, visit the United States Cybersecurity section.

Live Poll

Should federal agencies face stricter requirements for tracking and securing their networked devices?