bodtrade-pressNewsThe Broadside1 min read

86% of agencies missed SCuBA cloud deadline, IG finds

The compliance gap isn't about the quality of the baselines, it's that CISA has no authority to make anyone follow them, and the DHS IG just put that in writing.


TL;DR

A DHS Inspector General audit found that 86% of federal civilian agencies failed to implement all mandatory SCuBA cloud security baselines by the June 2025 deadline. The IG also concluded that CISA "lacks the authority necessary to require full and timely implementation of Binding Operational Directives", a finding that echoes GAO's 2020 assessment and that the IG explicitly cited as the reason it issued no recommendations to the agency. CISA didn't comment.

The SCuBA project itself isn't the problem. The DHS IG credited CISA with more than 80 stakeholder engagements, over 1,000 participants, and 130,000 downloads of the assessment tools. Former CISA CIO Bob Costello called the baselines "excellent" and noted that CISA itself implemented them successfully in its own Microsoft tenant.

But excellence in guidance doesn't matter if the guidance can be ignored. The IG report states plainly that FISMA 2014 gives DHS the authority to issue BODs but does not grant CISA the authority to enforce them. CISA's role, per the IG, is limited to developing policies, assisting agencies in implementation, and reporting on compliance, and CISA did that, through one-on-one outreach and Federal Enterprise Improvement Team meetings with agency CISOs.

The result: no recommendations, no consequences, and an 86% non-compliance rate.

The structural gap isn't new. GAO flagged it in 2020, noting that DHS "did not consistently ensure that agencies fully complied with the directives." Five years later, the mechanism hasn't changed. A 2023 Senate Homeland Security FISMA reform bill that would have strengthened CISA's oversight authority passed committee and then stalled.

Meanwhile, CISA is now shepherding a new AI-driven directive on prioritizing software vulnerabilities, one that is more operationally intrusive than SCuBA. The compliance curve isn't likely to improve without a penalty mechanism, whether from Congress or through OMB funding levers. Costello's framing is hard to argue with: "It's kind of like, well, if I don't get burned when I touch the stove, I'll probably keep touching the stove."


Published ·Deep Fathom

86% of agencies missed SCuBA cloud deadline, IG finds — The Broadside