fismatrade-pressNewsThe Broadside3 min read

GAO: Only 14 agencies inventoried IoT devices two years late

Agencies blame resources; GAO's report points at OMB, which issued no FY 2026 guidance and conducted zero oversight audits.


TL;DR

GAO's final biennial report on the IoT Cybersecurity Improvement Act finds 14 of 22 civilian CFO Act agencies had established networked device inventories as of September 2026, two years past OMB's September 2024 deadline, and only 10 captured all required metadata. Agencies cite technical constraints and competing priorities. GAO's target is OMB: it hasn't issued FY 2026 guidance, hasn't overseen the inventory mandate, and hasn't updated the deadline. Without those three things, the requirement is a suggestion.

The numbers tell the story GAO actually wants OMB to answer. Fourteen of 22 civilian CFO Act agencies had built IoT and operational technology device inventories by September 2026. Eleven were actively maintaining them. Ten included every required field, meaning only about half the government's civilian agencies know what firmware version is running on, say, the network-connected MRI controller or the building automation panel in their own facilities. And not a single agency has used the IoT cybersecurity waiver process OMB set up for devices that can't meet NIST standards.

That last data point deserves a beat. In GAO's December 2024 report on the same series, six agencies claimed waivers, but five of them turned out to have reported incorrectly, and OMB never verified any of the waiver data before passing it to Congress. Now the count is zero across all 22 agencies. Either nobody needs a waiver, or nobody is filling out the paperwork. GAO doesn't say which, and the history suggests the second option.

OMB's missing two years

Agencies are easy to criticize and GAO does criticize them. But the report's actual diagnosis lands on OMB. The December 2023 FISMA memo set the September 2024 inventory deadline and defined required metadata down to network connectivity, security controls, and vendor information. A January 2025 memo updated FY 2026 FISMA reporting requirements. Then nothing. OMB has not issued guidance covering FY 2026 beyond that January touchpoint, has not established a revised timeline, and according to the report "did not oversee the implementation of its requirements regarding establishing and maintaining inventories of networked IoT and OT devices within an established time frame."

That's two consecutive cycles without enforcement. Agencies cited technical and resource constraints and competing priorities, which is what agencies always cite. GAO's counter is procedural: without updated guidance that carries an effective date and an accountability mechanism, there is no imperative. The FISMA framework OMB manages has no teeth when the office itself doesn't bite back.

What this means on a Monday

For the compliance director at a civilian agency who still hasn't finished the inventory asset description fields, nothing changes on Monday because OMB hasn't said what's next. That's the point and the problem. For the Tier-1 supplier shipping OT controllers or connected building systems into federal facilities, the absence of an enforcement posture is a mixed signal. FAR-level IoT and OT procurement updates are still under consideration at the Federal Acquisition Regulatory Council, per GAO's 2022 critical-infrastructure report, and no agency inventory regime is being audited. So a CISO vendor asking for NIST-aligned firmware attestations is asking nicely. For the state CISO watching this, the pattern isn't reassuring. If the federal government can't get half its civilian agencies to document what's plugged in, its guidance to critical-infrastructure operators on the same asset class has a credibility ceiling.

This is the last report Congress ordered

The IoT Cybersecurity Improvement Act of 2020 mandated GAO's biennial progress review. The Sept. 30 report to House Oversight and House and Senate Homeland Security is the final installment in that series. There's no next check scheduled by statute. If OMB doesn't move on the FY 2026 guidance recommendation in the report, the count of agencies with complete inventory documentation is exactly what interested parties will learn next time through a Freedom of Information Act request rather than a mandated report card. For a program that's been tectonic by accident rather than by design, that's the more consequential change than the inventory gap itself.


Published ·Deep Fathom

GAO: Only 14 agencies inventoried IoT devices two years late — The Broadside