cisatrade-pressNewsThe Broadside2 min read

IG finds 86% of agencies missed CISA's cloud security deadline

The DHS IG confirms what practitioners have known: BOD deadlines land with a thud when CISA has no enforcement authority beyond monitoring and reporting.


TL;DR

The DHS Inspector General found that 88 of 102 federal civilian agencies failed to meet the June 2025 deadline for CISA's Binding Operational Directive 25-01, which requires cloud environments to align with SCuBA secure configuration baselines. As of February 2025, 76% remained non-compliant, with gaps in MFA enforcement, legacy authentication blocking, and PII protection remaining open. The IG concluded CISA lacks authority to compel implementation, leaving the federal cloud security posture weakened and agencies exposed to preventable threats.

IG finds 86% of agencies missed CISA's cloud security deadline
Editorial illustration · drawn by The Broadside

The numbers are grim but they shouldn't surprise anyone. The DHS Inspector General's audit of BOD 25-01 compliance found that 86% of FCEB agencies missed the June 2025 deadline for implementing SCuBA cloud security baselines. By February 2025, three-quarters were still not in compliance. The gap between mandate and reality isn't a one-off delay; it's the shape of the regime.

BOD 25-01, issued in December 2024, required agencies to identify cloud tenants, deploy SCuBA assessment tools, and align their Microsoft 365 and Google Workspace environments to CISA's secure configuration baselines. The baselines include blocking outdated authentication protocols, enforcing MFA, and protecting sensitive and PII data, the kind of controls that appear in incident postmortems when they're absent. That these remain unimplemented across most of the federal civilian enterprise isn't a marginal finding. It's the finding.

The enforcement gap isn't new

CISA can monitor. It can report. It can cajole. It cannot sanction. The IG report states plainly that "CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives" and that without "defined enforcement oversight of SCuBA policy compliance, the Federal cloud security posture across the Federal enterprise is weakened." This isn't a revelation to practitioners who've watched BOD cycles come and go, but it's now formalized in an IG finding rather than hallway grumbling.

The post-SolarWinds push for centralized cloud security configuration produced genuinely useful artifacts, the SCuBA baselines are well-constructed, the assessment tools are available. But a directive without an enforcement mechanism is a recommendation with a due date. For the security engineer at a non-compliant agency, Monday looks exactly like Friday: the legacy protocols stay enabled, the MFA gaps persist, and the attack surface CISA mapped in 2024 remains open.

Until Congress grants CISA the authority to make BOD deadlines binding rather than aspirational, the cycle is unlikely to break. The next IG report will find much the same thing.


Published ·Deep Fathom