# CISA Reports Federal Agencies Miss Cloud Security Deadlines

Recent Department of Homeland Security Inspector General reports reveal that **86% of federal civilian executive branch agencies failed to fully implement CISA's Secure Cloud Business Applications (SCuBA) policies by the June 2025 deadline**. The findings highlight CISA's limited enforcement authority over Binding Operational Directives (BODs), which has contributed to inconsistent adoption of mandated cloud security standards and increased cybersecurity risks across federal agencies.

- **Why this matters:** Procurement professionals should anticipate increased emphasis on enforceable cloud security requirements in future contracts as agencies work to close compliance gaps.
- The limited authority of CISA to mandate compliance suggests potential legislative or policy changes that could impact procurement strategies and contract terms.
- Contractors providing cloud services and cybersecurity solutions may find growing demand for offerings aligned with CISA's SCuBA policies and zero trust frameworks.
- Agencies and vendors should prioritize robust cloud security implementations to mitigate vulnerabilities and align with evolving federal cybersecurity mandates.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 24, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- Department of Homeland Security (DHS)
- Federal Civilian Executive Branch (FCEB)
- Federal Enterprise Improvement Team (FEIT)
- Senate Homeland Security and Governmental Affairs Committee

### Key Quotes
> Cloud adoption across the federal government continues to accelerate, but cloud security can’t remain optional or inconsistently implemented.
> — Gary Barlet, Federal Sector Chief Technology Officer, Illumio

### Sources
- [Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack | CyberScoop](https://cyberscoop.com/dhs-ig-report-federal-agencies-fail-cisa-cloud-security-directives) - CyberScoop
- [
        IG report finds government cyber directives lack teeth | Federal News Network](https://federalnewsnetwork.com/cybersecurity/2026/09/ig-report-finds-government-cyber-directives-lack-teeth) - Federal News Network