# GAO Flags Federal Networked-Device Security Gaps

A September 30, 2026, GAO audit found that only 7 of 22 civilian CFO Act agencies fully met OMB requirements for cybersecurity of networked devices, including IoT and operational technology (OT). Although 15 agencies had established device inventories, only 11 were maintaining them and 10 reported all required information. The original inventory deadline was September 2024. GAO recommended that OMB update its guidance, set an implementation timeline, and oversee agency implementation; that recommendation remains open. Agencies cited technical and resource constraints and competing priorities, and the signals identify no specific solicitation or contract.

- For procurement teams, the findings point to potential agency needs in device discovery, inventory management, OT/IoT security controls, and implementation support if OMB or agencies act on the recommendations.
- Contractors offering these capabilities can assess how their solutions address the stated inventory and cybersecurity needs; the audit does not establish a procurement schedule or confirm upcoming awards.
- Agencies that have not maintained complete inventories may face added implementation work, while technical and resource constraints could shape their support requirements.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 01, 2026

### Government Entities
- Government Accountability Office (GAO)
- Office of Management and Budget (OMB)

### Sources
- [Federal Agencies Lag on Networked Device Cybersecurity Requirements | Legis1](https://legis1.com/news/iot-device-inventory-most-federal-agencies-lack) - Legis1
- [GAO: Most Agencies Fall Short on Cyber Requirements for Networked Devices – MeriTalk](https://www.meritalk.com/articles/gao-most-agencies-fall-short-on-cyber-requirements-for-networked-devices) - MeriTalk