Skip to main content
Compliance

Agencies Flout CISA Cloud Security Directives, Heightening Cyber Risk

Dimly lit government office space with rows of cluttered desks and computers.

"Agencies may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat," the inspector general for the Department of Homeland Security wrote in a blunt assessment published Wednesday.

DHS Office of Inspector General findings

The DHS Office of Inspector General reviewed agency progress on implementing cloud security directives and concluded the federal enterprise remains largely out of compliance. The report found that 88 of 102 federal civilian executive branch agencies—86%—did not implement all mandatory Secure Cloud Business Applications (SCuBA) policies required by Binding Operational Directive 25-01. As of February 2026, the IG reported that compliance had not meaningfully improved: 78 out of 102 agencies, or 76%, still had not implemented all mandatory SCuBA policies.

The IG’s language is direct: failures to adopt required configurations or meet implementation deadlines "weaken" the federal cloud security posture and leave agency cloud environments "exposed to preventable threats." The report also states that "CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives," framing the compliance shortfall not only as an operational failure, but as a legal and governance gap.

SCuBA, BOD 25‑01 and the December 2024 directive

SCuBA — the Secure Cloud Business Applications project — was created in response to the 2022 SolarWinds attack and is intended to reduce the risk of breaches by providing secure configuration baselines, settings and assessment tools for cloud business applications. A December 2024 directive instructed agencies to align with SCuBA and listed mandatory requirements to be implemented by a June 2025 deadline. The IG’s review measured agency action against those mandatory SCuBA policies and the BOD that set the deadline.

Specific baselines left unimplemented

The IG gave concrete examples of baselines that many federal agencies had not implemented: blocking outdated authentication procedures, enforcing multifactor authentication, and implementing a policy to protect sensitive and personally identifiable information. The report argues these are not theoretical controls; "implementation of these baselines could mitigate vulnerabilities and threats from affecting the cloud business applications."

Because the IG attributes the shortfalls in part to CISA’s limited authority over BOD compliance, the report ties specific technical gaps directly to a governance issue. "Without defined enforcement oversight of SCuBA policy compliance, the Federal cloud security posture across the Federal enterprise is weakened," the IG wrote.

What this means for technologists, policymakers, and federal agencies

  • Technologists and security teams: The report identifies concrete configuration controls — authentication hardening, multifactor authentication, and PII-protection policies — that remain unimplemented; teams responsible for cloud environments will need to inventory gaps against the SCuBA baselines and prioritize those specific mitigations.
  • Policymakers and regulators: The IG's finding that "CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives" frames a legal and oversight question that will determine whether directives remain persuasive guidance or become enforceable requirements.
  • Federal agencies and program managers: With high noncompliance rates—86% at the initial June 2025 check and 76% as of February 2026—agency leaders face a choice between accelerating technical implementation to reduce exposure, or operating with continued risk and documenting why SCuBA baselines were not adopted.

The DHS IG report links measurable technical shortfalls to an institutional enforcement gap. CISA did not respond to the report, the IG notes, and the agency "didn’t immediately respond to a request for comment from CyberScoop." Absent a change to authorities or a new enforcement mechanism, the IG warns, federal cloud environments will remain exposed to "preventable cyberattacks and related threat." That conclusion leaves a clear question: if Binding Operational Directives cannot be compelled, who will ensure the mandatory configurations in BOD 25‑01 are actually implemented?

https://cyberscoop.com/dhs-ig-report-federal-agencies-fail-cisa-cloud-security-directives/