What happened
The Department of Homeland Security inspector general published a report finding that nearly nine out of ten federal civilian executive branch agencies failed to meet the June 2025 deadline for implementing cloud security requirements from CISA. In raw numbers, 88 of 102 agencies, or 86 percent, did not put all the mandatory secure configuration policies in place.
It got worse rather than better. As of February this year, 78 of 102 agencies, or 76 percent, were still out of compliance. The gaps were not exotic. Agencies had failed to block outdated authentication procedures, failed to enforce multifactor authentication, and in some cases failed to adopt a policy protecting sensitive and personally identifiable information.
The requirements came through a binding operational directive tied to the Secure Cloud Business Applications project, which CISA built after the 2022 SolarWinds compromise. The inspector general's central conclusion is uncomfortable: CISA lacks the authority necessary to require full and timely implementation of its directives.
Why this is a GRC story
This is the oldest failure mode in the discipline, documented in public. A control framework was published, deadlines were set, and the deadline passed with most of the population noncompliant. The interesting question is not whether the agencies were careless. It is whether a directive with no enforcement mechanism should ever have been counted as a control.
Reporting is not remediation. The directive required alignment to baselines. The baselines were scoped. The deadline was fixed. What was missing was any consequence for missing it, and the inspector general says so directly: without defined enforcement oversight, the federal cloud posture is weakened and agencies remain exposed to preventable threats.
Every GRC team runs a version of this. Internal policies that carry no audit follow up drift the same way. The pattern holds whether the directive comes from a regulator or from your own security committee: requirements without verification decay into documentation.
The wrong measure was tracked. Compliance was measured once at a deadline and then largely left alone, which is how a 14 percent compliance rate in mid 2025 could still be a 24 percent rate seven months later.
What to watch
Watch whether Congress moves to give CISA enforcement authority over its binding operational directives, since the report frames that as the root cause rather than agency apathy. Watch as well for how the remaining noncompliant agencies are named or tracked in future oversight reporting, because public attribution tends to move timelines more reliably than deadlines do. For anyone maintaining an internal control programme, the practical takeaway is to build the verification step into the requirement at the moment it is written, not after the first missed deadline.
Attribution: Analysis based on CyberScoop's reporting on the DHS inspector general report. This article is original commentary, not a repost of the source material.
