Back to Insights
War RoomSeptember 29, 2026

Agencies largely stonewall GAO on audit of DOGE’s data practices

GAO released a report showing that multiple federal agencies largely stonewalled or provided limited information during an 18-month audit of DOGE team members' access to agency IT systems that contain sensitive contract, grant, HR, and financial data.…

3 reports in this intelligence package

TL;DR

GAO released a report showing that multiple federal agencies largely stonewalled or provided limited information during an 18-month audit of DOGE team members' access to agency IT systems that contain sensitive contract, grant, HR, and financial data. Agencies named in the report cited litigation and other reasons for withholding information from congressional oversight, producing significant transparency and oversight gaps. The report raises immediate questions about external personnel access controls and auditability across systems that manage contracts and grants. Contractors operating in affected market segments should expect increased scrutiny, potential follow-on agency investigations, and shifting source-selection or compliance priorities. Short-term implications include uncertainty about how agencies govern external access, which may affect proposals, security posture disclosures, and risk assessments for ongoing work. Monitor agency responses and solicitations closely for policy or access-control changes.

Key Points

  • GAO reported that multiple agencies stonewalled or provided limited information during an 18-month audit of DOGE team members' access to agency IT systems holding sensitive contract, grant, HR, and financial data.
  • Who is affected: NAICS 541512, 541519, 541611, 541690, 518210, 541513, 541715; agencies including SBA, VA, CFPB, SEC, Education (ED), NOAA, DOC, and GAO; market segments such as IT Services, Cybersecurity, Data Management, System Administration, Cloud Services, Grants Management, Financial Management Systems, and HR Systems.
  • Timeline: 18-month audit (as reported by GAO).
  • What contractors should do NOW: inventory contracts and systems that provide external access, validate access-control and logging practices against applicable compliance surfaces (FISMA, NIST 800-53, NIST 800-171 (NIST Special Publication 800-171), FedRAMP (Federal Risk and Authorization Management Program), Privacy Act, OMB A-130, FOIA), update proposals and capture materials to address transparency and oversight concerns, and use Cabrillo Club tooling to rescore pipelines and flag affected opportunities.

Who Is Affected

  • NAICS: 541512, 541519, 541611, 541690, 518210, 541513, 541715.
  • Agencies: SBA, VA, CFPB, SEC, Education (ED), NOAA, DOC, GAO.
  • Contract vehicles: OASIS+, Alliant 3, 8(a) STARS III, VETS 2.
  • Market segments: IT Services; Cybersecurity; Data Management; System Administration; Cloud Services; Grants Management; Financial Management Systems; HR Systems.
  • Compliance regimes to monitor: FISMA; NIST 800-53; NIST 800-171; FedRAMP; Privacy Act; OMB A-130; FOIA.

Frequently Asked Questions

Q: What did GAO find about agency cooperation?

GAO found that multiple agencies either stonewalled or provided limited information during an 18-month audit examining DOGE team members' access to agency IT systems that contain sensitive contract, grant, HR, and financial data.

Q: Does this report change statutory or regulatory requirements for contractors?

Pending source review. The Summary reports transparency and oversight concerns but does not state that statutes or regulations have changed.

Q: What immediate actions should contractors take in response?

Immediately inventory where your personnel or subcontractors access agency systems, validate logging and access-control practices against the listed compliance surfaces, update capture/proposal narratives to address oversight transparency, and rescore affected opportunities using Cabrillo Club tooling.

Definitions

  • GAO: Government Accountability Office — the federal audit office that released the report referenced in the Summary.
  • DOGE: The team named in the GAO audit report; details on DOGE's composition and authorities are pending source review.

Intelligence Response

  • Cabrillo Signals War Room — Already detected this event and delivered this briefing. Continuously monitors regulatory changes, contract vehicles, and policy shifts to surface agency transparency/oversight signals.
  • Cabrillo Signals Match Engine — Automatically rescored affected opportunity pipelines when this event shifted the competitive and risk landscape; use it to reprioritize pursuits tied to the named agencies and vehicles.
  • Cabrillo Signals Intelligence Hub — Tracks the named agencies, NAICS codes, and contract vehicles and will run saved searches to alert when follow-on solicitations, policy responses, or oversight actions appear on SAM.gov (System for Award Management).
  • Proposal Studio (Proposal OS) and Proposal Studio Workflow Tracker — Use Proposal OS to update compliance matrices and win themes addressing transparency and access-control concerns; use Workflow Tracker to document a 9-gate capture response and create audit-ready routing for security and legal reviews.

Who to notify internally: Capture Lead, Security Officer/CISO, Proposal Manager, Contracts Lead, and Executive Sponsor.

First 48-hour playbook:

  • Hour 0–4: Use Cabrillo Signals War Room alert to assemble response team; run a Match Engine rescore on live opportunities for the named agencies and vehicles.
  • Hour 4–12: Inventory contracts and system access points; run Intelligence Hub saved searches for immediate follow-on solicitations or policy notices.
  • Hour 12–24: Populate Proposal Studio compliance matrices with current access-control/logging evidence; initiate Proposal Studio Workflow Tracker routing to Security and Legal for rapid review.
  • Hour 24–48: Prepare client-facing messaging and capture adjustments; document all actions and evidence in Workflow Tracker for audit readiness.

See the Secure Operations Guide (/insights/secure-operations-guide) for secure handling of sensitive government data and related guidance. Related reading: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide), CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide).