Back to Insights
War RoomSeptember 18, 2026

Despite upgrades, IRS cyber program still ‘not effective,’ watchdog says

TIGTA found the IRS's cybersecurity program "not effective" in its FISMA assessment for fiscal 2026, citing deficiencies across NIST Cybersecurity Framework functions — identify, protect, and detect.…

3 reports in this intelligence package
Blog post hero image

TL;DR

TIGTA found the IRS's cybersecurity program "not effective" in its FISMA assessment for fiscal 2026, citing deficiencies across NIST Cybersecurity Framework functions — identify, protect, and detect. The report highlights unacceptable maturity in configuration management, vulnerability remediation, and continuous monitoring capabilities. Contractors who support the IRS or handle taxpayer data should expect heightened scrutiny of cybersecurity controls and the potential for tightened security requirements on existing and future engagements. Agencies and acquisition teams are likely to revisit control baselines and monitoring expectations while the IRS addresses these gaps. Immediate implications include targeted audits, stronger compliance verification during source selection, and possible changes to contract-level security deliverables. Prepare to demonstrate improved maturity in configuration, vulnerability management, and continuous monitoring to remain competitive.

Key Points

  • What happened: The Treasury Inspector General for Tax Administration found the IRS's cybersecurity program "not effective" under FISMA for fiscal 2026, with deficiencies in the identify, protect, and detect functions of the NIST Cybersecurity Framework and shortfalls in configuration management, vulnerability remediation, and continuous monitoring capabilities.
  • Who is affected: Contractors in the listed market segments and NAICS codes; specified agencies include IRS, Treasury, and TIGTA; contract vehicles named in segmentation may be used to source follow-on work.
  • Timeline: Fiscal 2026 FISMA assessment reported these findings; further timeline details TBD pending source review.
  • What contractors should do NOW: Immediately inventory and validate controls tied to configuration management, vulnerability remediation, and continuous monitoring; prepare evidence of control maturity; flag affected proposals and task orders for enhanced security review; and notify capture and security leads to update bid/no‑bid and compliance strategies.

Who Is Affected

Specific NAICS codes, agencies, and contract vehicles pending source review.

Affected market segments (from segmentation): Cybersecurity; IT Services; Security Operations; Vulnerability Management; Continuous Monitoring; Configuration Management; Risk Management; Compliance and Assessment; Federal Civilian IT.

Compliance regimes called out (from segmentation): FISMA; NIST Cybersecurity Framework; NIST 800-53; NIST 800-171 (NIST Special Publication 800-171); IRS Publication 1075; FedRAMP (Federal Risk and Authorization Management Program); NIST 800-137.

Contract vehicles (from segmentation): SEWP; GSA (General Services Administration) IT Schedule 70; OASIS+; Alliant 2; CIO-SP3.

Agencies (from segmentation): IRS; Treasury; TIGTA.

Frequently Asked Questions

Q: What specifically failed in the IRS assessment?

The TIGTA FISMA assessment found the IRS's cybersecurity program "not effective" for fiscal 2026, with deficiencies in the identify, protect, and detect functions of the NIST Cybersecurity Framework and unacceptable maturity in configuration management, vulnerability remediation, and continuous monitoring capabilities.

Q: Will this change contract security requirements immediately?

Expect increased scrutiny and potential changes to security requirements, but specific changes to contract terms, task orders, or solicitations are TBD pending agency actions and further source review.

Q: What should contractors prioritize for the next procurement or task order?

Prioritize demonstrable maturity in configuration management, vulnerability remediation, and continuous monitoring; update evidence packages and compliance matrices; and prepare for intensified audit and assessment activity.

Definitions

  • FISMA: The Federal Information Security Modernization Act — the statutory framework for federal agency information security reporting and oversight referenced in the assessment.
  • NIST Cybersecurity Framework: The NIST framework referenced in the report; includes core functions such as identify, protect, and detect.
  • Configuration management: Practices and controls to manage system configurations and maintain secure baselines.
  • Vulnerability remediation: Processes to identify, prioritize, and remediate security vulnerabilities.
  • Continuous monitoring: Ongoing observation and assessment of security controls and system state to detect and respond to changes and threats.
  • Identify / Protect / Detect: Core functions of the NIST Cybersecurity Framework cited as deficient in the assessment.

Intelligence Response

Cabrillo Signals War Room has already detected this TIGTA FISMA event and delivered this briefing. Use the following Cabrillo products to operationalize response and capture actions:

  • Cabrillo Signals War Room — Already detected this event and delivered this briefing. Continuously monitors regulatory changes, contract vehicles, and policy shifts.
  • Cabrillo Signals Match Engine — Automatically rescoring opportunity pipelines to surface solicitations and task orders likely to change competitiveness as agencies tighten cybersecurity requirements.
  • Cabrillo Signals Intelligence Hub — Tracking affected agencies, NAICS codes, and contract vehicles; saved searches will alert capture teams when follow-on solicitations appear on SAM.gov (System for Award Management).
  • Proposal Studio (Proposal OS) and Proposal Studio Workflow Tracker — Use for rapid bid/no‑bid decisions, compliance matrix updates tied to configuration management and vulnerability remediation, and for 9-gate capture management with automated compliance routing and audit-ready documentation.

Notify: Capture Lead, Proposal Manager, Security/CISO or Security Lead, Program Manager, and Compliance Officer immediately. Begin targeted review of active proposals and task orders.

First 48-hour playbook:

  • Hour 0-4: Convene capture + security sync; declare affected opportunities; assign owners; pull current compliance artifacts for configuration management, vulnerability remediation, and continuous monitoring.
  • Hour 4-12: Use Proposal Studio to update compliance matrices and produce audit-ready evidence bundles; run Match Engine rescoring to reprioritize pipeline.
  • Hour 12-24: Security team conducts gap analysis against NIST functions identified (identify/protect/detect); produce remediation plan and timeline for evidence of maturity improvements.
  • Hour 24-48: Update capture strategy and bid/no‑bid decisions; prepare briefing for contracting officers or agency liaisons as needed; set saved searches in Intelligence Hub for solicitations and RFP amendments.

Relevant internal resources: Secure Operations Guide (/insights/secure-operations-guide). Related guides: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide).