Back to Insights
War RoomSeptember 29, 2026

DOGE: Congress and the Public Lack Assurance That Systems and Data Were Protected at Multiple Agencies

GAO reviewed DOGE teams at six agencies and found that teams at CFPB, Department of Education, NOAA, and SEC had access to more than 23 systems handling contracts, grants, HR, and finance data that include personally identifiable information (PII).…

3 reports in this intelligence package

TL;DR

GAO reviewed DOGE teams at six agencies and found that teams at CFPB, Department of Education, NOAA, and SEC had access to more than 23 systems handling contracts, grants, HR, and finance data that include personally identifiable information (PII). GAO could not determine whether DOGE team members had specific permissions (view or modify) on those systems. SBA and VA did not respond to GAO’s requests about system access. CFPB, Education, and SEC provided limited documentation on security controls (training, rules-of-behavior, background investigations); NOAA, SBA, and VA did not provide requested information about controls. As a result, Congress and the public lack assurance that agencies implemented controls to ensure DOGE team members appropriately protected systems and data. GAO says it has statutory authority to obtain this information but agencies did not fully cooperate. Contractors should assume increased oversight and demand for evidence of access controls, training, and personnel security in upcoming solicitations and capture activities.

Key Points

  • What happened: GAO found DOGE teams at six agencies were given access to agency systems; documentation was incomplete or not provided, so agency adherence to IT security rules and protection of PII could not be confirmed.
  • Who is affected: NAICS: 541512, 541519, 541611, 541618, 541690, 541990, 561320, 518210, 541511, 541513; Agencies: CFPB, Department of Education (ED), Department of Commerce (NOAA), SEC, SBA, VA; Market segments include Cybersecurity, IT Services, Privacy and Data Protection, and related areas.
  • Timeline: Timeline TBD pending source review.
  • What contractors should do NOW: Immediately validate your access control, training, and personnel-security deliverables for agency-facing work; prepare audit-ready artifacts (training records, rules-of-behavior acknowledgements, background-investigation status) and update capture pipelines to highlight compliance readiness using Cabrillo Signals and Proposal Studio.

Who Is Affected

Specific NAICS codes, agencies, and contract vehicles pending source review. Market and compliance surfaces explicitly named in available materials include:

  • Market segments: Cybersecurity; IT Services; Information Security; Privacy and Data Protection; IT Security Training; Background Investigation Services; Identity and Access Management; IT Compliance and Audit; System Security; Personnel Security.
  • Contract vehicles (listed in segmentation): OASIS+, Alliant 2, 8(a) STARS III, VETS 2, GSA (General Services Administration) Schedule 70.
  • Compliance surfaces (listed in segmentation): NIST 800-53; FISMA; Privacy Act; NIST 800-171 (NIST Special Publication 800-171); FedRAMP (Federal Risk and Authorization Management Program); OMB Circular A-130; NIST Cybersecurity Framework.

Frequently Asked Questions

Q: What did GAO find about agency DOGE team access to systems?

GAO found that DOGE teams at CFPB, Education, NOAA, and SEC had access to more than 23 systems that managed contracts, grants, HR, and finance and contained PII, but GAO could not determine the specific permissions of DOGE team members from the information provided.

Q: Which agencies did not provide requested information to GAO?

SBA and VA did not respond to GAO’s requests about which systems DOGE team members had access to. NOAA, SBA, and VA did not respond to GAO’s requests about whether they implemented controls to ensure adherence to IT security rules.

Q: What should contractors expect in procurement and compliance posture going forward?

Expect heightened scrutiny and requests for evidence of access controls, user training, background investigation records, and rules-of-behavior acknowledgements. Prepare audit-ready documentation and ensure capability statements and proposals emphasize demonstrable compliance with relevant frameworks (see compliance surfaces listed above). Specific solicitation impacts are Pending source review.

Definitions

  • DOGE (Department of Government Efficiency): The agency-level teams established to work with the United States DOGE Service (USDS) to modernize technology and maximize government efficiency, as referenced in the GAO review.
  • USDS (United States DOGE Service): The executive-branch service created by executive order to maximize government efficiency through technology modernization, and to which agency DOGE teams were meant to coordinate.
  • PII (Personally Identifiable Information): Data elements that identify or can be used to identify an individual; GAO noted affected systems contained PII.
  • GAO (Government Accountability Office): The audit agency that conducted the review and reported limitations in agency responses and documentation.

Intelligence Response

  • Cabrillo Signals War Room — Already detected this GAO report and delivered this briefing. War Room will flag traceable impacts across opportunities and regulatory tracking.
  • Cabrillo Signals Match Engine — Rescores pipeline opportunities where evidentiary compliance (training, background checks, access control artifacts) improves win probability; prioritize opportunities tied to affected agencies and vehicles.
  • Cabrillo Signals Intelligence Hub — Tracks affected agencies, NAICS codes, and contract vehicles and will alert when related solicitations or follow-on inquiries appear on SAM.gov (System for Award Management).
  • Proposal Studio (Proposal OS) & Proposal Studio Workflow Tracker — Use Proposal OS to build bid documents with compliance matrices and pre-populated artifacts (training logs, rules-of-behavior templates). Use Workflow Tracker to route compliance approvals and produce audit-ready documentation through the 9-gate capture process.

Who to notify:

  • Capture Lead — prioritize affected vehicles and update bid/no-bid decisions.
  • Security/Compliance Officer — validate training, background, and access-control artifacts.
  • Proposal Manager — ensure evidence is attached to proposals and compliance matrices.
  • Business Development — refresh pipeline scoring and outreach plans.

First 48-hour playbook

  • Hour 0–4: Convene response stand-up (Capture Lead, Security/Compliance Officer, Proposal Manager). Pull existing access-control and personnel-security artifacts for any work with affected agencies/vehicles.
  • Hour 4–12: Use Cabrillo Signals Intelligence Hub to surface active solicitations and Match Engine to rescore top opportunities; tag opportunities requiring immediate documentation.
  • Hour 12–24: Assemble audit package templates in Proposal Studio (training logs, rules-of-behavior acknowledgements, background-investigation status). Route artifacts through Proposal Studio Workflow Tracker for compliance signoff.
  • Hour 24–48: Update capture strategy and outreach sequence; notify partners and primes if subcontractors’ artifacts are missing; prepare responses to potential agency requests for evidence.

Use these Cabrillo guides for next steps: Winning Federal Contracts Guide (/insights/winning-federal-contracts). For compliance alignment, see CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide).

Contact for source report: Nick Marinos (per GAO report contact information in source).