Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices
GAO’s final bi‑annual report on networked devices finds that most civilian agencies have not fully implemented OMB’s IoT/OT inventory requirements established in December 2023 and updated in January 2025.…
Intelligence Package
Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices
Breaking analysis of what happened and who is affected.
GAO’s final bi‑annual report on networked devices finds that most civilian agencies have not fully implemented OMB’s IoT/OT inventory requirements established in December 2023 and updated in January 2025.…
Read full report →Segment ImpactInternet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices
Deep dive into how this impacts each market segment.
Affected segments pending source review. The GAO report identifies significant, government-wide gaps in implementing OMB’s networked device inventory requirements (requirements established December 2023 and updated January 2025; initial inventories required by September 2024).…
Read full report →Action KitInternet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices
Actionable checklists and implementation guidance.
GAO found most agencies have not fully implemented OMB's networked device inventory requirements (established Dec 2023; updated Jan 2025). Initial inventories were required by Sept 2024, but as of Sept 2026 only a minority of the 22 civilian CFO Act agencies had complete, maintained inventories…
Read full report →TL;DR
GAO’s final bi‑annual report on networked devices finds that most civilian agencies have not fully implemented OMB’s IoT/OT inventory requirements established in December 2023 and updated in January 2025. Initial inventories were required by September 2024, but as of September 2026 only 15 of 22 civilian CFO Act agencies had established an inventory, 11 were maintaining inventories, 10 included all required device information, and only 7 had fully met all three OMB requirements; no agency reported an IoT cybersecurity waiver. OMB has not issued updated guidance covering fiscal year 2026, leaving agencies without a clear directive or timeline to complete inventories and implement controls. The absence of complete inventories increases risk that agencies will not identify or secure vulnerable IoT/OT assets, potentially exposing sensitive systems and data. Contractors supporting asset inventories, procurement, and cybersecurity should treat this as an urgent capture and program support opportunity while actively monitoring for OMB guidance and agency remediation plans.
Key Points
- What happened: GAO found most civilian agencies have not fully met OMB’s networked device inventory requirements established Dec 2023 and updated Jan 2025; required initial inventories were due Sept 2024 and GAO reported agency status as of Sept 2026.
- Who is affected: 22 civilian Chief Financial Officer (CFO) Act agencies (per GAO’s review) and contractors that support agency IoT/OT asset management, procurement, and cybersecurity.
- Timeline: Requirements established December 2023, updated January 2025; initial inventories required by September 2024; GAO status snapshot as of September 2026. OMB guidance covering fiscal year 2026 has not been issued.
- What contractors should do NOW: Conduct rapid capability and capture reviews for IoT/OT asset inventory and remediation services; align messaging and proposals to OMB inventory and waiver processes; prioritize outreach to the 22 civilian CFO Act agencies and agency components that have not met requirements; and set automated monitoring for OMB and agency guidance updates.
Who Is Affected
Primary affected segments:
- 22 civilian Chief Financial Officer (CFO) Act agencies (as reviewed by GAO).
- Federal contractors providing IoT/OT asset discovery, inventorying, cybersecurity remediation, procurement support, and systems engineering for networked devices.
Specific NAICS codes, agencies, and contract vehicles pending source review.
Frequently Asked Questions
Q: How many agencies met OMB’s inventory requirements?
A: As of September 2026, GAO reports 15 of 22 civilian CFO Act agencies had established an inventory, 11 were maintaining inventories, 10 had included all required device information, and 7 had fully met all three OMB requirements. No agencies had reported an IoT cybersecurity waiver.
Q: Has OMB provided a new deadline or updated guidance for fiscal year 2026?
A: GAO states OMB has yet to issue updated guidance that covers fiscal year 2026; agencies therefore lack an updated imperative and timeline. Any further timing or deadlines are pending source review until OMB issues guidance.
Q: Does this report create new legal obligations for contractors?
A: The GAO report documents agency progress and OMB’s requirements; contractors should treat this as a driver for agency demand for inventory and remediation services. For any binding acquisition or compliance obligations, contractors should monitor OMB and agency solicitations and guidance — specifics are pending source review.
Definitions
- Internet of Things (IoT): Networked devices that interact with information systems and the physical world, such as building maintenance systems and medical/laboratory equipment (as used in the GAO summary).
- Operational Technology (OT): Devices and systems that interact with the physical world (e.g., programmable logic controllers), referenced alongside IoT in the GAO summary.
- Office of Management and Budget (OMB): Federal office that issued the networked device requirements referenced in the report.
- IoT Cybersecurity Improvement Act of 2020: Statute cited in the report that includes provisions for OMB and civilian CFO Act agencies to identify and protect networked devices.
- Chief Financial Officer (CFO) Act agencies: Civilian federal agencies referenced by GAO in its 22‑agency review.
Intelligence Response
- Detection: Cabrillo Signals War Room — Already detected this GAO report and delivered this briefing. War Room will continue to watch for OMB guidance updates, agency remediation plans, and related congressional or agency actions.
- Pipeline impact and prioritization: Cabrillo Signals Match Engine — Will automatically rescore opportunity pipelines and adjust capture priorities for teams with IoT/OT and cybersecurity offerings when OMB or agency actions change demand.
- Agency tracking and lead generation: Cabrillo Signals Intelligence Hub — Tracks the 22 civilian CFO Act agencies, flags those that have not met requirements, and runs saved searches to alert when related solicitations or amendments appear on SAM.gov (System for Award Management).
- Proposal execution: Proposal Studio (Proposal OS) and Proposal Studio Workflow Tracker — Use Proposal Studio to assemble compliance matrices addressing OMB inventory requirements and to generate bid materials; run the 9‑gate capture process and automated compliance routing with Workflow Tracker to produce audit‑ready documentation.
Who to notify:
- BD/Capture Lead — to initiate outreach and prioritize agency target lists.
- Proposal Manager — to prepare compliant response templates and pricing strategies.
- Cybersecurity/Technical Lead — to scope inventory/discovery and remediation solutions.
- Program Delivery/Service Ops — to evaluate delivery readiness and staffing.
First 48‑hour playbook
- Hour 0–4: War Room confirms GAO findings, tag affected agencies in the Intelligence Hub, and alert BD/Capture Lead and Proposal Manager.
- Hour 4–12: Match Engine rescoring completes; BD/Capture Lead triages high‑value agency targets and assigns capture owners. Proposal Studio scaffolds an inventory/remediation compliance matrix.
- Hour 12–24: Technical Lead performs a gap analysis of current capabilities vs. OMB inventory requirements; Proposal Manager initiates outreach materials and pre‑RFI messaging.
- Hour 24–48: Conduct targeted outreach to agency contacts, submit capability statements, and set saved searches in Intelligence Hub for OMB guidance and solicitations. Begin prioritizing resources for rapid task order responses.
Reference materials and playbooks: Winning Federal Contracts Guide (/insights/winning-federal-contracts). For cybersecurity alignment, see the CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide).