Back to Insights
War RoomOctober 7, 2026

IT Dashboard: Selected Agencies’ Investment Ratings Fail to Fully Consider Risks

GAO found that CIO risk ratings on the federal IT Dashboard do not fully reflect documented investment risks for a substantial share of reviewed investments. GAO reviewed 53 major IT investments (identified from 26 agencies’ FY2025 budget data) and found its independent risk assessments matched…

3 reports in this intelligence package
Blog post hero image

TL;DR

GAO found that CIO risk ratings on the federal IT Dashboard do not fully reflect documented investment risks for a substantial share of reviewed investments. GAO reviewed 53 major IT investments (identified from 26 agencies’ FY2025 budget data) and found its independent risk assessments matched CIO ratings 27 times, showed more risk 24 times, and showed less risk twice. Contributing factors included 21 of 53 CIO ratings not being updated timely under agencies’ own processes and two agencies using rating cycles longer than OMB’s quarterly guidance. In April 2026 OMB announced it will sunset the Dashboard and replace it with a new streamlined system but provided no release timeframe; in the interim agencies must correct CIO rating quality and cadence to avoid blind spots in oversight. For contractors, this raises short-term uncertainty around transparency and oversight of major IT investments and requires immediate BD/capture and compliance posture adjustments to avoid missed opportunities and mispriced bids.

Key Points

  • What happened: GAO reviewed CIO ratings on the IT Dashboard for 53 major IT investments and concluded the Dashboard ratings often understate documented risk; 27 ratings matched GAO, 24 showed more risk, and 2 showed less risk. Timeliness and rating-cycle variance were primary drivers of mismatches.
  • Who is affected: Market segments and NAICS explicitly identified in segmentation — NAICS 541511, 541512, 541513, 541519, 541611, 541618, 518210, 541990; agencies named in the input — OMB, GSA (General Services Administration), and GAO; contract vehicles named in the input — SEWP, OASIS+, 8(a) STARS III, Alliant 2, CIO-SP3; market segments include IT Services, IT Modernization, System Integration, Software Development, IT Program Management, Enterprise IT, Cloud Services, Cybersecurity; compliance surfaces include FITARA, OMB Circular A-11, OMB Circular A-130, NIST 800-53, FedRAMP (Federal Risk and Authorization Management Program).
  • Timeline: OMB announced in April 2026 that it is taking steps to sunset the IT Dashboard and replace it with a new streamlined system but did not provide a release timeframe; agencies must address rating issues in the interim.
  • What contractors should do NOW: Immediately validate active opportunity pipelines and capture plans for major IT investments; notify capture and BD leads to reassess bid/no-bid decisions where Dashboard ratings previously informed risk assessments; ensure proposals and pricing account for potential increased oversight or remedial actions; confirm compliance posture against the named compliance surfaces and prepare briefing materials showing how your solution mitigates the documented risks.

Who Is Affected

Affected segments are primarily contractors focused on federal IT modernization and acquisition for major investments. Specific NAICS codes, agencies, contract vehicles, and compliance regimes named in the input are:

  • NAICS: 541511, 541512, 541513, 541519, 541611, 541618, 518210, 541990
  • Agencies: OMB, GSA, GAO (note: GAO conducted the review; 12 agencies held the 53 selected investments but names for all 12 are not provided)
  • Contract vehicles: SEWP, OASIS+, 8(a) STARS III, Alliant 2, CIO-SP3
  • Market segments: IT Services, IT Modernization, System Integration, Software Development, IT Program Management, Enterprise IT, Cloud Services, Cybersecurity
  • Compliance surfaces: FITARA, OMB Circular A-11, OMB Circular A-130, NIST 800-53, FedRAMP

Frequently Asked Questions

Q: Why did GAO find differences between CIO ratings and its assessments?

A: GAO found differences because agencies used different processes to develop CIO ratings, many ratings were not updated timely (21 of 53), and two agencies used rating cycles longer than quarterly, contrary to OMB guidance. GAO based its assessments on investment risk documentation.

Q: Is the IT Dashboard going away immediately?

A: In April 2026 OMB announced steps to sunset the Dashboard and replace it with a streamlined system but did not provide a release timeframe. Agencies must address rating quality and frequency during the interim.

Q: How should contractors change immediate capture or bid strategy?

A: Reassess opportunities where Dashboard ratings influenced your risk assumptions; validate assumptions with agency points of contact, update pricing and risk reserves to reflect potential increased oversight, and prioritize wins where you can demonstrate documented risk mitigation tied to the compliance surfaces listed. For capture process support, use Cabrillo’s proposal and capture products to re-score pipelines and prepare compliant responses.

Definitions

  • IT Dashboard: OMB-launched transparency tool (launched 2009) that displays CIO ratings of federal IT investments; operated by GSA per the Summary.
  • CIO rating: Chief Information Officer’s assessment of an investment’s level of risk as reflected on the IT Dashboard.
  • GAO: U.S. Government Accountability Office — the body that reviewed CIO ratings and performed independent risk assessments for this report.

Intelligence Response

  • Cabrillo products to leverage: Cabrillo Signals War Room (already detected this event and delivered this briefing), Cabrillo Signals Match Engine, Cabrillo Signals Intelligence Hub, Proposal Studio (Proposal OS), and Proposal Studio Workflow Tracker.
  • Who to notify: BD leadership, capture leads, proposal managers, program managers for affected opportunities, and security/compliance officers responsible for FITARA/OMB/FedRAMP/NIST alignment.
  • First 48-hour playbook:
  • Hour 0–4: War Room alert — Cabrillo Signals War Room pushes this briefing to BD and capture leads; perform high-level triage of open opportunities tied to major investments.
  • Hour 4–12: Run Cabrillo Signals Match Engine to rescore opportunity pipeline and flag opportunities where Dashboard ratings previously reduced perceived risk; notify capture owners of changed scores.
  • Hour 12–24: Use Cabrillo Signals Intelligence Hub saved searches to confirm which named contract vehicles and NAICS categories map to your active pursuits; brief compliance leads on named compliance surfaces.
  • Hour 24–48: Launch Proposal Studio workflows for prioritized pursuits; create compliance matrices and risk-mitigation sections; route through Proposal Studio Workflow Tracker gates and schedule leadership brief for updated bid/no-bid decisions.

Reference materials and internal guides: Winning Federal Contracts Guide (/insights/winning-federal-contracts). For compliance alignment use related guides: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide).