Agencies largely stonewall GAO on audit of DOGE’s data practices

GAO released a report finding that multiple federal agencies (SBA, VA, CFPB, SEC, Education, NOAA) stonewalled or provided limited information during an 18-month audit into DOGE team members' access to agency IT systems that contain sensitive contract, grant, HR, and financial data.…

Cabrillo Club

Cabrillo Club

Editorial Team · September 29, 2026 · 4 min read

Share:LinkedInX

Cabrillo Club Insights

Agencies largely stonewall GAO on audit of DOGE’s data practices

Overview

GAO released a report finding that multiple federal agencies (SBA, VA, CFPB, SEC, Education, NOAA) stonewalled or provided limited information during an 18-month audit into DOGE team members' access to agency IT systems that contain sensitive contract, grant, HR, and financial data. The report raises transparency and oversight concerns about external personnel access to systems that manage procurement and financial information. Agencies cited litigation and other reasons for withholding information from congressional oversight, creating ambiguity about how access is granted, monitored, and audited. For contractors who supply IT, cybersecurity, cloud, grants management, HR, or financial management services, this uncertainty can affect risk posture, audit exposure, and how agencies evaluate access controls during source selection. Action is needed now to inventory your exposures, validate access and logging practices, and prepare for potential follow-on agency guidance, oversight requests, or solicitation changes. Use this Action Kit to prioritize immediate evidence-gathering, stakeholder notification, and gap remediation so your proposals and operations remain defensible.

Immediate Actions (This Week)

  • [ ] Inventory staff and subcontractors who have (or could have) access to agency systems in support of contracts, grants, HR, or financial systems; flag any assignments tied to the agencies named in the report (SBA, VA, CFPB, SEC, Education, NOAA, DOC).
  • [ ] Pull access logs, privileged-access records, and recent audit trails for systems that store or process sensitive contract, grant, HR, or financial data; preserve logs in read-only form for potential oversight requests.
  • [ ] Alert contracts, security, and legal teams about the GAO report and record current contract clauses on third-party/externally assigned personnel access; identify contracts that reference any of the compliance frameworks named in your Tags.
  • [ ] Review and secure non-disclosure, data-handling, and subcontract flow-down clauses for employees working on affected agency workstreams; ensure confidentiality and data protection obligations are documented.
  • [ ] Prepare a communication brief for leadership and capture teams summarizing exposure, current mitigations, and evidence retentions in case of agency follow-up or FOIA/oversight inquiries.

Short-Term Actions (30 Days)

  • [ ] Conduct a focused technical review of logging, monitoring, and privileged-access controls for systems supporting the affected functions; verify retention policies and tamper-evidence of logs.
  • [ ] Reconcile contractual access authorizations with identity and access management (IAM) records; close orphaned accounts and implement just-in-time access where practical.

Long-Term Actions (90+ Days)

  • [ ] Formalize an evidence-ready governance package for agency oversight requests: documented access approval workflows, audit log retention and integrity controls, and personnel access matrices.
  • [ ] Update capture and proposal materials to reflect strengthened access controls and oversight readiness; make these updates reusable across opportunities for SBA, VA, CFPB, SEC, Education, NOAA, and DOC opportunities.

Compliance Checklist

  • [ ] FISMA — Review applicability for any systems that could be considered federal information systems in-scope for agency hosting/management.
  • [ ] NIST 800-53 — Confirm system-level controls and assess whether control implementations and audit evidence are documented and readily producible.
  • [ ] NIST 800-171 (NIST Special Publication 800-171) — Where applicable, map contractor-owned systems that handle sensitive agency data to NIST 800-171 requirements and collect evidence for each control.
  • [ ] FedRAMP (Federal Risk and Authorization Management Program) — For cloud services used to process agency data, verify FedRAMP status or alternative agency authorization posture and document artifacts.
  • [ ] Privacy Act — Identify and document handling procedures for any Personally Identifiable Information (PII) that may be covered by the Privacy Act in your systems or deliverables.
  • [ ] OMB A-130 — Ensure system and data governance practices align with OMB A-130 expectations for information stewardship and oversight.
  • [ ] FOIA — Prepare counsel-reviewed procedures for responding to FOIA and oversight requests; maintain a record of preserved evidence and privileged determinations.

Resources

  • Secure Operations Guide (/insights/secure-operations-guide)
  • Related guides:
  • CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide)
  • CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide)
  • Monitor agency guidance and GAO releases for SBA, VA, CFPB, SEC, Education (ED), NOAA, DOC, and GAO for any follow-on instructions, oversight requests, or policy updates. (Agency-specific guidance and GAO report text — TBD pending source review.)

How Cabrillo Club Automates This

Cabrillo Signals War Room — Already detected this event and delivered this briefing within minutes. War Room will continuously monitor GAO publications and communications from the named agencies (SBA, VA, CFPB, SEC, Education, NOAA, DOC) and surface any follow-on reports, oversight letters, or agency FAQs related to external personnel access and data practices. Subscribers receive push alerts when agencies change disclosure posture or when GAO posts updates, so capture and compliance teams can act immediately.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Signals Match Engine — When an event like this shifts the marketplace, Match Engine automatically rescales opportunity relevance and risk scoring across your pipeline. It will update match scores for opportunities tied to the affected agencies and NAICS codes in your saved profile, flagging solicitations where access governance and transparency may become evaluation factors. This reprioritization helps bid/no-bid decisions reflect the new oversight risk.

Cabrillo Signals Intelligence Hub — Intelligence Hub tracks the affected agencies, NAICS codes, and contract vehicles provided in your account and recommends saved searches to monitor SAM.gov (System for Award Management) and agency procurement pages for follow-on solicitations or oversight requests. Use the saved search feature to receive alerts when solicitations or agency notices containing keywords from this event (audit, access, external personnel, oversight) appear.

Proposal Studio (Proposal OS) — Proposal Studio generates compliance matrices and first-draft technical approaches that incorporate your current controls and evidence artifacts. For responses that must address external-access governance or audit-readiness, Proposal OS can pull your documented access workflows and produce a draft technical approach and compliance appendix that highlights audit trails, log retention, and legal flow-downs.

Proposal Studio Workflow Tracker — The Workflow Tracker turns this event into actionable capture steps: it can create a 9-gate capture plan that routes evidence requests to security and legal, enforces review gates for privileged redactions, and assembles an audit-ready documentation package for proposal or oversight responses. Tracker maintains an auditable history of those reviews for future oversight or GAO-style inquiries.

Call to action: use the War Room briefing as the single source of truth for follow-on alerts, configure Intelligence Hub saved searches for the named agencies and NAICS codes, and run your highest-priority affected opportunities through Proposal Studio and the Workflow Tracker to build evidence-ready proposals and compliance packages.

(JSON output follows)

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.