CIOs often underestimated investment risks on IT dashboard, GAO says

A recent GAO audit found that federal CIOs frequently underestimated IT investment risks on ITdashboard.gov, with 24 of 53 sampled investments showing more risk than CIO ratings indicated.…

Cabrillo Club

Cabrillo Club

Editorial Team · October 7, 2026 · 4 min read

Share:LinkedInX
Blog post hero image

Overview

A recent GAO audit found that federal CIOs frequently underestimated IT investment risks on ITdashboard.gov, with 24 of 53 sampled investments showing more risk than CIO ratings indicated. The federal CIO office discontinued the public dashboard as of April 2025 and agencies are shifting to focus on statutorily required data reporting instead. GAO issued 17 recommendations to nine agencies to improve the accuracy and timeliness of risk assessments and reporting. For contractors this means federal IT investment scoring, monitoring, and reporting practices are likely to change and agencies may increase scrutiny of program-level risk indicators tied to procurements and contract performance. Contractors should proactively review how their work and reporting feed agency IT investment assessments and be prepared for revised agency guidance or new audit follow-ups. See the Secure Operations Guide (/insights/secure-operations-guide) and related guidance such as the CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide) for controls and proposal hygiene best practices.

Immediate Actions (This Week)

  • [ ] Inventory current contracts and task orders that contribute to agency IT investment reporting; tag those engagements for priority monitoring.
  • [ ] Confirm internal owners (program manager, CIO/IT lead, contracts lead) for each tagged engagement and schedule a short review of program-level risk indicators you submit to agencies.
  • [ ] Monitor agency and GAO follow-up notices for the nine affected agencies and for any agency-specific guidance about changes to investment reporting; set alerts for official postings and solicitations (Monitor for the official solicitation or guidance).

Short-Term Actions (30 Days)

  • [ ] Review deliverables, status reports, and monthly/quarterly metrics you provide to agencies; identify gaps where your reporting could understate schedule, cost, or technical risk.
  • [ ] Prepare a one-page risk-summary template (technical, schedule, cost, dependencies) that can be attached to proposals and monthly reports to increase transparency and reduce likelihood of misrating.

Long-Term Actions (90+ Days)

  • [ ] Update capture and proposal playbooks to require internal validation of agency-facing risk ratings and to include the risk-summary template in high-risk opportunities.
  • [ ] Establish a formal cadence with agency counterparts and prime/subcontractor teams to reconcile program risk indicators prior to formal reporting periods or solicitation evaluations.

Compliance Checklist

  • [ ] FITARA — align contractor reporting and dashboards to support agency FITARA-related oversight and CIO inquiries.
  • [ ] NIST 800-53 — ensure applicable security control documentation and evidence that feed investment risk assessments are current and audit-ready.
  • [ ] OMB Circular A-11 — confirm that any budgetary or program performance inputs you provide are consistent with agency A-11 reporting needs.
  • [ ] OMB Circular A-130 — validate how agency information governance and privacy practices are reflected in your system documentation and reporting.
  • [ ] Federal IT Acquisition Reform Act — be prepared for increased agency acquisition and oversight activities that affect program-level risk reporting.

Resources

  • GAO audit — TBD pending source review (/resources/gao-itdashboard-audit)
  • FITARA resources — TBD pending source review (/resources/fitara)
  • NIST SP 800-53 (NIST Special Publication 800-53) resources — TBD pending source review (/resources/nist-800-53)
  • OMB Circular A-11 — TBD pending source review (/resources/omb-circular-a-11)
  • OMB Circular A-130 — TBD pending source review (/resources/omb-circular-a-130)
  • Federal IT Acquisition Reform Act — TBD pending source review (/resources/federal-it-acquisition-reform-act)
  • Agency guidance index for affected agencies — TBD pending source review (/resources/agency-guidance-index)

How Cabrillo Club Automates This

Cabrillo Signals War Room — Already detected this event and delivered this briefing within minutes. War Room continuously monitors GAO outputs, agency postings, and policy shifts so your team receives immediate alerts when a GAO audit, dashboard retirement, or agency reporting change is published. For this event War Room flagged the ITdashboard.gov discontinuation and the GAO recommendations so your capture and delivery teams know to expect follow-up guidance from affected agencies.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Signals Match Engine — When agency scoring expectations or reporting emphases shift, Match Engine automatically rescales your opportunity pipeline. It adjusts match scores and keyword relevance for opportunities tied to IT investment risk, elevating pipelines where your capabilities in risk assessment, program management, and security controls align. This rescore surfaces wins/at-risk bids so capture leads can re-prioritize resources.

Cabrillo Signals Intelligence Hub — Intelligence Hub tracks the affected agencies and the policy tags from this event. Use saved searches and alerts to get notified when affected agencies post solicitations, clarifications, or revised reporting requirements on SAM or agency portals. Hub keeps a running list of opportunities and affected vehicles so you have a single view of downstream solicitations and agency guidance.

Proposal Studio (Proposal OS) — Proposal Studio generates compliance matrices, a first-draft technical approach, and a tailored risk-summary attachment using your past performance and contract artifacts. The bid/no-bid engine factors in changes detected by Signals so proposals can explicitly address agency audit findings and GAO-recommended transparency improvements. This reduces time to proposal and ensures consistent risk messaging across submissions.

Proposal Studio Workflow Tracker — The Workflow Tracker enforces a 9-gate capture process that now includes a risk-validation gate triggered by this event. It routes compliance reviews to contracts and legal, tracks supplier and security certifications, and generates audit-ready documentation packages for proposals and monthly reporting. This creates an evidence trail you can use if agencies increase post-award scrutiny.

Call-to-action: Review the flagged opportunities and recommended playbook updates in your Cabrillo workspace; if you need help standing up the risk-summary template or saved searches, open a War Room ticket to get hands-on assistance.

Related reading: Secure Operations Guide (/insights/secure-operations-guide), CMMC Compliance Guide (/insights/cmmc-compliance-guide), CUI-Safe CRM Guide (/insights/cui-safe-crm-guide)

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.