Despite upgrades, IRS cyber program still ‘not effective,’ watchdog says

The Treasury Inspector General for Tax Administration found the IRS cybersecurity program "not effective" under FISMA for fiscal 2026, citing deficiencies across the identify, protect, and detect functions of the NIST Cybersecurity Framework—notably configuration management, vulnerability…

Cabrillo Club

Cabrillo Club

Editorial Team · September 18, 2026 · 4 min read

Share:LinkedInX
Blog post hero image

Overview

The Treasury Inspector General for Tax Administration (TIGTA) found the IRS cybersecurity program "not effective" under FISMA assessments for fiscal 2026, citing deficiencies across the identify, protect, and detect functions of the NIST Cybersecurity Framework. Key shortfalls include configuration management, vulnerability remediation, and continuous monitoring capabilities. Contractors that work with the IRS or handle taxpayer data should expect heightened scrutiny of cybersecurity controls and likely changes to agency security requirements as the IRS addresses these gaps. This will increase audit and assessment activity and may alter contract-level compliance expectations. Suppliers should prioritize reassessing their handling of taxpayer data, verify that controls tied to the named NIST publications are implemented, and prepare to demonstrate remediation plans and continuous-monitoring improvements. For implementation guidance on operating with controlled unclassified information and secure processes, see the Secure Operations Guide and related resources below.

Immediate Actions (This Week)

  • [ ] Inventory all contracts, task orders, and subcontracts that involve IRS data or taxpayer data and flag them for priority review.
  • [ ] Identify and document where taxpayer data, CUI (Controlled Unclassified Information), or IRS-managed information resides in your environment (on-prem, cloud, third-party hosting) and map to owners.
  • [ ] Perform a high-level gap check on configuration management, vulnerability remediation, and continuous monitoring controls against the NIST Cybersecurity Framework and the named NIST publications.

Short-Term Actions (30 Days)

  • [ ] Run a focused technical assessment on configuration baselines, vulnerability management processes, and your continuous monitoring toolchain; produce an initial POA&M for any gaps.
  • [ ] Update incident response and evidence-collection playbooks to show how you will demonstrate remediation, patching timelines, and monitoring improvements to auditors and contracting officers.

Long-Term Actions (90+ Days)

  • [ ] Implement or mature continuous monitoring and configuration-management capabilities so they can produce audit-ready evidence on demand; track metrics tied to remediation SLAs.
  • [ ] Formalize a communications and compliance plan for customer/prime notifications, audit support, and revised contract language or requirement changes that may follow IRS remediation actions.

Compliance Checklist

  • [ ] FISMA — Ensure program-level documentation and metrics are up to date for FISMA reporting and readiness.
  • [ ] NIST Cybersecurity Framework — Assess and document maturity across the identify, protect, and detect functions, with emphasis on the noted weak areas.
  • [ ] NIST SP 800-53 (NIST Special Publication 800-53) — Review configuration-management and continuous-monitoring controls mapped to applicable families.
  • [ ] NIST SP 800-171 (NIST Special Publication 800-171) — Validate controls where NIST 800-171 (NIST Special Publication 800-171) applies to systems handling controlled information (e.g., taxpayer data).
  • [ ] IRS Publication 1075 — Confirm handling, safeguarding, and dissemination rules for taxpayer data are implemented and evidenced.
  • [ ] FedRAMP (Federal Risk and Authorization Management Program) — If using cloud services that host taxpayer data, verify FedRAMP authorization status and evidence for continuous monitoring.
  • [ ] NIST SP 800-137 — Ensure continuous monitoring strategy and supporting artifacts (metrics, dashboards, reporting cadence) are maintained.

Resources

  • NIST Cybersecurity Framework: https://www.nist.gov/cyberframework
  • NIST SP 800-53 (security and privacy controls): https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
  • NIST SP 800-171 (protecting controlled unclassified information): https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
  • NIST SP 800-137 (information security continuous monitoring): https://csrc.nist.gov/publications/detail/sp/800-137/final
  • FISMA resources (Federal Information Security Modernization Act): https://www.cisa.gov/fisma
  • IRS Publication 1075 (safeguarding federal tax information): https://www.irs.gov/pub/irs-pdf/p1075.pdf
  • Agency pages:
  • TIGTA: https://www.tigta.gov/
  • IRS: https://www.irs.gov/
  • U.S. Department of the Treasury: https://home.treasury.gov/

Related internal guidance:

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard

  • Secure Operations Guide (/insights/secure-operations-guide)
  • CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide)
  • CUI-Safe CRM Guide (/insights/cui-safe-crm-guide)

How Cabrillo Club Automates This

Cabrillo Signals War Room — Already detected this event and delivered this briefing within minutes. War Room continuously monitors federal sources for TIGTA reports, FISMA findings, and agency security updates so your team is alerted the moment the IRS or TIGTA posts new assessments or follow-on guidance. For this event War Room will push prioritized alerts to affected opportunity owners and compliance leads.

Cabrillo Signals Match Engine — When IRS controls and audit focus shift, Match Engine automatically rescales opportunity relevance and risk scores across your pipeline. It will re-rank contracts and solicitations tied to affected agencies and capability areas (configuration management, vulnerability remediation, continuous monitoring) so capture teams see which opportunities need an updated bid/no-bid review.

Cabrillo Signals Intelligence Hub — Use the Intelligence Hub saved searches to track follow-on solicitations, audits, or updated agency guidance tied to IRS, TIGTA, or Treasury. The Hub correlates affected NAICS and contract vehicles (as tagged in your account) and triggers alerts when SAM.gov (System for Award Management) or agency pages publish matching solicitations or security requirement changes.

Proposal Studio (Proposal OS) — Proposal Studio generates compliance matrices, first-draft technical approaches, and POA&M narratives tailored to the named frameworks (NIST CSF, NIST 800-53, NIST 800-171, IRS Publication 1075). It pulls past performance snippets and evidence artifacts from your library to populate remediation plans and rationale for increased continuous-monitoring capabilities.

Proposal Studio Workflow Tracker — The Workflow Tracker converts this event into a 9-gate capture flow: opportunity reassessment, technical remediation plan, compliance review, Xact evidence collection, executive approval, and submission packaging. It routes compliance reviews to legal/contracts, tracks supplier certifications, and produces an audit-ready documentation package aligned to the compliance checklist above.

Call to action: Explore these features in your Cabrillo console to map affected contracts, generate a prioritized remediation POA&M, and automate proposal updates tied to the IRS/TIGTA findings.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.