DOGE: Congress and the Public Lack Assurance That Systems and Data Were Protected at Multiple Agencies

GAO’s review found DOGE teams were granted access to more than 23 systems across six agencies (CFPB, Department of Education, NOAA, SEC, SBA, VA) that contain sensitive data including PII; agencies provided limited or no documentation showing training, signed rules of behavior, and…

Cabrillo Club

Cabrillo Club

Editorial Team · September 29, 2026 · 5 min read

Share:LinkedInX

Cabrillo Club Insights

DOGE: Congress and the Public Lack Assurance That Systems and Data Were Protected at Multiple Agencies

Overview

GAO’s review found that Department of Government Efficiency (DOGE) teams from the United States DOGE Service were given access to more than 23 agency systems across six agencies (Consumer Financial Protection Bureau, Department of Education, National Oceanic and Atmospheric Administration, Securities and Exchange Commission, Small Business Administration, and Department of Veterans Affairs). Those systems support contracts, grants, HR, and finance functions and contain sensitive information, including PII. GAO found gaps in documentation and evidence that agencies consistently enforced IT security rules for DOGE team members (examples include training completion, signed rules of behavior, and background-investigation adjudication). Several agencies did not provide requested information to GAO, leaving Congress and the public without assurance that appropriate controls are in place. For contractors that support these agencies or systems, this increases scrutiny, the likelihood of follow-on oversight requests, and the need to show audit-ready evidence of training, access controls, and personnel security. Action is needed now to validate your controls, evidence packages, and capture messaging so you can respond quickly to agency questions and changing solicitation requirements.

Immediate Actions (This Week)

  • [ ] Inventory any engagements with the six affected agencies (CFPB, Department of Education, NOAA, SEC, SBA, VA) and flag programs where your personnel or systems may interact with DOGE team members.
  • [ ] Pull and centralize evidence for personnel security and access controls for staff who touch agency systems (training completion records, background-investigation status, signed rules of behavior, access approval logs).
  • [ ] Confirm account and permission review procedures for systems that contain PII or financial/HR data; identify any gaps in least-privilege enforcement and logging.
  • [ ] Notify capture/proposal leads for active opportunities against these agencies to expect heightened audit and documentation requests; mark those opportunities for immediate attention.
  • [ ] Monitor agency public communications and GAO follow-ups for changes to oversight requirements or solicitation language.

Short-Term Actions (30 Days)

  • [ ] Complete a formal evidence package template for each agency engagement that documents: system access lists, training records, signed rules of behavior, background-investigation status, and audit log retention.
  • [ ] Update internal SOPs to require confirmation of government third-party access controls (e.g., DOGE/USDS access) before deploying personnel or integrating systems.
  • [ ] Run an access-review for accounts with rights to systems containing PII and remediate any accounts lacking documented approval or training.
  • [ ] Prepare a one-page compliance summary you can attach to proposals and inquiries showing how you meet agency IT security expectations.

Long-Term Actions (90+ Days)

  • [ ] Implement or formalize recurring evidence-refresh cycles (quarterly) so training, background checks, and signed rules-of-behavior are always audit-ready.
  • [ ] Strengthen IAM and privileged access procedures (role-based access reviews, time-limited elevated access, automated log collection and retention) and map them to agency audit points.
  • [ ] Incorporate standard contract language and FAR (Federal Acquisition Regulation)/agency clause checks into pre-award reviews to ensure solicitations and resulting awards capture obligations around third-party government access and oversight.
  • [ ] Build a reusable contract compliance package for agencies that documents adherence to relevant federal security and privacy frameworks named by the agency.

Compliance Checklist

Compliance scope includes the frameworks and statutes identified in this event’s materials. Re-evaluate scope when agencies publish additional guidance.

  • [ ] NIST 800-53 — system security controls, access control, audit and accountability, personnel security
  • [ ] FISMA — agency-level security program documentation and reporting
  • [ ] Privacy Act — handling and protections for PII
  • [ ] NIST 800-171 (NIST Special Publication 800-171) — controls for nonfederal systems handling controlled information (use if applicable)
  • [ ] FedRAMP (Federal Risk and Authorization Management Program) — if you host cloud services used by agencies, ensure authorization posture is documented
  • [ ] OMB Circular A-130 — policies for federal information resource management and privacy
  • [ ] NIST Cybersecurity Framework — map detection, protection, and response controls to agency audit expectations
  • [ ] Evidence items to collect (cross-cutting):
  • [ ] Training completion records for all personnel with system access
  • [ ] Signed rules-of-behavior / IT use agreements
  • [ ] Background-investigation status and adjudication records
  • [ ] Access approval records and least-privilege justification
  • [ ] Audit logs and retention schedules for systems containing PII and financial data

Resources

  • Agency guidance sources (named agencies): CFPB, Department of Education, NOAA (Department of Commerce), SEC, SBA, VA — guidance documents and agency responses: TBD pending source review.
  • Regulation/framework texts named in the materials: NIST 800-53, FISMA, Privacy Act, NIST 800-171, FedRAMP, OMB Circular A-130, NIST Cybersecurity Framework — official texts: TBD pending source review.
  • Internal Cabrillo Club reading:
  • Winning Federal Contracts Guide (/insights/winning-federal-contracts)
  • CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide)
  • CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide)

How Cabrillo Club Automates This

  • Cabrillo Signals War Room — Already detected this event and delivered this briefing within minutes. War Room continuously monitors federal sources and GAO activity so your team received this risk signal immediately. For subscribers, War Room will push follow-up briefs if GAO posts updates or if affected agencies publish responses, reducing manual monitoring time.
  • Cabrillo Signals Match Engine — When this event changes agency posture or elevates scrutiny for the six affected agencies, Match Engine automatically rescoring opportunity pipelines, reprioritizing active pursuits that intersect with those agencies, and flagging opportunities where your evidence packages need strengthening. Use it to identify which active opportunities are most at risk or most likely to require rapid audit-ready documentation.
  • Cabrillo Signals Intelligence Hub — Tracks affected agencies and lets you save searches for solicitations or agency notices related to DOGE/USDS activity. Configure saved searches to alert you when the agencies named in this report publish follow-on solicitations, policies, or GAO responses so you can immediately assign capture resources.
  • Proposal Studio (Proposal OS) — Generates compliance matrices and first-draft technical approaches tailored to the evidence items GAO and agencies are asking for (training, background investigations, rules-of-behavior, access controls). Proposal Studio pulls from your past performance and your centralized evidence repository to create audit-ready language and attachments you can drop into proposals.
  • Proposal Studio Workflow Tracker — Triggers a 9-gate capture workflow when an opportunity intersects with the affected agencies or when War Room raises a compliance alert. It routes compliance reviews to contracts and legal, verifies required personnel security documentation is present, and produces an audit-ready package for agency questions or GAO-style requests.

Call to action: use War Room to track follow-ups, set saved searches in Intelligence Hub for the six agencies, and run any at-risk proposals through Proposal Studio and the Workflow Tracker to harden your evidence packages.

---

JSON summary for integrations and automation:

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.