Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices

GAO found most agencies have not fully implemented OMB's networked device inventory requirements (established Dec 2023; updated Jan 2025). Initial inventories were required by Sept 2024, but as of Sept 2026 only a minority of the 22 civilian CFO Act agencies had complete, maintained inventories…

Cabrillo Club

Cabrillo Club

Editorial Team · September 30, 2026 · 4 min read

Share:LinkedInX

Cabrillo Club Insights

Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices

Overview

GAO’s report highlights that OMB established networked device inventory requirements (Dec 2023; updated Jan 2025) and that most civilian CFO Act agencies have not yet fully implemented those requirements. Agencies were required to complete initial inventories by September 2024, but as of September 2026 only a minority have completed and maintained inventories with required fields (for example, asset description and software version); no agency has reported an IoT cybersecurity waiver. OMB has not yet issued updated guidance covering fiscal year 2026, leaving agencies without a clear timeline or enforcement push. For contractors this means higher near-term attention from procuring agencies on device visibility, device metadata, and support for agency inventory processes. Expect agencies to prioritize vendors who can supply consistent device metadata, easy inventory onboarding, and documentation to support waiver and cybersecurity review processes once OMB issues follow‑on guidance. Take action now to ensure product data and proposal materials demonstrate how you enable agency inventory and risk management needs.

Immediate Actions (This Week)

  • [ ] Inventory your own products and services that are networked IoT/OT devices or embed them; capture minimum fields agencies are asking for (asset description, software/firmware version, unique identifiers) so you can provide this data quickly.
  • [ ] Review existing contracts and proposals to identify where your deliverables introduce networked devices and document how you will support agency inventory processes and reporting.
  • [ ] Monitor OMB communications and GAO follow‑ups for new guidance covering fiscal year 2026 and any updated timelines; set up an internal alert so capture and proposals teams are informed when OMB issues guidance.

Short-Term Actions (30 Days)

  • [ ] Prepare a template device data package (CSV/JSON) that maps to agency inventory fields described in OMB requirements (asset description, software version, etc.) to speed agency onboarding and response to information requests.
  • [ ] Update sales and capture collateral to include explicit statements about device inventory support, device-level metadata availability, and processes for firmware/software updates and vulnerability notification.

Long-Term Actions (90+ Days)

  • [ ] Institutionalize a product lifecycle process that records and preserves device metadata (descriptions, firmware/software version history, unique IDs) for all networked devices you ship or support.
  • [ ] Build proposal deliverables and contract language clauses that describe how you will assist agencies with inventory maintenance, evidence for audits, and support for any waiver processing or cybersecurity reviews OMB/agency teams may require.

Compliance Checklist

  • [ ] IoT Cybersecurity Improvement Act of 2020 — evaluate how your products and procurement support obligations described in the Act and be prepared to supply information agencies will need under the Act.
  • [ ] OMB networked device inventory requirements (Dec 2023; updated Jan 2025) — be ready to provide required inventory fields (for example, asset description and software/firmware version) and support agency inventory maintenance and reporting.
  • [ ] Maintain readiness to support agency waiver processes — although GAO reported no agencies had reported an IoT cybersecurity waiver as of Sept 2026, agencies may require vendor input if/when waivers are requested.

Resources

  • IoT Cybersecurity Improvement Act of 2020 — full text (link: TBD pending source review)
  • OMB networked device guidance (Dec 2023; Jan 2025 updates) — (link: TBD pending source review)
  • GAO report: "Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices" — (link: TBD pending source review)

Related reading: Winning Federal Contracts Guide (/insights/winning-federal-contracts)

See also: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide)

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

How Cabrillo Club Automates This

  • Cabrillo Signals War Room — This briefing was delivered by the War Room within minutes of detection. War Room continuously monitors OMB, GAO, and other federal sources for policy updates and will notify you the moment OMB publishes the FY2026 guidance or any follow‑on clarifications so your capture and product teams can act immediately.
  • Cabrillo Signals Match Engine — When agencies tighten inventory and device reporting expectations, Match Engine automatically rescales opportunity relevance across your pipeline. It re‑scores opportunities where networked devices are in scope, surfaces solicitations where your device metadata capabilities are a competitive advantage, and reprioritizes leads for capture resources.
  • Cabrillo Signals Intelligence Hub — Use the Intelligence Hub saved searches to track affected agencies (e.g., the 22 civilian CFO Act agencies referenced in the GAO report), and configure alerts for solicitations or amendments that reference OMB networked device requirements or the IoT Cybersecurity Improvement Act of 2020. The Hub centralizes matching NAICS/vehicle signals and flags follow‑on solicitations as they appear on SAM.gov (System for Award Management).
  • Proposal Studio (Proposal OS) — Proposal Studio generates compliance matrices and first‑draft technical approaches that explicitly call out inventory support, device metadata delivery formats, and firmware update/notification processes. It pulls your past performance examples to populate proof points showing you can meet OMB/agency inventory expectations and supports bid/no‑bid decisions driven by events like this.
  • Proposal Studio Workflow Tracker — The Workflow Tracker creates a 9‑gate capture plan triggered by this event: it routes compliance and legal reviews of inventory/data delivery commitments, tracks supplier and subcontractor certification evidence for device software/firmware controls, and produces an audit‑ready documentation package ready to attach to proposals or contract modifications.

Call to action: review the immediate checklist above and open the Cabrillo Signals War Room alert for "IoT/Networked Device — OMB guidance" so your team is notified as soon as OMB publishes FY2026 guidance. Use Proposal Studio to generate the device data package template and the Workflow Tracker to enforce review gates on proposals that include networked devices.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.