IT Dashboard: Selected Agencies’ Investment Ratings Fail to Fully Consider Risks

The GAO found CIO risk ratings on the IT Dashboard often understate risk because agencies used varied and sometimes untimely rating processes; GAO reviewed 53 investments (from FY2025 budget data using a $35M threshold) and found mismatches driven by untimely updates and processes that did not…

Cabrillo Club

Cabrillo Club

Editorial Team · October 7, 2026 · 5 min read

Share:LinkedInX
Blog post hero image

Overview

The GAO found that CIO risk ratings on the IT Dashboard do not consistently reflect the actual level of investment risk, and that selected agencies used different and sometimes untimely processes to set those ratings. In GAO’s sample of 53 major investments (selected from fiscal year 2025 budget data and using a $35 million development-activity threshold), GAO’s independent risk assessments matched CIO ratings in about half the cases and showed higher risk in many others. Two drivers of the mismatches were CIO ratings that were not updated in a timely way and agency rating processes that did not follow OMB’s recommended quarterly cadence. OMB announced in April 2026 that it is taking steps to sunset the Dashboard and replace it with a new system, but has not published a timeframe; in the interim, accurate CIO ratings are critical to ensure proper oversight of IT investments. Contractors that sell IT modernization, system integration, cloud, or cybersecurity services (and firms pursuing the contract vehicles and NAICS areas identified in your pipeline) should act now to help customers and to adjust capture strategies while the Dashboard transition unfolds. See the Winning Federal Contracts Guide (/insights/winning-federal-contracts) for capture and proposal fundamentals.

Immediate Actions (This Week)

  • [ ] Monitor OMB and GSA (General Services Administration) public communications and the IT Dashboard for updates, and flag any announcements about the Dashboard sunsetting or replacement.
  • [ ] Inventory current and near-term opportunities in your pipeline that map to the affected market segments (IT Services, IT Modernization, System Integration, Software Development, IT Program Management, Enterprise IT, Cloud Services, Cybersecurity).
  • [ ] Review agency-reported risk documentation (where available) for any investments in your pursuit list—pay particular attention to investments that meet or exceed the $35 million development-activity threshold used in GAO’s review.
  • [ ] Prepare short advisories for agency customers and capture leads that explain how stale CIO ratings can increase oversight risk and delay interventions.

Short-Term Actions (30 Days)

  • [ ] Run an internal gap assessment: map your proposed solutions and service delivery milestones to risk controls and monitoring practices agencies expect (e.g., schedule, cost, performance, security).
  • [ ] Update capture strategies for solicitations on the contract vehicles and NAICS segments in your pipeline; notify capture teams to watch for follow-on solicitations from affected agencies and adjust win themes to emphasize timely risk reporting and transparency.

Long-Term Actions (90+ Days)

  • [ ] Develop capability offerings and service lines that help agencies improve CIO rating accuracy and update cadence (e.g., risk-annotation services, dashboard data hygiene, or automated reporting feeds).
  • [ ] Embed monitoring and reporting practices in your delivery contracts so that agency CIOs can get timely, audit-ready evidence for risk-rating updates; build templates that map program status directly to OMB-recommended rating factors.
  • [ ] Maintain continuous monitoring of OMB’s transition to the new system and be ready to adapt deliverables and data feeds once OMB releases implementation guidance.

Compliance Checklist

  • [ ] FITARA — align solution status reporting and transparency practices to agency FITARA expectations where applicable.
  • [ ] OMB Circular A-11 — ensure budget and program reporting materials used in capture/proposal documents reflect the format and metrics agencies commonly report to OMB.
  • [ ] OMB Circular A-130 — verify information resource management and governance practices in proposals and delivery plans conform with applicable agency guidance.
  • [ ] NIST 800-53 — map system security controls and evidence packages to NIST 800-53 baselines where agencies require them.
  • [ ] FedRAMP (Federal Risk and Authorization Management Program) — include FedRAMP posture and evidence for cloud services proposals when cloud services are part of the solution and when agencies require FedRAMP authorization.

(Compliance scope TBD — re-evaluate when official guidance or agency-specific solicitation language is published.)

Resources

  • GAO report on IT Dashboard findings — search GAO.gov for the titled report described in this briefing.
  • OMB April 2026 announcement regarding the IT Dashboard transition — monitor OMB public communications for the official announcement and follow-up guidance.
  • GSA information about the IT Dashboard operation — GSA operates the Dashboard; check GSA public guidance for operational notices.

Also see these internal guides for capture and compliance planning:

  • Winning Federal Contracts Guide (/insights/winning-federal-contracts)
  • CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide)
  • CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide)

How Cabrillo Club Automates This

  • Cabrillo Signals War Room — Cabrillo Signals War Room has already detected this GAO/OMB event and delivered this briefing within minutes. War Room continuously monitors OMB and GSA communications, GAO outputs, and Dashboard changes so your team is alerted the moment a policy shift or audit finding impacts your opportunities. Use War Room alerts to automatically push event summaries to capture leads and program managers.
  • Cabrillo Signals Match Engine — When an event like this changes agency oversight priorities or highlights risk exposures, Cabrillo Signals Match Engine automatically rescoring your opportunity pipeline. It updates match scores, keyword relevance, and agency alignment in real time so capture teams immediately see which pursuits are now higher-risk or higher-priority for agencies focused on improved CIO rating accuracy.
  • Cabrillo Signals Intelligence Hub — Intelligence Hub tracks affected agencies, the NAICS segments in your tag list, and the contract vehicles you follow. Configure saved searches in the Intelligence Hub to get notified when follow-on solicitations appear on SAM.gov (System for Award Management) or in agency portals that match this event’s profile (e.g., IT modernization, system integration, cloud). Intelligence Hub keeps a historical audit of which agencies and investments are tied to similar GAO findings.
  • Proposal Studio (Proposal OS) — Proposal Studio uses your past performance data and Cabrillo’s event feeds to generate first-draft technical approaches and compliance matrices that emphasize timely risk reporting, audit-ready evidence, and OMB/agency reporting expectations. The bid/no-bid engine automatically factors events like the Dashboard transition into your capture decision logic and suggests win themes that reduce agency oversight friction.
  • Proposal Studio Workflow Tracker — The Workflow Tracker enforces a 9-gate capture process tailored to events like this: it routes compliance reviews to contracts and legal, tracks supplier certifications and NIST/FedRAMP evidence, and produces audit-ready documentation packages to support timely CIO rating updates. Use the Workflow Tracker to ensure your delivery teams supply the evidence agencies will need to justify timely rating changes.

Explore these features in your Cabrillo Club dashboard or contact your account team to enable event-driven alerts and automated capture flows. These tools accelerate your ability to respond to agency needs around investment risk transparency and the IT Dashboard transition.

---

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.