IT Systems Annual Assessment: DOD Should Improve IT Fraud Risk Management Practices

The GAO found gaps in fraud risk awareness, software development tracking, and cybersecurity planning across DOD's 18 major IT business programs (OCIO reported $10.3 billion planned for FY 2024–2026).…

Cabrillo Club

Cabrillo Club

Editorial Team · September 28, 2026 · 4 min read

Share:LinkedInX

Cabrillo Club Insights

IT Systems Annual Assessment: DOD Should Improve IT Fraud Risk Management Practices

Overview

The Government Accountability Office (GAO) found that the Department of Defense (DOD) relies heavily on its IT business programs and that gaps exist in fraud risk awareness, software development tracking, and cybersecurity planning across those programs. DOD’s Office of the Chief Information Officer (OCIO) reported planned spending of $10.3 billion on 18 major IT business programs for FY 2024–2026; GAO’s analysis highlights uneven adoption of required performance metrics and training to recognize IT fraud. Some programs lack approved cybersecurity strategies or zero trust plans, and many do not fully track Agile development metrics or customer satisfaction measures. Because GAO has previously issued recommendations (see GAO-22-105330 and GAO-25-107649) and issued this 2026 assessment (GAO-26-108596), contractors that support or compete for DOD IT work should act now to reduce bid risk, close gaps in fraud awareness training, and ensure proposals demonstrate compliance with DOD cybersecurity expectations, including plans for zero trust. This Action Kit focuses on immediate and sustained steps contractors can take to protect contracts, strengthen proposals, and align program controls with the issues GAO identified.

Immediate Actions (This Week)

  • [ ] Identify whether your company is prime or subcontractor on any of the DOD’s 18 major IT business programs or on task orders that support them; flag those contracts for priority review.
  • [ ] Pull the GAO reports referenced (GAO-26-108596, GAO-22-105330, GAO-25-107649) and distribute summaries to capture, proposal, security, and program teams for situational awareness.
  • [ ] Inventory current fraud-detection and fraud-awareness training for employees assigned to DOD IT work; document training completion rates and training content.
  • [ ] Verify whether affected programs have an approved cybersecurity strategy and a documented zero trust implementation plan; escalate any gaps to program leadership.
  • [ ] Communicate to business development and capture leads: monitor for DOD and GSA (General Services Administration) follow-on guidance or solicitations tied to GAO recommendations and policy updates.

Short-Term Actions (30 Days)

  • [ ] Run a focused fraud-risk assessment for each affected contract or proposal line of effort, concentrating on software development, supply chain, and CI/CD pipelines.
  • [ ] Update or create role-based fraud-awareness training for program staff who design, implement, or operate IT systems; set measurable completion targets and reporting.
  • [ ] Ensure performance metric inventories exist for customer satisfaction, strategic/business results, financial performance, and innovation; map existing KPIs to the GSA five-metric requirement and close gaps.
  • [ ] Review Agile/iterative development tracking practices and document how you will demonstrate metrics (e.g., velocity, acceptance rates, customer feedback loops) in proposals and program reporting.

Long-Term Actions (90+ Days)

  • [ ] Formalize and publish program-level cybersecurity strategies where missing; include an explicit plan and timeline for Zero Trust Architecture adoption aligned to DOD’s stated target year.
  • [ ] Implement continuous monitoring of software development metrics and customer satisfaction indicators; integrate those measures into program reporting and post-award performance management.
  • [ ] Institutionalize fraud risk management across IT programs: periodic assessments, insider-threat indicators, tamper-detection controls, supplier vetting, and mandatory role-based training.
  • [ ] Incorporate GAO findings and remediation plans into capture artifacts and past performance narratives to show proactive risk management in future proposals.

Compliance Checklist

Note: these regimes are named in the event tags and should be evaluated against program requirements.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

  • [ ] Map program controls to NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover).
  • [ ] Review and align to NIST 800-171 (NIST Special Publication 800-171) where Controlled Unclassified Information (CUI (Controlled Unclassified Information)) handling applies.
  • [ ] Assess CMMC (Cybersecurity Maturity Model Certification) applicability and documentation status for contracts that require certification.
  • [ ] Validate FedRAMP (Federal Risk and Authorization Management Program)/FISMA implications for cloud-hosted systems and document authorizations or plans to obtain them.
  • [ ] Create or review a Zero Trust Architecture implementation plan aligned to DOD expectations and timelines (DOD 2027 target referenced).
  • [ ] Confirm programs reference or comply with DoD (Department of Defense) Instruction 8500.01 cybersecurity policy where applicable.

Resources

  • GAO report GAO-26-108596 — assessment of DOD IT business programs (TBD pending source review)
  • GAO report GAO-22-105330 — prior GAO recommendations (TBD pending source review)
  • GAO report GAO-25-107649 — prior GAO recommendations (TBD pending source review)
  • DOD — agency guidance and OCIO materials (TBD pending source review)
  • GSA performance metric guidance — minimum five metrics across categories (TBD pending source review)
  • DoD Instruction 8500.01 — cybersecurity policy text (TBD pending source review)

Related reading:

  • Winning Federal Contracts Guide (/insights/winning-federal-contracts)
  • CMMC Compliance Guide (/insights/cmmc-compliance-guide)
  • CUI-Safe CRM Guide (/insights/cui-safe-crm-guide)

How Cabrillo Club Automates This

Cabrillo Signals War Room

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

  • Cabrillo Signals War Room has already detected this GAO event and delivered the briefing that informed this Action Kit. It will continuously monitor GAO publications, DOD/OCIO releases, and GSA guidance so your team receives alerts the moment follow-on guidance, solicitations, or remedial policy documents are published. Use War Room alerts to trigger capture and security reviews immediately.

Cabrillo Signals Match Engine

  • Match Engine will automatically rescore your active opportunity pipeline when this event changes the competitive landscape or agency priorities. Opportunities supporting DOD IT, cybersecurity, zero trust, or fraud-risk management receive updated match scores and keyword relevance so capture leads know which pursuits to prioritize or re-evaluate.

Cabrillo Signals Intelligence Hub

  • Intelligence Hub centralizes the affected-agency and contract-vehicle signals and lets you create saved searches for DOD and GSA updates tied to IT business programs. Configure saved searches for the listed contract vehicles and market segments to receive near-real-time alerts when SAM.gov (System for Award Management) or agency pages publish related solicitations, amendments, or guidance.

Proposal Studio (Proposal OS)

  • Proposal Studio generates compliance matrices, first-draft technical approaches, and win-theme variants that incorporate the GAO findings (fraud risk mgmt, zero trust plans, Agile metrics). It can pull your past-performance elements and auto-populate statements of work and evidence demonstrating approved cybersecurity strategies or training programs.

Proposal Studio Workflow Tracker

  • The Workflow Tracker enforces 9-gate capture management: it routes compliance reviews, fraud-risk assessment deliverables, and cybersecurity documentation to contracts, legal, and security SMEs; tracks training completion evidence; and compiles audit-ready proposal packages tied to DOD/GSA requirements.

Call to action: use your Cabrillo Signals War Room alert and create saved searches in the Intelligence Hub for this GAO item now; then run a Proposal Studio draft that highlights your fraud-risk controls and zero trust roadmap to respond faster to emerging solicitations.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.