Cabrillo Club
ServicesPlatform
Pricing
Talk to a founder
Cabrillo Club

Seven private AI products for government contractors. Find. Win. Deliver. Protect.

Products

  • Signals
  • ProposalOS
  • CalibrationOS
  • FinanceOS
  • Platform & roadmap

Solutions

  • Defense & GovCon
  • Your Business
  • Membership
  • Pricing

Resources

  • Insights
  • Tools
  • Community
  • CMMC Assessment

Company

  • About
  • Team
  • Proof
  • Contact
Cabrillo Club LLC·10 E. Yanonali St., Suite 129, Santa Barbara, CA 93101·CAGE Code: 19CA1·SAM UEI: L4CAFCQ6C173

© 2026 Cabrillo Club LLC. All rights reserved.

PrivacyTermsCookiesDo Not Sell or Share
  1. Home
  2. Insights
  3. VA fails watchdog FISMA audit on IT security, but agency disagrees
Compliance & Risk

VA fails watchdog FISMA audit on IT security, but agency disagrees

The VA OIG reported the VA failed its FY2025 FISMA audit due to deficiencies in vulnerability management, incident response, configuration management, and access controls. The VA disputes some findings, but contractors supporting VA IT should expect heightened scrutiny, tighter evidence…

Cabrillo Club

Cabrillo Club

Editorial Team · July 28, 2026 · 4 min read

Share:LinkedInX

Cabrillo Club Insights

VA fails watchdog FISMA audit on IT security, but agency disagrees

Also in this intelligence package

Flash Brief

Breaking analysis of what happened and who is affected.

Read report →
Segment Impact

Deep dive into how this impacts each market segment.

Read report →
In This Guide
  • Overview
  • Immediate Actions (This Week)
  • Short-Term Actions (30 Days)
  • Long-Term Actions (90+ Days)
  • Compliance Checklist
  • Resources
  • How Cabrillo Club Automates This

Overview

The VA Office of Inspector General reported that the VA failed its FY2025 FISMA audit, citing deficiencies in vulnerability management, incident response, configuration management, and access controls. The VA disputes some findings but the report signals ongoing cybersecurity compliance challenges that can change contractor oversight and deliverable expectations for VA IT systems. Contractors supporting VA IT infrastructure should expect heightened scrutiny, tighter evidence requirements, and more frequent audits or requests for corrective action documentation. This will likely affect how contractors demonstrate continuous monitoring, patching, incident handling, and access control enforcement in proposals and in-performance. Early preparedness reduces bid risk and shortens remediation cycles if the agency tightens contract-level security requirements. Review your contract clauses, evidence packages, and technical approaches now so you can respond quickly to follow-on VA guidance or contract modifications. For implementation guidance, see the Secure Operations Guide and related compliance materials linked below.

Immediate Actions (This Week)

  • [ ] Convene a cross-functional rapid response: security lead, contracts, program manager, and legal to review potential impacts on current VA work.
  • [ ] Locate and inventory VA contracts and task orders you support; identify contract clauses that reference FISMA, NIST 800-53, FedRAMP (Federal Risk and Authorization Management Program), or related requirements.
  • [ ] Run a focused health check on these areas: vulnerability management (patching cadence, open high/critical findings), incident response playbooks and recent exercises, configuration baselines, and identity/access controls (account reviews, privileged access).
  • [ ] Pull and preserve evidence packages that show current compliance (scan/results, patch logs, incident reports, change-control records, access reviews).
  • [ ] Monitor VA and VA OIG public statements and solicit client or contracting officer guidance; subscribe to Cabrillo Signals War Room alerts for updates.

Short-Term Actions (30 Days)

  • [ ] Perform a scoped gap assessment against FISMA and NIST 800-53 baseline controls for any systems you operate for VA; prioritize remediation of high/critical gaps.
  • [ ] Run at least one incident response tabletop focused on VA-specific scenarios and produce a short after-action report with corrective actions and owners.
  • [ ] Validate FedRAMP status or equivalent security posture for any cloud services used in VA work and document authorization boundaries.
  • [ ] Update subcontractor flow-downs and supplier attestations to require timely vulnerability reporting and incident notification.

Long-Term Actions (90+ Days)

  • [ ] Implement continuous monitoring and measurable KPIs for vulnerability remediation SLAs, incident detection/response time, configuration drift, and privileged access reviews.
  • [ ] Embed evidence collection into delivery pipelines (automated scan export, configuration snapshots, signed change records) so audit packages are audit-ready.
  • [ ] Update technical approaches and past-performance narratives to emphasize strengthened vulnerability management, incident response maturity, configuration management, and access control practices for future VA bids.
  • [ ] Plan for an external or independent security assessment if contractually required or if VA guidance requests third-party validation.

Compliance Checklist

  • [ ] FISMA — review obligations and evidence tied to agency assessments.
  • [ ] NIST SP 800-53 (NIST Special Publication 800-53) — map implemented controls and document control status for vulnerability management, incident response, configuration management, and access control families.
  • [ ] NIST SP 800-171 (NIST Special Publication 800-171) — verify applicability for controlled unclassified information in scope of work and confirm implementation status where relevant.
  • [ ] FedRAMP — confirm cloud service authorizations and documented continuous monitoring for any hosted services in VA solutions.
  • [ ] NIST Cybersecurity Framework — align risk responses and improvement plans to CSF functions (Identify, Protect, Detect, Respond, Recover).
  • [ ] OMB A-130 — ensure agency/system-level policy alignment where guidance applies.
  • [ ] FIPS 199 / FIPS 200 — confirm correct information impact level determinations and applicable baseline controls.
  • [ ] Vulnerability Management — documented scanning cadence, triage process, remediation SLAs, and evidence of remediation.
  • [ ] Incident Response — tested playbooks, reporting timelines, and retention of incident records.
  • [ ] Configuration Management — baseline configuration documentation, change control logs, and configuration drift detection.
  • [ ] Access Controls — privileged account inventories, periodic access reviews, and multi-factor authentication status where required.

Resources

  • [FISMA statute text — TBD pending source review]
  • [VA / VA OIG guidance and reports — TBD pending source review]
  • Internal guidance:
  • Secure Operations Guide (/insights/secure-operations-guide)
  • CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide)
  • CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide)

How Cabrillo Club Automates This

Cabrillo Signals War Room — Already detected this event and delivered this briefing within minutes. War Room continuously monitors VA, VA OIG, and federal reporting sources so you receive near-real-time alerts when agency audits, reports, or policy changes publish. For this event it preserves the audit notice, timelines in the narrative, and flagging of affected control areas so your capture and delivery teams see the issue immediately.

Cabrillo Signals Match Engine — The Match Engine automatically rescors your opportunity pipeline when events like this shift requirements or agency scrutiny. It will lower or raise match scores for live VA opportunities and related vehicles based on increased emphasis on FISMA/NIST controls, updating keyword relevance and showing which past-performance examples best demonstrate remediation and continuous monitoring.

Cabrillo Signals Intelligence Hub — Intelligence Hub tracks the tagged agencies, NAICS codes, and contract vehicles associated with this event and provides saved-search alerts for follow-on solicitations or amendments that reference FISMA/NIST requirements. Configure saved searches for the VA, the listed NAICS codes, and the named vehicles to get earliest notice of RFPs or contract modifications.

Proposal Studio (Proposal OS) — Proposal Studio uses your past performance and control evidence to generate compliance matrices, first-draft technical approaches, and remediation narratives tailored to FISMA and NIST 800-53 concerns called out in this event. The win/no‑bid engine factors in event-driven risk and will surface the strongest artifacts (test results, incident reports, patch histories) to include in the proposal.

Proposal Studio Workflow Tracker — Workflow Tracker enforces a 9-gate capture and compliance review process: it can auto-route required control evidence to contracts and legal, track supplier certifications and FedRAMP/cloud authorizations, and produce an audit-ready documentation package for VA contracting officers. For this event it will add additional compliance review gates focused on vulnerability management and incident response documentation.

Call to action: review the flagged opportunities and evidence packages in your Cabrillo workspace, enable the suggested saved searches in Signals Intelligence Hub, and run a proposal readiness generation in Proposal Studio to produce an audit-ready compliance package.

---

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or try our free Intelligence Dashboard→

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.

TwitterLinkedIn

Continue reading

Flash Brief

Breaking analysis of what happened and who is affected.

Read report →
Segment Impact

Deep dive into how this impacts each market segment.

Read report →
Back to all articles

25-minute assessment. Custom implementation plan.

Try Signals Free

Stop missing opportunities

AI matches SAM.gov contracts to your NAICS codes.

What brought you here? (optional)

No spam. Unsubscribe anytime.