CIOs often underestimated investment risks on IT dashboard, GAO says
A GAO audit found federal CIOs frequently underestimated IT investment risks on ITdashboard.gov, with 24 of 53 sampled investments showing more risk than CIO ratings indicated. The federal CIO office discontinued the dashboard as of April 2025 and is directing agencies to focus on statutorily…
Cabrillo Club
Editorial Team · October 7, 2026 · 4 min read

Also in this intelligence package
TL;DR
A GAO audit found federal CIOs frequently underestimated IT investment risks on ITdashboard.gov, with 24 of 53 sampled investments showing more risk than CIO ratings indicated. The federal CIO office discontinued the dashboard as of April 2025 and is directing agencies to focus on statutorily required data reporting instead. GAO issued 17 recommendations to nine agencies to improve risk assessment accuracy and timeliness. This shift removes a public portfolio-facing tool and moves emphasis to agency-level statutory reporting and GAO-driven corrective actions, which could change how contractors' IT investments are evaluated and monitored. Contractors should expect increased scrutiny of investment risk documentation and may see changes in how agencies request and consume risk data for acquisition and oversight. Immediate implications include the need to validate risk posture on agency reporting feeds, update internal portfolio controls, and prepare capture/proposal materials to align with agency-specific reporting expectations.
Key Points
- What happened: GAO audited ITdashboard.gov and found frequent underestimation of IT investment risk; 24 of 53 sampled investments had more risk than CIO ratings indicated, and the federal CIO office discontinued the dashboard as of April 2025 while agencies pivot to statutorily required data reporting. GAO issued 17 recommendations to nine agencies to improve risk assessment accuracy and timeliness.
- Who is affected: NAICS 541512, 541511, 541513, 541519, 518210, 541330, 541690; agencies: GSA (General Services Administration), OMB, DOD, DHS (Department of Homeland Security), HHS, DOE, DOT, VA, DOJ; contract vehicles: OASIS+, 8(a) STARS III, SEWP, GSA IT Schedule 70, Alliant 2, CIO-SP3, NITAAC CIO-SP4; market segments: IT Services, IT Modernization, Enterprise IT, IT Program Management, IT Risk Management, IT Portfolio Management, Federal IT Consulting; compliance surfaces: FITARA, NIST 800-53, OMB Circular A-11, OMB Circular A-130, Federal IT Acquisition Reform Act.
- Timeline: ITdashboard.gov discontinued as of April 2025; GAO issued 17 recommendations to nine agencies (timing of agency responses TBD pending source review).
- What contractors should do NOW: inventory and validate risk data for active investments, align documentation with agency statutory reporting expectations, update proposal and capture materials to reflect accurate risk posture, brief capture/proposal teams and security/risk owners, and configure Cabrillo Signals to monitor agency responses and follow-on solicitations.
Who Is Affected
Specific NAICS codes, agencies, and contract vehicles pending source review. At a market level, the event affects federal IT services and modernization providers that supply program and portfolio management, IT risk management, and enterprise IT capabilities to the federal government.
Frequently Asked Questions
Q: What did GAO find in the audit?
A: The GAO audit found that federal CIOs frequently underestimated IT investment risks on ITdashboard.gov; specifically, 24 of 53 sampled investments showed more risk than CIO ratings indicated. GAO issued 17 recommendations to nine agencies to improve risk assessment accuracy and timeliness.
Q: Is ITdashboard.gov still active?
A: No. The federal CIO office discontinued the dashboard as of April 2025 and has shifted agencies to focus on statutorily required data reporting instead.
Q: How will this affect contractors' proposals and reporting?
A: Expect agencies to place more emphasis on formal statutory reporting channels and on accurate, timely risk documentation. Contractors should validate and, where necessary, strengthen investment risk artifacts (e.g., risk registers, milestone tracking, remediation plans). Specific changes to solicitation language or reporting requirements are pending source review.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →
Definitions
- CIOs: Chief Information Officers — senior officials responsible for IT strategy and oversight at federal agencies (term used in the Title and Summary).
- ITdashboard.gov: The federal IT portfolio dashboard referenced in the Summary, now discontinued as of April 2025.
- GAO: Government Accountability Office — the audit organization that produced the audit and recommendations cited in the Summary.
Intelligence Response
Cabrillo Signals War Room detected this GAO audit and delivered this briefing. Use the following Cabrillo products to operationalize monitoring, capture, and proposal actions:
- Cabrillo Signals War Room — Already detected this event and delivered this briefing. Continue real-time monitoring of GAO follow-ups and agency responses.
- Cabrillo Signals Match Engine — Rescore opportunity pipelines and adjust bid/no-bid signals where agency risk assessment practices may affect competitiveness.
- Cabrillo Signals Intelligence Hub — Track the listed agencies, NAICS codes, and contract vehicles; run saved searches to alert on follow-on solicitations and agency corrective actions.
- Proposal Studio (Proposal OS) — Update proposal content, compliance matrices, and win themes to reflect strengthened risk posture and to document responses to heightened agency scrutiny.
- Proposal Studio Workflow Tracker — Use the 9-gate capture workflow to automate compliance routing, capture approvals, and maintain audit-ready documentation for risk artifacts.
Notify immediately: Capture Director, Proposal Manager, Security/Risk Lead (CISO or equivalent), Business Development Lead for affected agencies, and Program Managers for at-risk investments.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →
First 48-hour response playbook:
- Hour 0–4: Convene capture + security + BD stand-up; confirm affected opportunities and active investments; assign owners. Activate Cabrillo Signals War Room alerting.
- Hour 4–12: Run Match Engine rescore of pipeline; surface highest-risk investments and near-term opportunities. Configure Intelligence Hub saved searches for agency responses and solicitations.
- Hour 12–24: Pull and validate investment risk artifacts (risk registers, remediation plans, schedule health); start Proposal Studio updates for at-risk bids.
- Hour 24–48: Finalize immediate proposal edits and compliance matrices; prepare briefing for agency BD leads and program offices; schedule follow-up monitoring cadence in War Room.
Reference: Secure Operations Guide (/insights/secure-operations-guide)
Related: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide), CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide)
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.