CIOs often underestimated investment risks on IT dashboard, GAO says
The GAO audit found federal CIOs frequently underestimated IT investment risks on the now-sunsetted ITdashboard.gov (24 of 53 sampled investments showed more risk than CIO ratings).…
Cabrillo Club
Editorial Team · October 7, 2026 · 5 min read

Also in this intelligence package
Executive Summary
The GAO audit found federal CIOs frequently underestimated IT investment risks on the now-sunsetted ITdashboard.gov, with 24 of 53 sampled investments showing greater risk than CIO ratings indicated. The federal CIO office discontinued the dashboard as of April 2025 and is shifting agencies toward statutorily required data reporting. GAO issued 17 recommendations to nine agencies to improve the accuracy and timeliness of risk assessments and reporting. This combination of findings, dashboard removal, and recommended changes creates a medium-scale policy shock to how agencies monitor and evaluate contractor-supported IT investments.
Contractors across the IT-related market segments named in the Tags should pay attention because evaluation and monitoring practices are likely to change (and may become more reliant on statutory reporting channels and agency-level processes). That can affect program performance reviews, contract oversight, and how risk and status are communicated to procuring agencies. Firms that proactively adapt their risk reporting, compliance posture, and portfolio visibility for agencies named in the Tags (for example GSA (General Services Administration), OMB, DOD, DHS (Department of Homeland Security), HHS, DOE, DOT, VA, DOJ) will reduce bid and performance risk and may gain program-level advantages when agencies implement GAO’s recommendations.
Impact Matrix
IT Services
- Risk Level: Medium
- Opportunity: Agencies reviewing reporting practices may increase demand for third-party validation, continuous monitoring, and deliverables that demonstrate accurate risk posture. Specific NAICS codes: 541512, 541511, 541513, 541519, 518210, 541330, 541690. Specific contract vehicles: OASIS+, 8(a) STARS III, SEWP, GSA IT Schedule 70, Alliant 2, CIO-SP3, NITAAC CIO-SP4.
- Timeline: Dashboard discontinued as of April 2025; agencies shifting to statutorily required data reporting.
- Action Required: Ensure service delivery includes clear, auditable risk reporting tied to statutory reporting needs; update statements of work (SOWs) and performance work statements (PWS) to reflect how contractor metrics map to agency reporting.
- Competitive Edge: Offer packaged service lines that map operational metrics to statutory reporting fields and provide independent verification of risk indicators.
IT Modernization
- Risk Level: Medium
- Opportunity: Modernization efforts will be scrutinized for realistic risk assessments; opportunities for contractors to supply modernization roadmaps with stronger risk governance and measurable checkpoints. Specific NAICS codes and contract vehicles listed above apply.
- Timeline: Dashboard discontinued as of April 2025; agencies shifting to statutorily required data reporting.
- Action Required: Embed improved risk-assessment methodologies into modernization proposals; document how modernization milestones produce traceable outputs for statutory reporting.
- Competitive Edge: Differentiate by demonstrating tools/processes that translate project status into agency-required reporting formats and metrics aligned with GAO expectations.
Enterprise IT
- Risk Level: Medium
- Opportunity: Enterprise IT contracts may see increased demand for centralized, auditable dashboards and reconciled status reporting that feed statutory submissions. Use of listed NAICS codes and vehicles applies.
- Timeline: Dashboard discontinued as of April 2025; agencies shifting to statutorily required data reporting.
- Action Required: Validate enterprise-level KPIs against likely statutory reporting needs and prepare to supply reconciled data to agency CIO offices.
- Competitive Edge: Provide enterprise reporting modules that can be rapidly adapted to the formats agencies require for statutory submissions.
IT Program Management
- Risk Level: High
- Opportunity: Agencies and program offices will likely re-examine program-level risk posture; demand for stronger program management services, risk reconciliation, and faster corrective-action reporting may rise. NAICS and vehicles listed above apply.
- Timeline: Dashboard discontinued as of April 2025; agencies shifting to statutorily required data reporting.
- Action Required: Strengthen program-level risk assessments, increase cadence of independent risk reviews, and align program reporting artifacts to statutory data elements. Prepare to support agencies responding to GAO’s recommendations.
- Competitive Edge: Position program-management offerings to include frequent, evidence-backed risk posture updates and remediation tracking aligned to GAO-style findings.
IT Risk Management
- Risk Level: High
- Opportunity: Clear opportunity for firms that can deliver improved, auditable risk-assessment frameworks and tools to replace or complement the discontinued dashboard and to support agencies implementing GAO recommendations. Relevant compliance surfaces: FITARA, NIST 800-53, OMB Circular A-11, OMB Circular A-130, Federal IT Acquisition Reform Act. NAICS and vehicles from Tags apply.
- Timeline: Dashboard discontinued as of April 2025; agencies shifting to statutorily required data reporting.
- Action Required: Update risk-management approaches to produce timely, independently verifiable risk ratings; document how contractor tools and processes support agency compliance with existing statutory/regulatory frameworks.
- Competitive Edge: Offer independent risk-assessment services and tool integrations that map to statutory reporting fields and recognized compliance regimes named in the Tags.
IT Portfolio Management
- Risk Level: High
- Opportunity: Portfolio management practices are directly implicated by an underestimating-of-risk finding; agencies may require more rigorous portfolio-level analysis and reconciled investment-level risk justifications. NAICS and vehicles from Tags apply.
- Timeline: Dashboard discontinued as of April 2025; agencies shifting to statutorily required data reporting.
- Action Required: Ensure portfolio reporting supports statutory reporting requirements and can demonstrate alignment between investment risk and corrective actions; prepare artifacts to support agency responses to GAO recommendations.
- Competitive Edge: Provide portfolio analytics that clearly reconcile investment-level risks to portfolio decisions and statutory reporting commitments.
Federal IT Consulting
- Risk Level: High
- Opportunity: Consulting demand may rise to help agencies implement GAO’s 17 recommendations and to redesign reporting processes now that the dashboard is discontinued. Agencies named in Tags (GSA, OMB, DOD, DHS, HHS, DOE, DOT, VA, DOJ) are relevant stakeholders. NAICS and vehicles from Tags apply.
- Timeline: Dashboard discontinued as of April 2025; agencies shifting to statutorily required data reporting.
- Action Required: Prepare consulting offerings focused on improving risk-assessment accuracy, supporting statutory reporting, and operationalizing GAO recommendations. Develop briefings and capability statements showing experience with the compliance surfaces listed in Tags.
- Competitive Edge: Combine subject-matter expertise in risk assessment with hands-on help implementing reporting-process changes tied to statutory requirements and GAO-style remediation plans.
Cross-Segment Implications
- Portfolio management and IT risk management are tightly coupled: changes in how risk is assessed and reported at the portfolio level will cascade into program management and enterprise IT execution. Poorly reconciled investment risk ratings can produce downstream program remediation, schedule slippage, or increased oversight.
- Federal IT consulting and IT program management firms will likely be engaged to help agencies implement GAO’s 17 recommendations; that creates demand that spans IT Services, Modernization, and Enterprise IT segments.
- Compliance surfaces named in the Tags (FITARA, NIST 800-53, OMB Circular A-11, OMB Circular A-130, Federal IT Acquisition Reform Act) create common requirements contractors must map to across segments, so firms that standardize reporting capabilities against those regimes can serve multiple segments and agencies named in the Tags (GSA, OMB, DOD, DHS, HHS, DOE, DOT, VA, DOJ).
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.