Director of National Intelligence: Status of Open GAO Recommendations
GAO has issued 139 recommendations to the DNI from July 2011 through September 15, 2026; ODNI has implemented 76 (55%), closed six for other reasons, and has 57 remaining open recommendations. GAO designated six of those 57 as priorities in July 2026.…
Cabrillo Club
Editorial Team · September 30, 2026 · 5 min read
Cabrillo Club Insights
Director of National Intelligence: Status of Open GAO Recommendations
Also in this intelligence package
Executive Summary
GAO has made 139 recommendations to the Director of National Intelligence (DNI) covering the period July 2011 through September 15, 2026. As of September 15, 2026, the Office of the DNI (ODNI) has implemented 76 recommendations (55 percent), closed six for other reasons, and has 57 remaining open recommendations. In July 2026 GAO designated six of those 57 as priority recommendations for the DNI to address. The James M. Inhofe NDAA (National Defense Authorization Act) for FY2023 requires GAO to transmit lists of unimplemented recommendations annually through 2028; this submission is GAO’s fourth.
Contractors that serve the Intelligence Community and related support markets should treat this as a near-term programmatic and procurement signal. The open recommendations and the six GAO-prioritized items create demand for work across personnel vetting and security-clearance processing, workforce management, intelligence enterprise management, facilities and infrastructure remediation, and supporting IT and professional services. Firms that can quickly align offerings to those functional gaps and demonstrate compliance with the listed compliance surfaces have a stronger position when agencies move from oversight findings to acquisition activity.
Impact Matrix
Intelligence Community
- Risk Level: High
- Opportunity: Support to ODNI and IC components to implement GAO recommendations affecting enterprise management and oversight. Relevant agencies listed in Tags: ODNI, DNI, CIA, NSA, DIA, NGA, NRO. Specific opportunities TBD pending solicitation language. Contract vehicles and NAICS in Tags (e.g., OASIS+, STARS III, Alliant 3, 8(a) STARS III; NAICS list) identify common procurement routes to monitor.
- Timeline: As of September 15, 2026; GAO’s fourth submission and annual reporting through 2028 per the FY2023 NDAA provision. GAO identified six priority recommendations in July 2026.
- Action Required: Monitor GAO enclosures and ODNI responses; map capability statements to oversight gaps; position for task orders on multi-award vehicles that serve IC customers.
- Competitive Edge: Maintain cleared personnel and formal relationships with prime holders on the listed vehicles to accelerate award responsiveness when task orders align to GAO priorities.
Security Clearance Processing
- Risk Level: Critical
- Opportunity: Modernization, surge staffing, process-improvement, and systems integration to address personnel vetting and clearance backlogs tied to GAO recommendations. Specific opportunities TBD pending solicitation language; relevant NAICS in Tags include 561210, 561311, 561320.
- Timeline: As of September 15, 2026; six priority recommendations highlighted July 2026.
- Action Required: Prepare rapid-response teams for vetting and adjudication support; ensure offerings address both process and tool modernization; document prior performance in clearance-processing work.
- Competitive Edge: Offer scalable, compliance-aligned vetting solutions (including staffing and automated tool integration) and partner with primes on listed vehicles to be positioned for task orders.
Personnel Vetting
- Risk Level: Critical
- Opportunity: Advisory, operational, and technical services to remediate GAO-identified weaknesses in personnel vetting programs. Specific opportunities TBD pending solicitation language; NAICS and vehicles from Tags apply.
- Timeline: As of September 15, 2026; July 2026 prioritized recommendations.
- Action Required: Align policies, training, and technical offerings to support prioritized vetting reforms; prepare case studies and compliance documentation.
- Competitive Edge: Combine process improvement consulting with proven toolsets and staffing models to present an integrated remediation offering.
Intelligence Enterprise Management
- Risk Level: Critical
- Opportunity: Program and portfolio management, governance, and audit-closure support to implement enterprise-level GAO recommendations. Specific opportunities TBD pending solicitation language; NAICS 541611, 541690, 541990 are relevant.
- Timeline: As of September 15, 2026; prioritized items in July 2026.
- Action Required: Offer governance, performance-measurement, and oversight-support services; help agencies translate recommendations into executable plans.
- Competitive Edge: Demonstrate track record in enterprise governance and in closing audit/GAO findings; package measurable remediation milestones tied to GAO language.
Facilities Management
- Risk Level: High
- Opportunity: Remediation, maintenance, and program management tied to infrastructure/facilities recommendations. Specific opportunities TBD pending solicitation language; NAICS in Tags include 236220 and 237990 for infrastructure-related work.
- Timeline: As of September 15, 2026.
- Action Required: Prepare facilities assessment and modernization capabilities; align security- and compliance-related facility services with IC requirements listed in Tags.
- Competitive Edge: Offer integrated facility assessments that map deficiencies to prioritized GAO recommendations and to compliance surfaces.
Workforce Management
- Risk Level: High
- Opportunity: HR systems modernization, workforce planning, training, and retention programs to address GAO-identified workforce management issues. Specific opportunities TBD pending solicitation language.
- Timeline: As of September 15, 2026.
- Action Required: Develop offerings for workforce analytics, training, and succession planning tuned to intelligence community needs.
- Competitive Edge: Present data-driven workforce planning products that can be deployed under existing vehicles and include metrics that align to GAO recommendation language.
IT Services
- Risk Level: High
- Opportunity: Cybersecurity, systems modernization, and management of IT environments to support enterprise and vetting reforms. Relevant NAICS from Tags include 541513, 541512, 541611, 541690, 541990. FedRAMP (Federal Risk and Authorization Management Program), NIST 800-171 (NIST Special Publication 800-171), NIST 800-53, ICD 503, ICD 705, FISMA, and other compliance surfaces are listed in Tags and should guide solution design.
- Timeline: As of September 15, 2026.
- Action Required: Validate cloud and information-system solutions against the compliance surfaces in Tags; prepare FedRAMP-capable offerings or compliance-assist services.
- Competitive Edge: Bring pre-certified or compliance-ready modules (e.g., NIST/FedRAMP-aligned) and tie them to remediation roadmaps that respond to GAO priorities.
Professional Services
- Risk Level: Medium
- Opportunity: Advisory and program-support engagements to help ODNI and components implement GAO recommendations. Relevant NAICS include 541611, 541690, 541990.
- Timeline: As of September 15, 2026.
- Action Required: Market consulting services that map to specific GAO findings; prepare staffing and proposal templates for rapid response.
- Competitive Edge: Offer bundled advisory + implementation packages and propose clear metrics for closing GAO recommendations.
Management Consulting
- Risk Level: Medium
- Opportunity: Strategic planning, change management, and process redesign to close enterprise-level recommendations. Specific opportunities TBD pending solicitation language.
- Timeline: As of September 15, 2026.
- Action Required: Align practice areas to GAO priority topics and prepare to support program-planning and performance-measurement initiatives.
- Competitive Edge: Differentiate by demonstrating prior success closing audit/oversight recommendations and offering measurable remediation timelines.
Infrastructure Services
- Risk Level: High
- Opportunity: Support for infrastructure elements identified by GAO, including remediation and lifecycle management. NAICS 236220 and 237990 listed in Tags point to relevant capabilities.
- Timeline: As of September 15, 2026.
- Action Required: Prepare infrastructure assessment and remediation teams; ensure proposals reflect the security- and compliance-related constraints of IC work.
- Competitive Edge: Combine facilities/infrastructure delivery with security and compliance controls to shorten the path from assessment to funded remedial work.
Cross-Segment Implications
- Personnel vetting and security-clearance processing are tightly coupled with workforce management and Intelligence Enterprise Management: improvements (or procurement to address GAO findings) in vetting processes will drive demand for workforce-planning and IT integration services.
- IT Services and compliance surfaces (NIST 800-171, NIST 800-53, FedRAMP, ICD 503/705, FISMA, etc.) are cross-cutting requirements that will influence contracts across professional services, management consulting, and infrastructure/facilities work. Contractors must present technically compliant solutions alongside programmatic proposals.
- Facilities and infrastructure remediation may require concurrent program management, consulting, and IT modernization to address enterprise-level GAO recommendations — creating integrated opportunity packages rather than discrete buys.
- The FY2023 NDAA reporting cadence (annual through 2028) and GAO’s July 2026 identification of six priority recommendations increase the probability of staged, prioritized procurements; contractors should track subsequent annual GAO transmissions and ODNI responses to anticipate task-order timing.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.