Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices

Affected segments pending source review. The GAO report identifies significant, government-wide gaps in implementing OMB’s networked device inventory requirements (requirements established December 2023 and updated January 2025; initial inventories required by September 2024).…

Cabrillo Club

Cabrillo Club

Editorial Team · September 30, 2026 · 3 min read

Share:LinkedInX

Cabrillo Club Insights

Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices

Executive Summary

Affected segments pending source review.

The GAO report identifies significant, government-wide gaps in implementing OMB’s networked device inventory requirements (requirements established December 2023 and updated January 2025; initial inventories required by September 2024). As of September 2026, across the 22 civilian CFO Act agencies GAO reviewed, many agencies have incomplete or nonmaintained inventories: 15 had established an inventory, 11 were maintaining their inventories, 10 had included all required information (such as asset description and software version), and only 7 had fully addressed all three OMB requirements. OMB has not yet issued updated guidance covering fiscal year 2026, and no agencies had reported an IoT cybersecurity waiver.

Contractors should pay attention now because agencies face a clear compliance and capability gap that creates both risk and near-term demand for services to inventory, assess, secure, and sustain networked devices (including Internet of Things (IoT) and operational technology (OT) in building systems and specialized equipment in hospitals and laboratories). The lack of updated OMB guidance and uneven agency progress mean agencies may prioritize remediation in the coming months when guidance or oversight is renewed, creating opportunities for firms that can rapidly help agencies complete inventories, remediate gaps, and demonstrate auditable processes.

Impact Matrix

Internet of Things (IoT)

  • Risk Level: Critical
  • Opportunity: Agencies need assistance completing and maintaining device inventories; services include asset inventory tools and services, vulnerability assessment, device lifecycle management, and remediation planning. Specific opportunities TBD pending solicitation language.
  • Timeline: OMB requirements established December 2023 and updated January 2025; initial inventories were required by September 2024; status reported as of September 2026. OMB has not issued updated guidance covering fiscal year 2026.
  • Action Required: Prepare inventory and asset-management offerings that capture required fields (e.g., asset description, software version), develop rapid-deployment inventory pilots, and be ready to support agencies when OMB issues updated guidance or oversight resumes.
  • Competitive Edge: Demonstrate prior experience delivering auditable inventories and fast rollouts, provide standard templates that map directly to OMB-required fields, and package inventory work with follow-on remediation and sustainment services.

Operational Technology (OT) devices

  • Risk Level: Critical
  • Opportunity: Agencies operating OT (e.g., building maintenance systems, programmable logic controllers in critical sectors) will need risk assessment, segmentation, monitoring, and mitigation services. Specific opportunities TBD pending solicitation language.
  • Timeline: Same OMB timeline as above; GAO cites a July 2026 OT disruption in the water sector as an example of risk to networked OT.
  • Action Required: Position OT security offerings that include discovery of controllers and embedded devices, risk-prioritization services, and incident-response playbooks tailored to OT environments; emphasize minimal disruption approaches for operational systems.
  • Competitive Edge: Build integrated IoT/OT discovery and monitoring demonstrations, highlight safe OT testing capabilities, and offer vendor-agnostic approaches that reduce operational impact during discovery and remediation.

Specialized equipment in hospitals and laboratories

  • Risk Level: High
  • Opportunity: Healthcare-affiliated devices that are networked require inventorying and security controls; hospitals and labs may seek help to identify devices and their software versions and to apply appropriate controls. Specific opportunities TBD pending solicitation language.
  • Timeline: Same OMB timeline as above; agencies reported inventory status as of September 2026.
  • Action Required: Prepare compliant inventory and risk-assessment offerings that account for clinical/operational constraints, and emphasize coordination with facility and clinical engineering stakeholders to avoid care disruption.
  • Competitive Edge: Partner with healthcare systems or medical-device security specialists to offer low-impact discovery and prioritized remediation plans that align security fixes with clinical safety needs.

Cross-Segment Implications

  • Inventories (or lack thereof) are a foundational dependency: incomplete IoT inventories impede OT security efforts and complicate protection of healthcare devices; remediation in one segment (e.g., OT segmentation) may be ineffective without comprehensive IoT visibility.
  • OMB’s absence of updated guidance for FY2026 creates programmatic uncertainty across all segments, slowing agency prioritization and procurement until guidance or oversight is renewed; contractors that have prebuilt compliant offerings will be able to act faster when agencies move.
  • Incidents in one sector (GAO cited a July 2026 water-sector OT disruption) illustrate cascading operational and reputational risk, increasing the likelihood that agencies will seek cross-segment solutions (discovery + monitoring + incident response) rather than point products.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.