IT Dashboard: Selected Agencies’ Investment Ratings Fail to Fully Consider Risks

The GAO found that CIO risk ratings on the IT Dashboard understate risks for many major federal IT investments; of 53 investments reviewed, CIO ratings matched GAO 27 times, showed more risk 24 times, and showed less risk twice.…

Cabrillo Club

Cabrillo Club

Editorial Team · October 7, 2026 · 5 min read

Share:LinkedInX
Blog post hero image

Executive Summary

The GAO review found that CIO risk ratings on the IT Dashboard understated risks for many major IT investments: of 53 investments GAO assessed, CIO ratings matched GAO 27 times, showed less risk 24 times, and showed less risk than GAO in only 2 cases. GAO identified two main contributors to these differences: 21 of the 53 CIO ratings were not updated in a timely manner per agencies’ processes, and two agencies used rating cadences longer than quarterly, contrary to OMB guidance. GAO emphasized that until agencies correct rating quality and frequency issues, critical IT investments may not receive needed oversight and emerging risks may go unidentified.

OMB announced in April 2026 that it is taking steps to sunset the IT Dashboard and replace it with a new streamlined system but did not provide a release timeframe. During this interim period, agencies, oversight bodies, and contractors operating across the affected market segments should expect heightened scrutiny of investment reporting and increased demand for services that improve risk transparency, portfolio monitoring, and corrective actions. Contractors that can help agencies improve CIO rating accuracy, provide rapid program-level remediation, or enable compliant reporting tied to relevant compliance surfaces are positioned to convert this oversight gap into near-term demand.

Impact Matrix

IT Services

  • Risk Level: High
  • Opportunity: Agencies will seek vendors to support improved reporting, program risk assessments, and remediation work. Specific opportunities TBD pending solicitation language. NAICS references from Tags: 541511, 541512, 541513, 541519, 541611, 541618, 518210, 541990. Contract vehicles in Tags that may be relevant: SEWP, OASIS+, 8(a) STARS III, Alliant 2, CIO-SP3.
  • Timeline: April 2026 — OMB announced steps to sunset the Dashboard; replacement timeframe not provided. Interim period requires agencies to address rating quality and frequency now.
  • Action Required: Prepare offerings for CIO-rating alignment support, portfolio risk assessment, and documentation processes that map to OMB guidance and agency procedures. Ensure delivery teams can produce timely evidence for quarterly reviews.
  • Competitive Edge: Demonstrate rapid, repeatable reporting and audit-ready artifacts that shorten agencies’ update cycles and improve CIO confidence.

IT Modernization

  • Risk Level: Critical
  • Opportunity: Agencies will need modernization accelerators focused on risk mitigation and status transparency for major investments. Specific opportunities TBD pending solicitation language. Relevant NAICS and vehicles listed in Tags.
  • Timeline: April 2026 announcement; replacement Dashboard timeframe not provided — agencies must act in the interim to avoid oversight gaps.
  • Action Required: Position offerings that combine modernization roadmaps with risk monitoring, timeline recovery plans, and real-time status dashboards aligned to agency CIO processes.
  • Competitive Edge: Offer integrated modernization + governance packages that produce measurable risk-reduction metrics and artifacts for CIO review.

System Integration

  • Risk Level: High
  • Opportunity: Demand for integrators who can provide consolidated status, dependency mapping, and evidence to justify CIO ratings. Specific opportunities TBD pending solicitation language. NAICS and vehicles from Tags apply.
  • Timeline: April 2026 announcement; replacement timeframe not provided.
  • Action Required: Be ready to support system-level health reporting, schedule and budget reconciliation, and quicker update cadences to match quarterly expectations.
  • Competitive Edge: Emphasize capability to automate data feeds into agency rating workflows to reduce stale ratings.

Software Development

  • Risk Level: High
  • Opportunity: Short-term demand for corrective development sprints, rebaselining, and delivery transparency to align actual status with CIO ratings. Specific opportunities TBD pending solicitation language. NAICS and vehicles in Tags may apply.
  • Timeline: April 2026 announcement; replacement timeframe not provided.
  • Action Required: Prepare to deliver short, measurable increments that demonstrate schedule and performance improvements and supply artifacts for rating updates.
  • Competitive Edge: Provide development + reporting bundles that tie sprint outcomes directly to CIO-rating criteria.

IT Program Management

  • Risk Level: Critical
  • Opportunity: Strong demand for program management and governance services that improve the accuracy and cadence of CIO risk ratings. Specific opportunities TBD pending solicitation language. NAICS and vehicles from Tags are relevant.
  • Timeline: April 2026 announcement; replacement timeframe not provided.
  • Action Required: Offer governance, portfolio review, and CIO-rating process support that align with OMB guidance and agency processes; emphasize timely updates.
  • Competitive Edge: Deliver program-management frameworks that incorporate periodic, evidence-based rating checkpoints and reduce missed updates.

Enterprise IT

  • Risk Level: High
  • Opportunity: Needs include enterprise-level risk analytics, portfolio management, and transparency tools to ensure investments reflect current risk. Specific opportunities TBD pending solicitation language. NAICS and vehicles as listed in Tags.
  • Timeline: April 2026 announcement; replacement timeframe not provided.
  • Action Required: Develop enterprise-level dashboards, analytics, and SOPs to support timely CIO ratings and internal oversight.
  • Competitive Edge: Offer cross-program analytics that surface emerging risks earlier than current processes.

Cloud Services

  • Risk Level: High
  • Opportunity: Agencies may require cloud migration assistance combined with compliant controls evidence to inform CIO risk ratings and FedRAMP (Federal Risk and Authorization Management Program) considerations. Specific opportunities TBD pending solicitation language. Tags list FedRAMP among compliance surfaces and include relevant NAICS and vehicles.
  • Timeline: April 2026 announcement; replacement timeframe not provided.
  • Action Required: Align cloud offerings with FedRAMP expectations and provide evidence packages that support CIO assessments and timely updates.
  • Competitive Edge: Bundle cloud delivery with compliance-ready evidence to shorten the time between status change and rating update.

Cybersecurity

  • Risk Level: High
  • Opportunity: Increased demand for security posture assessments and artifacts mapped to NIST 800-53 (listed in Tags) to support more accurate risk ratings. Specific opportunities TBD pending solicitation language.
  • Timeline: April 2026 announcement; replacement timeframe not provided.
  • Action Required: Be prepared to provide rapid cybersecurity assessments, remediation plans, and documentation that feed into CIO rating processes.
  • Competitive Edge: Offer rapid evidence-of-fix services and continuous monitoring approaches that help agencies update ratings more frequently.

Cross-Segment Implications

  • Inaccurate or stale CIO ratings create a cross-cutting oversight gap: deficiencies in IT Program Management and Enterprise IT reporting can cascade into higher risk for modernization, system integration, software development, cloud, and cybersecurity efforts. Contractors that can bridge program management, technical delivery, and compliance evidence can reduce this cascading risk.
  • Contract vehicles and procurement corridors listed in Tags (SEWP, OASIS+, 8(a) STARS III, Alliant 2, CIO-SP3) may be common paths for agencies to request corrective services; coordinated capture strategies across segments will be advantageous.
  • Compliance surfaces named in Tags (FITARA, OMB Circular A-11, OMB Circular A-130, NIST 800-53, FedRAMP) are cross-cutting reference points agencies will use to validate investment health and risk; offerings that map deliverables to these surfaces will be more compelling.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.