Cabrillo Club
ServicesPlatform
Pricing
Talk to a founder
Cabrillo Club

Seven private AI products for government contractors. Find. Win. Deliver. Protect.

Products

  • Signals
  • ProposalOS
  • CalibrationOS
  • FinanceOS
  • Platform & roadmap

Solutions

  • Defense & GovCon
  • Your Business
  • Membership
  • Pricing

Resources

  • Insights
  • Tools
  • Community
  • CMMC Assessment

Company

  • About
  • Team
  • Proof
  • Contact
Cabrillo Club LLC·10 E. Yanonali St., Suite 129, Santa Barbara, CA 93101·CAGE Code: 19CA1·SAM UEI: L4CAFCQ6C173

© 2026 Cabrillo Club LLC. All rights reserved.

PrivacyTermsCookiesDo Not Sell or Share
  1. Home
  2. Insights
  3. VA fails watchdog FISMA audit on IT security, but agency disagrees
Compliance & Risk

VA fails watchdog FISMA audit on IT security, but agency disagrees

The VA's Office of Inspector General reported the agency failed its FY2025 FISMA audit, citing deficiencies in vulnerability management, incident response, configuration management, and access controls.…

Cabrillo Club

Cabrillo Club

Editorial Team · July 28, 2026 · 7 min read

Share:LinkedInX

Cabrillo Club Insights

VA fails watchdog FISMA audit on IT security, but agency disagrees

Also in this intelligence package

Flash Brief

Breaking analysis of what happened and who is affected.

Read report →
Action Kit

Actionable checklists and implementation guidance.

Read report →

Executive Summary

The VA Office of Inspector General reported the agency failed its FY2025 FISMA audit, citing deficiencies in vulnerability management, incident response, configuration management, and access controls. The VA disputes the findings but the report signals continued cybersecurity and compliance challenges at the agency. Severity is labeled MEDIUM, meaning heightened attention rather than an immediate procurement-wide crisis, but the outcome will likely increase scrutiny on VA IT systems and contractor deliverables that touch those controls.

Segments named in the Tags — including Cybersecurity, IT Services, Healthcare IT, Vulnerability Management, Incident Response, Configuration Management, Identity and Access Management, Security Operations, and Compliance and Risk Management — should expect nearer-term demand for remediation, audit-readiness, and demonstrable evidence of FISMA-aligned controls (including alignment with the compliance surfaces listed in the Tags). Contractors supporting VA platforms and services should prioritize proving control effectiveness, accelerating remediation efforts tied to vulnerability and configuration management, and preparing for tighter oversight on deliverables for FY2025-related work.

Impact Matrix

Cybersecurity

  • Risk Level: High
  • Opportunity: Increased demand for security assessments, continuous monitoring, and remediation services. Relevant NAICS: 541512, 541513, 541519, 541330, 541690, 518210, 541511, 334118. Relevant contract vehicles: VA T4NG, VETS 2, GSA (General Services Administration) IT Schedule 70, OASIS+, CIO-SP4, Alliant 2.
  • Timeline: FY2025 (per the FY2025 FISMA audit referenced).
  • Action Required: Prepare to demonstrate FISMA and NIST-based control implementations (see compliance surfaces in Tags), accelerate vulnerability patching and monitoring, and document evidence of control operation for VA reviewers and auditors.
  • Competitive Edge: Offer packaged audit-readiness engagements combining assessment, remediation roadmaps, and evidence collection to shorten time-to-compliance for VA programs.

IT Services

  • Risk Level: Medium
  • Opportunity: Support for strengthening baseline configuration management, change control, and operational security across VA systems. Relevant NAICS and contract vehicles as listed above.
  • Timeline: FY2025.
  • Action Required: Validate and harden configurations, integrate security requirements into service delivery, and ensure SLAs and deliverables reflect enhanced oversight.
  • Competitive Edge: Demonstrate integrated DevSecOps or managed services models that embed documented FISMA/NIST control checks into routine IT operations.

Healthcare IT

  • Risk Level: Medium
  • Opportunity: Work to ensure clinical systems and health data flows meet the heightened scrutiny on access controls and configuration management. Relevant NAICS and contract vehicles as listed above.
  • Timeline: FY2025.
  • Action Required: Map clinical systems to FISMA/NIST requirements cited in Tags, prioritize identity/access controls and configuration baselines for health IT components, and prepare artifact packages to satisfy auditors.
  • Competitive Edge: Provide health-IT-specific compliance packages that align clinical workflows with FISMA/NIST evidence requirements.

Vulnerability Management

  • Risk Level: Critical
  • Opportunity: Direct remediation work, vulnerability scanning, prioritization and patch management services. Relevant NAICS and contract vehicles as listed above.
  • Timeline: FY2025.
  • Action Required: Demonstrate effective vulnerability scanning cadence, triage, and remediation metrics; close high/critical findings and prepare remediation evidence for inspectors.
  • Competitive Edge: Combine automated scanning with verified remediation verification and reporting tailored to FISMA audit expectations.

Incident Response

  • Risk Level: High
  • Opportunity: Incident response planning, tabletop exercises, playbook development, and forensics support. Relevant NAICS and contract vehicles as listed above.
  • Timeline: FY2025.
  • Action Required: Validate incident response capabilities, update playbooks to reflect audit focus areas, and prepare IR evidence and after-action documentation.
  • Competitive Edge: Offer incident response retainer models with predefined audit-oriented reporting and evidence preservation workflows.

Configuration Management

  • Risk Level: High
  • Opportunity: Baseline configuration specification, hardening, and drift detection services. Relevant NAICS and contract vehicles as listed above.
  • Timeline: FY2025.
  • Action Required: Establish or tighten configuration baselines, automate drift detection and remediation, and maintain evidence of configuration control for auditors.
  • Competitive Edge: Deliver automated configuration compliance pipelines that produce auditor-ready attestations.

Identity and Access Management

  • Risk Level: High
  • Opportunity: Access control reviews, privileged access management, role design, and enforcement mechanisms. Relevant NAICS and contract vehicles as listed above.
  • Timeline: FY2025.
  • Action Required: Review and remediate access control deficiencies, tighten privileged access, and produce access logs and control evidence aligned with audit needs.
  • Competitive Edge: Bundle IAM services with continuous monitoring and access attestation workflows that support FISMA reporting.

Security Operations

  • Risk Level: High
  • Opportunity: Security operations center (SOC) enhancements, monitoring, and event management aligned to audit expectations. Relevant NAICS and contract vehicles as listed above.
  • Timeline: FY2025.
  • Action Required: Strengthen detection and response, ensure SOC processes map to FISMA/NIST controls, and prepare SOC reporting for oversight reviewers.
  • Competitive Edge: Provide managed SOC capabilities that export auditor-friendly metrics and evidence packages.

Compliance and Risk Management

  • Risk Level: Critical
  • Opportunity: Compliance assessments, POA&M development, risk assessments, and audit support tied directly to FISMA and listed compliance surfaces (e.g., NIST 800-53). Relevant NAICS and contract vehicles as listed above.
  • Timeline: FY2025.
  • Action Required: Reassess control posture against the compliance surfaces in Tags, update POA&Ms and remediation timelines, and prepare formal audit evidence and attestations.
  • Competitive Edge: Deliver end-to-end compliance programs that tie technical remediation to risk acceptance documentation and audit artifacts.

Cross-Segment Implications

  • Technical gaps in vulnerability management, configuration management, and IAM will drive demand across Cybersecurity, Security Operations, and Incident Response simultaneously—remediating one area will often require coordinated work across these segments (for example, patching a vulnerability requires configuration management controls, verification by security operations, and potential incident response if exploitation is discovered).
  • Compliance and Risk Management acts as the integrator: audit findings from VA OIG (FY2025 FISMA audit) will cascade into procurement and oversight changes that touch IT Services and Healthcare IT contracts, increasing requirements for demonstrable controls and evidence from many contractor roles.
  • Contract vehicles and program offices listed in Tags are likely the procurement pathways for remediation work; contractors that can provide bundled services covering assessment, remediation, and audit evidence across these segments will be positioned to respond to VA’s heightened scrutiny.

```json:

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or try our free Intelligence Dashboard→

{

"tldr": "The VA Office of Inspector General reported the agency failed its FY2025 FISMA audit, citing deficiencies in vulnerability management, incident response, configuration management, and access controls. The VA disputes the findings but the report signals continued cybersecurity and compliance challenges at the agency. Severity is labeled MEDIUM, meaning heightened attention rather than an immediate procurement-wide crisis, but the outcome will likely increase scrutiny on VA IT systems and contractor deliverables that touch those controls. Segments named in the Tags — including Cybersecurity, IT Services, Healthcare IT, Vulnerability Management, Incident Response, Configuration Management, Identity and Access Management, Security Operations, and Compliance and Risk Management — should expect nearer-term demand for remediation, audit-readiness, and demonstrable evidence of FISMA-aligned controls (including alignment with the compliance surfaces listed in the Tags). Contractors supporting VA platforms and services should prioritize proving control effectiveness, accelerating remediation efforts tied to vulnerability and configuration management, and preparing for tighter oversight on deliverables for FY2025-related work.",

"segments": [

{

"segment": "Cybersecurity",

"risk_level": "High",

"opportunity": "Increased demand for security assessments, continuous monitoring, and remediation services. Relevant NAICS: 541512, 541513, 541519, 541330, 541690, 518210, 541511, 334118. Relevant contract vehicles: VA T4NG, VETS 2, GSA IT Schedule 70, OASIS+, CIO-SP4, Alliant 2.",

"timeline": "FY2025 (per the FY2025 FISMA audit referenced).",

"action": "Prepare to demonstrate FISMA and NIST-based control implementations, accelerate vulnerability patching and monitoring, and document evidence of control operation for VA reviewers and auditors.",

"competitive_edge": "Offer packaged audit-readiness engagements combining assessment, remediation roadmaps, and evidence collection to shorten time-to-compliance for VA programs."

},

{

"segment": "IT Services",

"risk_level": "Medium",

"opportunity": "Support for strengthening baseline configuration management, change control, and operational security across VA systems. Relevant NAICS and contract vehicles as listed above.",

"timeline": "FY2025.",

"action": "Validate and harden configurations, integrate security requirements into service delivery, and ensure SLAs and deliverables reflect enhanced oversight.",

"competitive_edge": "Demonstrate integrated DevSecOps or managed services models that embed documented FISMA/NIST control checks into routine IT operations."

},

{

"segment": "Healthcare IT",

"risk_level": "Medium",

"opportunity": "Work to ensure clinical systems and health data flows meet the heightened scrutiny on access controls and configuration management. Relevant NAICS and contract vehicles as listed above.",

"timeline": "FY2025.",

"action": "Map clinical systems to FISMA/NIST requirements, prioritize identity/access controls and configuration baselines for health IT components, and prepare artifact packages to satisfy auditors.",

"competitive_edge": "Provide health-IT-specific compliance packages that align clinical workflows with FISMA/NIST evidence requirements."

},

{

"segment": "Vulnerability Management",

"risk_level": "Critical",

"opportunity": "Direct remediation work, vulnerability scanning, prioritization and patch management services. Relevant NAICS and contract vehicles as listed above.",

"timeline": "FY2025.",

"action": "Demonstrate effective vulnerability scanning cadence, triage, and remediation metrics; close high/critical findings and prepare remediation evidence for inspectors.",

"competitive_edge": "Combine automated scanning with verified remediation verification and reporting tailored to FISMA audit expectations."

},

{

"segment": "Incident Response",

"risk_level": "High",

"opportunity": "Incident response planning, tabletop exercises, playbook development, and forensics support. Relevant NAICS and contract vehicles as listed above.",

"timeline": "FY2025.",

"action": "Validate incident response capabilities, update playbooks to reflect audit focus areas, and prepare IR evidence and after-action documentation.",

"competitive_edge": "Offer incident response retainer models with predefined audit-oriented reporting and evidence preservation workflows."

},

{

"segment": "Configuration Management",

"risk_level": "High",

"opportunity": "Baseline configuration specification, hardening, and drift detection services. Relevant NAICS and contract vehicles as listed above.",

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or try our free Intelligence Dashboard→

"timeline": "FY2025.",

"action": "Establish or tighten configuration baselines, automate drift detection and remediation, and maintain evidence of configuration control for auditors.",

"competitive_edge": "Deliver automated configuration compliance pipelines that produce auditor-ready attestations."

},

{

"segment": "Identity and Access Management",

"risk_level": "High",

"opportunity": "Access control reviews, privileged access management, role design, and enforcement mechanisms. Relevant NAICS and contract vehicles as listed above.",

"timeline": "FY2025.",

"action": "Review and remediate access control deficiencies, tighten privileged access, and produce access logs and control evidence aligned with audit needs.",

"competitive_edge": "Bundle IAM services with continuous monitoring and access attestation workflows that support FISMA reporting."

},

{

"segment": "Security Operations",

"risk_level": "High",

"opportunity": "Security operations center (SOC) enhancements, monitoring, and event management aligned to audit expectations. Relevant NAICS and contract vehicles as listed above.",

"timeline": "FY2025.",

"action": "Strengthen detection and response, ensure SOC processes map to FISMA/NIST controls, and prepare SOC reporting for oversight reviewers.",

"competitive_edge": "Provide managed SOC capabilities that export auditor-friendly metrics and evidence packages."

},

{

"segment": "Compliance and Risk Management",

"risk_level": "Critical",

"opportunity": "Compliance assessments, POA&M development, risk assessments, and audit support tied directly to FISMA and listed compliance surfaces (e.g., NIST 800-53). Relevant NAICS and contract vehicles as listed above.",

"timeline": "FY2025.",

"action": "Reassess control posture against the compliance surfaces in Tags, update POA&Ms and remediation timelines, and prepare formal audit evidence and attestations.",

"competitive_edge": "Deliver end-to-end compliance programs that tie technical remediation to risk acceptance documentation and audit artifacts."

}

],

"cross_implications": [

"Vulnerability management, configuration management, and IAM gaps will simultaneously drive work across Cybersecurity, Security Operations, and Incident Response—remediation requires coordinated cross-segment efforts.",

"Compliance and Risk Management serves as the integrator: VA OIG findings from the FY2025 FISMA audit will cascade into procurement and oversight changes that affect IT Services and Healthcare IT contracts, increasing requirements for demonstrable controls and evidence.",

"Contract vehicles and program offices listed in Tags are likely the procurement pathways for remediation work; bundled service providers that span assessment, remediation, and audit evidence will be favored."

]

}

```

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or try our free Intelligence Dashboard→

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.

TwitterLinkedIn

Continue reading

Flash Brief

Breaking analysis of what happened and who is affected.

Read report →
Action Kit

Actionable checklists and implementation guidance.

Read report →
Back to all articles

25-minute assessment. Custom implementation plan.

Try Signals Free

Stop missing opportunities

AI matches SAM.gov contracts to your NAICS codes.

What brought you here? (optional)

No spam. Unsubscribe anytime.