IT Systems Annual Assessment: DOD Should Improve IT Fraud Risk Management Practices

GAO found that the Department of Defense’s 18 major IT business programs show uneven performance reporting, incomplete fraud risk awareness, and mixed adoption of software development and cybersecurity practices.…

Cabrillo Club

Cabrillo Club

Editorial Team · September 28, 2026 · 4 min read

Share:LinkedInX

Cabrillo Club Insights

IT Systems Annual Assessment: DOD Should Improve IT Fraud Risk Management Practices

TL;DR

GAO found that the Department of Defense’s 18 major IT business programs show uneven performance reporting, incomplete fraud risk awareness, and mixed adoption of software development and cybersecurity practices. DOD planned to spend $10.3 billion on those 18 programs for FY 2024–FY 2026, with the four largest programs accounting for roughly half of that planned spending. GAO’s April 2026 questionnaire responses show 7 of 18 programs reported staff were unaware of or lacked training to detect fraud in IT systems, 10 programs reported using Agile approaches but many lacked required metrics, and 6 programs had not developed plans to implement zero trust by DOD’s 2027 deadline. GAO cites prior recommendations (see GAO-22-105330 and GAO-25-107649) and published this assessment as GAO-26-108596. Immediate implication: contractors supporting DOD IT programs should assume increased scrutiny on fraud risk management, performance metric reporting, cybersecurity strategies, and zero trust planning — and should update capture and compliance plans accordingly.

Key Points

  • What happened: GAO’s IT systems assessment (GAO-26-108596) found gaps across DOD major IT business programs in fraud risk awareness, performance reporting, software development metrics, and readiness for zero trust.
  • Who is affected: Segments named in the notice including NAICS codes 541512, 541513, 541519, 541330, 541511, 518210, 541690, 611430; agencies DOD and GSA (General Services Administration); and market segments such as Cybersecurity, IT Services, Defense, Software Development, Agile Development, Artificial Intelligence, Fraud Risk Management, IT Security Training, Performance Metrics and Analytics, Zero Trust Implementation, and Business Systems.
  • Timeline: DOD planned spending referenced covers FY 2024 through FY 2026; GAO used questionnaire data as of April 2026; DOD’s zero trust implementation deadline referenced as 2027.
  • What contractors should do NOW: inventory and document fraud-risk training and reporting processes for affected programs; validate performance metrics and reporting capabilities for any DOD IT business program you support; ensure cybersecurity strategies and zero trust implementation plans are documented where applicable; and begin capturing evidence and compliance artifacts for proposal responses and post-award oversight.

Who Is Affected

Specific NAICS codes, agencies, and contract vehicles pending source review.

Market segments called out in the event’s segmentation include Cybersecurity, IT Services, Defense, Software Development, Agile Development, Artificial Intelligence, Fraud Risk Management, IT Security Training, Performance Metrics and Analytics, Zero Trust Implementation, and Business Systems. Contract vehicles listed in segmentation include SEWP, OASIS+, ITES-SW2, and CHESS.

Frequently Asked Questions

Q: Did GAO identify specific programs by name?

A: The summary describes 18 major IT business programs and notes the four largest account for half of planned spending, but program names beyond that are not provided in the Summary. Specific program names are pending source review.

Q: Does GAO require new contractor training or certifications?

A: GAO’s findings note that 7 of 18 programs reported staff lacked training or awareness to recognize and report fraud in IT systems. GAO recommends improved fraud risk management practices; whether DOD will change training requirements for contractors is pending source review. Contractors should proactively document and offer role-appropriate fraud detection and reporting training to program staff.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Q: How does this affect zero trust and AI use on programs I support?

A: GAO reported 12 of 18 programs reported having an approved cybersecurity strategy and 12 of 18 implementing zero trust, while 6 had not developed zero-trust plans for DOD’s 2027 deadline; five programs reported using AI tools but three lacked an approved cybersecurity strategy. Contractors should ensure any AI use is covered by an approved cybersecurity strategy and that zero trust implementation planning is underway where applicable.

Definitions

  • Fraud risk awareness: Staff-level training and awareness to recognize and report signs of fraud or tampering in IT systems, as reported in GAO’s assessment.
  • Zero trust: A cybersecurity approach referenced in the Summary tied to DOD’s 2027 implementation deadline.
  • Agile and iterative software development: Development approaches referenced in the Summary where 10 of 18 programs reported active use.

Intelligence Response

  • Cabrillo Signals War Room — Already detected this event and delivered this briefing. Use War Room to monitor follow-on GAO actions, DOD responses, and any guidance updates that affect program management or solicitations. War Room will push alerts when source documents (e.g., updated DOD guidance or GAO follow-ups) are released.
  • Cabrillo Signals Match Engine — Rescore opportunity pipelines to prioritize pursuits where programs demonstrate gaps (fraud awareness, metrics, zero trust) that match your firm’s strengths; update win probability and capture priorities accordingly.
  • Cabrillo Signals Intelligence Hub — Execute saved searches for follow-on solicitations and policy updates tied to DOD IT business programs; Intelligence Hub will track affected NAICS, agencies, and the named contract vehicles from segmentation and notify capture teams when solicitations or amendments appear.
  • Proposal Studio (Proposal OS) and Proposal Studio Workflow Tracker — Spin up compliance matrices and a 9-gate capture workflow to document fraud-risk training, performance metrics, cybersecurity strategies, and zero trust planning for proposals. Use the Proposal OS win/no-bid engine and library to align win themes to GAO findings and to assemble audit-ready documentation.

Who to notify immediately: BD Director (capture posture and pursuit prioritization), Capture Manager (opportunity rescore and bid/no-bid), Proposal Manager (proposal skeleton and compliance artifacts), Security/Compliance Lead (fraud training evidence, cybersecurity strategy, zero trust plans), and Program Manager (post-award performance metric and reporting plans).

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

First 48-hour response playbook

  • Hour 0–4: War Room alert and briefing to BD and Capture teams. Configure immediate Cadillac alerts in Cabrillo Signals for any updates to the GAO report, DOD responses, or solicitations tied to the 18 programs.
  • Hour 4–12: Match Engine run to rescore active pipelines and identify high-value pursuits exposed by capability gaps noted in GAO. Notify Capture Manager of top rescored opportunities.
  • Hour 12–24: Intelligence Hub saved-search execution for named contract vehicles and agencies; pull relevant solicitation histories and assemble list of programs where fraud-awareness, zero trust, or cybersecurity strategy deficiencies create advantage.
  • Hour 24–48: Proposal Studio: initialize compliance matrix for prioritized pursuits; Proposal Studio Workflow Tracker: create 9-gate capture timeline, assign roles, and collect evidence of training, performance-metric reporting, cybersecurity strategy documents, and zero trust roadmaps.

Further reading and resources: Winning Federal Contracts Guide (/insights/winning-federal-contracts). For security and compliance guidance see CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide).

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.