VA fails watchdog FISMA audit on IT security, but agency disagrees
The VA's Office of Inspector General reported the agency failed its FY2025 FISMA audit, citing deficiencies in vulnerability management, incident response, configuration management, and access controls.…
Cabrillo Club
Editorial Team · July 28, 2026 · 4 min read
Cabrillo Club Insights
VA fails watchdog FISMA audit on IT security, but agency disagrees
Also in this intelligence package
TL;DR
The VA's Office of Inspector General reported the agency failed its FY2025 FISMA audit, citing deficiencies in vulnerability management, incident response, configuration management, and access controls. The VA disputes the report and says many controls are in place or underway, but the finding signals ongoing cybersecurity compliance risk for VA IT systems. Contractors supporting VA IT infrastructure should expect heightened scrutiny in deliverables, stronger oversight, and requests for evidence of controls mapped to FISMA and associated frameworks. This may increase compliance workloads, audit-readiness documentation, and evidence collection for government reviews. Early preparation and focused remediation on the cited control areas will reduce near-term program risk and preserve competitive posture on VA opportunities.
Key Points
- What happened: The VA OIG reported the VA failed its FY2025 FISMA audit due to deficiencies in vulnerability management, incident response, configuration management, and access controls.
- Who is affected: Contractors and teams in Cybersecurity, IT Services, Healthcare IT, Vulnerability Management, Incident Response, Configuration Management, Identity and Access Management, Security Operations, and Compliance and Risk Management; specific NAICS codes and agencies are listed in segmentation.
- Timeline: FY2025 FISMA audit (as reported). Additional timing details TBD pending source review.
- What contractors should do NOW: Immediately validate and document controls in the four cited areas, update evidence packages, trigger heightened monitoring and incident response playbooks, and prepare to present remediations and timelines to VA customers and oversight teams.
Who Is Affected
- Affected segments at a glance: Cybersecurity, IT Services, Healthcare IT, Vulnerability Management, Incident Response, Configuration Management, Identity and Access Management, Security Operations, Compliance and Risk Management.
- Specific NAICS codes, agencies, contract vehicles, and compliance regimes from segmentation:
- NAICS: 541512, 541513, 541519, 541330, 541690, 518210, 541511, 334118
- Agencies: VA, VA OIG
- Contract vehicles: VA T4NG, VETS 2, GSA (General Services Administration) IT Schedule 70, OASIS+, CIO-SP4, Alliant 2
- Compliance surfaces: FISMA, NIST 800-53, NIST 800-171 (NIST Special Publication 800-171), FedRAMP (Federal Risk and Authorization Management Program), NIST Cybersecurity Framework, OMB A-130, FIPS 199, FIPS 200
Frequently Asked Questions
Q: Does the OIG finding change contractor obligations immediately?
A: The Summary indicates contractors should expect heightened scrutiny and that deficiencies were identified; contractors supporting VA IT infrastructure should prepare for increased oversight and evidence requests. Specific new contractual obligations or directions are pending source review.
Q: Which contract vehicles should teams prioritize for review and outreach?
A: The segmentation identifies VA T4NG, VETS 2, GSA IT Schedule 70, OASIS+, CIO-SP4, and Alliant 2 as relevant contract vehicles. Prioritize outreach and program reviews on awarded work under those vehicles. Additional task-order‑level impacts are pending source review.
Q: Which compliance frameworks should contractors emphasize in remediation?
A: The event specifically implicates FISMA and related controls; segmentation also lists NIST 800-53, NIST 800-171, FedRAMP, NIST Cybersecurity Framework, OMB A-130, FIPS 199, and FIPS 200. Align remediation and evidence collection to those regimes.
Definitions
- VA: The Department of Veterans Affairs, the federal agency overseeing veterans' benefits and services.
- VA OIG: The VA's Office of Inspector General, the agency office that conducts audits and oversight.
- FISMA: The Federal Information Security Modernization Act, the federal law and audit regime for information security compliance.
- Vulnerability management: Processes to identify, prioritize, remediate, and track software/hardware vulnerabilities.
- Incident response: Processes and capabilities to detect, respond to, and recover from cybersecurity incidents.
- Configuration management: Processes to maintain secure and authorized configurations for systems and devices.
- Access controls: Policies and technical controls that govern user and system access to resources.
Intelligence Response
- Cabrillo products to leverage:
- Cabrillo Signals War Room — Already detected this event and delivered this briefing; continue monitoring OIG communications, VA responses, and follow-on solicitations.
- Cabrillo Signals Match Engine — Rescore and reprioritize active opportunity pipelines where increased FISMA emphasis changes win probability.
- Cabrillo Signals Intelligence Hub — Track affected NAICS, agencies, and contract vehicles; configure saved searches to alert when related solicitations or corrective action requests appear on SAM.gov (System for Award Management).
- Proposal Studio (Proposal OS) — Use to assemble updated compliance matrices and evidence packages tied to the four cited control areas.
- Proposal Studio Workflow Tracker — Drive a 9-gate capture workflow for impacted opportunities with automated compliance routing and audit-ready documentation.
- Who to notify now:
- Capture/BD lead — re-assess pursuit posture and win strategy.
- Program manager — coordinate contract-level communications and deliverable impact.
- Security lead/CISO or Security PM — lead remediation, evidence collection, and control validation.
- Contracts officer/legal — review potential contractual implications and reporting obligations.
- Proposal manager — prepare updated compliance narratives and templates.
- First 48-hour playbook:
- Hour 0–4: Convene crisis stand-up with capture, program, security, and contracts leads; confirm list of VA engagements and task orders under the named vehicles.
- Hour 4–12: Run immediate control inventory for vulnerability management, incident response, configuration management, and access controls; pull existing evidence and gap list.
- Hour 12–24: Configure Cabrillo Signals Intelligence Hub saved searches for VA/VA OIG activity and enable War Room alerting for follow-on solicitations or OIG updates; reprioritize pipeline via Match Engine.
- Hour 24–48: Task Proposal Studio to build an audit-ready evidence package and compliance matrix; route through Proposal Studio Workflow Tracker gates for approvals and client briefings. Share remediation timelines with VA contacts as appropriate.
Primary hub: Secure Operations Guide (/insights/secure-operations-guide)
Related guides:
- CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide)
- CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide)
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor try our free Intelligence Dashboard→

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.