Cabrillo Club
Platform
Proof
Pricing
Talk to a founder
Cabrillo Club

Seven private AI products for government contractors. Find. Win. Deliver. Protect.

Products

  • Signals
  • ProposalOS
  • CalibrationOS
  • FinanceOS
  • Platform & roadmap

Solutions

  • Defense & GovCon
  • Your Business
  • Membership
  • Pricing

Resources

  • Insights
  • Tools
  • Community
  • CMMC Assessment

Company

  • About
  • Team
  • Proof
  • Contact

© 2026 Cabrillo Club LLC. All rights reserved.

PrivacyTermsCookiesDo Not Sell or Share
  1. Home
  2. Insights
  3. VA Software Asset Management: Adherence to Leading Management Practices Needed to Achieve Intended Outcomes
Compliance & Risk

VA Software Asset Management: Adherence to Leading Management Practices Needed to Achieve Intended Outcomes

The Government Accountability Office (GAO) found that the Department of Veterans Affairs (VA) has not fully implemented selected leading planning and management practices for its enterprise software asset management (eSAM) program or for the software license inventory project, leaving both efforts…

Cabrillo Club

Cabrillo Club

Editorial Team · July 22, 2026 · 4 min read

Share:LinkedInX

Cabrillo Club Insights

VA Software Asset Management: Adherence to Leading Management Practices Needed to Achieve Intended Outcomes

Also in this intelligence package

Segment Impact

Deep dive into how this impacts each market segment.

Read report →
Action Kit

Actionable checklists and implementation guidance.

Read report →
In This Guide
  • TL;DR
  • Key Points
  • Who Is Affected
  • Frequently Asked Questions
  • Definitions
  • Intelligence Response

TL;DR

The Government Accountability Office (GAO) found that the Department of Veterans Affairs (VA) has not fully implemented selected leading planning and management practices for its enterprise software asset management (eSAM) program or for the software license inventory project, leaving both efforts at risk of failing to achieve departmentwide software asset management. GAO assessed multiple practice areas as not implemented, minimally implemented, or partially implemented, and highlighted shortcomings in governance, stakeholder engagement, risk documentation, and oversight. VA’s oversight shortfalls were compounded by turnover in its IT management organization, including the absence of a permanent Chief Information Officer (CIO) since January 2025. The report warns VA may miss opportunities to realize significant cost savings from departmentwide software-license analysis at a time when VA planned to spend about $985 million on software in fiscal year 2025. Immediate implications for contractors: expect continued program uncertainty, possible new central reporting requirements as eSAM matures, and an elevated need to track solicitation and policy changes affecting VA software/license management. Use Cabrillo Signals to monitor follow-on solicitations and reposition pipelines now.

Key Points

  • What happened: GAO found VA did not fully implement selected leading program and project planning and management practices for the eSAM program and the software license inventory project, rating several practice areas as not implemented, minimally implemented, or partially implemented.
  • Who is affected: Department of Veterans Affairs (VA); VA programs that acquire software; contractors supporting VA software and software license management.
  • What the timeline is: VA planned to spend about $985 million on software in fiscal year 2025; the CIO position has been vacant since January 2025; overall implementation timeline for eSAM and the inventory project is TBD pending source review.
  • What contractors should do NOW: Immediately inventory VA-facing software/license work, flag dependent opportunities for rescoring, update capture artifacts to reflect governance uncertainty, prepare compliance and cost-savings narratives, and configure Cabrillo Signals pipelines and saved searches to alert on VA solicitations and GAO/VA follow-ups.

Who Is Affected

  • Primary: Department of Veterans Affairs (VA) and VA programs that historically acquired software independently.
  • Secondary: Contractors providing commercial software, software license management services, and program/project management support to VA.
  • Specific NAICS codes, agencies, and contract vehicles pending source review.

Frequently Asked Questions

Q: What did GAO specifically find was missing or weak in VA’s approach?

A: GAO assessed six practice areas for the eSAM program and six for the inventory project. VA had governance not implemented, several areas minimally implemented (including strategic alignment, managing changes, and software license management), and other areas partially implemented (stakeholder engagement, life cycle management planning, scope and risk management). GAO also cited incomplete risk registers and missing planned risk responses.

Q: Does this mean VA will cancel eSAM or the inventory project?

A: The GAO summary does not state cancellation. It states the program and project have not fully implemented selected leading practices and are at risk of not achieving departmentwide software asset management. Program continuation, changes, or cancellations are TBD pending source review.

Q: What immediate contract or compliance changes should contractors expect?

A: Expect potential future requirements for centralized reporting of software license data to VA’s IT management organization as eSAM matures. Specific solicitation or compliance changes are not detailed in the GAO summary; monitor VA actions and follow-on solicitations (pending source review).

Definitions

  • eSAM: Enterprise Software Asset Management — VA’s department-wide effort to change how it manages software assets, including centralized reporting of software license data.
  • Software license inventory: The project component of eSAM intended to implement a centralized inventory of software licenses.
  • CIO: Chief Information Officer — VA did not have a permanent CIO in place since January 2025 per the GAO summary.
  • GAO: Government Accountability Office — the auditing body that produced the report (GAO-26-108641).

Intelligence Response

  • Which Cabrillo products to leverage: Use Cabrillo Signals War Room (already detected this event and delivered this briefing) to maintain continuous monitoring of VA policy updates and GAO follow-ups; run rescoring through Cabrillo Signals Match Engine to reprioritize opportunities affected by governance uncertainty; configure agency- and topic-specific saved searches in Cabrillo Signals Intelligence Hub to alert on VA solicitations, rulemaking, or GAO/agency responses; and mobilize Proposal Studio (Proposal OS) and Proposal Studio Workflow Tracker to update bid/no-bid decisions and lock down compliance matrices and audit-ready capture documentation.
  • Who to notify: Capture/BD lead — immediate opportunity reprioritization; Proposal manager — update compliance matrices and win themes; Security/compliance lead — assess impacts of central reporting expectations; Contracts manager — monitor contracting implications; Program delivery/ops lead — prepare for potential onboarding changes.
  • First 48-hour playbook:
  • Hour 0–4: Acknowledge alert from Cabrillo Signals War Room, circulate this brief to capture/BD, proposal, contracts, and compliance leads; assign owners.
  • Hour 4–12: Run Cabrillo Signals Match Engine to rescore live VA opportunities and flag high-risk items; create Intelligence Hub saved searches for VA eSAM and GAO-26-108641 follow-ups.
  • Hour 12–24: Update Proposal Studio win/no-win decisions and refresh compliance matrices reflecting centralized reporting risk and governance gaps; begin drafting technical approaches that address stakeholder coordination and license reporting.
  • Hour 24–48: Build outreach plan for VA engagement (pending source review), finalize updated capture documentation in Proposal Studio Workflow Tracker, and schedule weekly War Room reviews until VA issues follow-on guidance.

Relevant Cabrillo guidance: Winning Federal Contracts Guide (/insights/winning-federal-contracts). Related compliance reading: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide), CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide).

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or try our free Intelligence Dashboard→

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.

TwitterLinkedIn

Continue reading

Segment Impact

Deep dive into how this impacts each market segment.

Read report →
Action Kit

Actionable checklists and implementation guidance.

Read report →
Back to all articles

25-minute assessment. Custom implementation plan.

Try Signals Free

Stop missing opportunities

AI matches SAM.gov contracts to your NAICS codes.

No spam. Unsubscribe anytime.