Federal Agencies Largely Fail CISA Cloud Security Mandates, Inspector General Reports
A Department of Homeland Security Inspector General report reveals that 86% of federal agencies missed a key deadline for implementing CISA's Secure Cloud Business Applications (SCuBA) directives, leaving systems vulnerable.

A critical report from the Department of Homeland Security's Inspector General has found that a significant majority of federal agencies failed to comply with cybersecurity directives aimed at securing their cloud environments. The audit revealed that 86% of federal civilian executive branch agencies did not meet the June 2025 deadline for implementing the Cybersecurity and Infrastructure Security Agency's (CISA) Secure Cloud Business Applications (SCuBA) directives. This widespread non-compliance leaves federal cloud infrastructure exposed to preventable cyberattacks.
The SCuBA project, established in the wake of the 2022 SolarWinds attack, provides essential secure configuration baselines, settings, and assessment tools designed to mitigate risks in cloud business applications. CISA issued a directive in December 2024, mandating agencies align with SCuBA requirements by June 2025. However, the Inspector General's investigation, which examined compliance as of February 2026, found that 88 out of 102 agencies surveyed had not implemented all mandatory SCuBA policies.
Examples of non-compliance cited in the report include critical security measures such as blocking outdated authentication methods, enforcing multi-factor authentication (MFA), and implementing policies to protect sensitive and personally identifiable information (PII). The failure to adopt these fundamental security baselines directly undermines the effectiveness of cloud business applications and increases their susceptibility to known vulnerabilities and threats.
Compounding the issue, the Inspector General highlighted a significant deficiency in CISA's enforcement capabilities. The report states that CISA "lacks the authority necessary to require full and timely implementation of Binding Operational Directives (BODs)." This lack of enforcement power means that agencies can fall behind on critical security updates without facing direct repercussions, thereby weakening the overall federal cloud security posture.
The IG's findings indicate that compliance did not improve between the initial deadline and February 2026, with 76% of agencies still not fully compliant. The report explicitly warns that "without defined enforcement oversight of SCuBA policy compliance, the Federal cloud security posture across the Federal enterprise is weakened." This persistent non-compliance creates a broader attack surface for adversaries targeting federal systems.
The report underscores the direct link between the missed deadlines and increased security risks. When agencies fail to adopt required configurations or meet implementation timelines, their cloud environments remain vulnerable to threats that could have been mitigated. The Inspector General concluded that these exposures "undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat."
CISA has not yet publicly responded to the findings of the Inspector General's report. The agency did not immediately provide a comment when contacted by CyberScoop. The widespread failure to implement basic cloud security measures, coupled with CISA's limited enforcement authority, presents a significant challenge to the federal government's efforts to secure its digital infrastructure against an evolving threat landscape.