A federal directive written in response to the SolarWinds breach was supposed to close the cloud security gaps that let that attack happen. Four years later, a government watchdog says most of Washington still has not closed them, and the agency that wrote the rule has no way to make anyone comply.
The Department of Homeland Security’s Office of Inspector General published its findings on September 21, 2026, in report OIG-26-30. The audit examined how well Federal Civilian Executive Branch agencies implemented Binding Operational Directive 25-01, the Cybersecurity and Infrastructure Security Agency’s mandate for securing cloud business applications through its Secure Cloud Business Applications, or SCuBA, project. The verdict: enforcement without authority produces compliance on paper, not in practice.
A mandate built on a breach that already happened
CISA created SCuBA in 2022 after the 2020 SolarWinds attack, in which a compromised software update gave intruders a backdoor into the networks of multiple federal agencies and private companies. The project gives agencies secure configuration baselines and free assessment tools, ScubaGear and ScubaGoggles, to check their cloud tenants against those baselines. On December 17, 2024, CISA turned that guidance into a binding order: BOD 25-01 set three deadlines for FCEB agencies to inventory their cloud tenants, deploy the assessment tools, and implement the mandatory security policies.
The OIG credits CISA with real effort. The agency ran more than 80 engagements with over 1,000 participants, and its assessment tools were downloaded more than 130,000 times. That outreach did not translate into compliance. By the June 20, 2025 deadline, 88 of 102 agencies, or 86 percent, had not implemented all the mandatory SCuBA policies. As of February 2026, 78 agencies, or 76 percent, were still non-compliant.
The baselines that went unimplemented are basic ones
The audit is specific about what “non-compliant” means in practice. Agencies fell short on baseline controls that any enterprise security team would recognize as fundamentals: blocking outdated authentication procedures, enforcing multi-factor authentication, and applying policy to protect sensitive and personally identifiable information. These are not exotic cloud-native controls. They are identity hygiene, the same category of gap that shows up repeatedly in breach postmortems across the private sector.
Why the deadlines slipped at every stage
The failure was not confined to the final policy-implementation deadline. Earlier checkpoints slipped too: 39 percent of agencies missed the February 2025 deadline to report their full inventory of cloud tenants, and 52 percent missed the April 2025 deadline to deploy the SCuBA assessment tools across those tenants. Each missed early deadline made the next one harder to hit, since agencies cannot assess or remediate cloud environments they have not fully inventoried.
The authority gap is the real finding
The OIG’s sharper point is not about any single agency’s slow rollout. It is that CISA has no mechanism to force compliance once a directive is issued. Binding Operational Directives compel action in name, but the Federal Information Security Modernization Act gives CISA the power to develop and oversee policy, not to enforce it. Non-compliance can be escalated to the Office of Management and Budget and folded into annual FISMA reporting, but there is no penalty that attaches to a missed BOD deadline.
“CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives,” the Department of Homeland Security Office of Inspector General wrote in report OIG-26-30, adding that without defined enforcement oversight of SCuBA policy compliance, “the Federal cloud security posture across the Federal enterprise is weakened.”
The report also notes this is not a new problem. In the past 16 years, DHS OIG has published two prior reports flagging the same structural gap in enforcement authority. CISA declined to submit management comments on the new findings, and the OIG made no recommendations, saying the underlying limitation on CISA’s enforcement authority remains a legislative one, not an operational one CISA can fix on its own.
What it means for the security leader
For a CISO inside an FCEB agency, this audit is a mandate to stop waiting on federal enforcement to force the issue internally. A BOD deadline with no penalty attached functions, in practice, as a strong recommendation. Security leaders who have been prioritizing SCuBA implementation against other work on the assumption that a compliance deadline carries consequences should recalibrate: the consequence is a published audit finding, not a funding or operational penalty.
For security leaders outside government, the read-across is about what “mandatory” means when the mandating body cannot enforce. CISA’s patch deadlines for actively exploited vulnerabilities have faced a similar adoption gap, and the pattern recurring in cloud configuration baselines suggests the gap between what CISA can mandate and what it can enforce is systemic, not specific to one directive. Any vendor or integrator selling into the federal space should expect procurement language and audit requirements to tighten around identity hygiene and MFA enforcement specifically, since those are the baselines this audit called out by name as unimplemented.
The fix has to come from outside CISA
The OIG’s own history on this point is instructive: two prior reports over 16 years found the same enforcement gap, and neither produced a legislative fix. Congress, not CISA, controls whether BODs get teeth. Until that changes, the agencies and contractors relying on cloud services to run federal business should treat SCuBA baselines as a checklist they need to self-enforce, the same way security teams have had to self-enforce hardening on the management consoles now being targeted directly by attackers. Waiting for a directive to carry consequences is, at this point, a documented losing strategy.

