The US Government Accountability Office said in a report published September 30, 2026 that most federal civilian agencies have not fully met the Office of Management and Budget's requirements for inventorying networked Internet of Things and operational technology devices. GAO recommended that OMB issue updated cybersecurity guidance for such devices and oversee how agencies implement the requirements.
What GAO found
OMB established networked device requirements in December 2023 and updated them in January 2025, with agencies' initial inventories due by September 2024, according to the report.
As of September 2026, of the 22 civilian Chief Financial Officer (CFO) Act agencies GAO reviewed, 15 had established an inventory, 11 were maintaining their inventories, and 10 had included all required information — such as asset description and software version — for each device. Only seven agencies had fully addressed all three OMB requirements, GAO said.
GAO also said no agencies had reported an IoT cybersecurity waiver. Agencies cited technical and resource constraints and competing priorities among the reasons inventories were not completed or maintained.
The guidance gap
GAO said OMB has yet to issue updated guidance covering fiscal year 2026, which it said leaves agencies without a clear imperative to prioritize implementation of the requirements or a timeline for doing so.
Without inventories, GAO said, agencies may lack awareness of the number and type of connected devices in their systems and be at risk of not protecting those systems from cyberattacks. It added that without updated guidance and oversight, agencies may continue to struggle to apply appropriate security controls to vulnerable systems, potentially compromising highly sensitive data and systems.
OMB did not provide comments on the report, GAO said. The single recommendation is listed as open.
Why the review was done
GAO said the nation's infrastructure relies on information systems, including networked IoT and OT devices that interact with the physical world, such as building maintenance systems and specialized equipment in hospitals and laboratories. It described increasing cybersecurity threats to these devices as an issue on its High Risk List.
As an example of the threat, GAO said that in July 2026 cyber threat actors disrupted operations in the water sector by modifying passwords to disconnect networked programmable logic controllers, a type of OT. It also said emerging technologies such as artificial intelligence can compound the risks facing these technologies and devices.
The IoT Cybersecurity Improvement Act of 2020 includes provisions for OMB and civilian CFO Act agencies to identify and protect networked devices, and for GAO to report every two years on IoT guidance and the waiver process through 2026. GAO said this is the final report in a series of three, and that it compared the 22 agencies' inventory efforts with OMB's requirements and interviewed agency officials.
What to do
- GAO recommends that the Director of OMB issue updated cybersecurity guidance covering requirements for networked IoT and operational technology devices.
- GAO says that guidance should include a clear imperative for agencies to prioritize implementation of the networked device requirements and a timeline for doing so.
- GAO recommends that OMB oversee agencies' implementation of the networked device requirements.
Key facts and where they come from
- Only seven of 22 civilian CFO Act agencies fully addressed all three OMB networked device requirements as of September 2026.
Overall, only seven agencies had fully addressed all three of OMB’s requirements.
- 15 agencies had established an inventory, 11 were maintaining it, and 10 included all required information.
15 had established an inventory, 11 were maintaining their inventories, and 10 had included all required information (such as asset description and software version) for each device
- OMB's requirements were set in December 2023 and updated in January 2025, with initial inventories due by September 2024.
OMB’s networked device requirements, which were established in December 2023 and updated in January 2025. Specifically, agencies’ initial inventories were required to be completed by September 2024.
- No agency has reported an IoT cybersecurity waiver.
Further, no agencies had reported an IoT cybersecurity waiver.
- OMB has not issued guidance covering fiscal year 2026.
OMB has yet to issue updated guidance to agencies that covers fiscal year 2026
- GAO cites a July 2026 water sector incident involving programmable logic controllers.
in July 2026, cyber threat actors disrupted operations in the water sector by modifying passwords to disconnect networked programmable logic controllers, which are a type of OT
- GAO's recommendation to OMB remains open and OMB did not comment.
OMB did not provide comments on this report.
