Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices
SCALE
- 22 civilian agencies reviewed; as of September 2026, 15 inventories established, 11 maintained, 10 complete, seven agencies fully compliant
- eight categories of information required for every networked device, from asset description to software version and security controls
- no device waiver reported by any of the 22 agencies
COMPLIANCE
- a 2020 federal statute on the cybersecurity of networked devices, with a procurement prohibition and a waiver route
- budget-office memoranda setting the inventory requirement, its content and its September 2024 deadline
- federal information-security legislation and the binding operational directives issued under it
ECONOMY
- resource constraints cited as a reason inventories stay incomplete
- asset-management software bought but not yet deployed
- the inventory requirement set against competing mission priorities
EFFICIENCY
- pace of inventory work since the September 2024 deadline
- the procurement rule proposed in 2023 and still in comment resolution
- asset-discovery tools, and what they can and cannot see
EFFECTIVENESS
- completeness of inventories against the eight required categories
- central guidance and oversight of implementation
- use made of the waiver route the statute created
1. A deadline two years past, and a third of the organisations have met it
Goal-setting Target Policy implementation Monitoring
The requirement is not new and the date is not in dispute: inventories were 'established in December 2023 and updated in January 2025' and 'agencies' initial inventories were required to be completed by September 2024' (Highlights). Progress since the previous audit is real - 'from December 2024 to September 2026, the number of agencies that had established inventories increased from three to 15' (p.21) - but the finish line is still distant: 'As of September 2026, of the 22 CFO Act agencies, seven agencies had fully addressed all three of OMB's requirements--establishing inventories, maintaining inventories, and including all required information in their inventories' (p.23). The report states the gap in plain arithmetic: 'as of September 2026, seven of the 22 agencies had not yet established initial device inventories which were due almost 2 years ago (in September 2024), four agencies with complete inventories were not properly maintaining their repositories, and five agencies had not included all of the OMB-required information in their inventories' (p.29). The pattern is a requirement with a date attached and nothing attached to the date.
- Function: Security, Governance
- Value: Regulatory system
- Stakeholders: Policy setter, Management
- Quality: Clear objectives and goal-setting Functioning oversight and governance
2. An inventory is built once and then left to go stale
Data management Data governance Monitoring Activity tracking Procedures
Building the list turns out to be easier than keeping it: 'As of September 2026, of the 15 CFO Act agencies that had established initial inventories 11 were maintaining their inventories, three agencies were in the process of developing a plan to maintain their inventories, and one did not have a plan to maintain its inventory' (p.22). The reasons given are the ordinary ones. One department 'established its initial inventory in 2024, which included all OMB-required information. However, officials stated that individual components were responsible for maintaining their inventories. The department was also not maintaining its inventory across the entire enterprise on a recurring basis' (p.24). Another had an inventory complete on the day it was made but 'was not maintaining its inventory on a recurring basis. Officials stated that this was due to significant staffing turnover and resource constraints over the last year' (p.24). A device inventory is worth what its last update is worth; the report ties the point to the purpose - 'updated inventories enable agencies to monitor and detect unauthorized, abnormal, or potentially malicious activities' (p.27).
- Function: IT, Security
- Value: Assets, Human capital
- Stakeholders: Management, Operator
- Quality: Reliable, integrated information base Adequate resources and competences
3. The list exists but holds little of what it was required to hold
Data management Data governance Documentation Reporting
Eight categories of information were required for each device - identification, description, categorisation, system owner, vendor, software and firmware versions, network connectivity, security controls (p.19). Counting the entries rather than the inventories gives a different picture: of the 15 agencies with inventories, '10 had included all the required information, four agencies had included some of the required information, and one agency had not included any of the required information' (p.23). The examples show how far 'some' can reach. One department's inventory 'only included two of the eight required categories of information, partially included one, and did not include the remaining five', and officials 'did not have a timeline' for fixing it (p.25). Another had established an inventory that 'did not include any of the OMB-required information' (p.25). At a third, 'inventory information was removed in fiscal year 2025 due to the lack of meaningful data or sensitivity' (p.24) - a record emptied by decision rather than by neglect.
- Function: IT, Regulations
- Value: Assets
- Stakeholders: Management, Oversight
- Quality: Reliable, integrated information base Clear objectives and goal-setting
4. The body that set the requirement stopped issuing guidance and stopped answering
Guidance Goal-setting Monitoring Responsibility Accountability
The requirement came from a series of annual memoranda, and the series stops: 'OMB has not issued an updated memorandum on networked device cybersecurity for fiscal year 2026' (p.15). Asked about it, the office said nothing - 'OMB did not respond to our February and June 2026 requests for updated information on the status of its guidance' (p.15, note 47), and again, 'OMB did not respond to our February and June 2026 requests for updated information on the status of its guidance and agencies' implementation of the requirements' (p.27, note 64). Nor was implementation watched: 'OMB did not oversee the implementation of its requirements regarding establishing and maintaining inventories of networked IoT and OT devices within an established time frame' (p.27). The auditors draw the consequence for the agencies below: 'In the absence of such guidance, agencies are left without a clear imperative to prioritize implementation of the requirements or a timeline for doing so' (p.27). The single recommendation of the report is addressed here, not to the agencies (p.29).
- Function: Governance, Regulations, Strategy
- Value: Regulatory system
- Stakeholders: Policy setter, Oversight
- Quality: Functioning oversight and governance Clear objectives and goal-setting
5. A waiver route built into the statute that nobody has used
Procedures Policy implementation Documentation Access
The law forbids an agency to buy or use a device that cannot meet the national standards, and lets the head of the agency waive the prohibition on one of three grounds - national security, research, or the device being 'secured using alternative and effective methods appropriate to its function' (p.10). A standardised process for this was built and published in January 2025, with the waiver limited to two years and documented in system security plans and contract files (p.28). The use made of it: 'none of the 22 agencies in our review reported such a waiver. While one agency--HHS--reported a waiver in 2024, the agency subsequently removed those IoT devices from the system in question. As a result, that waiver is no longer relevant' (p.28). An earlier recommendation that the central office verify agency-reported waivers is still open (p.28). A control that is never exercised yields no evidence about whether the prohibition behind it is being observed.
- Function: Regulations, Product/service purchase
- Value: Regulatory system
- Stakeholders: Lawmaker, Oversight, Management
- Quality: Functioning oversight and governance Streamlined, standardized processes
6. The devices to be counted cannot reliably be told apart by the tools that count them
Data management Data governance Monitoring Access
Agencies were asked to inventory a class of device that the available tooling does not cleanly recognise. Officials at one agency that had completed its inventory 'noted that, in their experience, there are no asset discovery tools that have a reliable way of distinguishing between IT, IoT, and OT. They noted that this is due to the overlapping nature of technology and definitions' (p.26). Scanning harder is not a free option: 'there are challenges with tools that use active queries against devices for asset discovery, which can disrupt or disable some sensitive systems' (pp.26-27). The size of the blind spot shows when the tooling changes - at one department 'the agency's new hardware asset management system identified over 160 IoT devices that were not reported by its legacy system' (p.26). The definitions themselves moved under the agencies as well: the 2023 memorandum introduced 'covered IoT', and in January 2025 that phrase was dropped and agencies were directed to inventory both networked IoT and OT devices (p.4, note 15).
- Function: IT, Infrastructure
- Value: Assets, Domain knowledge
- Stakeholders: Operator, Supplier, Management
- Quality: Appropriate use of technology and automation Reliable, integrated information base
7. The procurement rule that would carry the statute into contracts is still a draft
Procedures Policy implementation Guidance Design
The statute's prohibition reaches a buyer through the procurement regulation, and that step has not been taken. 'In October 2023, the FAR Council published a proposed rule in the Federal Register that would require contracts for the management of a federal information system to specify any cybersecurity requirements necessary for IoT devices in accordance with NIST SP 800-213. The proposed rule would also implement the IoT Cybersecurity Improvement Act of 2020's prohibition on agencies' acquisition of an IoT device determined to be non-compliant with NIST standards and guidelines, absent a waiver by the agency head' (p.17). Comments closed almost two years before the audit: 'Public responses to the initial rule were submitted to the FAR Council in December 2024. However, as of July 2026, acquisition program staff members continue to address comments on the proposed rule' (p.17). Meanwhile the technical guidance the rule would point to is itself being rewritten, with a first draft of the revised publication issued in June 2026 (p.12, note 31).
- Function: Regulations, Product/service purchase, Planning
- Value: Regulatory system
- Stakeholders: Lawmaker, Policy setter, Supplier
- Quality: Streamlined, standardized processes Clear objectives and goal-setting
Control focus
| ICS phase | Control function | Cases |
|---|---|---|
| Initial phase | Goal-setting | 1. A deadline two years past, and a third of the organisations have met it<br/>4. The body that set the requirement stopped issuing guidance and stopped answering |
| Guidance | 4. The body that set the requirement stopped issuing guidance and stopped answering<br/>7. The procurement rule that would carry the statute into contracts is still a draft | |
| Responsibility | 4. The body that set the requirement stopped issuing guidance and stopped answering | |
| Design | 7. The procurement rule that would carry the statute into contracts is still a draft | |
| Goal-setting | Target | 1. A deadline two years past, and a third of the organisations have met it |
| Procedures | Policy implementation | 1. A deadline two years past, and a third of the organisations have met it<br/>5. A waiver route built into the statute that nobody has used<br/>7. The procurement rule that would carry the statute into contracts is still a draft |
| Work processes | Monitoring | 1. A deadline two years past, and a third of the organisations have met it<br/>2. An inventory is built once and then left to go stale<br/>4. The body that set the requirement stopped issuing guidance and stopped answering<br/>6. The devices to be counted cannot reliably be told apart by the tools that count them |
| Procedures | 2. An inventory is built once and then left to go stale<br/>5. A waiver route built into the statute that nobody has used<br/>7. The procurement rule that would carry the statute into contracts is still a draft | |
| Organic elements of a process | Data management | 2. An inventory is built once and then left to go stale<br/>3. The list exists but holds little of what it was required to hold<br/>6. The devices to be counted cannot reliably be told apart by the tools that count them |
| Access | 5. A waiver route built into the statute that nobody has used<br/>6. The devices to be counted cannot reliably be told apart by the tools that count them | |
| Data management | Data governance | 2. An inventory is built once and then left to go stale<br/>3. The list exists but holds little of what it was required to hold<br/>6. The devices to be counted cannot reliably be told apart by the tools that count them |
| Monitoring | Activity tracking | 2. An inventory is built once and then left to go stale |
| Functions applied to all stages | Documentation | 3. The list exists but holds little of what it was required to hold<br/>5. A waiver route built into the statute that nobody has used |
| Reporting | 3. The list exists but holds little of what it was required to hold | |
| Responsibility | Accountability | 4. The body that set the requirement stopped issuing guidance and stopped answering |