Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found.
The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat,” and “CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives,” or BODs.
The latter is a question that has surfaced before about CISA directives, which the agency uses to pressure agencies into improving their cyber defenses.
The IG took a look at the Secure Cloud Business Applications (SCuBA) project, created in response to the 2022 SolarWinds attack. It provides secure configuration baselines, settings and assessment tools to help agencies reduce the risk of breaches.
A December 2024 directive gave agencies a list of requirements to align with SCuBA, with a deadline of June 2025.
The IG found that 88 of 102 agencies, or 86%, didn’t implement all the mandatory SCuBA policies from BOD 25-01. As of February of this year, “compliance with BOD 25-01 had not improved. A total of 78 out of 102 (76%) [Federal Civilian Executive Branch] agencies were still not in compliance with implementing all mandatory SCuBA policies.”
“Some examples of baselines that FCEB agencies did not implement included blocking outdated authentication procedures, enforcing multifactor authentication, and implementing a policy to protect sensitive and personally identifiable information,” the IG report states. “Implementation of these baselines could mitigate vulnerabilities and threats from affecting the cloud business applications.”
That’s the result of CISA’s lack of power to enforce its BODs, which translates into greater risk, the IG concluded.
“Without defined enforcement oversight of SCuBA policy compliance, the Federal cloud security posture across the Federal enterprise is weakened,” the report states. “When agencies do not adopt required configurations or meet implementation deadlines, their cloud environments remain exposed to preventable threats.”
CISA didn’t respond to the report, according to the IG.
The agency didn’t immediately respond to a request for comment from CyberScoop.

