Of the 22 civilian Chief Financial Officers (CFO) Act agencies GAO reviewed, 15 had established inventories of networked IoT and OT devices as of September 2026.
Only seven agencies had fully met all three requirements, GAO found.
“Until OMB issues this guidance, agencies will lack appropriate direction on how and when to complete their device inventories,” GAO said.
GAO recommended that OMB issue updated cybersecurity guidance for networked IoT and OT devices and oversee agencies’ compliance with the requirements.
The report is the third and final GAO review required under the IoT Cybersecurity Improvement Act of 2020.