Watchdog: 86% of agencies missed CISA cloud security directive deadline
A DHS inspector general report found that 88 of 102 federal civilian agencies failed to meet the June 2025 deadline for mandatory SCuBA cloud security requirements under BOD 25-01. By February 2026, 76% of agencies were still non-compliant, including on MFA and blocking outdated authentication. The IG said CISA lacks authority to enforce its binding operational directives.
- 88 of 102 agencies (86%) missed the June 2025 BOD 25-01 deadline
- By February 2026, 76% of agencies were still non-compliant
- Missing baselines include MFA and blocking outdated authentication
- IG: CISA lacks authority to enforce its directives
Read next
Security