In December 2024, the Cybersecurity and Infrastructure Security Agency issued a directive with a name that sounds like a threat, Binding Operational Directive 25-01. It ordered the entire Federal Civilian Executive Branch, all 102 agencies under CISA’s cybersecurity umbrella, to lock down their cloud tenants against the kind of misconfiguration that let hackers walk through SolarWinds in 2020 wearing the digital equivalent of a stolen badge. CISA director Jen Easterly said at the time that the directive would help “reduce risk to the federal civilian enterprise.” The word “binding” was doing a lot of work in that sentence, because a new DHS Inspector General report (OIG-26-30, released September 21, 2026) has confirmed what the word never actually meant, which is that CISA can write the rules and cannot make anyone follow them.
The Toolbox Nobody Was Required to Open
To its credit, CISA built the thing it said it would build. Through the Secure Cloud Business Applications project, launched in 2022 in direct response to SolarWinds, the agency produced ScubaGear and ScubaGoggles, free automated tools that scan an agency’s Microsoft 365 or Google Workspace tenant and flag every deviation from a defined security baseline; blocking outdated authentication, enforcing multifactor login, protecting personally identifiable information, the greatest hits of “things a competent IT department should already be doing.” CISA ran more than 80 outreach engagements with over 1,000 participants, put the tools in front of more than 130,000 requesters, and personally walked 17 agencies through implementation. By the OIG’s own account, none of this was phoned in (BOD 25-01, Implementation Guidance).
BOD 25-01 laid out three deadlines. By February 21, 2025, agencies had to hand over a complete inventory of their cloud tenants. By April 25, they had to deploy the assessment tools and start reporting continuously. By June 20, they had to actually implement the mandatory security policies and begin continuous monitoring. Three deadlines, each one a smaller and more specific ask than the last, each one accompanied by a CISA outreach campaign, each one missed by a majority of the government it was written for.
Sixty One, Then Fifty Two, Then Eighty Six
The numbers get worse as the asks get more concrete, which is the part that should bother you. Forty of 102 agencies (39 percent) failed to even name their own cloud tenants by the first deadline, meaning nobody, not CISA, not the agency itself, could verify what needed protecting in the first place. Fifty three agencies (52 percent) had not deployed the assessment tools by the second deadline. By the third and most consequential deadline, the one requiring agencies to actually implement the security policies, 88 of 102 agencies, 86 percent of the entire FCEB, were noncompliant.
Then it stopped improving. As of February 12, 2026, eight months past the original deadline, 78 of 102 agencies, 76 percent, were still not implementing all mandatory SCuBA policies. That is not a rollout lagging behind schedule; that is a rollout that reached its ceiling and stayed there. CISA’s own report acknowledges the specific failures, agencies leaving outdated authentication procedures in place, skipping multifactor authentication, declining to implement protections for sensitive personal data, the exact configurations the SolarWinds postmortem told everyone to fix five years earlier.
A Compulsory Directive With No Compulsion Attached
Here is the part the OIG buried in a single paragraph that should have been the headline. The Federal Information Security Modernization Act of 2014 gives the Secretary of Homeland Security authority to issue these directives; it does not give the Secretary, or CISA, any mechanism to force an agency to obey one. CISA can notify OMB. CISA can log the noncompliance in the annual FISMA metrics cycle. CISA can send its Directives and Policy team to sit down with an agency’s Chief Information Security Officer and ask nicely, again. What CISA cannot do is anything that resembles enforcement in the ordinary English sense of the word, and DHS OIG has now said so in writing three separate times across sixteen years, first in 2009, again in 2010, and now in 2026, joined by a fourth outside voice in GAO-20-133, February 2020, which found that DHS did not consistently validate agencies’ self-reported compliance in the first place.
That last detail matters more than it looks like it should. An enforcement mechanism built on agencies grading their own homework was never going to survive contact with an agency that had a reason not to want a passing grade recorded. The OIG’s own data reliability check in this report found duplicate tenant submissions and mismatched agency counts between systems, discrepancies the OIG says it “reconciled,” which is a generous word for finding out the compliance numbers were built on the same self-certification honor system that produced the compliance failures in the first place.
CISA, for its part, declined to submit management comments on this report. Not a rebuttal, not a clarification, not even the standard bureaucratic paragraph about “ongoing efforts to strengthen” whatever it is agencies say when they have nothing to add. Silence, on the record, in response to a finding that the flagship tool of your flagship post-SolarWinds initiative is being ignored by seven out of ten agencies eighteen months after the deadline.
The Recommendation That Doesn’t Exist
The single strangest sentence in the entire report comes at the end of the highlights page: “This report contains no recommendations.” Not because there is nothing to fix, but because the OIG has apparently concluded there is nothing left to recommend to an agency that already knows it lacks the authority to fix the problem itself. You cannot recommend that CISA enforce compliance, because Congress never gave CISA anything to enforce with. The recommendation, if there is one, has to go to the people who wrote the Federal Information Security Modernization Act of 2014 and left the enforcement clause out, and they are not the ones reading OIG reports.
So the government spent two years building a genuinely useful set of free cybersecurity tools, distributed them to more than 130,000 people, walked federal agencies through installation by hand, and produced a compliance rate that, eight months after the deadline, sits at 24 percent. The tools work. The directive was binding in the sense that a strongly worded letter is binding. Everyone involved did their job except the one entity whose job was to make sure everyone else did theirs, and that entity does not exist, because Congress never built it. The next SolarWinds will not be stopped by a better baseline. It will be stopped, or it will not be, by whichever 24 percent happened to read the memo.
Sources: DHS Office of Inspector General, CISA’s Implementation of Binding Operational Directive 25-01 (OIG-26-30, September 21, 2026); CISA, Binding Operational Directive 25-01: Implementing Secure Practices for Cloud Services; GAO-20-133, Federal Information Security: Agencies Need to Develop and Implement Adequate Policies for Complying with New Requirements (February 2020).
