A Department of Homeland Security inspector general found that 88 of 102 Federal Civilian Executive Branch agencies failed to fully implement CISA's mandatory Secure Cloud Business Applications (SCuBA) policies by the June 2025 deadline under Binding Operational Directive 25-01. As of February 2026, 78 agencies remained noncompliant, leaving required cloud-security baselines only partially deployed.
The missing measures include blocking legacy authentication methods, enforcing multifactor authentication, and safeguarding sensitive and personally identifiable information. The inspector general warned that the gaps leave federal cloud environments vulnerable to preventable attacks and concluded that CISA lacks sufficient authority to compel agencies to implement Binding Operational Directives completely and on time.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
As of February 2026, 78 of 102 agencies remained noncompliant with SCuBA requirements, including baselines for outdated authentication, multifactor authentication, and protection of sensitive and personally identifiable information.
By the deadline for mandatory SCuBA policies, 88 of 102 federal civilian executive branch agencies, or 86%, had not fully implemented the required controls.
CISA issued Binding Operational Directive 25-01 requiring federal civilian executive branch agencies to align with specified Secure Cloud Business Applications (SCuBA) requirements.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.