The first list of weaknesses was not the final status
A September 21 federal audit identified outdated cybersecurity references in four of eight selected Federal Aviation Administration systems. But three of those four were corrected after the review, and an overdue annual assessment was completed. Reporting only the initial counts would erase corrective work that the auditors documented.
What’s the Scoop With Broach compared the initial findings, subsequent-action paragraph and final recommendations in GAO-26-108439. The resulting record shows that 75% of the identified outdated-reference cases were corrected during the review process, while a different and broader issue remained: seven of the eight systems needed formal risk assessments tailored to their specific threats.
| Issue | Initial finding | Documented subsequent action | Remaining scope in the report |
|---|---|---|---|
| Outdated NIST references | 4 systems | 3 updated | 1 system |
| Overdue annual security assessment | 1 system, last completed in 2023 | Assessment completed | Identified overdue assessment addressed |
| System-specific risk-assessment reports | 7 of 8 systems lacked them | General assessment cited by FAA | Formal tailored reports recommended for 7 |
| Inconsistent impact classification | 1 system | No resolution documented | Review and correction recommended |
A general assessment did not answer system-specific questions
FAA officials pointed to a general risk assessment covering threats, likelihood and impacts. GAO found that the document did not provide the system-specific analysis needed for seven selected National Airspace System systems. Its first recommendation calls for formal reports addressing their particular risks, including spectrum attacks, spoofing and jamming.
That distinction limits the finding. The records do not establish that FAA had conducted no risk analysis at all. They establish a gap between a general assessment and documentation tailored to individual systems. The eight systems were selected for this review, so seven of eight—87.5%—is not an estimate of the share of every FAA system lacking such reports.
Missing entries in a plan are not proof every protection is absent
GAO also found that five systems’ security plans did not include all required baseline controls for high-impact systems. Its explanation says the plans did not fully reflect implemented high-baseline controls, including areas such as contingency planning and denial-of-service protection. That is a documentation inconsistency; treating it as proof that five systems had no such protections would overstate the evidence.
For another system, some documents classified its impact as high while others said moderate. Because classification informs the required security baseline, GAO recommended reviewing the categorization and aligning the records. These groups can overlap. The newsroom does not add four outdated-reference cases, five incomplete plans and one classification case into a count of ten separate affected systems.
The agency agreed to recommendations, but agreement is not closure
The Department of Transportation, FAA’s parent agency, concurred with all nine recommendations. It told GAO that it was strengthening its risk-assessment process, expanding aviation-community outreach and continuing work with industry and government partners. GAO’s public recommendation tracker still listed all nine as open when checked October 3.
Open recommendations do not undo the corrections already documented in the report. Conversely, updating a standards reference or completing one annual assessment does not automatically resolve the separate recommendations on system-specific risks, monitoring, information sharing or aircraft-communications protections.
Method: distinguish repaired records from unresolved assessments
This original public-document analysis reconciles three parts of the audit that can otherwise be read as separate lists: the initial system findings, the paragraph describing FAA’s subsequent corrections, and the final recommendations. It retains their different units and dates and calculates the three-of-four correction share. The report is a September 2026 audit, not a live penetration test.
The records support accountability for incomplete risk documentation and remaining oversight work. They do not establish a successful cyberattack, a crash caused by these weaknesses or an October 3 service outage. No systems were accessed or tested by this publication, and agency statements here are attributed to the response reproduced by GAO.
Sources and further reading
GAO-26-108439, September 21, 2026; status checked October 3 ↗
