A maintained list can still omit the information needed to assess protection

Does maintaining an inventory of government-connected devices mean the inventory tells officials how those devices are protected? At four federal agencies, the answer in a newly released audit is no. What’s the Scoop With Broach matched the maintenance ratings in table 1 of GAO’s September 30 report with the eight information categories in table 5. Energy, Transportation, the Nuclear Regulatory Commission and the Small Business Administration all received full credit for maintaining their inventories, but none received credit for including the required security-controls information.

Those four represent 36.4% of the eleven agencies that met the maintenance test. They are also every agency in that eleven-agency group whose inventory information was incomplete. The original comparison isolates a common gap that an inventory-exists or inventory-maintained headline would conceal: keeping the list current and documenting its devices’ protections were separate requirements, and performance on one did not establish performance on the other.

The finding concerns records. GAO’s rating means an agency did not provide evidence that its inventory addressed that information requirement. It does not establish that every device lacked passwords, encryption, physical protection or other safeguards, and it does not demonstrate a successful attack. The audit’s assessment is a September 2026 snapshot, not an independent inspection of agency systems on October 5.

Our cross-match of GAO tables 1 and 5; September 2026 status
AgencyMaintenanceSecurity-controls informationSoftware/firmware informationNetwork/API information
EnergyFully addressedNot addressedNot addressedNot addressed
TransportationFully addressedNot addressedNot addressedNot addressed
Nuclear Regulatory CommissionFully addressedNot addressedNot addressedNot addressed
Small Business AdministrationFully addressedNot addressedFully addressedPartially addressed
Sources: GAO, tables 1 and 5 and rating definitions

What the missing category was supposed to contain

The underlying January 15, 2025 OMB memorandum requires an updated, enterprise-wide inventory of networked Internet of Things and operational-technology assets. These include sensors, controllers and building-management equipment that connect computing to the physical world. The memorandum asks agencies to record eight kinds of information, including ownership, manufacturer, installed software, network connections and security controls.

For the security-controls category, OMB specifically calls for descriptions of physical and technological safeguards. Its examples include account permissions, encryption for stored and transmitted data, physical controls and authentication methods. The adjacent software category covers installed versions and patches; the network category covers connection details, integrations and application programming interfaces. Energy, Transportation and NRC lacked fully addressed information in all three of those adjoining categories. SBA had software information and partially addressed network information, an important difference that disappears if all four are called equally incomplete.

OMB permits inventories built around other accepted standards, but only if they contain the required data points. The requirement therefore concerns the information available to decision-makers rather than the purchase of a particular inventory product. OMB’s memorandum describes inventories as a prerequisite for locating vulnerabilities, prioritizing mitigation and monitoring abnormal activity. An inventory can identify a device without yet supplying those additional details.

Sources: OMB M-25-04, IoT and OT Inventory requirements, pages 7–8

The explanations differ across the four agencies

Energy officials told GAO that inventory information was removed in fiscal 2025 because the data were not meaningful or were sensitive. The department’s inventory fully included four categories, partially included one and omitted three. That explanation is part of the record; it is not evidence that the information was publicly exposed. These are agency inventories, and the obligation to maintain information does not mean publishing sensitive device details on an open website.

Transportation fully included two categories, partially included one and omitted five. Its officials told GAO they were working toward full compliance but supplied no completion timeline. NRC fully included two, partially included three and omitted three; its officials described additional tools being implemented without providing a timeline. SBA had the same two-full, three-partial, three-not-addressed distribution as NRC, although the actual categories differed. SBA officials also did not provide a completion timeline.

The maintenance rating itself has a defined evidentiary basis: GAO examined agency plans and procedures for maintaining inventories. It should not be read as this publication observing every update or testing whether each individual device record was current. The report’s discussion of discovery tools also supplies counterevidence against treating inventory work as mechanically simple. NASA officials described difficulty distinguishing ordinary IT from IoT and operational technology, and warned that active discovery queries can disrupt sensitive systems. NASA nevertheless met all three of GAO’s overall inventory tests.

Eight established inventories still failed at least one remaining test

A second reconciliation shows why counting only completed initial inventories overstates the result. Fifteen of the 22 reviewed agencies had established inventories. Seven met both the maintenance and complete-information requirements. Four met maintenance but not complete information; three had complete information but did not fully meet maintenance; and Treasury fully met neither of those two remaining tests. The categories sum to fifteen, leaving eight established inventories with at least one outstanding requirement.

Commerce, Justice and Social Security made up the three with complete information but incomplete maintenance. Treasury’s initial inventory lacked all eight required information categories, and its maintenance plans were still being documented. The seven agencies meeting all three tests were Education, Homeland Security, State, EPA, GSA, NASA and OPM. The other seven reviewed agencies had not established initial inventories.

GAO credited substantial progress since its 2024 review. Comparisons need a qualification: the earlier review covered 23 agencies, while this one covered 22 because USAID could not supply timely information after a substantial personnel reduction. Neither the missing USAID response nor the inventory deficiencies establish a count of compromised systems.

Oversight and the limits of this examination

GAO recommended that OMB issue updated networked-device guidance with a clear implementation priority and timetable, and oversee compliance. The report says OMB had not supplied updated guidance covering fiscal 2026 or overseen implementation within an established time frame. OMB did not comment on the draft. Commerce, DHS, NASA and OPM supplied technical comments, which GAO incorporated as appropriate; the other eighteen reviewed agencies said they had no comments on the draft. Their lack of draft comments does not erase the explanations provided during the audit.

This investigation is public-document analysis. We cross-classified all 22 agency rows in GAO’s table 1, checked the four maintained-but-incomplete inventories against the individual fields in table 5, and read the actual OMB inventory instructions. The percentage is four divided by eleven. We preserve GAO’s full, partial and not-addressed distinctions rather than treating a partial rating as zero activity. The work identifies a shared documentation weakness and the agencies responsible for it; it does not measure the effectiveness of their safeguards or establish that the September ratings remain unchanged today. No interviews or system testing by Billy Roach are claimed.

Sources and further reading

GAO-26-108937, September 30, 2026, full report and agency responses ↗

OMB M-25-04, January 15, 2025, pages 7–8: required inventory information ↗

NIST photograph reuse policy ↗