samsearch
    Platform
    01InfluenceShape the requirement before it's on your competitor's radar.
    Signal
    Recompete window opens in 42 days
    Facilities maintenance IDIQ$8.4M
    Forecast
    Agency spend up 18% next FY
    DoD facilitiesQ3 window
    02CaptureFind and qualify the work across every market.
    Federal91%
    Network engineering support — GSA MAS
    GSA541512
    SLED88%
    Custodial services — Fairfax County Public Schools
    K-12561720
    DIBBS79%
    Aircraft hydraulic fitting — DLA Aviation
    DLANSN 5330
    03AnalyzeExtract requirements and build the compliance matrix.
    Compliance matrix
    L.2.1Technical approachVol I
    L.3.4Staffing planVol I
    M.1Past performanceEvaluated
    SOW breakdown
    Requirements extracted38
    Mapped to Section L/M38
    Every extractionCited
    Ask Sammy
    “Do we meet the small business set-aside?”
    04ManageRun the pursuit through to award.
    Pipeline
    QualifyFacilities support · USACE
    CaptureComms upgrade · DLA
    ProposalShipyard dredging · NAVSEA
    PriyaAlex
    This week
    Submit past performance refsThu
    Confirm subK teamingFri
    Upload SF 33Mon
    05RespondDraft and submit your response.
    Drafting · Volume I
    247 words
    RFI response
    CompanyAcme Robotics LLC
    UEIJK4M8…
    Capability narrativeDrafted
    06FinanceGet paid faster on what you win.
    Capital available
    $2.4M against your award
    Facilities maintenance IDIQAwarded
    Partner matched
    LenderFederal Capital Partners
    Draw available$2.4M
    UnderwritingCleared
    The platform
    Influence
    Capture
    Analyze
    Manage
    Respond
    Finance
    One pipeline, six stages, start to award.
    See the whole platform
    Solutions
    By industry
    Tech & softwareSoftware and SaaS companies entering GovCon.Defense contractorsPrimes and subs in the defense industrial base.ConstructionBuilders bidding federal, state, and local work.CybersecuritySecurity vendors pursuing federal mandates.
    By team
    Capture managers & BDPipeline, qualification, and win strategy.Proposal teamsCompliance matrices and proposal drafting.Subcontractors & primesTeaming, subcontracting, and partner fit.
    By company size
    Small businessesSet-aside and small business contractors.EnterpriseLarge contractors running multiple pursuits.ConsultantsAdvisors and capture consultants.
    Browse all industries
    CustomersPricing
    ResourcesNew
    Learn
    AcademyCourses, guides, and playbooks.WebinarsLive sessions and recordings.DocsProduct documentation and setup guides.Implementation planOperational rollout guidance.
    Tools & data
    Free GovCon toolsCalculators, lookups, and more.Gov ExploreContracts, agencies, and NAICS codes.GovCon eventsConferences, training, and set-aside events.
    Latest blogIntroducing the New SamSearch: The Operating System for Government ContractingSamSearch has a new brand, a new site, and a new way of explaining what the platform actually does — the operating system for government contracting, organized around six stages instead of a single search box. Here's what changed and why.Read the post →
    All resources and tools
    Sign inRequest a demo
    Home/News/IRS Cybersecurity Program Declared 'Not Effective' by TIGTA
    federal_newspolicy

    IRS Cybersecurity Program Declared 'Not Effective' by TIGTA

    The IRS's effort to enhance its cybersecurity measures is hindered by ongoing vulnerabilities, according to a recent TIGTA report. This situation presents procurement opportunities for vendors in cybersecurity solutions, as the agency seeks to meet critical compliance and security challenges.

    September 18, 2026Internal Revenue Service, Treasury Inspector General for Tax Administration, National Institute of Standards and Technology

    Key Signals

    • IRS to enhance cybersecurity governance due to ongoing assessment failures
    • Vendors should prepare for increased solicitations from IRS for cybersecurity infrastructure
    • Compliance and risk management firms can leverage IRS's focus on NIST standards

    "The IRS will continue enhancing its governance documentation and program artifacts to improve traceability and transparency."

    — Kaschit Pandya, Chief Information Officer

    The Internal Revenue Service (IRS) is facing significant challenges in improving its cybersecurity posture, as highlighted by the recent report from the Treasury Inspector General for Tax Administration (TIGTA). The report indicates that, despite some advancements, the IRS's cybersecurity program remains classified as "not effective" for the fiscal year 2026. This designation is alarming, as it points to vulnerabilities that could potentially expose sensitive taxpayer data to malicious actors. While IRS leadership, including Chief Information Officer Kaschit Pandya and Commissioner Daniel Werfel, have acknowledged these challenges and are committed to enhancing their cybersecurity framework, the persistent deficiencies raise procurement implications for stakeholders in the GovCon space.

    The TIGTA report assessed the IRS based on the Federal Information Security Modernization Act (FISMA) metrics, which evaluates agencies across six key domains: govern, identify, protect, detect, respond, and recover. The IRS performed adequately in areas such as govern, respond, and recover, earning an effective rating. However, the agency scored poorly in the identify, protect, and detect categories, which are critical for establishing a robust cybersecurity defense. This disparity signifies that while the IRS has made some progress in governance and recovery practices, major gaps still exist in its ability to proactively identify and protect against cyber threats.

    Procurement professionals should view this situation as a clarion call for increased demand within the cybersecurity sector. As the IRS grapples with vulnerabilities that could lead to unauthorized access and misuse of taxpayer information, there is a clear path for contractors and vendors who specialize in providing cybersecurity solutions. The IRS's focus on strengthening its governance documentation and program artifacts highlights an increasing need for vendors skilled in compliance and risk management solutions that align with NIST standards.

    The urgency surrounding this situation is amplified by the acknowledgment from the IRS leadership that further steps are needed to mitigate these security deficiencies. The TIGTA report emphasizes the need for the IRS to fully implement corrective actions and bolster its information security continuous monitoring (ISCM) strategy. This represents an opportunity for cybersecurity firms to engage with the IRS through potential solicitations aimed at modernizing its outdated cybersecurity infrastructure and supporting its remediation efforts. Moreover, organizations that offer consulting and implementation services may find strategic entry points, as the IRS outlines plans to enhance its security measures to safeguard sensitive taxpayer data.

    In response to the report, IRS officials expressed their commitment to ongoing improvements, stating that the agency appreciates the feedback from TIGTA and will take further action based on the findings. Kaschit Pandya, the CIO, noted, "The IRS will continue enhancing its governance documentation and program artifacts to improve traceability and transparency," indicating that the agency is not only aware of its shortcomings but is also prepared to address them through strategic procurement and partnerships with relevant vendors.

    As such, the procurement landscape is expected to evolve significantly as the IRS prioritizes its cybersecurity needs. Vendors should be prepared to offer innovative, NIST-compliant solutions to meet the demands of the IRS and ensure the protection of sensitive taxpayer information. The need for effective cybersecurity tools and services is more pressing than ever, and organizations that can align their offerings with the IRS's immediate requirements are well-positioned to benefit from potential contracts and collaborations.

    • The IRS's cybersecurity program rated "not effective" for FY 2026 by TIGTA.
    • The report emphasizes vulnerabilities that could jeopardize taxpayer data security.
    • The IRS scored effectively in governance, response, and recovery but poorly in identify, protect, and detect.
    • Increased procurement opportunities for vendors specializing in cybersecurity solutions and compliance tools.
    • IRS committed to enhancing governance documentation for better transparency and traceability.
    • Potential solicitations from IRS for modernizing cybersecurity infrastructure and remediation efforts on the horizon.
    • Organizations providing cybersecurity consulting services should prepare to engage with the IRS urgently.

    Overall, the findings from the TIGTA report underscore an urgent procurement landscape in the field of cybersecurity within one of the government's most critical financial agencies.

    Agencies

    • Internal Revenue Service
    • Treasury Inspector General for Tax Administration
    • National Institute of Standards and Technology

    Sources

    • Despite upgrades, IRS cyber program still ‘not effective,’ watchdog says | FedScoopFedScoop · Sep 18
    • IRS Security Program 'Not Effective' In 2026, TIGTA Says - Law360 Tax Authoritylaw360.com · Sep 18
    CybersecurityInformation TechnologyGovCon ProcurementRisk Management
    ← Back to News
    samsearch

    The Complete AI Platform for Government Contracting

    Platform
    • Product
    • Pricing
    • ROI calculator
    • Integrations
    • Changelog
    Solutions
    • Solutions
    • Customers
    • Comparisons
    • Market watch
    Resources
    • Blog
    • Free GovCon tools
    • Glossary
    • Docs
    Company
    • API & partnerships
    • Careers
    • Support
    • Compliance
    • Trust centre
    • Contact
    Recognised & verified
    SOC 2 Type II Compliant, SamSearchAWS Partner - Advanced, SamSearch on AWS MarketplaceGartner Peer Insights Customer First, SamSearch5.0RATED ON G2
    Ask AI about samsearch
    Ask ChatGPTAsk ClaudeAsk Perplexity
    Follow

    © 2026 samsearch. All rights reserved.

    Terms of usePrivacy policy