VA Struggles with FISMA Compliance Amid Cybersecurity Upgrade Plans

    The VA's FY 2025 FISMA audit revealed significant cybersecurity deficiencies, despite the agency's push for improvements. Procurement professionals should expect a surge in demand for cybersecurity services to address these compliance issues.

    Department of Veterans Affairs, Government Accountability Office, Department of Agriculture

    Key Signals

    • VA failed FY 2025 FISMA audit, identifying major cybersecurity deficiencies.
    • VA outlines multi-year cybersecurity enhancement plan from FY 2026-2029.
    • VA disputes audit findings, citing existing security measures and ongoing improvements.

    "VA continues to face significant challenges in complying with FISMA due to the nature and maturity of its information security program."

    CliftonLarsonAllen LLP

    The Department of Veterans Affairs (VA) has faced scrutiny after failing its fiscal year 2025 Federal Information Security Modernization Act (FISMA) audit, conducted by independent auditor CliftonLarsonAllen LLP (CLA). The deficiencies identified include serious lapses in vulnerability management, incident response, and identity controls, signaling that the VA’s cybersecurity measures may not yet meet federal standards. This unresolved status raises alarms about the effectiveness of the current frameworks in place and underscores the ongoing challenges within the VA’s information security program.

    The comprehensive audit by CLA revealed numerous critical areas needing improvement. Key vulnerabilities include inadequate handling of former account holder access, insufficient background checks on personnel in high-risk positions, outdated software systems, and failures in timely incident recovery. According to CLA, "VA continues to face significant challenges in complying with FISMA due to the nature and maturity of its information security program." This statement reflects a broader perspective on how entrenched issues can impede the agency’s compliance efforts, calling into question the resilience of its cybersecurity infrastructure.

    In defending its position, the VA has expressed disagreement with the findings, attributing this stance to the ongoing advancements in its cybersecurity measures. The Department states that significant strides have been made in enhancing its security posture, invoking the completion of the Cybersecurity Supply Chain Risk Management Strategy and the installation of automated tools for anomaly detection. The VA believes some of the audit's findings do not adequately reflect the effectiveness of its current cybersecurity efforts. This discord introduces a complex dynamic, as the agency grapples with remediation goals for its cybersecurity strategy even while operationalizing its existing improvements.

    For procurement professionals, this controversy brings forth several implications regarding future contracts and the VA's evolving cybersecurity landscape. The agency has outlined ambitious plans from fiscal years 2026 to 2029, which encompass achieving significant milestones like enrolling 100% of enterprise identities into an Identity Governance Administration solution and protecting half of its medical devices through advanced firewall-based isolation strategies. As the VA commits to investing in its IT security improvements, it presents a multitude of opportunities for contractors with expertise in federal cybersecurity frameworks.

    Potential contractors should closely monitor how the VA responds to the audit's findings and the development of future procurements aimed at addressing the highlighted vulnerabilities. The agency's procurement initiatives in the cybersecurity domain are expected to intensify, targeting solutions to bridge the identified compliance gaps. Organizations offering specialized services in the realm of cybersecurity compliance should prepare to engage the VA as it transforms its requirements in response to evolving federal mandates and technological demands. Ultimately, those involved in government contracting should remain vigilant, as this could shift procurement approaches and priorities significantly in the coming months.

    • The VA's FISMA audit for FY 2025 revealed major cybersecurity deficiencies.
    • 19 formal recommendations were made by the independent auditor, most of which the VA disputes.
    • Key areas of concern include vulnerability management and identity controls as identified by CLA.
    • VA aims to enhance cybersecurity with a multi-year improvement plan from FY 2026 to 2029.
    • Procurement professionals should note increasing demand for cybersecurity compliance solutions within the VA.
    • Key goals for the VA include 100% enrollment in identity governance and 50% protection for medical devices.
    • The VA's defense of its actions indicates ongoing investment in cybersecurity despite audit discrepancies.
    • The agency's response suggests adjustments in procurement priorities as it seeks better compliance outcomes.
    • Contractors with expertise in cybersecurity compliance frameworks stand to gain from future VA initiatives.
    • Monitoring the VA's cybersecurity posture will be essential for interested contractors in coming years.

    Agencies

    • Department of Veterans Affairs
    • Government Accountability Office
    • Department of Agriculture

    Vendors

    • CliftonLarsonAllen LLP