Federal agencies are leaning on commercial cloud platforms to run mission systems, but several are not watching those environments closely enough to catch control failures or emerging threats. In a report issued June 25, 2026, the Government Accountability Office found that only three of eight reviewed cloud systems had fully implemented continuous monitoring, leaving agencies with what it called a diminished ability to identify and mitigate problems. The findings appear in Cybersecurity: Selected Agencies Need to Better Protect Cloud Data (GAO-26-108443), which examined cloud security practices at the Departments of State, Transportation, and Veterans Affairs, and the Small Business Administration.
Background
Federal agencies have migrated large portions of their data and applications to cloud service providers under the Federal Risk and Authorization Management Program, known as FedRAMP, which sets a baseline of security controls a provider must meet before an agency can put government data on its platform. But an authorization at a point in time is not the same as ongoing assurance. Cloud environments change constantly as providers update software, reconfigure infrastructure, and add services. Continuous monitoring is the discipline that keeps an authorization honest: it requires agencies to track the security state of their systems and the deliverables their providers owe them, so that a control that quietly stops working is caught quickly rather than discovered after a breach.
GAO scoped its review to four agencies and eight cloud systems spread across them. The selection spans civilian mission agencies of varying size and maturity, from a cabinet department like State to a smaller independent agency like SBA, which makes the consistency of the shortfalls notable. The watchdog assessed how well each agency implemented continuous monitoring, whether it had adequate service-level agreements with its providers, and how prepared it was to respond to incidents in cloud environments it does not directly control.
Key Details
The headline number is stark: only three of the eight systems had fully implemented continuous monitoring capabilities. The remaining five fell short, meaning the agencies running them lacked complete, current visibility into whether the security controls protecting their data were operating as intended. GAO found that agencies did not always review the continuous monitoring deliverables their providers furnished, and warned that without robust continuous monitoring, agencies have a diminished ability to identify and mitigate control deficiencies and emerging threats.
Service-level agreements were also uneven. Five of the eight systems had adequate agreements with their cloud providers; the remaining three lacked consistent definitions of performance metrics or enforcement mechanisms. Service-level agreements are the contractual spine of a cloud relationship. They define what the provider must deliver, how performance is measured, and what happens when the provider falls short. When those agreements omit measurable metrics or give the agency no lever to enforce them, the government loses its ability to hold a provider accountable for security obligations it is paying for.
GAO directed 12 recommendations at three of the four agencies it reviewed: State, VA, and SBA. The Department of Transportation received none. The recommendations push the agencies to strengthen continuous monitoring of provider deliverables, tighten cloud security controls, and improve incident response. Taken together, the recommendations describe a single underlying problem. The agencies have stood up cloud systems and obtained authorizations, but they have not built the ongoing oversight machinery that keeps those systems secure as the underlying environments evolve. The gap is not in the initial decision to use the cloud; it is in the day-to-day work of verifying that the cloud keeps doing what it promised.
The report implicates the providers as well as the agencies. FedRAMP-authorized contractors and the cloud service providers behind these systems owe deliverables, including evidence that controls remain effective, that agencies are supposed to receive and review on a continuous basis. When an agency does not monitor those deliverables, a provider's lapse can go unnoticed. GAO's framing makes clear that effective cloud security is a shared responsibility: the agency must demand and examine evidence, and the provider must furnish it on time and in a usable form.
What It Means for Contractors
For companies that sell cloud services to the government, the report is a preview of tougher oversight conversations. Agencies acting on GAO's 12 recommendations will likely sharpen the service-level agreements in their next solicitations and contract modifications, adding the specific performance metrics and enforcement provisions GAO found missing. Vendors should expect prospective customers to ask harder questions about how they deliver continuous-monitoring evidence, how quickly they report incidents, and how they prove that authorized controls remain in place over time. A provider that can document a mature, automated stream of monitoring artifacts will have a competitive edge over one that treats a FedRAMP authorization as a finished product.
Integrators and managed-service providers face a parallel obligation. Where a contractor operates or oversees a cloud system on an agency's behalf, the continuous-monitoring shortfalls GAO identified become the contractor's performance risk. Clear, measurable deliverables in the underlying contract protect both sides: they give the agency the enforcement lever GAO wants to see, and they give the contractor an unambiguous standard to meet rather than an open-ended expectation. Firms bidding on cloud work at State, VA, and SBA in particular should anticipate that these agencies will be implementing corrective actions and will scrutinize monitoring and incident-response commitments closely.
The broader signal is that the government's cloud oversight is maturing from a one-time authorization checkpoint toward sustained, evidence-driven accountability. Contractors who build that expectation into their pricing, staffing, and tooling now will be better positioned as the recommendations ripple across more agencies. Those who do not may find themselves explaining, as these eight systems did, why no one was watching when a control quietly stopped working.