Congress cannot say whether DOGE teams protected sensitive data at six federal agencies, because the agencies would not hand over the records needed to check. The Government Accountability Office reached that conclusion in a report released Tuesday, and it matters to any contractor whose grant, contract, payment or personnel data sits in the systems DOGE staff reached. FedScoop reported that an 18-month audit "yielded few answers" and that GAO rebuked several agencies for withholding information or ignoring requests altogether.
The report, GAO-26-108192, covers the Consumer Financial Protection Bureau, the Department of Education, the National Oceanic and Atmospheric Administration, the Securities and Exchange Commission, the Small Business Administration and the Department of Veterans Affairs. The audit ran from March 2025 to September 2026. Ranking members of several Senate and House committees and five other Democratic lawmakers requested it, according to FedScoop.
What Could GAO Actually Confirm About DOGE Access?
Not much. The watchdog found that DOGE teams had access to more than 23 systems across four of the agencies: CFPB, Education, SEC and NOAA. Those systems include tools for managing contracts, grants, finances and personnel. GAO could not independently establish the full extent of that access or the permission levels attached to it.
The other two agencies gave GAO even less. Per Nextgov, VA declined to provide records or explain why, and SBA left GAO's requests unanswered. Neither agency identified which systems its DOGE team members could reach. SBA and VA also did not engage with GAO on whether DOGE followed agency controls and IT security rules, and FedScoop reported that NOAA did not either.
CFPB gave GAO the most detail. Nextgov reported that CFPB officials said they granted access to 19 systems. One DOGE team member could view, modify and delete information in the bureau's primary human resources system, and three had full access to a Microsoft system used to manage user access. CFPB said DOGE staff did not access systems containing market monitoring, supervision, enforcement or fair lending information, though Nextgov noted the report says two team members had permissions sufficient to grant themselves or others access to those systems. The bureau said they did not do so.
NOAA's account, as Nextgov relayed it, was thinner and more troubling. NOAA said one detailee received permission to create, change and delete internal website content to remove material related to diversity, equity and inclusion. Other detailees got access to contract and grant systems, but GAO could not confirm the complete scope of their permissions.
Both CFPB and SEC reported no DOGE-related security or privacy incidents. Nextgov said GAO lacked the records to verify those assurances. That gap defines the report. An agency saying nothing went wrong is not the same as an agency showing nothing went wrong.
Why Did SEC and NOAA Say GAO Had No Authority?
Two agencies took the most aggressive position. Nextgov reported that SEC and NOAA challenged GAO's authority to conduct the review. NOAA's general counsel told GAO that it did not believe the watchdog had the "necessary statutory authority to conduct an audit at the request of a ranking member of a congressional committee," FedScoop reported.
The other agencies gave different reasons. Education cited litigation and privacy concerns, according to Nextgov. CFPB called the review a "fishing expedition" and said further requests were burdensome. FedScoop reported that CFPB, SEC and Education cited pending litigation or "the nature of the information" for not answering some questions.
GAO rejected those arguments in the report's own words, as quoted by FedScoop:
"GAO has ample statutory authority to both conduct this work and obtain the information in support of Congress."
The report continued, "Despite this clear authority, the agencies did not respond to GAO's requests for the information needed to fully answer the questions posed by members of Congress." It added that the agencies' stated reasons "do not alter or diminish GAO's statutory right of access to this information."
The dispute over ranking-member requests matters beyond this audit. If an agency could decline a GAO review because a minority-party committee member asked for it, the watchdog's reach into any politically contested program would shrink. GAO's report treats the objection as meritless, and FedScoop noted the report also says GAO has routinely obtained this kind of information from these and other agencies on past cybersecurity audits.
The Assurance Gap GAO Says Congress Now Faces
GAO's bottom line is a statement about what it could not do. "Without the ability to examine the requested information, Congress and the public lack assurance that the six reviewed agencies implemented controls needed to ensure DOGE team members appropriately secured information," the GAO said, as FedScoop quoted the report.
This audit follows earlier GAO work on DOGE and Treasury payment systems. Nextgov described an April GAO review that identified failures to follow security procedures, including an instance in which a DOGE employee improperly shared unencrypted information. The new report says Treasury's Bureau of the Fiscal Service had not implemented any of the six recommendations from that review as of September.
Timing adds a wrinkle. Nextgov noted that the executive order creating DOGE set a July 4, 2026, termination date for its temporary organization, but GAO observed that the broader U.S. DOGE Service, a rebrand of the U.S. Digital Service, was not terminated.
FedScoop reported that the SEC declined to comment through a spokesperson and that the other five agencies did not respond to its requests for comment by publication time.
What It Means for Contractors
Contractors and grantees should read this as a data-handling question first and a politics question second. Four of the six agencies reported DOGE teams had access to systems used for contracts, grants, finances and personnel. Depending on what a firm has submitted, such systems could hold vendor banking details, proposal data or personnel information tied to contract staff. GAO could not confirm who could see or change what.
Practical steps follow from the report:
- Ask your contracting officer directly. If you submitted sensitive data to CFPB, Education, NOAA, SEC, SBA or VA since early 2025, ask whether the agency can document who accessed the systems holding it. GAO's findings suggest some agencies could not or would not.
- Review what you put in agency portals. Limit proprietary pricing and personnel detail to what a solicitation or award requires.
- Watch for follow-on oversight. The requesters now have a documented record of agency non-cooperation, which could prompt further congressional action that touches vendors.
- Prepare your own records. If your firm's data is ever the subject of an inquiry, contemporaneous logs of what you submitted, when, and through which system will matter more than an agency's assurance.
- Track the Treasury recommendations. The Fiscal Service had implemented none of six recommendations from GAO's April review of DOGE access to Treasury payment systems as of September. Contractors paid through those systems have a direct interest in whether that changes.
Neither FedScoop nor Nextgov reports that any contractor's data was misused. The finding is narrower and, for procurement, more uncomfortable: GAO could not verify how the access was used and controlled.