Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
CISA's Toothless Directives Won't Save Federal CloudCloud Security & Providers
4 min readFor Compliance Officers

CISA's Toothless Directives Won't Save Federal Cloud

When the Cybersecurity and Infrastructure Security Agency (CISA) issues a Binding Operational Directive (BOD), agencies are expected to comply. That's the theory.

However, the Department of Homeland Security (DHS) Inspector General recently revealed that this theory doesn't hold up. Out of 102 federal civilian executive branch agencies, 88, or 86%, failed to implement mandatory SCuBA policies from BOD 25-01 by the June 2025 deadline. By February, compliance hadn't improved; 76% still weren't meeting the requirements.

The compliance community often treats BODs like enforceable regulations. But CISA can issue directives without real enforcement power, a distinction that many program managers overlook.

The Limits of CISA's Authority

The common belief is that BODs carry weight because they're "binding" and issued under CISA's authority. While this isn't incorrect, it creates risky assumptions.

The IG report clearly states: "CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives." CISA can't control budgets, withhold funding, or directly enforce compliance beyond escalating issues to the Office of Management and Budget (OMB) or the White House.

Compare this to other enforcement regimes. Missing a Cybersecurity Maturity Model Certification (CMMC) assessment window means losing contract eligibility under 32 CFR Part 170. Failing a FedRAMP audit results in losing authorization. Violating DFARS 252.204-7012 could lead to False Claims Act liability.

BODs don't carry these consequences. An agency ignoring SCuBA policies might only receive a stern letter in an IG report.

Evidence of Ineffectiveness

The SCuBA project arose after the SolarWinds compromise, which exploited cloud misconfigurations. BOD 25-01 required agencies to block outdated authentication, enforce multifactor authentication, and protect sensitive information in cloud environments.

These controls align with basic NIST SP 800-53 Rev 5 families: IA-2 (Identification and Authentication), AC-17 (Remote Access), and SC-13 (Cryptographic Protection). Agencies using the Risk Management Framework should already have these in place.

Yet, 86% didn't meet the deadline. The IG found compliance with BOD 25-01 hadn't improved months later. Some agencies didn't configure baselines; others missed deadlines entirely.

The IG concluded: "Without defined enforcement oversight of SCuBA policy compliance, the Federal cloud security posture across the Federal enterprise is weakened."

This isn't about staffing or budget. It's about authority. CISA can publish excellent guidance, but without enforcement, it becomes optional.

Practical Steps for Compliance Officers

If you're managing federal cloud deployments, don't treat BODs as hard requirements in your risk register. Consider them strong guidance that may become requirements if adopted by another agency or oversight body.

Map BOD requirements to enforceable controls. SCuBA policies align with NIST SP 800-53 controls you're implementing under FISMA and OMB Circular A-130. Document this alignment. Implementing IA-2(1) for multifactor authentication meets both the Risk Management Framework obligation and the BOD recommendation. The former is enforceable; the latter isn't.

Watch for flow-down mechanisms. BODs often become part of agency-specific policies, OMB memoranda, or Federal Acquisition Regulations System clauses. When this happens, they gain enforcement power. Track policy updates from your agency CIO and contracting officers.

Assume IG scrutiny. Even if CISA can't enforce, inspectors general can expose non-compliance. This DHS IG report publicly names non-compliant agencies. If you're managing a federal system, expect your BOD implementation status to appear in an audit finding eventually. It's not enforcement, but it's pressure.

Prioritize based on real risk, not directive language. SCuBA baselines that block outdated authentication and enforce MFA reduce attack surfaces. Implement them because they're sound security practices, not just because a BOD says so. If you're waiting for enforcement to drive your cloud security posture, you're already behind.

Don't invent compliance where none exists. You can't claim BOD compliance as risk mitigation in your System Security Plan if you haven't implemented the controls. CISA's lack of enforcement doesn't mean assessors will ignore the gap.

The Real Impact of BODs

BODs do matter, just not in the way many think.

They signal priorities. When CISA issues a BOD, it's highlighting where threat intelligence and incident data point. The SCuBA project exists because SolarWinds exploited cloud misconfigurations. That's a real risk pattern, regardless of CISA's enforcement ability.

They create audit trails. Even without direct enforcement, BODs establish a documented standard. If your agency suffers a breach that a BOD could have prevented, it becomes evidence of negligence in investigations. Consider whether you want to explain to Congress why you ignored CISA guidance after an incident.

They influence procurement. Federal acquisition teams increasingly reference CISA directives in contract language. If you're a cloud service provider pursuing federal work, BOD alignment becomes a competitive differentiator, even if not contractually required.

And they sometimes gain enforcement later. The Federal Information Security Modernization Act requires agencies to implement CISA directives. It's slow, but it's a form of enforcement.

The belief that BODs are binding isn't entirely wrong. It's just misunderstood regarding the mechanism. They're binding through political pressure, audit exposure, and eventual policy incorporation, not through direct CISA enforcement.

Build your compliance program accordingly. Implement controls to reduce risk, document implementation because auditors will ask, and stop assuming CISA can force compliance. The agency's role is to publish good guidance. Your role is to implement it, whether enforcement exists or not.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like