Cloud Security Baselines are no longer just a technical preference for federal agencies; they are a governance test. Recent federal oversight findings show a repeated pattern: policy expectations exist, but agency implementation has been partial across monitoring, incident response, service-level agreements, and authorization controls. For cloud programs, that gap matters because provider-hosted systems still require agency-side verification, documentation, and enforceable operating requirements.
The case study is useful because it does not point to a single tool failure. It points to a control-management problem across acquisition, security operations, and vendor oversight. Agencies have federal policy, FedRAMP processes, and technical reference material available, yet the evidence in recent GAO work shows that use of these mechanisms has not always produced consistent baseline enforcement.
Cloud Security Baselines Are Still Uneven
Agency Findings From 2026
GAO-26-108443, published on June 17, 2026, reviewed four CFO Act agencies: the Departments of State, Transportation, and Veterans Affairs, along with the Small Business Administration. GAO found that none of the four fully met all three key cloud provider practices it assessed: continuous monitoring, incident response and recovery, and service-level agreements. The report also found that many SLAs lacked defined performance metrics or enforcement mechanisms, according to GAO-26-108443.
That combination is significant. Continuous monitoring is the feedback loop that helps agencies see whether controls remain in place after deployment. Incident response and recovery procedures define how agencies and providers coordinate when failures or security events occur. SLAs define what performance, availability, and accountability terms the provider must meet. If one of these areas is weak, the agency may still operate a cloud service, but its ability to prove control effectiveness is reduced.
Cloud Security Baselines Depend On Measurable Controls
Cloud Security Baselines require more than a documented configuration checklist. The GAO findings indicate that agencies also need measurable performance terms and clear enforcement paths. A baseline that says monitoring should occur is less useful if the agency cannot confirm the monitoring cadence, evaluate alerts, or determine who is accountable for remediation. A baseline that references incident response is incomplete if recovery expectations and provider obligations are not documented in operational terms.
The June 2026 report also stated that federal law and policy already set expectations. It referenced FISMA, FedRAMP policy M-24-15 issued on July 25, 2024, and existing OMB and NIST guidance. The implementation issue was not the absence of federal direction. The problem GAO identified was that agencies often did not ensure cloud service providers complied with those expectations in practice.
| Control Area | Observed Issue In Federal Findings | Operational Implication |
|---|---|---|
| Continuous monitoring | Not fully implemented across the agencies assessed in GAO-26-108443 | Agencies may lack timely evidence that controls remain effective |
| Incident response and recovery | Provider practices were not fully met by the agencies reviewed | Response roles and recovery duties can remain unclear during an event |
| Service-level agreements | Many SLAs lacked defined performance metrics or enforcement mechanisms | Accountability can weaken if service expectations are not measurable |
| FedRAMP authorization | Nine CFO Act agencies reported using cloud services without FedRAMP authorization in the 2024 GAO report | Authorization growth did not eliminate non-authorized use |
The Policy Stack Is Clearer Than Execution
FedRAMP Use Increased But Gaps Remained
GAO-24-106591, released on January 18, 2024, found that the 24 CFO Act agencies increased their use of FedRAMP authorizations by about 60 percent from July 2019 to April 2023. The same report found that nine of those agencies still reported using cloud services that lacked FedRAMP authorization, according to GAO-24-106591.
Those two findings can both be true. Authorization usage can rise while residual gaps remain. For agency leaders, the key lesson is that adoption metrics alone do not confirm that every active cloud service is operating inside the expected authorization model. Inventory quality, procurement controls, contract review, and exception handling all affect whether authorization policy becomes operational practice.
Configuration Templates Need Adoption Discipline
The research record also points to technical baseline material that agencies can use. CISA’s SCuBA program published Microsoft 365 security configuration baselines on October 20, 2022, and agencies have piloted them under the Federal Civilian Executive Branch SCuBA initiative. The Cloud Security Technical Reference Architecture version 2, published around October to November 2023, emphasized continuous monitoring, strong identity and access management, encryption, and machine-readable baselines for agency cloud systems.
These resources address a practical issue: agencies need repeatable configuration evidence. Machine-readable and template-based controls can reduce ambiguity, but they do not implement themselves. Uptake has varied depending on agency risk posture and resources, based on the research provided. That means program maturity still depends on staffing, tooling, ownership, and the agency’s ability to turn recommended settings into maintained configurations.
Procurement And Accountability Limits

SLA Language Without Enforcement Weakens Oversight
Cloud Security Baselines also expose a procurement problem. GAO-26-108443 found that many SLAs lacked defined performance metrics or enforcement mechanisms. Without measurable terms, agencies may have difficulty determining whether a provider met expectations. A contract can contain security language, but if it does not define how performance is measured, how exceptions are handled, and what remedy applies, oversight becomes less precise.
This has a direct effect on technical teams. Security operations staff may need provider data to verify monitoring, investigate alerts, or validate recovery. If those duties are not supported by enforceable service terms, the agency may depend on ad hoc coordination rather than pre-defined evidence flows. That is a governance risk, not just a contracting issue.
Historical Buying Data Limits Risk Visibility
The research also identifies procurement decision limits. In GAO-26-107530, dated June 23, 2026, senior officials from 22 of 24 CFO Act agencies said they rely primarily on historical procurement data when making cloud acquisition decisions. The reported concern is that this reliance can limit forward-looking risk and cost analysis.
For cloud programs, historical spending may show what an agency bought before, but it may not show whether the next workload will require stronger monitoring, more identity controls, different recovery terms, or updated configuration baselines. Cost analysis and security analysis need to meet earlier in the acquisition process. Otherwise, the agency may select services before it has fully defined the evidence required to operate them safely.
- Define required monitoring evidence before awarding or renewing cloud service contracts.
- Require SLAs to include measurable performance terms and clear enforcement mechanisms.
- Track exceptions where cloud services lack FedRAMP authorization or approved baseline alignment.
- Connect procurement planning to incident response, recovery, and configuration management needs.
There is also an administrative burden concern. Agencies already face overlapping cyber reporting and compliance processes, and duplicate reporting can dilute attention from control validation. A related analysis of cybersecurity reporting duplication explains why redundant obligations can create friction for teams that need to focus on evidence quality.
Cloud Security Baselines For Federal Agencies
What Agencies Can Defend With Evidence
The strongest implication from the federal findings is that agencies should treat Cloud Security Baselines as evidence systems, not static documents. A defensible baseline should identify the required setting or practice, the system or provider boundary, the verification method, the review frequency, and the responsible owner. That structure is consistent with the oversight findings because the recurring weaknesses involve proof, accountability, and follow-through.
The May 18, 2023 GAO report cited in the research reviewed 15 cloud systems across the Departments of Agriculture, Homeland Security, Labor, and Treasury. Some agencies fully implemented three or four key practices for most systems, but none fully implemented all six practices. GAO identified 35 recommendations in that report, including areas such as continuous monitoring, SLA definition, and incident response documentation. Those earlier findings help explain why the 2026 findings should not be read as isolated defects.
DOT-specific audit work finalized around mid-2023 also found that many cloud-based systems did not consistently use secure configuration baselines, multifactor authentication, or regular software updates. The same research notes that DOT’s Zero Trust Architecture implementation lacked detailed schedules and migration steps. That case supports a cautious interpretation: federal cloud security depends on both technical controls and execution planning.
For agency executives, inspectors general, and cloud program managers, the actionable point is narrow but important. Cloud programs need inventories that identify authorization status, contracts that define measurable provider obligations, monitoring that produces reviewable evidence, and incident procedures that specify recovery duties. Readers looking to understand infrastructure and security implementation patterns across technology domains may find additional insights on techncoins.net, a related site in the same network.
Cloud Security Baselines will not remove all cloud risk, and the available findings do not prove that every agency or system is equally exposed. They do show that partial implementation has remained a recurring federal issue across multiple reports. The practical standard is therefore not whether a baseline exists on paper, but whether an agency can prove that the baseline is adopted, monitored, enforced, and updated as cloud services change.


