Governance Risk and Compliance is essential for federal agencies, as annual point-in-time audits no longer provide sufficient real-time visibility. Weeks of evidence gathering, screenshots, spreadsheets, and sign-offs, all aimed at proving a security posture that was accurate months ago and may not be accurate today. Ask most compliance leads what changed on their network since the last assessment, and you get a pause before an honest “I’m not entirely sure.” That pause is the real finding, not whatever number ends up in the report. For the CIOs and ISSOs we work with, that gap between the paper trail and the live network is where audit findings, breaches, and budget fights actually start.
Here is why the pause happens. The Federal Information Security Modernization Act sets the baseline most agencies still operate under: an independent evaluation once a year, reported up through the agency CIO to OMB and Congress. That cadence has not changed in any meaningful way since the last modernization in 2014. A bill to update it has cleared committee in the House and moved through the Senate more than once since 2023, and as of this writing it still has not become law. Among other things, it would codify the federal chief information security officer role and give CISA more explicit authority to respond to breaches on civilian networks, changes most people in this field broadly support. Until it passes, annual is not a bad habit agencies fell into. It is the letter of the law, and it shapes how every GRC framework federal agencies use gets built.
The clearest recent proof of what that cadence misses came out of the IRS this fall. The Treasury Inspector General for Tax Administration rated the IRS’s cybersecurity program not effective for fiscal year 2025, and the reason is worth sitting with. It was not that the IRS failed everywhere. Three function areas, GOVERN, RESPOND, and RECOVER, scored a full 4.0, the “Managed and Measurable” level FISMA treats as effective. The trouble sat in IDENTIFY, PROTECT, and, tellingly, DETECT: the continuous monitoring function itself came in at 3.0, one full level below where it needed to be. Across the board, 68 percent of the metrics tested landed at level 3 or lower. Auditors found three cloud systems missing from the IRS’s own inventory as of May 2025, and 53 systems holding sensitive taxpayer data without audit logs that met the required standard. None of that is really a story about one agency falling short. It is what happens when a program is built to pass a yearly checkpoint rather than stay accurate between checkpoints.
Zoom out and the pattern is not new or isolated. Federal information security has sat on GAO’s High-Risk List since 1997, and GAO has made more than 4,387 cybersecurity-related recommendations since 2010, with 764 of them still open. Cybersecurity has kept that designation longer than almost any other high-risk area GAO tracks, which says less about any one CIO and more about how the incentive structure around annual compliance was built in the first place. Government IT spending runs past $100 billion a year, and most of it keeps legacy systems alive rather than modernizing them. A once-a-year audit cycle was never going to keep pace with that much surface area.
What continuous actually looks like in practice
The Pentagon is the clearest place to watch the alternative take shape. DoD’s own Continuous Authorization Implementation Guide lays out what it calls cATO: real-time coupling between the people who own a system’s requirements and the people building it, instead of a static authorization package that goes stale the day it is signed. Army CIO Leo Garciga described the early results this spring: one pipeline went from supporting two concurrent development efforts to twenty-three, with delivery time dropping from a thirty-to-forty-five-day cycle to roughly a week. The Army is, in Garciga’s own words, on the cusp of full DoD CIO approval to run continuous ATO service-wide. That is not a pilot anymore. It is a production model with real numbers attached, and it is the strongest evidence yet that continuous ATO belongs in the FISMA maturity conversation, not off to the side of it.
The mechanics underneath continuous compliance are less dramatic than the results, and that is the point. NIST’s Risk Management Framework has included a “Monitor” step for years. What is changing in 2026 is the push to automate it through OSCAL, the Open Security Controls Assessment Language, so control status updates as machine-readable data instead of a document someone edits by hand every twelve months. CISA’s Continuous Diagnostics and Mitigation program does similar work at the network layer, feeding a live sensor picture into agency dashboards instead of a point-in-time snapshot. None of this requires new legislation. It requires agencies willing to build the plumbing before the law eventually catches up.
What I’d actually do this quarter
Whatever happens with FISMA modernization on the Hill, it does not touch the exposure your program is carrying right now on a self-assessment or a POA&M that has not been independently checked between annual cycles. That risk is yours to manage on your own timeline, not once a bill finally passes.
If your KRI and KPI reporting is something a person updates from memory before a briefing, rather than something that pulls from live control data, that gap is the highest-value place to start this quarter. We built our Strategy & Governance and Risk Management practices around exactly that shift, moving agencies from a document-heavy A&A cycle toward continuous monitoring and authorization they can actually defend between audits. Talk to us before next year’s audit tells you something your own dashboard should have caught in July.
The ritual I described at the start is not inevitable. It is a design choice, made years ago, when annual was the best anyone could do. It is not the best anyone can do anymore. Governance, risk and compliance in 2026 has the tools to be a living system rather than a fall deadline, and the agencies moving in that direction now will not be writing next year’s version of the IRS report. The same shift is showing up next door in how agencies use AI to keep that evidence current instead of hand-collected once a year, which is really the same governance problem wearing a different label.
Related reading:
Governed AI: Putting Copilot to Work Securely in Government | KSG Strategy & Governance Services | KSG Risk Management Services
Topics: GRC | Continuous ATO | FISMA | Federal IT | Risk Management | Compliance