IRS Cybersecurity Program Was Not Effective for Fiscal Year 2026, Says Report

Taxes | September 18, 2026

IRS Cybersecurity Program Was Not Effective for Fiscal Year 2026, Says Report

86 percent (6 out of 7) of the sampled information systems had critical vulnerabilities not remediated within 30 days, as required.

Isaac M. O'Bannon

As part of the Federal Information Security Modernization Act of 2014 (FISMA) legislation, the Treasury Inspector General for Tax Administration (TIGTA) is required to perform annual assessments of its agency’s information security programs and practices. The agency recently reported on its assessment of the effectiveness of the IRS’ information security program.

The agency’s cybersecurity program was considered not effective because three functions were not at an acceptable overall maturity level. Specifically, the IDENTIFY, PROTECT, and DETECT function areas were not effective. The remaining three function areas, “GOVERN, RESPOND, and RECOVER were rated effective.” The FISMA reporting metrics scoring methodology defines effective as being at a maturity Level 4, Managed and Measurable, or above.

The full report is available (PDF) on TIGTA’s website. The IRS’s Cybersecurity Program Was Not Effective for Fiscal Year 2026.

In Fiscal Year 2026, TIGTA tested the 20 core reporting metrics, 5 supplemental metrics, and 10 editorial metrics. The editorial metrics provide additional information regarding the effectiveness (whether positive or negative) of the IRS’s Cybersecurity Program areas.

The report found that, while the IRS has made some improvements over last fiscal year’s reported maturity level ratings, the Treasury Inspector General determined that the IRS needs to take further steps to improve its security program deficiencies. “IRS Cybersecurity management needs to fully implement all security program components in compliance with FISMA requirements. “

For example, 86 percent (6 out of 7) of the sampled information systems had critical vulnerabilities not remediated within 30 days, as required. If the IRS does not take steps to mitigate these deficiencies, taxpayer data could be vulnerable to inappropriate and undetected use, modification, or disclosure.

TIGTA said it does not make recommendations as part of its annual FISMA evaluation. It “only reports on the level of performance the IRS achieved using the guidelines for the applicable evaluation period.”

Sign in to get access to this free resource, and all of our whitepapers and reports.

Download this content today!

Register to get free access to this content, as well as newsletters, continuing education, podcasts, and more…

Leave a Reply

Isaac M. O'Bannon

Isaac M. O'Bannon

Managing Editor

Isaac M. O'Bannon is the managing editor and digital content manager for CPA Practice Advisor (www.CPAPracticeAdvisor.com), drawing on two decades of experience covering the areas of professional accounting, taxation, business productivity and consumer technologies. . Prior to CPA Practice Advisor, O'Bannon was a consultant at firms in San Francisco, Denver and Tulsa, serving clients that included Logitech, Polycom, Hilti, Microsoft, the Stanford Research Institute, the University of Oklahoma's College of Engineering and other technology leaders. He is a U.S. Navy groundforces veteran (never a SEAL). Email: isaac.obannon - @ - cpapracticeadvisor.com . Isaac OBannon 2019 Cropped Small Headshot