Skip to main content

DOGE: Congress and the Public Lack Assurance That Systems and Data Were Protected at Multiple Agencies

GAO-26-108192 Published: Sep 29, 2026. Publicly Released: Sep 29, 2026.
Jump To:

Fast Facts

An executive order required federal agencies to establish Department of Government Efficiency teams to implement the administration's goals.

We reviewed the access 6 agencies' DOGE teams had to information systems and the controls the agencies used to ensure those systems were protected. Of these agencies:

  • 4 gave us information on system access and 2 didn't
  • 3 gave us information on controls and 3 didn't

DOGE teams had access to more than 23 systems at the 4 agencies, but we couldn't determine the extent of it with the information provided. Information on controls was limited, e.g., only covering certain controls, systems, or team members.

 

Screenshot from Department of Government Efficiency Website.

Screenshot from Department of Government Efficiency Website.

Skip to Highlights

Highlights

What GAO Found

Four agencies in GAO’s review—the Consumer Financial Protection Bureau (CFPB), Department of Education, National Oceanic and Atmospheric Administration (NOAA), and Securities and Exchange Commission (SEC)—established Department of Government Efficiency (DOGE) teams and collectively reported that those teams had access to more than 23 systems. These systems were used to manage contracts, grants, human resources, and finances and contained sensitive information, including personally identifiable information (PII). However, whether DOGE team members had specific system permissions or were allowed certain actions (e.g., view PII or modify data) could not be determined based on the information provided. The other two agencies in GAO’s review—Small Business Administration (SBA) and the Department of Veterans Affairs (VA)—did not respond to requests for information to which systems DOGE team members had access to.

CFPB, Education, and SEC provided limited documentation related to the extent to which they implemented controls for ensuring adherence to their IT security rules and their DOGE team members followed the rules. For example,

  • CFPB demonstrated that six DOGE team members received a privacy briefing and four completed security training. Such training is important for ensuring that system users are aware of their responsibilities for addressing cyber and privacy risks. However, the bureau did not provide evidence that the remaining team members completed the necessary training.
  • Education provided IT system rules of behavior documents signed by five of the six DOGE team members. Acknowledgment of these documents is key to holding system users accountable for not following IT security rules. However, the department did not respond to GAO’s repeated requests for the document signed by the remaining team member.
  • SEC demonstrated that a background check was underway for one team member and had been conducted for another team member in 2017. These investigations are important for ensuring that system users can be trusted with sensitive information. However, the agency did not respond to GAO’s requests to confirm that the 2017 investigation was favorably adjudicated.

In addition, NOAA, SBA, and VA did not respond to requests for information on whether they implemented controls for ensuring adherence to the IT security rules and their DOGE team members followed those rules. Without the ability to examine the requested information, Congress and the public lack assurance that the six reviewed agencies implemented controls needed to ensure DOGE team members appropriately secured information.

GAO has ample statutory authority to both conduct this work and obtain the information in support of Congress. Despite this clear authority, the agencies did not respond to GAO’s requests for the information needed to fully answer the questions posed by members of Congress. Agencies cited various reasons for not fully responding to GAO’s requests, but their stated reasons do not alter or diminish GAO’s statutory right of access to this information.

Why GAO Did This Study

The United States DOGE Service (USDS) was created by executive order to maximize government efficiency by modernizing technology. The order also called for the heads of executive branch agencies to establish DOGE teams that work with USDS.

GAO was asked to review efforts to ensure that agency DOGE teams appropriately protected the systems and information they accessed at multiple agencies. The objectives of this review were to (1) describe the systems to which the DOGE teams at six agencies had been provided access and (2) evaluate the extent to which these agencies implemented controls to ensure that the DOGE team followed the agency’s IT security rules and the DOGE team followed those rules.

This report focuses on the following agencies: Education, VA, CFPB, NOAA, SEC, and SBA. GAO analyzed documentation related to DOGE access to agency systems, IT security rules, security and privacy training, and background investigations.

GAO provided a draft of this report to the six agencies for review and comment. Education, NOAA, SBA, SEC, and VA stated that they did not have any comments. CFPB expressed concerns with the accuracy of the report. GAO stands by the accuracy of the facts presented in the report.

For more information, contact Nick Marinos at marinosn@gao.gov.

Full Report

GAO Contacts

Nick Marinos
Managing Director
Information Technology and Cybersecurity

Media Inquiries

Sarah Kaczmarek
Managing Director
Office of Public Affairs

Public Inquiries

Topics

Information securityCybersecurityPrivacyGovernment efficiencyPersonally identifiable informationGovernment auditing standardsEmployment statusInformation systemsPolicies and proceduresFederal agencies