Skip to content

The IRS's cybersecurity programme is still "not effective", its watchdog says

The tax agency improved on last year but fell short in identifying, protecting and detecting threats. Six of seven sampled systems had unpatched critical flaws.

By IQGov Editors

Cybersecurity, Report. 18 September 2026, 3 min read

The Internal Revenue Service building in Washington
Photo: G. Edward Johnson / Wikimedia Commons, CC BY 4.0

The Internal Revenue Service's information security programme was rated "not effective" for fiscal 2026, according to a report by the Treasury Inspector General for Tax Administration (TIGTA) under the Federal Information Security Modernization Act, FedScoop reported.

"If the IRS does not take steps to mitigate these deficiencies, taxpayer data could be vulnerable to inappropriate and undetected use, modification, or disclosure," the report said.

Where it falls short

Agencies are assessed on six functions from the National Institute of Standards and Technology's cybersecurity framework: govern, identify, protect, detect, respond and recover. The IRS was rated effective on govern, respond and recover, but below an acceptable maturity level on identify, protect and detect.

Six of seven sampled information systems had critical vulnerabilities that were not fixed within 30 days, as the rules require, and the agency did not provide an inventory of its critical software. A reorganisation held up an agency-wide continuous monitoring strategy. "The IRS needs to fully establish automated analysis tools," TIGTA said.

Some progress

Auditors credited improvements since fiscal 2025, including a unique identifier added to several system repositories and cyber risk information brought into a central reporting tool.

The pattern is common across large agencies: plans, governance and incident response mature first, while the daily discipline of knowing every system and patching it quickly lags. For an agency holding the financial records of every American taxpayer, those are the controls that decide whether an intrusion is stopped or noticed months later.

IQGov Editors

Newsroom, Online

Stories by the IQGov newsroom are researched and written by AI agents to our editorial rulebook, checked against their sources by a separate fact-checking agent, and approved by the publisher before publication. Every fact links to its source.

Keep reading

More Security

Liked this story? Get the Monday Briefing.

Weekly, free. Unsubscribe with one click.