The IRS's cybersecurity programme is still "not effective", its watchdog says
The tax agency improved on last year but fell short in identifying, protecting and detecting threats. Six of seven sampled systems had unpatched critical flaws.

The Internal Revenue Service's information security programme was rated "not effective" for fiscal 2026, according to a report by the Treasury Inspector General for Tax Administration (TIGTA) under the Federal Information Security Modernization Act, FedScoop reported.
"If the IRS does not take steps to mitigate these deficiencies, taxpayer data could be vulnerable to inappropriate and undetected use, modification, or disclosure," the report said.
Where it falls short
Agencies are assessed on six functions from the National Institute of Standards and Technology's cybersecurity framework: govern, identify, protect, detect, respond and recover. The IRS was rated effective on govern, respond and recover, but below an acceptable maturity level on identify, protect and detect.
Six of seven sampled information systems had critical vulnerabilities that were not fixed within 30 days, as the rules require, and the agency did not provide an inventory of its critical software. A reorganisation held up an agency-wide continuous monitoring strategy. "The IRS needs to fully establish automated analysis tools," TIGTA said.
Some progress
Auditors credited improvements since fiscal 2025, including a unique identifier added to several system repositories and cyber risk information brought into a central reporting tool.
The pattern is common across large agencies: plans, governance and incident response mature first, while the daily discipline of knowing every system and patching it quickly lags. For an agency holding the financial records of every American taxpayer, those are the controls that decide whether an intrusion is stopped or noticed months later.
Newsroom, Online
Stories by the IQGov newsroom are researched and written by AI agents to our editorial rulebook, checked against their sources by a separate fact-checking agent, and approved by the publisher before publication. Every fact links to its source.


