BlackLeafwatch the watchmen
Aviation cybersecurity oversight (FAA and TSA)

TSA's Cybersecurity Roadmap Is Still From 2018, GAO Finds

Summary

A July 16, 2026 audit from the Government Accountability Office -- Congress's own independent auditor -- found that the Federal Aviation Administration clearly defined who at the agency is responsible for aviation cybersecurity, while the Transportation Security Administration did not: TSA's governing document is still its 2018 Cybersecurity Roadmap, which its own internal plan said should have been updated by 2026 and hasn't been. Separately, GAO found FAA left one of its own cybersecurity programs -- $16.9 million across fiscal years 2024 through 2026 -- off the spending reports it owes the Office of Management and Budget every year.

By Nero · July 16, 2026

GAO -- the Government Accountability Office, Congress's own independent, nonpartisan auditor, whose recommendations agencies are expected to answer -- examined how and manage cybersecurity across the interconnected systems that keep aircraft flying safely, from onboard avionics to air traffic control on the ground. passed the first test: its Cybersecurity Strategy names which of its seven internal entities owns which piece of the job. did not. 's answer to "who's responsible" is still a 2018 roadmap that predates the current Department of Homeland Security Cybersecurity Strategy it's supposed to align with, and that doesn't name a single office as accountable for carrying it out.

TSA's plan is eight years old -- and its own deadline to fix that was this year

's 2018 Cybersecurity Roadmap lays out goals for prioritizing cybersecurity inside the agency and across the wider transportation sector. What it does not do, found, is describe 's role in overseeing the cybersecurity of airport and aircraft-operator security programs, or say which offices are supposed to carry any of it out. That matters mechanically, not just as a paperwork gap: without a document that assigns the work to a named office, cannot hold anyone accountable for doing it, and outside reviewers -- Congress, , the airlines and manufacturers regulates -- have no baseline to check 's cybersecurity effort against.

The 2018 roadmap isn't merely aging by neglect. 's own internal planning document, the Administrator's Intent 3.0, set the standard: 's roadmaps -- cybersecurity included -- were supposed to be updated sometime between 2018 and 2026. That window closes this year, and 's July 2026 review found the update still hadn't happened. 's fix is recommendation one of five in the report: 's Administrator should update the roadmap to name responsible offices, align it with 's current strategy, and communicate the revised plan to outside stakeholders. DHS agreed and set an estimated completion date of May 31, 2027 -- nearly a year after the audit's release -- tying the fix to a broader realignment of 's roadmap with 's Cybersecurity Strategy and the White House's 'Cyberstrategy for America,' released in March 2026.

The confusion has reached the industry regulates. Of 11 aviation stakeholders interviewed -- manufacturers, airlines, and industry groups -- three said they struggled to understand what 's role in aviation cybersecurity actually is. One airline told it felt lacked the resources, authority, and expertise to properly regulate cybersecurity in the first place. Some of that confusion traces to 's March 2023 Joint Emergency Amendment, which added cybersecurity requirements to airport and aircraft-operator security programs; stakeholders said they assumed such requirements would come from , not , until the 2024 Reauthorization Act clarified that -- not -- has exclusive authority to regulate the cybersecurity of civil aircraft itself.

Unreported cybersecurity spending
$16.9M
FAA's Information Security/Cybersecurity Program's FY2024-26 budget requests -- left out of the agency's OMB cyber-spending reports in all three years
TSA's cybersecurity roadmap
8 years old
Written in 2018; TSA's own plan said it would be updated by 2026 -- GAO's July 2026 audit found it still hadn't been
FAA's own strategy, self-graded
3 of 7
Objectives FAA fully implemented toward its Cybersecurity Strategy's network-defense goal -- and only 1 of 7 entities showed the monitoring the strategy itself required
Three separate "out of seven" shortfalls in FAA's own cybersecurity strategy
How much of its own cybersecurity plan FAA had actually completed, per GAO's review as of February 2026
NIST zero-trust practices fully aligned
3
Strategy objectives fully implemented
3
Entities that showed required monitoring
1
Source: GAO-26-107693, pp.38-41
View data as table
FAA's Zero Trust Implementation Plan fully aligned with 3 of the 7 NIST practices for migrating to a zero-trust architecture. FAA fully implemented 3 of the 7 objectives supporting its Cybersecurity Strategy's protect-and-defend goal. And only 1 of the 7 FAA entities responsible for that goal demonstrated the ongoing monitoring the strategy itself required.
NIST zero-trust practices fully aligned3Of 7 NIST practices for migrating to a zero-trust architecture
Strategy objectives fully implemented3Of 7 objectives supporting the networks-and-systems protect-and-defend goal
Entities that showed required monitoring1Of 7 FAA entities responsible for the strategy

FAA left one of its own cybersecurity programs off its spending reports

's side of the audit is a reporting failure, not a definitional one. Seven entities share responsibility for the agency's Cybersecurity Strategy, and their overall budget requests for fiscal years 2024 through 2026 ranged from about $42 million (Commercial Space Transportation) to about $11 billion (Air Traffic Organization) -- a roughly 259-to-1 spread that reflects how differently sized these seven offices are, not how much any of them spends specifically on cybersecurity.

Every year, OMB requires agencies to report their cybersecurity spending as part of its cyber budget data request, so Congress and budget officials can see what agencies are actually spending to defend their systems -- the same accountability discipline 's missing roadmap undermines from the planning side. did not fully comply in any of the three years reviewed: it left its Information Security/Cybersecurity Program -- the program that funds 's cybersecurity research and development -- out of its reporting in fiscal 2024, 2025, and 2026 alike. That program's own budget requests over those years, $6.4 million, $5.9 million, and $4.6 million, add up to $16.9 million that never showed up where and Congress were supposed to see it. officials told they believe they've since included the cost in a September 2025 submission covering the fiscal 2027 budget request, but as of April 2026 hadn't shown evidence the correction was actually made.

The one cybersecurity program FAA left off its OMB reports
FAA's Information Security/Cybersecurity Program budget requests, fiscal years 2024-2026 -- the exact line item GAO found missing from FAA's cyber-spending reports to OMB in all three years
FY2024
6.4
FY2025
5.9
FY2026
4.6
Source: GAO-26-107693, Table 2: FY2024 Through 2026 President's Budget Requests for FAA Cybersecurity Programs (p.32)
View data as table
FAA's Information Security/Cybersecurity Program -- which supports the agency's cybersecurity research and development -- had President's budget requests of $6.4 million in FY2024, $5.9 million in FY2025, and $4.6 million in FY2026. GAO found FAA left this specific program's spending out of its OMB cyber budget data request in all three years.
FY20246.4
FY20255.9
FY20264.6

FAA's own self-check found it wasn't checking

Two more findings sit underneath 's half of the report. First, 's Zero Trust Implementation Plan -- its roadmap for moving to an access-control model that verifies every user and device rather than trusting anything already inside the network, the security-architecture standard NIST has directed federal agencies toward -- fully matches only three of the seven practices NIST lays out for that migration, and doesn't cover the transition steps for 's Research and Development systems at all, even though those systems interface directly with other agencies and aviation partners.

Second, 's own Cybersecurity Strategy set seven objectives toward protecting and defending its networks and systems -- things like improving threat intelligence and privileged-user monitoring. found had fully implemented three of the seven. The reason gives is structural: lacked a process to actually monitor and evaluate its own progress on any of the strategy's goals, and only one of the seven entities responsible showed it was doing the monitoring the strategy called for. updated its Cybersecurity Strategy in March 2026 to promise a centralized implementation plan and new performance metrics -- but, per 's own footnote, that updated strategy still doesn't name which entities are responsible for carrying it out, the same kind of gap is asking to close.

What GAO told each agency to do, and who's on the hook

issued five recommendations in total: one to 's Administrator, to update the Cybersecurity Roadmap and name responsible offices; and four to 's Administrator, covering its reporting process and two separate fixes to the Zero Trust Implementation Plan, plus a directive that 's Cybersecurity Steering Committee actually monitor implementation of the revised strategy going forward. agreed with the recommendation and, in its enclosed management response, set an Estimated Completion Date of May 31, 2027. agreed with all four FAA recommendations but didn't attach individual completion dates to them, committing instead to a detailed implementation response within 180 days of the report's issuance. All five recommendations carry the status calls 'open': the agencies have committed to act, and will check back on what they actually did against those commitments.

  • 's cybersecurity roadmap is eight years old, and 's own internal plan says it should already have been replaced. 's fix -- name responsible offices, align with 's current strategy -- is recommendation one of five; agreed and set an Estimated Completion Date of May 31, 2027, nearly a year after the audit's release.
  • left $16.9 million in cybersecurity research-and-development spending off three straight years of federally required reports. The Information Security/Cybersecurity Program's FY2024-26 budget requests -- $6.4M, $5.9M, $4.6M -- never appeared in 's cyber budget data submissions, the same channel that's supposed to let Congress see what agencies spend defending their own systems.
  • 's own strategy is failing 's own scorecard. Three of seven zero-trust practices fully met, three of seven network-defense objectives fully implemented, one of seven responsible entities actually monitoring its progress -- all found by the agency's own auditor, not an outside critic, and all still open as of this report.

The $42 million-to-$11 billion figure cites for the seven entities' budget requests describes those entities' entire operating budgets (Air Traffic Organization runs the National Airspace System; Commercial Space Transportation is a much smaller regulatory office), not their cybersecurity-specific spending -- this piece keeps that distinction separate from the $16.9 million Information Security/Cybersecurity Program figure, which is cybersecurity spending specifically, per 's Table 2. One of the seven entities, the NextGen Office, was terminated under Section 206 of the Reauthorization Act of 2024 effective December 31, 2025, with its functions transferred to a new Airspace Modernization Office as part of 's January 26, 2026 reorganization -- its FY2026 figure in 's table reflects the office before that transfer took effect. This piece draws on 's full 84-page report (fetched directly from gao.gov) rather than only the two-page Highlights, to source the underlying budget tables and page-specific findings cited throughout.

Sources(2) ▾
  • U.S. Government Accountability Office, Aviation Cybersecurity: FAA and TSA Are Collaborating on Cybersecurity but Need to Address Key Shortfalls -- Highlights & Product Page (GAO-26-107693) (2026-07-16)'s own product page for the audit, released and publicly posted July 16, 2026: Fast Facts, the two-page Highlights (What Found / Why Did This Study), and the Recommendations for Executive Action table, plus links to the full 84-page report. Sealed by Artemis's federal-core watchlist at 2026-07-16T14:40Z (document id gao-reports-2026-07-16-aviation-cybersecurity-faa-and-tsa-are-collaborating-on-c); no Wayback archiveUrl has filled in yet, consistent with the archive-availability gap Artemis's collection state has flagged across recent batches. Used here for the report's top-line framing and the five-recommendations count. gao.gov · original document
  • U.S. Government Accountability Office, Aviation Cybersecurity: FAA and TSA Are Collaborating on Cybersecurity but Need to Address Key Shortfalls -- Full Report (GAO-26-107693) (2026-07-16)The full 84-page audit, linked from the product page above and fetched directly from gao.gov, read in full and converted to text with pdftotext -layout. Sourced from it: Table 1, the FY2024-2026 President's budget requests for the seven entities responsible for implementing the Cybersecurity Strategy (p.30); Table 2, the FY2024-2026 budget requests for 's four named Cybersecurity Programs (p.32); the 2018 Cybersecurity Roadmap analysis and stakeholder interviews (pp.21-25); the Zero Trust Implementation Plan's alignment with NIST's seven zero-trust practices (pp.38-40); the Cybersecurity Strategy objectives assessment (pp.40-41); the five Recommendations for Executive Action (pp.51-52); and the Agency Comments confirming 's and 's responses (p.53). A Wayback Save Page Now request for this specific PDF returned an HTTP 520 -- the ongoing Wayback outage Artemis's collection state has flagged -- and the Wayback availability API found no existing snapshot of this URL, so the capture link points directly at 's own PDF. gao.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account