Government Technology Review
CIO StrategyLong read

Federal CIO Council Priorities and Governance Structure

Correspondent · · 11 min read
Cover illustration for “Federal CIO Council Priorities and Governance Structure”
CIO Strategy · August 12, 2026 · 11 min read · 2,376 words

Three OMB officials anchor the Council. The Deputy Director for Management chairs it; the Administrator of the Office of Electronic Government, who also carries the title of Federal CIO, runs day-to-day Council activities on the DDM's behalf; and the Administrator of the Office of Information and Regulatory Affairs rounds out the core. Membership extends from there to the CIOs of CFO Act agencies and other selected agencies, plus any officer or employee the chair designates.

The vice chair is elected from among member agencies. That election is how agency-level CIOs get a genuine leadership voice in Council governance rather than just receiving directives from above.

The Council sits within GSA's Office of Executive Councils, housed inside the Office of Government-wide Policy, which coordinates what it calls the CXO ecosystem: the Chief Data Officers Council, the Chief Acquisition Officers Council, the Chief Financial Officers Council, the Chief Human Capital Officers Council, and the Federal Privacy Council. Cross-council coordination is wired into the architecture itself.

The Federal CIO's portfolio covers federal technology spending oversight, IT policy, and strategic planning for all federal IT investments. It also carries responsibility for a government-wide enterprise architecture spanning interoperability, information sharing, security, and privacy. Workforce quality, performance monitoring, and investment optimization all flow from standards the Council sets.

The Council was established by Executive Order 13011 and later codified by the E-Government Act of 2002 as "the principal interagency forum for improving agency practices" related to federal information resources. FITARA, enacted in December 2014, reinforced that foundation by assigning 35 key IT management responsibilities to agency CIOs. The FITARA Scorecard, developed by the House Oversight and Government Reform Committee alongside GAO and first released in November 2015, grades agencies A through F on implementation twice a year. It is a public accountability mechanism, not an internal report card.

The Council's statutory duties include developing recommendations for OMB's Director on government information resources management, sharing best practices across agencies, assisting the Federal CIO in identifying and coordinating multi-agency IT projects, and working with OPM on IT workforce hiring, training, classification, and professional development. These are obligations.

The scale of federal IT the Council oversees, and why that scale shapes everything it does

Venn diagram: Federal IT Budget: Civilian vs. Defense. Compares Civilian IT and Defense IT; overlap: Shared Priorities.

The Trump administration's FY2027 budget proposes $75.7 billion in federal civilian IT spending, up from $67.9 billion in FY2026. Defense IT is a separate universe entirely: the Department of Defense IT budget request was $66.1 billion in FY2026 alone, none of which falls under the Council's governance.

Within the civilian budget, the concentration is striking. The Department of Veterans Affairs leads proposed FY2027 civilian IT investment at $12.2 billion, followed by the Department of Homeland Security at $11.7 billion. Those two agencies account for nearly a third of the civilian total by themselves.

A 2023 GAO audit found 6,708 IT investments reported across IT portfolio categories. As of March 2026, roughly 90% are on time and 84% are on budget, which is better than the federal IT program's historical reputation would suggest. But a separate GAO finding defines the Council's enduring strategic problem: agencies have historically spent approximately 80% of their IT budgets on operations and maintenance of existing systems, legacy infrastructure included. If that ratio holds, modernization spending is structurally squeezed before a single new initiative gets approved.

At tens of billions of dollars and thousands of active projects, the Council cannot manage each investment directly. Its real function is setting the frameworks, standards, and priorities that agency CIOs then implement. The scale is the reason the governance model is built the way it is.

The current leadership moment: Gregory Barbaccia, unusual agency CIO turnover, and what the 16 principles signal

Gregory Barbaccia became Federal CIO in January 2025, replacing Clare Martorana. His background spans Army intelligence, Palantir, and Elementus, a profile that diverges sharply from the traditional federal IT career pathway. Barbaccia arrived with a private-sector and national security orientation, not a long tenure in civilian agency IT governance.

The agency-level CIO landscape around him is unusually unsettled. The Departments of Interior, Treasury, and EPA all named new CIOs in 2025. The Energy Department was on its third CIO since January of that year. As of mid-2025, seven CIO positions were either vacant or filled by acting officials.

GovCIO Media reported that many incoming agency CIOs lacked significant federal agency experience, and it was unclear whether several had previously held a CIO role at all. Two examples from that reporting are worth naming directly. Sam Corcos became Treasury CIO while also serving as co-founder of the health technology company Levels, carrying a prior DOGE association. Aram Moghaddassi, formerly a senior engineer at X and Neuralink and a DOGE employee at the Labor Department, became the Social Security Administration's CIO for technology and customer products. SSA's decision to split the traditional CIO function into two separate roles, one for technology and customer products under Moghaddassi and one for core business functions under Michael Russo, is a structural experiment without clear federal precedent.

Barbaccia's 16 operating principles, issued in 2025, read differently against that context. Former federal executives have interpreted them as an effort to establish baseline expectations for agency CIOs who did not come up through government IT. The principles are not general management philosophy; they are the Federal CIO using a Council communication channel to operationalize expectations during a moment of genuine personnel flux, when the people responsible for implementing federal IT policy at the agency level do not share a common frame of reference for how that work gets done.

The administration's push to modernize federal technology, expand AI use, and streamline IT operations through executive actions means agency CIOs are being asked to move faster than the typical pace of federal IT change. Asking for speed from a cohort that is still finding its institutional footing is a genuine governance tension.

The AI adoption priority: moving federal agencies from pilots to embedded workflows

The Council's stated goal on AI is direct: every federal employee should have access to baseline AI-enabled productivity tools covering document analysis, data synthesis, customer service, and operational efficiency. As of January 2025, agencies publicly reported more than 1,700 ways they are using AI to advance their missions, per cio.gov.

Breadth of use cases does not equal depth of adoption. Reporting 1,700 applications confirms that experimentation is widespread; it says very little about how many of those applications are embedded in daily workflows, producing measurable outcomes, or still essentially proof-of-concept pilots. The Council's actual priority is the move from the pilot stage to the embedded, measurable, everyday-use stage.

The most concrete 2025 policy action on this front is the FedRAMP acceleration effort. On August 12, 2025, the CIO Council sent a letter asking FedRAMP to prioritize AI cloud services for approval based on five criteria, one of which is demand from at least five CFO Act agencies or a specific CIO Council recommendation. That criterion gives the Council a direct lever on which AI tools get cleared fastest, without requiring legislative action.

The state of play as of August 2025 illustrates why that lever matters. Of the three AI tools GSA contracted through agreements with Google's Gemini, OpenAI's ChatGPT, and Anthropic's Claude, only Gemini had earned a FedRAMP authorization; the others were available through contractual arrangements but had not completed the full authorization process. Barbaccia has explicitly backed the "FedRAMP 20x" initiative, GSA's effort to use automation and streamlined processes to accelerate authorizations: "We're fully committed to the GSA 20x initiative."

The FedRAMP bottleneck is fundamentally a governance problem, not a technical one. The authorization process was designed for a procurement environment where a few major systems needed careful vetting over extended timelines. AI tools proliferate far faster than that process was built to handle. The Council's response is process reform: changing how approvals are sequenced and prioritized, not simply asking reviewers to work faster.

Cybersecurity as the Council's most consistently cited priority, and where the budget tells a different story

A MeriTalk survey conducted between May and August 2024, covering 12 CFO Act Agency CIOs, found that 67% named cybersecurity and risk management as a top priority for the coming year. In practice, that means improving identity and risk management, modernizing infrastructure, increasing automation, and balancing security with user experience. Zero trust sits at the center of most of that work, particularly around identity management.

The CISO Council and CDO Council jointly released the Federal Zero Trust Data Security Guide in October 2024, with a revised version in May 2025. More than 30 federal agencies and departments contributed to it, as required by OMB M-22-09. The fact that it produced one shared operational document rather than parallel guidance that agencies interpret independently is precisely what the ecosystem coordination structure is supposed to make possible.

Despite cybersecurity being the top stated priority among agency CIOs, the Trump administration's FY2027 budget proposes a decrease in civilian cybersecurity funding, from approximately $12.5 billion in FY2026 to $12.2 billion in FY2027. That tracks with the administration's decision to cut CISA's budget by hundreds of millions of dollars. The stated priority and the funded priority are not the same thing.

Zero trust also functions as more than a security framework. It is the organizing architecture for shared identity infrastructure and data access controls across agencies, which connects it directly to the interoperability and shared services priorities that follow.

How the Council's "buy-first, build-rarely" and shared services doctrine tries to solve the 80% problem

Buy-first, build-rarely means exactly what it says. Building bespoke systems should be the exception, reserved for mission needs so genuinely unique that no commercial or government-wide shared solution can meet them. The default is to buy proven commercial solutions or adopt existing shared services. Building from scratch incurs not just development cost but long-term maintenance cost, and those maintenance costs are precisely what the 80% figure from GAO reflects.

The Council also promotes establishing technical standards, integration patterns, and performance requirements before any contract is written. This creates a level playing field for vendors and reduces lock-in risk. The deeper purpose is ensuring that whatever gets procured can actually integrate with the broader federal technology environment, rather than becoming another isolated system requiring custom interfaces and dedicated maintenance staff years later.

Shared services follow the same logic. Every agency solving the same problem independently, whether that problem involves identity management, data exchange, cybersecurity tooling, or cloud infrastructure, wastes resources and produces inconsistency. The domains where shared services operate are the same domains where zero trust frameworks are being implemented. That is not accidental.

The 80% problem is structural. If agencies are already spending the bulk of their IT budgets maintaining existing systems, the only way to create meaningful headroom for modernization is to ensure new procurement decisions do not replicate the same maintenance burden. Buy-first and shared services do not eliminate the legacy maintenance problem in the near term. They are designed to stop it from compounding.

Data governance as the connective tissue across every other priority the Council is pursuing

The Council's framing on data is unambiguous: data underpins every federal technology priority. Cybersecurity analytics, AI-enabled services, and shared infrastructure all depend on agencies treating data as a mission-critical managed resource rather than an incidental byproduct of operations.

The current policy framework includes OMB Memorandum M-25-05 and the Foundations for Evidence-Based Policymaking Act. Together, they direct agencies to designate Chief Data Officers, develop evidence-building plans, and manage data assets with appropriate security and privacy protections. The CDO Council works alongside the CIO Council on these requirements, another instance of the cross-council coordination the governance design is supposed to enable.

The Federal Zero Trust Data Security Guide, produced jointly by the CISO Council and CDO Council, is simultaneously a cybersecurity document and a data governance document. Data security and data governance are not separable problems.

The AI connection here is direct. AI tools are only as useful as the data they can access, and that access depends on interoperable data standards, consistent classification practices, and clear governance rules about who can see what. Shared services depend on agencies being able to exchange data reliably, which requires those same standards. Cybersecurity frameworks govern how data moves between systems. Pull on any of the Council's current priorities and data governance is somewhere in the thread.

The Council's statutory obligation to work with OPM on IT workforce development extends, in practice, to data literacy. Agencies cannot govern data well without people who understand both the technical mechanics and the policy requirements; that mandate, written into the Council's founding statute, is what connects the human capital piece to everything else.

How the Council's structure and current priorities fit together as a system

The Council's design reflects a deliberate wager: horizontal coordination across agencies, through shared standards, shared services, and shared forums, produces better outcomes than each agency optimizing in isolation. FITARA Scorecard results and GAO IT portfolio reviews suggest it works, at least on the on-time and on-budget metrics, when the coordination infrastructure is functioning well.

The current moment is putting that wager under unusual stress. Elevated CIO turnover at the agency level, a Federal CIO whose network skews toward private-sector and DOGE-adjacent figures rather than career federal IT leadership, and an administration pushing aggressive modernization timelines mean the Council's coordination function is absorbing more institutional friction than is typical. The people responsible for implementing shared standards and shared services at the agency level are, in many cases, still learning the governance environment in which those standards operate.

The 16 principles, the FedRAMP prioritization letter, and the Federal Zero Trust Data Security Guide are expressions of the same underlying mechanism. The Council uses its statutory forum authority to push policy positions into agency-level behavior without requiring legislation and without holding formal procurement or budget authority. It is normative and coordinative power, and normative power has a specific vulnerability: it only works when the people receiving the norms understand the context that makes those norms meaningful.

Right now, that context is unevenly distributed across the agency CIO cohort. The Council publishes documents; people turn those documents into practice. When the people are still finding their footing, the distance between what the Council publishes and what agencies actually do gets wider, quietly, without any formal announcement that the gap has opened.

Sources

  1. cio.gov
  2. cio.gov
  3. sgp.fas.org
  4. govinfo.gov
Filed underCIO Strategy

More in CIO Strategy