Government Technology Review
CIO StrategyLong read

IT Capital Planning and Investment Control in Federal Agencies

Agencies manage $102 billion in IT spending through a three-phase portfolio process.

Senior Writer · · 12 min read
Cover illustration for “IT Capital Planning and Investment Control in Federal Agencies”
CIO Strategy · August 25, 2026 · 12 min read · 2,704 words

Federal agencies spent $102.31 billion on information technology in fiscal year 2025. That kind of money doesn't get managed by gut feeling or year-end scrambling; it gets managed through Capital Planning and Investment Control, or CPIC, a process that treats an agency's IT holdings the way a pension fund manager treats a stock portfolio. You balance mission value against cost against risk, across thousands of investments at once, instead of judging each project in isolation.

That portfolio framing is the whole point, and it's worth sitting with for a second. A single agency doesn't buy one system and call it done; it runs hundreds or thousands of them simultaneously, some ancient, some brand new, some quietly rotting in a data center basement somewhere in Virginia. CPIC exists to make sure someone is looking at all of them together, asking whether the mix makes sense, and pulling the plug on the ones that don't. It touches strategic planning, enterprise architecture, security, budgeting, and procurement all at once, which is a lot to ask of any single "process." Calling CPIC a checklist undersells it. It functions closer to a governing philosophy, one that shapes how every dollar gets justified, tracked, and eventually judged.

The laws and policies that made CPIC mandatory

Nobody sat down in one afternoon and invented CPIC. The Clinger-Cohen Act of 1996 is usually cited as the origin story, and for good reason: it required agencies to run a disciplined process across the entire lifecycle of an IT investment and, maybe more importantly, created the modern agency Chief Information Officer role with real budget and management teeth. Before Clinger-Cohen, an agency's top technology decision-maker might have had influence. Afterward, they had authority written into statute.

FITARA came nearly two decades later, in 2014, and didn't so much replace Clinger-Cohen as sharpen it. FITARA insisted that IT resources actually align with agency missions, and it gave CIOs visibility into IT spending happening well outside their own office (a detail that matters more than it sounds like it should). Plenty of agencies had shadow IT spending buried in program offices that the CIO never saw a dime of. FITARA closes some of that gap.

Then there's the policy layer, which is where things get less glamorous but no less load-bearing. OMB Circular A-130, last given a full rewrite in 2016, operationalizes both Clinger-Cohen and FITARA: it treats government data as a strategic asset and lays out the actual requirements for oversight, security, privacy, and records management. OMB Circular A-11, Section 55 is the annual paperwork engine behind all of it, the mechanism through which agencies report IT budget data alongside their formal budget submission, with CIOs attaching evaluation reports for major and standard investments alike.

Layer in the Paperwork Reduction Act, the E-Government Act of 2002, the Chief Financial Officers Act, the Federal Acquisition Streamlining Act, and the Modernizing Government Technology Act of 2017, and you start to see the shape of the thing. CPIC accreted, statute by statute, guidance memo by guidance memo, over roughly three decades, rather than arriving through a single clean bill. That history explains, incidentally, why no two agencies run CPIC quite the same way even though they're all technically following the same rulebook.

The scale of federal IT spending that CPIC governs

Start with the headline number again: $102.31 billion in FY2025, of which $30.696 billion was classified as major investments, the modernization projects and mission-critical systems that draw the most scrutiny. Strip out the Department of Defense and the civilian side alone still comes to $75.1 billion. DoD's own IT budget for FY2026 hit $66.1 billion by itself, which should tell you something about why a unified governance process across both civilian and defense IT actually matters. These aren't small, isolated line items; they're comparable to the GDP of a mid-sized country, split across two very different bureaucratic cultures.

The FY2025 portfolio breaks down into 4,446 individual investments spread across 25 agencies, with 595 of those tagged "major." Administrative services and support eat up roughly 10% of proposed spending, and the rest gets divided among mission delivery, infrastructure, security, and IT management functions. None of that is surprising on its face. What's more interesting, and more of a structural headache, is the split between maintaining what already exists and building what comes next.

For FY2024, agencies planned to spend $74 billion just operating and maintaining existing systems, against only $21 billion on new development and modernization. Read that ratio twice. For every dollar spent building something new, roughly three and a half dollars go toward keeping the lights on for systems that, in many cases, predate the employees maintaining them. That's the legacy tax, and CPIC has to manage a portfolio where the majority of the money is defensive rather than forward-looking.

Agency-level swings make the picture even messier. The Department of Homeland Security's IT budget grew 23% year-over-year to roughly $11 billion in FY2025. The Department of Energy's jumped 37% to $5.5 billion. Meanwhile the Office of Personnel Management's IT budget shrank 64% compared to the prior year, a drop steep enough to make anyone doing portfolio math wince. CPIC manages something closer to a living organism that grows a limb here and loses one there, depending on which way administration priorities and funding cycles happen to blow, far more than it manages a static pie chart that shifts slightly each year.

Diagram: The Legacy Tax: Where Federal IT Dollars Actually Go. Visualizes: Visualize the stark spending imbalance in the FY2024 federal IT budget between maintaining existing systems and building new ones.

How the three core CPIC phases work in sequence

Table: The Three CPIC Phases. Compares Core Purpose, Key Mechanism, Who's Involved and Feeds Into by Select, Control and Evaluate.

The framework itself runs in three phases: Select, Control, Evaluate. Each one feeds the next, and skipping a step tends to produce exactly the kind of chaos the whole system was built to prevent.

Select comes first, and its job is deciding what gets funded before a dollar moves. Agencies build Major IT Business Cases and submit them to OMB for every major investment, laying out mission alignment, projected cost, risk factors, and expected outcomes. OMB reviews these submissions and tracks them going forward through the Federal IT Dashboard, checking actual cost, schedule, and performance against whatever was promised on paper. OMB sorts investments into five categories: Major, Non-Major, IT Migration, Funding Transfer, and Standard, each carrying a different reporting burden. Getting labeled "major" isn't a compliment; it means high executive visibility, significant policy stakes, unusual cost or funding structures, or simply that the agency's own CPIC process flagged it as such. More scrutiny, more paperwork, more people watching.

Control is where the ongoing babysitting happens. Once an investment is funded, agency CIOs assign it a risk rating on a 1-to-5 scale, with 5 being lowest risk. A high rating triggers a root cause analysis pulling in the CIO, the program director, and OMB's E-Government administrator, which is bureaucratic speak for "everyone stops and figures out what's actually going wrong before it gets worse." The FITARA IT Portfolio Review process requires the CIO and senior officials to review active investments at least once a year as part of budget development, keeping strategic planning, capital planning, and acquisition roughly in sync. Layered on top of that is the Technology Business Management framework, or TBM, which OMB requires agencies to use when categorizing and reporting spending in annual budget requests. TBM is what lets someone actually answer the question "where does the IT money go" at a granular level, rather than a vague departmental total that hides everything interesting inside it.

Evaluate closes the loop. Did the investment do what it said it would do? CIOs file formal CIO Evaluation Reports for both major and standard investments as part of the annual OMB submission, and whatever those reports find is supposed to feed back into the next round of Select-phase decisions. This is arguably where the portfolio metaphor earns its keep: a completed investment's track record should change how an agency prices risk on the next proposal that walks through the door. Whether that actually happens consistently is a fair question, and one worth holding onto as you read further into how agencies execute this in practice.

All of this runs on a calendar. Agencies work through an initial OMB submission, typically early fall, and then again through the President's Budget submission window, typically winter into early spring. Those two dates structure when each phase's work has to be finished, which means CPIC happens twice a year in overlapping waves, not once a year in a single burst.

How individual agencies adapt the CPIC framework to their own governance

The three-phase skeleton is universal. What agencies build on top of it is where things get idiosyncratic, and honestly, kind of fun to compare.

The Social Security Administration adds an explicit "Plan" phase before Select, on the reasonable theory that systems as large and mission-critical as SSA's benefit platforms need real pre-investment groundwork before anyone can credibly write a business case. The Department of the Interior frames CPIC as one integrated governance process tying together annual IT budget development, CIO decision authority, and the alignment between strategic planning and acquisition, with its OCIO coordinating reviews that stretch across individual bureaus. At EPA, the CIO and senior officials are on the hook for analyzing and revising mission and administrative processes before signing off on significant investments, meaning the CPIC review sits inside the broader management decision chain rather than existing as a bolted-on compliance step somebody has to remember to run.

USDA ties its CPIC work directly to FITARA's requirement that spending translate into measurable mission results, treating capital planning less like a budgeting exercise and more like a performance accountability mechanism. The Department of Labor takes a more tools-and-documentation approach, running its portfolio through a dedicated system called eCPIC and publishing detailed guides for project managers who actually have to walk this process day to day. That last detail matters: program offices carry real operational weight here, filling out business cases and risk assessments as part of their regular job, not as a favor to the CIO's office, and CPIC extends well beyond an OCIO exercise happening somewhere upstairs.

Across all of these variations, one trend holds steady: the CIO role has grown from someone who reviews a budget line to someone who actively makes investment decisions. And the mechanism keeping that growth honest, or at least keeping it visible, is the annual FITARA scorecard, which is worth its own section, because it's the closest thing to a public report card this whole system has.

The Federal IT Dashboard and how investment transparency has been managed and is changing

The Federal IT Dashboard launched in 2009 as OMB's answer to a fairly basic question: how does anyone, inside or outside government, actually see where IT money is going and whether it's working? GSA rolled out a modernized version in March 2022, pitched at the time as a one-stop replacement for the legacy system. Fast forward to April 2026, and the platform is in transition again. The current administration is sunsetting the existing dashboard site, calling the reporting process behind it costly and inefficient, and agencies are shifting toward a leaner setup focused on data that's statutorily required rather than everything that could conceivably be tracked.

Federal CIO Greg Barbaccia has confirmed a new, more modern version is in the works, with the current platform sitting in steady state while that build happens. Meanwhile, on the tools side, GSA's Folio platform has taken over as the successor to the legacy eCPIC application. Folio is a government-owned, web-based SaaS system supporting both internal agency portfolio management and external OMB reporting, and it's realistically the infrastructure layer most CPIC practitioners spend their actual working hours inside, regardless of what the public-facing dashboard looks like on any given month.

This transition isn't just a website getting a facelift. The IT Dashboard is how OMB monitors cost, schedule, and performance against what agencies promised in their business cases, which means changes to what the dashboard tracks directly affect the visibility that the Control and Evaluate phases depend on. Strip away the wrong data field and you might not notice a cost overrun until it's a full-blown crisis instead of a yellow flag.

So here's a fair question to sit with, one this piece won't pretend to answer definitively: does a streamlined, statutorily-focused dashboard serve the oversight function as well as a more comprehensive one did? Reducing reporting burden sounds great on paper, and probably is great for the analyst who no longer has to fill out three redundant fields. Accountability and convenience don't always point the same direction, though, and that tension is very much unresolved as of this writing.

What the FITARA scorecard reveals about how well agencies are executing CPIC in practice

If CPIC is the internal machinery, the FITARA scorecard is the report card taped to the refrigerator for everyone to see. Congress issues it, grading agencies across categories including CIO authority, IT modernization progress, and the kind of risk management practices that sit at the center of CPIC's Control phase. In recent releases, a notable share of agencies have earned A grades, a signal of growing institutional maturity across the scorecard's roughly decade-long history. That trajectory is real, not a participation trophy.

The scorecard does something internal reviews can't: it makes an agency's IT governance performance public and political in a way that a quiet portfolio review buried in an OCIO spreadsheet never will be. Agency CIOs get graded by name, essentially, and that changes incentives in ways that internal accountability mechanisms tend not to.

Here's the catch, though, and it's worth taking seriously rather than glossing over: strong scorecard grades don't automatically translate into strong IT outcomes. Remember that $74 billion spent in FY2024 just to operate and maintain systems that already exist? An agency can ace every governance category on the scorecard while still pouring the bulk of its budget into keeping decades-old infrastructure limping along rather than advancing its mission. The scorecard grades the process, things like CIO authority, data transparency, and risk management discipline. It doesn't grade whether any individual investment actually worked. A well-governed portfolio can still produce a project that crashes and burns; good governance reduces that risk without eliminating it.

What improvement on the scorecard really signals, then, is infrastructure-building: agencies establishing the institutional muscle (meaning real CIO authority, genuine portfolio visibility, and consistent risk rating discipline) that makes better decisions more likely over time. It's a leading indicator, not a guarantee.

What CPIC means for practitioners navigating federal IT governance today

CPIC isn't a box you check once a year and forget about until the next deadline. The Select-Control-Evaluate loop runs continuously, tethered to the annual budget calendar, OMB's two submission windows, and ongoing CIO portfolio reviews that never really stop happening in the background.

The CIO sits at the center of all of it. Between Clinger-Cohen and FITARA, that role has evolved from a technical advisor into someone accountable for connecting IT spending to actual mission outcomes, in ways that OMB, Congress, and the public can all independently check. Program managers and project teams, meanwhile, live inside the Control phase whether they think about it in those terms or not: risk ratings, business case updates, TBM categorizations. These aren't abstract governance vocabulary; they're the paperwork sitting in someone's inbox every quarter.

The tooling underneath all of this is shifting too. Folio has taken over from eCPIC, and the IT Dashboard is mid-transition toward whatever Barbaccia's team builds next. Practitioners working in or around federal IT right now have to hold two things in their heads at once: what the rules require today, and what's actively changing under their feet.

The underlying logic, though, isn't going anywhere. At $102.31 billion a year, federal IT spending is too large and too tied to actual government function to manage through instinct or improvisation. The specific forms, dashboards, and reporting tools will keep evolving, probably faster than anyone would like. But the core idea, treating IT investment as a portfolio to be balanced rather than a stack of unrelated purchases, is going to outlast every tool built to support it. Understanding that framework matters for anyone working inside, alongside, or in observation of federal IT. It's the reason federal IT decisions look the way they do, and the starting point for asking whether they should.

Filed underCIO Strategy

More in CIO Strategy