FedRAMP Became the Price of Admission, Even When it Wasn't Needed

The Department of Veterans Affairs recently told its vendor community something a lot of small tech companies have been waiting years to hear: Having a cloud-based product does not automatically mean a company needs FedRAMP authorization to sell to VA.
Instead, the VA says the requirement depends on the specific use case, and whether that use actually falls within FedRAMP’s scope. That distinction may seem routine, but it’s a radical departure from the norm in government technology procurement.
FedRAMP has for years been the price of admission to sell technology to the government. And the price isn’t cheap. A recent GAO review found that two small cloud providers spent between $367,000 and $3 million updating their infrastructure to pursue FedRAMP authorization. Agencies reported spending tens or hundreds of thousands of dollars on individual authorizations. Eleven of the fifteen agencies GAO interviewed had run into situations where they could not procure a cloud service because of FedRAMP delays or confusion about what had actually been authorized.
Those numbers explain why VA’s clarification is so groundbreaking. For years, one question has quietly determined whether many technology companies can sell to the federal government. Are you FedRAMP authorized?
FedRAMP was created with good intentions, but agencies defaulted to a binary view of technology vendors—FedRAMP certified or not.
FedRAMP is a good idea. When federal agencies use commercial cloud services to store or process government information, they need assurance those services meet appropriate security standards. Rather than having every agency conduct its own security assessment of the same product, FedRAMP created a common framework agencies could reuse. Assess once, use many times. It was an efficient concept.
But over time, many agencies began treating FedRAMP as something much broader. If a product was cloud-based and the government wanted to use it, the assumption was often that it needed FedRAMP authorization. That default assumption was never what FedRAMP was supposed to mean, and it had consequences. For a large technology company with hundreds of millions of dollars in federal business, spending substantial time and money on FedRAMP authorization is a reasonable cost of doing business. For a small technology company trying to sell an innovative product to its first federal customer, it can be an insurmountable barrier.
That is beginning to change, and VA’s announcement is part of a broader pattern. The shift started in 2024, when the Office of Management and Budget updated the government’s FedRAMP policy. Buried in that guidance was an important sentence: FedRAMP does not apply to every use of an internet-based service by a federal agency. OMB identified several situations that can fall outside FedRAMP, including certain systems developed or deployed for a single agency, commercial information services that don’t collect federal information, and ancillary services whose compromise would pose negligible risk.
The current administration picked up that thread and pulled it further. In spring 2025, President Trump signed Executive Order 14271, directing agencies to prioritize commercial, cost-effective solutions over custom-built ones. A year later, OMB followed with a memo reinforcing that direction and adding reporting requirements to make sure agencies actually complied. That same month, GSA launched FedRAMP 20x, an effort explicitly framed around cutting the time and cost of authorization through automation rather than paperwork. Meaningful change has come as a result. Average authorization time has dropped from more than a year to roughly five weeks, and FedRAMP authorized more than double the number of cloud services in fiscal year 2025 compared with the year before.
FedRAMP has also made the implications of the 2024 policy considerably clearer. Its current guidance says the agency’s specific use case determines whether FedRAMP applies. The same technology can be within FedRAMP’s scope in one situation and outside it in another.
Consider an AI coding assistant. If a federal employee feeds sensitive government source code or internal information into a commercial AI service, the security implications are significant. But if that same employee uses the same tool exclusively to work with publicly available code, FedRAMP guidance says the use can fall outside the program. That’s why agencies need ask what risks a specific use case introduces when deciding whether a technology product must be FedRAMP certified.
The easier question for an agency to ask is simply whether a vendor has FedRAMP authorization. It produces a yes-or-no answer and transfers much of the judgment somewhere else. The harder questions are what information the product will handle, how it will be deployed, what would happen if the service were compromised, and what security controls are appropriate for that particular risk. That requires judgment, and government bureaucracies tend to prefer requirements that can be checked off a list.
VA’s clarification shows that the government is starting to ask the harder questions. The department isn’t abandoning FedRAMP or lowering its security standards. VA remains one of the government’s largest users of FedRAMP-authorized cloud services. But VA and other agencies are starting to be deliberate about when FedRAMP is actually the right security mechanism to require, and when it isn’t.
That change could matter enormously to smaller technology companies. Imagine a young software company with a genuinely useful product and an opportunity to conduct a $250,000 pilot with a federal agency. If the company must first spend hundreds of thousands of dollars, or potentially much more, preparing for FedRAMP authorization, the economics may simply not work. The government loses access to the product before anyone has seriously considered whether its use would actually create the risk FedRAMP was designed to address.
Multiply that decision across hundreds of companies and agencies and the consequences become much larger. The government says constantly that it wants greater competition, more commercial technology, and more participation by innovative small businesses. Yet it has also created a technology marketplace in which companies with established federal businesses have a significant advantage simply because they can afford the infrastructure of federal compliance.
Importantly, making FedRAMP use case-specific doesn’t weaken cybersecurity. A cloud provider storing veterans’ medical records or sensitive investigative information still faces FedRAMP’s rigorous security requirements. But rigorous security and universal FedRAMP requirements are not the same thing.
FedRAMP 20x and the use-case clarifications belong together. Where FedRAMP is necessary, make it work better. Where it isn’t necessary, stop requiring it.
There is also a broader lesson here. Government has a tendency to turn risk-management tools into compliance regimes. A control is created to address a particular risk, and over time, applying the control universally becomes easier than deciding when the risk actually warrants it. Eventually, following the process becomes the objective rather than managing the underlying risk.
FedRAMP is a particularly visible example because the costs are so substantial. But the same dynamic exists throughout government. The better approach is to ask risk-based questions.
What information will this system contain?
What could happen if it were compromised?
How consequential would that failure be?
What controls would materially reduce that risk?
Those questions require more judgment than asking whether a vendor has the right certification, but they are the questions government should be asking. The emerging changes to FedRAMP have the potential to open the federal technology market to companies that have been effectively excluded by compliance costs that were never justified by the risk of their particular products or use cases.
FedRAMP remains an important part of federal cybersecurity. The government just needs to stop treating it as the price of admission. The most important FedRAMP reform isn’t making the process faster, it’s teaching agencies when they don’t need to use it at all.
Article first posted on GovIntegrity.