The Department of Veterans Affairs’ recent memo on cloud security isn’t breaking new ground. It’s not even changing policy.
The best comparison for the memo from Zack Schwartz, VA’s principal deputy chief information officer, reminding VA contracting officers and program managers that vendors do not have to have their FedRAMP certification before responding to or submitting proposals for solicitations or requests for information is it’s mythbusting.
Over the years, like barnacles on the bottom of a boat, the myths around FedRAMP have built up among acquisition and technology workers, creating unnecessary barriers to adopting the latest technology.
“The issue is agencies expect companies to spend millions of dollars to get FedRAMP certification prior to being eligible for award and therefore you are limiting the companies that may not have that cash to find sponsor. Agencies are then only selecting from a smaller group of companies, and it puts them in a tight spot,” said a government official familiar with the memo, who requested anonymity in order to talk to the press. “This allows VA to not just have test the latest and greatest technology, but it gives VA the ability to move faster. There are tools that are FedRAMP’ed that are versions behind their commercial counterparts. So agencies lose capabilities.”
Schwartz wrote in the memo that any VA-related acquisition effort from requests for information to request for proposals “shall not state or imply that existing FedRAMP certification is required for an offeror to compete for or receive an award at VA.”
Documentation to support the ATO
A VA spokesperson said in an email to Federal News Network that the memo is clarifying the agency’s position to reduce hurdles for vendors.
“This is a significant step forward for veterans and for innovation at VA. By removing unnecessary barriers to competition while maintaining our rigorous security and authorization standards, we’re expanding access to the best commercial technologies, accelerating delivery of modern digital services and ensuring we continue to protect veterans’ data,” the spokesperson said.
Schwartz said in the memo that VA isn’t lowering the security bar for these cloud services as they still must go through a rigorous authority to operate (ATO) process in 60 days.
“To support VA’s authorization process, post contract award cloud service providers should be prepared to provide security and privacy related documentation to receive a determination for operating in VA’s environment,” the memo stated.
Schwartz outlined in the memo that at a minimum, this includes the vendor providing documentation to support:
- Security assessment report
- Architecture/data flow diagrams
- Asset inventory
- Vulnerability scans
- If applicable, implementation status of FedRAMP 20x key security indicators
The government official said VA’s, or really any agency’s, ATO process for cloud services is built on FedRAMP standards and requirements. Under the legacy FedRAMP process, approvals came from either the Joint Authorization Board or the agency sponsor. Under the new 20x process, agency sponsors aren’t needed, but vendors must pass through three gates to reach the highest level of certification.
“Just because a product is not pre-certified under FedRAMP, we can take the time to make sure all the security controls are there. VA was limiting themselves,” the source said. “The security standards stay the same, but if the best tool with the best value to the government exists but is not FedRAMP’ed, you still can put it through the same security controls. Really, this is about not being lazy about looking at technologies and applying the ATO process.”
Similar memos could be on tap
Sources say VA’s reminder received broad support from the FedRAMP program management office as well as Federal CIO Greg Barbaccia.
A source familiar with FedRAMP’s plans, but not authorized to speak to the press, said the program management office is planning to supply similar draft memos to agencies as a blueprint for them to formalize the use of cloud services as external services within any information systems as long as they follow the requirements outlined in the National Institute of Standards and Technology’s special publication 800-53, SA-9 control for external systems.
Emails to OMB seeking comment from the Federal CIO’s office were not returned.
Pete Waterman, the director of FedRAMP, wrote on LinkedIn that he “loved” the memo because it brought forward two key points that the program office has been telling agencies for some time.
“FedRAMP certification should never be a wall, and requiring it to compete or receive an award artificially limits access to great tools. FedRAMP 20x, especially Class A and B, are designed for a well-engineered product following security best practices to obtain a FedRAMP certification quickly. A business that receives an award will be able to get that certification faster than an agency can build out their own security plan and get through testing (which often takes 12-plus months). Get an award, get the contract requirements, tie it to guaranteed revenue, invest in the FedRAMP certification [and] everyone wins. It’s how it should work for new services,” Waterman wrote. “The reminder and doubling down on the agency need to follow the risk management framework and build proper security plans for the agency information system that will use the external service is exactly right. Too many agencies (including the VA from recent reports) think a cloud service does everything for them and forget their own responsibilities. Cloud services need to be leveraged as an external service within an agency system security plan that ensures the agency will operate it in a secure manner, and this memo makes that clear for VA.”
Bill James, a former VA deputy assistant secretary for development and operations (devops) in the Office of Information and Technology, said while he agreed with the idea that having a single gate that technology has to get through isn’t efficient and could impact veterans, he also believes the biggest issue is understanding and accepting the risk that comes with any technology.
“I endorse the idea that the CIO should be able to bring in and apply solutions that are not FedRAMP’ed while simultaneously understanding and accepting the risks for doing so,” James wrote in an email to Federal News Network. “But understanding and accepting risk requires thorough and complete analysis. I am concerned that the attractiveness of lower priced non-FedRAMP’ed solutions can short circuit and stop the analysis at the boundary of OIT, and not thoroughly understand the associated operational risks to the Veterans Health Administration or the outcomes risks to veterans.”
The memo by itself will not change the way VA acquisition workers and program managers work. The government official said VA and other agencies who follow the same path will have to held accountable. The best way to do that, the official said, is by vendors pointing out when RFIs and RFPs mandate FedRAMP ahead of award.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
