fedramptrade-pressNewsThe Broadside1 min read

VA Drops FedRAMP Pre-Cert for Vendors, GSA Flips Standards Playbook

VA decouples procurement from FedRAMP without lowering the security bar, and GSA finally admits that building standards before touching technology is backward.


TL;DR

VA told acquisition teams vendors no longer need FedRAMP certification before competing for VA business, the ATO stays, but the pre-competition gate is gone. Separately, GSA is inverting the standards timeline: test technology first, then feed results back into standards, a reversal of the traditional two-to-three-year policy-first sequence. OneGov has signed more than two dozen tech companies and flagged $1.18 billion in savings.

VA drops the gate, keeps the lock

The Department of Veterans Affairs issued a memo telling acquisition teams that vendors no longer need FedRAMP certification before competing for VA business. The ATO process stays (still targeted at 60 days) but the pre-competition FedRAMP requirement is gone. For cloud vendors who've been locked out of VA opportunities because authorization pipelines ran slower than procurement cycles, this is a meaningful operational shift: you can now bid while your authorization is in flight.

The memo doesn't lower the security bar. VA's ATO rigor remains intact, and nothing in the policy suggests the agency is relaxing its assessment standards. What it does is decouple the procurement timeline from the FedRAMP timeline, a pragmatic move that mirrors broader signals from GSA and OMB about making FedRAMP less of a gate and more of a continuous validation process.

Which brings us to GSA.

GSA flips the standards sequence

GSA CIO David Shive described a deliberate inversion: instead of spending two to three years developing standards and then testing technology against them, GSA now tests technology first and feeds results back into the standards process. OneGov has signed more than two dozen tech companies and identified $1.18 billion in savings. The "move fast" cliché has an actual government office behind it now, and the FedRAMP 20x push toward machine-readable, continuous security validation (backed explicitly by Federal CIO Greg Barbaccia) provides the underlying architecture that makes a test-first approach viable rather than reckless.


Published ·Deep Fathom