fedramptrade-pressNewsThe Broadside1 min read

VA drops pre-award FedRAMP requirement for cloud contracts

VA is betting that post-award security outcomes matter more than pre-award paperwork, but the 60-day ATO clock will decide whether the bet holds.


TL;DR

The Department of Veterans Affairs will no longer require cloud service providers to hold FedRAMP certification at contract award, per a memo from Principal Deputy Assistant Secretary Zack Schwartz obtained by FedScoop. Contractors must instead achieve a VA Authorization to Operate within 60 days of award, meeting NIST standards and VA security requirements before any system goes live. The policy opens the door for primes, subs, and ISVs that lack pre-existing FedRAMP status. But it shifts the authorization burden to post-award, where timeline risk now lives.

Principal Deputy Assistant Secretary for IT Zack Schwartz instructed VA acquisition officials this week to stop requiring, or even implying, that cloud vendors hold FedRAMP certification at the time of bid. The memo, obtained by FedScoop, frames the change as preserving "acquisition flexibility while maintaining VA's risk management and operational security standards." It's a move that aligns with the FedRAMP modernization push OMB launched in M-24-15, which told agencies not to "assume that particular paths or sponsors of FedRAMP authorizations are unacceptable."

The security bar isn't moving. Contractors must still meet NIST standards and VA's full suite of security requirements under Directive 6500 and Handbook 6500.6, and must secure a VA Authorization to Operate before any cloud system goes live. The memo envisions ATO within 60 days of award.

VA's move doesn't come out of nowhere. The agency's Enterprise Cloud currently runs on just two providers, AWS and Azure, which together support roughly 757 applications. A November 2025 RFI signaled interest in expanding that portfolio now that more CSPs have FedRAMP High authorization (FedScoop, Nov. 3, 2025). Schwartz has previously framed VA's procurement posture bluntly: as "the largest customer for nearly all of our technology vendors," the department is setting new expectations for how agencies contract and hold vendors accountable for outcomes. Dropping the pre-award FedRAMP requirement extends that logic. It's a trade of credential-checking at the door for outcome-verification after entry.

What the memo doesn't address is the obvious failure scenario. If a vendor can't clear the ATO bar in 60 days, the policy is silent on remedies. A post-award authorization failure doesn't just stall one deployment; it ties up a procurement vehicle that could have gone to a vendor that was ready. The 60-day window is the policy's load-bearing assumption, and it hasn't been tested at scale.


Published ·Deep Fathom