Major VA Policy Shift: Pre-Award FedRAMP Requirement Dropped for Cloud Vendors

Big shift in federal cloud procurement! The Department of Veterans Affairs (VA) is dropping the pre-existing FedRAMP certification requirement for cloud contracts to speed up innovation and access to new technology.

According to an internal memo obtained by FedScoop, the VA is making a major move to remove barriers for cloud contractors. Zack Schwartz, a top IT official at the VA, announced that tech companies no longer need to have completed the governmentwide FedRAMP security check prior to winning bids.

Here is what you need to know:

  • No More Pre-Requisite: Moving forward, acquisition documents (RFIs, RFPs, RFQs) will no longer state or imply that cloud companies need an existing FedRAMP certification to bid on contracts.
  • Speeding Up Procurement: The goal is to preserve acquisition flexibility, avoid “unnecessary delays,” and quickly bring high-quality, secure commercial technologies to the VA.
  • Security Remains a Priority: This does not lower the bar for security. Before any system goes live, vendors must still comply with NIST standards and VA directives and earn a VA Authorization to Operate (ATO), which could potentially be granted in just 60 days.
  • Post-Award Accountability: After winning a contract, vendors must still provide rigorous security documentation, including vulnerability scans and compliance with FedRAMP 20x key indicators, to operate within the VA’s environment.

As the VA changes how it contracts and sets new expectations for vendors, this shift marks a significant step toward expanding access to modern digital services for our Veterans without compromising their data.

Will this open the door for more innovative tech and smaller businesses in the federal space?

1 Like

Important to highlight that this isn’t a free pass on security. The VA is shifting the burden from pre-award qualification to post-award validation. Vendors still need to meet NIST standards, undergo vulnerability scans, and align with FedRAMP 20x indicators before going live. The real test will be whether the VA can reliably hit that 60-day ATO turnaround without creating a massive backlog in their Authorizing Official (AO) office.

1 Like

Absolutely. The opportunity is significant, but the bottleneck may simply shift from pre-award certification to post-award authorization. Execution will determine whether this change truly accelerates innovation

Big win for acquisition velocity. Upfront FedRAMP requirements have long been a moat that kept innovative mid-tier and smaller tech firms out of the running. Moving security validation to post-award under VA ATO standards preserves security while lowering the barrier to entry. The real test now will be how quickly post-award authorizations actually move through the pipeline.

1 Like

The barrier to entry is clearly being lowered, but success will depend on execution. If VA authorization timelines remain predictable and timely, we could see greater participation from innovative small and mid-sized firms without compromising security.