Big shift in federal cloud procurement! The Department of Veterans Affairs (VA) is dropping the pre-existing FedRAMP certification requirement for cloud contracts to speed up innovation and access to new technology.
According to an internal memo obtained by FedScoop, the VA is making a major move to remove barriers for cloud contractors. Zack Schwartz, a top IT official at the VA, announced that tech companies no longer need to have completed the governmentwide FedRAMP security check prior to winning bids.
Here is what you need to know:
- No More Pre-Requisite: Moving forward, acquisition documents (RFIs, RFPs, RFQs) will no longer state or imply that cloud companies need an existing FedRAMP certification to bid on contracts.
- Speeding Up Procurement: The goal is to preserve acquisition flexibility, avoid “unnecessary delays,” and quickly bring high-quality, secure commercial technologies to the VA.
- Security Remains a Priority: This does not lower the bar for security. Before any system goes live, vendors must still comply with NIST standards and VA directives and earn a VA Authorization to Operate (ATO), which could potentially be granted in just 60 days.
- Post-Award Accountability: After winning a contract, vendors must still provide rigorous security documentation, including vulnerability scans and compliance with FedRAMP 20x key indicators, to operate within the VA’s environment.
As the VA changes how it contracts and sets new expectations for vendors, this shift marks a significant step toward expanding access to modern digital services for our Veterans without compromising their data.
Will this open the door for more innovative tech and smaller businesses in the federal space?
