VA’s Cloud Security Guidance: Debunking Myths, Not Introducing New Policies

0
2

Key Takeaways

  • The VA memo clarifies that FedRAMP certification is not a prerequisite for vendors to compete for or receive VA cloud‑service contracts.
  • Vendors must still undergo VA’s Authority‑to‑Operate (ATO) process, which mirrors FedRAMP standards and must be completed within 60 days post‑award.
  • Required documentation for the ATO includes a security assessment report, architecture/data‑flow diagrams, asset inventory, vulnerability scans, and, when applicable, FedRAMP 20x key‑security‑indicator implementation status.
  • FedRAMP 20x (especially Classes A and B) is designed to let vendors achieve certification more quickly after winning a contract, preserving security while expanding competition.
  • Agency officials and FedRAMP leaders stress that removing the pre‑award certification barrier does not lower security; it simply shifts the timing of the certification effort to after award, encouraging innovation and faster delivery of modern services to veterans.

VA Memo’s Purpose and Scope
The Department of Veterans Affairs issued a memo from Principal Deputy CIO Zack Schwartz that reiterates longstanding policy: VA solicitations must not state or imply that existing FedRAMP certification is required for an offeror to compete for or receive an award. The memo does not create new policy; it serves as a “myth‑busting” reminder that acquisition officers and program managers have been inadvertently imposing an unnecessary barrier by expecting vendors to arrive with a FedRAMP badge in hand. By explicitly stating that certification is not a pre‑condition, the VA aims to broaden the pool of eligible contractors and reduce procurement delays.


Why the Myth Persisted
Over time, a misconception took root among acquisition and technology staff that FedRAMP certification acted as a gate‑keeping prerequisite. This belief caused agencies to limit competition to only those vendors that could afford the multi‑million‑dollar investment needed to obtain certification before bidding. As a result, innovative tools—often newer, more capable versions of commercial products—were excluded simply because they lacked the FedRAMP label, even though they could meet VA’s security requirements through the standard ATO process.


Security Standards Remain Unchanged
Schwartz emphasizes that the VA is not lowering its security bar. Cloud service providers must still complete VA’s rigorous Authority‑to‑Operate (ATO) process, which is grounded in FedRAMP standards and the National Institute of Standards and Technology’s Special Publication 800‑53. The ATO must be awarded within 60 days after contract award, ensuring that any cloud offering used by the VA satisfies the same security controls that a pre‑certified FedRAMP product would provide.


Documentation Required for the ATO
To support the ATO determination, vendors must submit a specific set of security and privacy artifacts at a minimum:

  • A Security Assessment Report detailing test results and remediation status.
  • Architecture or data‑flow diagrams showing how data moves within the VA environment.
  • An Asset inventory listing all hardware, software, and data components involved.
  • Recent Vulnerability scans identifying and addressing weaknesses.
  • If applicable, the implementation status of FedRAMP 20x key security indicators (e.g., encryption, identity management, incident response).

These items enable VA officials to verify that the cloud service satisfies all required controls before it is authorized to operate.


FedRAMP 20x as a Post‑Award Pathway
The memo highlights the advantages of the FedRAMP 20x framework, particularly Classes A and B, which are structured for rapid certification after a contract is secured. Under this model, a vendor can win a VA award, use the guaranteed revenue stream to fund the certification effort, and achieve FedRAMP status faster than the VA could develop its own security plan and complete testing—a process that often exceeds 12 months. This approach aligns incentives: the vendor invests in certification knowing the contract provides a stable market, while the VA gains access to cutting‑edge technology without delaying deployment.


Industry and Federal Support
The VA’s clarification has received broad endorsement from the FedRAMP Program Management Office and Federal CIO Greg Barbaccia. Pete Waterman, Director of FedRAMP, praised the memo on LinkedIn, noting that it reinforces two core messages: (1) FedRAMP certification should never serve as a wall that artificially limits competition, and (2) agencies must still follow the Risk Management Framework (RMF) and develop proper security plans for the systems that will consume external cloud services. Waterman emphasized that treating cloud services as external components within an agency’s system security plan ensures that the VA retains responsibility for operating those services securely.


Operational Risk Considerations
Bill James, a former VA deputy assistant secretary for DevOps, agrees that removing the pre‑award FedRAMP requirement can improve access to innovative tools but warns against complacency. He stresses that understanding and accepting risk requires thorough analysis; agencies must not let lower‑cost, non‑FedRAMP solutions short‑circuit due diligence. Operational risks to the Veterans Health Administration and outcome risks to veterans must be evaluated comprehensively, even when the security bar is met through the ATO process.


Accountability and Enforcement
The memo itself will not automatically change behavior; VA acquisition workers and program managers will need to be held accountable for adhering to its guidance. A government official familiar with the memo suggests the most effective enforcement mechanism is for vendors to call out solicitations that incorrectly mandate FedRAMP certification ahead of award. By flagging such language, contractors can prompt corrections and reinforce the principle that certification is a post‑award activity, not a pre‑qualification hurdle.


Broader Implications for Federal Acquisition
Sources indicate that similar memos may be issued across other federal agencies, using the VA’s clarification as a blueprint. The FedRAMP program office plans to distribute draft memos that encourage agencies to treat cloud services as external services within their information systems, provided they comply with NIST SP 800‑53, SA‑9 controls for external systems. This approach would standardize the practice of leveraging commercial cloud innovations while preserving rigorous security authorization across the government.


Conclusion
The VA memo does not alter policy; it reiterates that FedRAMP certification is not a prerequisite for competing for VA cloud contracts. Vendors must still satisfy VA’s ATO process, which mirrors FedRAMP standards and must be completed within 60 days post‑award. By removing the pre‑award certification barrier, the VA hopes to widen competition, accelerate adoption of modern technologies, and maintain the same high level of security protection for veterans’ data. The initiative has garnered support from FedRAMP leaders and senior federal officials, who view it as a pragmatic step toward more innovative, efficient, and secure federal cloud acquisition—provided agencies continue to perform thorough risk analyses and uphold their responsibilities under the RMF.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here