Guest Listing

The Future of FedRAMP Reauthorization and Cloud Security

Written by Fed Gov Today | Aug 4, 2026, 6:00:03 PM

Original Broadcast Date: 8/9/2026

As Congress prepares to consider reauthorizing FedRAMP, lawmakers are looking at how the program can continue evolving to meet the changing needs of federal agencies and industry. Congressman James Walkinshaw, D-VA, says recent improvements have positioned the program for its next stage, but additional work remains to streamline authorizations, strengthen agency expertise, and improve collaboration across government and industry.

Building on Recent Progress

Walkinshaw says he is encouraged by the direction FedRAMP has taken in recent years, pointing to the success of automation and process improvements that have helped modernize the program.

He highlights FedRAMP 20x as an important step in streamlining assessments and reducing the backlog of cloud service authorizations. Rather than viewing reauthorization as simply renewing existing legislation, he sees it as an opportunity to continue improving how the program operates.

"I think 20x has been a success in automating a lot of the work and assessments and streamlining the process that cleared the backlog," Walkinshaw says.

With reauthorization on the horizon, he believes Congress has an opportunity to gather feedback from industry while identifying new challenges that have emerged as cloud technologies continue to evolve.

Strengthening Collaboration

A central theme of Walkinshaw's discussion is collaboration among the organizations responsible for maintaining and improving FedRAMP. He says continued communication between Congress, the FedRAMP Program Management Office, and industry partners will be essential as lawmakers consider updates to the program.

Rather than treating reauthorization as a standalone legislative exercise, Walkinshaw describes it as an opportunity to understand where the program has succeeded, identify remaining obstacles, and incorporate lessons learned from agencies and cloud providers alike.

He also points to the broader benefits of improving the program. According to Walkinshaw, every enhancement to FedRAMP ultimately benefits taxpayers by expanding access to secure cloud services, improving government capabilities, and creating opportunities to reduce costs while maintaining strong security standards.

Investing in Technical Expertise

While automation has helped improve efficiency, Walkinshaw emphasizes that technology alone cannot address every challenge facing the authorization process.

He says agencies need experienced personnel with the technical knowledge required to evaluate cloud security as technologies continue to change. Specifically, he points to both the FedRAMP Program Management Office and agency Chief Information Officer organizations as areas where staffing and technical expertise remain critical.

Without sufficient personnel, he says, authorizations can stall even after cloud providers successfully complete the FedRAMP certification process.

Walkinshaw explains that once a certification is issued, agencies still need qualified staff to complete their own authorization activities. Ensuring those teams have the capacity to perform that work remains an important part of improving the overall process.

Addressing Workforce Challenges

Walkinshaw also acknowledges that workforce capacity has become a growing concern across the federal government.

He notes that many agencies have experienced staffing reductions, creating additional pressure on organizations responsible for evaluating cloud security and processing authorizations.

Rather than focusing solely on current staffing challenges, he says agencies must also think about the future by recruiting and retaining the technical talent needed to support increasingly complex cloud environments.

Developing that workforce, in his view, will help ensure that modernization efforts continue without unnecessary delays caused by limited staffing or technical capacity.

Reducing Duplicate Work

Another priority for Walkinshaw is continuing to improve how agencies use existing FedRAMP authorizations. The concept of reuse has been part of the program for years, allowing agencies to build on existing security assessments rather than repeating the same work for every cloud service.

Walkinshaw says progress has been made, and he is encouraged that reuse has become a more common practice across government.

Even so, he continues hearing from companies that portions of the authorization process still require work that closely resembles activities already completed during FedRAMP certification. "I still hear from businesses that they feel like they're redoing some of the work that they already completed in their FedRAMP process when they go to an agency," he says.

Closing that gap remains one of his priorities as lawmakers evaluate potential updates to the program. Reducing unnecessary duplication could allow agencies to adopt secure cloud services more efficiently while helping vendors move through agency authorization processes with fewer delays.

Looking Ahead

For Walkinshaw, the upcoming reauthorization represents more than a legislative milestone. It provides an opportunity to refine a program that continues to play an important role in the federal government's cloud security strategy.

Automation has helped improve efficiency, but maintaining that momentum will require continued collaboration, investment in technical expertise, and a focus on eliminating unnecessary barriers throughout the authorization process.

As discussions continue, Walkinshaw sees an opportunity to build on the program's recent progress while ensuring agencies have the people, processes, and partnerships needed to support secure cloud adoption across government.