FedRAMP Reauthorization Can Turn Recent Progress Into Lasting Reform

Presented by Carahsoft

Rep. James Walkinshaw believes FedRAMP has reached an important moment. Recent changes have helped automate more of the assessment process, streamline reviews and reduce the backlog that has frustrated both agencies and technology providers. The next challenge, he says, is making sure that progress becomes a permanent part of how the federal government evaluates and adopts cloud services.

Walkinshaw, who represents Virginia’s 11th Congressional District, sees the expected reauthorization of FedRAMP as an opportunity to bring Congress, the FedRAMP Program Management Office, federal agencies and industry together around the program’s next phase.

Screenshot 2026-07-30 at 3.23.42 PM“I see the reauthorization next year as an opportunity to build on that success,” Walkinshaw said. That process should include listening to companies about the obstacles they continue to face and ensuring that the federal government has the resources to address them.

For Walkinshaw, the value of a stronger FedRAMP program extends well beyond faster approvals for technology companies.

“Every time we improve this program, the American taxpayers benefit,” he said. Agencies gain access to better options and services, costs can come down, and the government can improve its overall security posture.

But policies and processes alone will not be enough. Walkinshaw said the FedRAMP PMO and agency CIO organizations need the technical expertise and staffing required to evaluate a rapidly changing cloud security environment. A company can complete the FedRAMP process and still encounter delays if the agency seeking to use the product does not have enough people to review the package and issue an authorization to operate.

The federal government must therefore find better ways to recruit and retain technology and cybersecurity talent. Otherwise, certifications may continue to become stalled inside agency approval processes.

Walkinshaw also wants the government to make more progress on reciprocity and reuse. Companies still report having to repeat parts of the work they completed during FedRAMP when they approach an individual agency.

“We’ve made progress in that regard,” he said, “but I still want to find more ways to close the gap.”

Agencies must continue making their own risk decisions, but reuse should mean something in practice. Reducing duplicative work would allow agencies to adopt secure technology faster and give providers a more predictable path into the federal market.

For Walkinshaw, that is the broader promise of FedRAMP reform: a system that protects government information without allowing unnecessary process to stand between agencies and the technology they need.