Presented by Carahsoft
Turning FedRAMP Progress Into Lasting Reform
Rep. James Walkinshaw of Virginia’s 11th Congressional District discusses the opportunity for Congress, GSA, federal agencies and industry to build on the progress made through FedRAMP’s modernization. Walkinshaw says future reauthorization efforts should strengthen collaboration across the FedRAMP community while ensuring the program and agency CIO organizations have the technical expertise and staffing required to evaluate cloud technologies and complete authorizations efficiently. He also emphasizes the need to reduce duplicative work after a product earns FedRAMP certification, arguing that stronger reuse can give agencies more secure technology choices, lower costs for taxpayers and prevent certifications from becoming stalled within individual agency approval processes.
Key Takeaways
- Congressional reauthorization offers an opportunity to institutionalize recent FedRAMP improvements.
- Agency CIO offices need sufficient staffing and technical expertise to evaluate evolving cloud security risks.
- FedRAMP certification should reduce—not recreate—security review work at the agency level.
- Greater reciprocity and reuse can expand agency technology choices while reducing taxpayer costs.
- Collaboration among Congress, GSA, agencies and industry will be essential to maintaining momentum.
Opening the Federal Market to Mission-Focused Innovators
Drew Mykelgard, Executive Director of Federal Programs at Carahsoft, explains why federal agencies need a broader range of technology providers participating in the government market. Smaller companies can often develop highly specialized capabilities that address narrow but important mission requirements, but they must also be prepared to meet the government’s elevated security expectations. Mykelgard says vendors should treat security as a foundational responsibility rather than something added at the end of product development. He also reflects on the federal government’s movement away from annual, paper-based compliance reviews and toward continuous evaluation, automation and security outcomes that more closely reflect the pace and sophistication of modern cyber threats.
Key Takeaways
- Federal missions often require specialized solutions that can come from smaller, highly focused companies.
- Technology providers must build security into their products from the beginning.
- Working with government can be difficult, but mission commitment helps companies navigate acquisition and security requirements.
- Federal agencies benefit when industry brings modern product development and security practices into government programs.
- Continuous evaluation will increasingly replace annual, documentation-heavy security reviews.
From Compliance Program to Continuous Trust Platform
Ryan Hoesing, Chief of Staff for FedRAMP, and Pete Waterman, Director of FedRAMP at the General Services Administration, describe the fundamental shift taking place through FedRAMP 20x. Instead of relying primarily on point-in-time assessments and hundreds of checkbox controls, FedRAMP is moving toward persistent validation, machine-readable security data and evidence showing how organizations actually perform over time. Waterman says agencies need visibility into how quickly providers respond to vulnerabilities—not merely written plans describing what they intend to do. Hoesing explains that persistent validation may be based on time, system changes, deployments or suspicious telemetry, allowing agencies and providers to focus resources on meaningful security events. They also stress that FedRAMP certification provides agencies with reusable evidence, but agencies must still examine that evidence and make risk decisions based on their own missions and data.
Key Takeaways
- FedRAMP is shifting from static compliance documentation to continuous security assurance.
- Agencies will increasingly evaluate providers using real performance data and response metrics.
- Persistent validation can be triggered by deployments, system changes, telemetry or defined time intervals.
- Machine-readable security information will make it easier for agencies to consume and analyze provider data.
- FedRAMP certification supports reciprocity, but it does not replace an agency’s responsibility to make risk decisions.
- Cloud service providers must provide the evidence and assurance needed to earn and maintain agency trust.
Balancing Security, Performance and Cost Across the Cloud
Michael Cardaci, CEO of FedHIVE, explains how agencies can balance security, performance and cost by aligning cloud architecture with mission requirements and the sensitivity of the data involved. Rather than treating every workload the same, Cardaci says agencies should evaluate how many people could be affected by a security incident, how damaging exposure would be and where the workload should reside across on-premises infrastructure, private cloud environments and hyperscale commercial platforms. As cloud services become operational environments rather than simply storage destinations, agencies must account for more users, more access points and increasingly distributed work. Cardaci says the move toward near-real-time awareness of security posture represents an important step beyond documented compliance and toward operational security.
Key Takeaways
- Security, performance and cost can be balanced when decisions are tied to mission and data sensitivity.
- Agencies should assess both the number of people affected and the potential severity of a data compromise.
- Cloud strategies will continue to blend on-premises systems, private clouds and hyperscale environments.
- Remote and distributed access creates additional security considerations for cloud-based operations.
- Agencies need ongoing awareness of their security posture rather than point-in-time documentation.
- Operational security should take precedence over simply demonstrating documented compliance.
Connecting Data, AI and Security Across the Federal Enterprise
Darryl Peek, Vice President of Partner Sales for U.S. Public Sector at Elastic, discusses how agencies are rethinking data architecture to improve mission outcomes, control costs and support artificial intelligence at the edge. Peek says agencies are moving away from exclusively centralized models and toward distributed or data-mesh approaches that allow users and applications to reach data where it resides. This shift is especially important for disconnected, hybrid and edge environments across defense and civilian missions. He also highlights the growing importance of observability and continuous monitoring as agencies seek to connect infrastructure, cybersecurity and business data. Open telemetry, automation and AI-assisted analysis can help agencies identify threats, reduce swivel-chair operations and turn large volumes of data into actionable intelligence.
Key Takeaways
- Distributed data architectures can improve access to insights while reducing movement and infrastructure costs.
- Agencies are increasingly exploring AI capabilities for disconnected and edge environments.
- Leaders need greater visibility into both upfront and hidden costs associated with data and AI platforms.
- Observability connects system performance, security activity and mission data.
- Continuous monitoring is increasingly important as AI accelerates both defensive and offensive cyber operations.
- Open telemetry can help agencies integrate information from legacy, cloud and multi-cloud environments.
- AI can support faster decisions, while human oversight remains important for higher-risk actions.
Replacing Cybersecurity by PDF With Operational Visibility
Branko Boken, Chief of the Architecture and Engineering Center of Excellence at the Cybersecurity and Infrastructure Security Agency, explains how trust can help agencies use cybersecurity as an enabler of innovation rather than a barrier to adoption. Boken says complex and expensive compliance processes have made it more difficult for smaller providers and agencies to participate in the federal cloud ecosystem without necessarily producing better security. The alternative is greater operational visibility through machine-to-machine communication, machine-readable data and information delivered in “cyber-relevant time.” He says humans can no longer process the volume of security information generated by modern systems, making automation essential. Boken also highlights secure configuration baselines, CISA cyber directives and Secure by Design principles as important tools for reducing vulnerabilities before software reaches production.
Key Takeaways
- Trust is essential to accelerating secure cloud adoption across government.
- Expensive compliance processes can become barriers without necessarily improving security outcomes.
- Machine-to-machine communication is necessary to process modern volumes of cybersecurity data.
- Security information must be available in machine-readable formats and delivered when it is operationally relevant.
- Agencies need to distinguish valuable telemetry from noise and continually reevaluate what data they collect.
- Cloud providers can support adoption by offering transparent security evidence and secure configuration baselines.
- Secure by Design practices can reduce the number of preventable vulnerabilities shipped to customers.
Building Zero Trust Into the Software Supply Chain
Avery Lyford, Vice President of Commercial Partnerships at RapidFort, discusses the next stage of zero trust: applying its principles directly to software development and the software supply chain. As agencies rely more heavily on open-source components, prefabricated code and AI-assisted development, Lyford says organizations must understand where every software component originated, what it contains and whether known vulnerabilities have been addressed. Modern development is increasingly an act of composing existing components rather than writing every line of code from scratch, making traceability and trusted building blocks critical. Lyford argues that security must shift left into development so vulnerabilities can be addressed before systems reach production. Agencies should also plan for new attack methods that emerge after deployment by maintaining the ability to identify, isolate and remediate threats throughout the software lifecycle.
Key Takeaways
- Zero trust must extend beyond identity and networks into software architecture and development.
- Agencies need visibility into the origin and composition of every software component.
- AI-assisted development can increase speed, but it also introduces new software supply-chain risks.
- Trusted and continuously maintained open-source components provide a stronger foundation for mission applications.
- Security should be designed into development rather than tested only after deployment.
- Traceability for software and code should be treated with the same seriousness as physical supply-chain traceability.
- Zero trust software architectures must support detection, isolation and remediation as new threats emerge.
