The conversations recorded at the Carahsoft Summit on FedRAMP revealed a federal cloud security community moving toward a fundamentally different model of trust. Across Congress, government and industry, leaders repeatedly returned to the same conclusion: security can no longer be demonstrated primarily through static documents and periodic assessments. Agencies need current evidence about how systems operate, where their data is moving, how quickly providers respond and which vulnerabilities present genuine mission risk.
That transformation is central to FedRAMP’s next chapter, but it reaches well beyond the authorization program. It is reshaping federal acquisition, zero trust, software development, hybrid infrastructure and the relationship between government and its technology providers.
Rep. James Walkinshaw of Virginia’s 11th Congressional District said recent efforts to streamline FedRAMP and reduce its backlog have created an opportunity for lasting reform. Future reauthorization, he argued, should strengthen collaboration among Congress, GSA, federal agencies and industry while ensuring government organizations have the technical personnel needed to evaluate modern cloud environments.
That progress could still be undermined if agency CIO offices lack the expertise or staffing to act on a FedRAMP certification. Walkinshaw also called for continued improvements in reciprocity so providers are not required to repeat work as they move from FedRAMP certification into an individual agency authorization process.
For Rashaan Green, Vice President of Security at Second Front Systems, the evolution Walkinshaw described must ultimately produce a more current picture of operational risk. Green expects federal agencies to move toward continuous evaluation of authorizations to operate and the security posture of the systems supporting their missions.
AI and automation can help agencies answer immediate questions that periodic compliance reviews often cannot: Is the system reachable? Is it exploitable? What would the blast radius be if an attacker succeeded?
Previously, Green said, security teams had to filter through enormous amounts of data before making that distinction. AI and automation can help them reach the relevant information within minutes and make a decision based on the mission environment.
FedRAMP Director Pete Waterman and Chief of Staff Ryan Hoesing described how FedRAMP 20x is intended to support that transition. Rather than asking only whether hundreds of security controls were present during an audit, the government can examine evidence showing how those controls perform over time.
“We need compliance built in with engineering,” Waterman said, “and we need everyone moving fast together.”
That shift requires security data that machines can consume. Agencies cannot depend on employees manually reviewing extensive spreadsheets and documents while systems and threats evolve at machine speed. FedRAMP leaders instead envision persistent validation triggered by deployments, configuration changes, suspicious activity or an appropriate time interval.
Continuous assurance is only useful when agencies understand the environments they are attempting to secure.
Chris Szostek, Head of Public Sector Channels at Skyhigh Security, cautioned federal leaders against treating zero trust as either an identity-only project or a wholesale rip-and-replace initiative.
I
“True zero trust needs to also ask, what are you accessing? What are you trying to do? And should you still be allowed to do it?” Szostek said.
At the other extreme, replacing an entire environment too quickly can ignore the realities of federal missions. Many defense and intelligence organizations cannot move every workload into the cloud for operational, security or economic reasons.
That reality has produced hybrid environments in which applications, users, workloads and data move across cloud and on-premises infrastructure. The goal should not be to maintain separate security postures for each environment, Szostek said, but to extend consistent policies across both.
The difficulty is that agencies may not understand those environments as well as they believe they do. Shadow IT, personal email, public AI tools and other workarounds can create gaps that remain invisible until an organization closely examines how information is actually moving.
Szostek said agencies sometimes begin by describing their security posture as airtight, only to discover that employees have placed sensitive information into public AI applications or sent government data to personal devices.
His advice is to avoid beginning with a predetermined technology ideology.
“You have to start with the mission first,” Szostek said.
Some workloads benefit from cloud elasticity. Others may require on-premises controls. The appropriate architecture depends on the mission, traffic, data and existing environment—not on a universal mandate to move in one direction.
Compliance requirements were created to improve security, but Boken said they have sometimes become expensive barriers for providers and agencies without necessarily producing better outcomes.
“We made security extremely difficult and extremely expensive,” he said.
That burden can be particularly damaging to smaller providers attempting to enter the federal market. It can also prevent smaller government organizations from purchasing secure cloud capabilities because the cost of satisfying the process becomes too high.
Modern systems generate more information than human analysts can process. Agencies therefore need machine-to-machine communication, machine-readable telemetry and data delivered in what CISA calls “cyber-relevant time.”
That does not mean every signal must arrive instantaneously. An active incident may require immediate data, while a later investigation may depend on logs preserved for weeks. The objective is to provide the right information when defenders need it.
Operational visibility also gives agencies a better foundation for acquisition. Providers should be able to demonstrate what they are doing to protect their systems and show customers that relevant security data will remain available after implementation.
That transparency can become a stronger source of confidence than a static declaration that a product has satisfied a requirement.
Boken also emphasized secure configuration baselines and Secure by Design principles. Providers should help agencies understand how to deploy their products securely, while developers should reduce preventable vulnerabilities before software reaches federal customers.
Green carried that concept into the development pipeline. He said agencies should stop attaching security after a process or product has already been designed.
“Security should be in the passenger seat shotgun from day one,” Green said.
Security gates embedded throughout a continuous authorization process can create checkpoints before an application advances to the next stage. Automated evidence can then replace many of the manual screenshots and reviews that previously consumed the time of security teams without providing a live picture of risk.
“There’s such a wide variety of mission sets,” Mykelgard said.
Agencies may need niche products that large providers would never develop. He pointed to a Department of Veterans Affairs application created by veterans to help other veterans stop smoking. It addressed a focused but meaningful mission need without requiring the resources of a global software company.
Smaller providers can introduce specialized products and modern development practices into government, but they must recognize that federal participation carries significant security responsibilities.
“Our systems have to be safe and secure,” Mykelgard said.
Federal agencies hold tax records, health information, student loan data and other information that citizens expect them to protect. A breach can damage more than an individual system. It can weaken confidence in government services and discourage people from using programs intended to help them.
Mykelgard acknowledged that working with government remains difficult. Acquisition and security processes can be painful, particularly for companies without large compliance organizations. Yet the providers that persist are often deeply committed to the mission and willing to work with agencies on long-term product development.
Government should make that process easier where possible, but not by weakening security. The more effective approach is to replace repetitive documentation with continuous evidence showing how a provider protects its systems.
That idea connects the government and industry perspectives heard throughout the summit. Companies need a more predictable and efficient way to enter the federal market. Agencies need stronger assurance that the technology will continue to operate securely after an authorization is granted.
Continuous evidence can serve both objectives.
Across the conversations, FedRAMP emerged not simply as a certification program, but as part of a wider effort to bring federal cybersecurity closer to the speed of modern technology.
Walkinshaw’s call for stronger reuse and a more capable federal workforce, Mykelgard’s emphasis on opening government missions to specialized providers, Szostek’s mission-based approach to hybrid zero trust, Green’s focus on continuous risk decisions and Boken’s demand for machine-readable operational visibility all point in the same direction.
The government is moving away from processes that show what was true during an audit and toward systems capable of revealing what is happening now.
That change is becoming more urgent as AI and autonomous technologies expand the scale and speed of cyber activity. Waterman warned that the government is entering an environment in which automated systems may be able to find and exploit internet-facing vulnerabilities across a massive number of targets.
“We have to be prepared to respond at the speed of autonomous systems,” he said.
FedRAMP can establish the framework for that response, but certification alone cannot create trust. Providers must supply meaningful assurance, agencies must examine the evidence, and government leaders must make risk decisions based on the mission rather than a checklist.
As Waterman put it, “FedRAMP provides the framework, but it’s always going to be on the cloud service provider to provide the assurance.”
The government is not lowering its cybersecurity expectations. It is attempting to replace slow and expensive processes with a model that is more transparent, more continuous and more closely connected to actual risk. The success of that transition will depend on whether agencies and providers can turn the summit’s shared principles—automation, visibility, secure development and mission-based decision-making—into the normal way federal cloud security operates.