July 28, 2026
Julie Dunne believes FedRAMP is entering one of the most significant periods of change since the program was first established. Following the recent FedRAMP summit, the former Federal Acquisition Service commissioner at the General Services Administration says the government's new FedRAMP 20x initiative introduces meaningful improvements, but agencies and cloud providers are still working through what those changes mean in practice.
Dunne reflects on FedRAMP's evolution over more than a decade, recalling discussions from her time on the House Oversight Committee about whether an Office of Management and Budget memorandum alone would be enough to establish the program. She notes that Congress later codified FedRAMP into law and says she is encouraged to see lawmakers already beginning conversations about reauthorizing the program before the current authorization expires in December 2027.
While she praises the FedRAMP Program Management Office for driving change, Dunne acknowledges that implementing government-wide transformation is never easy. She points to automation and real-time engagement as two of the strongest features of FedRAMP 20x but says many organizations remain uncertain about how quickly agencies will embrace the new approach. She also hears concerns about differences between civilian agencies and the Department of Defense, particularly around how cloud providers will navigate varying security expectations as the program evolves.
According to Dunne, the federal cloud landscape has changed dramatically since FedRAMP launched in 2011. Cloud technologies have matured, cybersecurity threats have intensified, and agencies now rely on cloud services in ways that were difficult to anticipate when the program began. Despite those changes, she says the program's core principles remain the same: avoiding duplication, promoting reuse, and ensuring secure cloud solutions across government. The discussion today, she says, centers on how those goals are implemented rather than whether they still matter.
One of the biggest challenges, Dunne explains, is helping agencies adapt to a different way of evaluating cloud security. She says continuous risk monitoring and automation are becoming essential parts of modern cybersecurity, replacing approaches that rely on a single point-in-time assessment. At the same time, she emphasizes that agencies and cloud providers need clear guidance during the transition. She cautions against creating a situation where vendors must prepare different authorization packages depending on which federal customer they are serving.
Dunne believes much of the hesitation surrounding FedRAMP 20x stems from the realities of organizational change. Federal agencies are balancing numerous technology priorities, and many organizations, particularly in the civilian sector, face staffing and resource constraints. Security officials are accustomed to reviewing authorization packages a certain way, and they now need to understand new expectations while continuing to approve their own authorities to operate. She also notes that agencies have different risk profiles, meaning adoption will naturally vary across government.
To help smooth the transition, Dunne suggests there may be an opportunity for broader government-wide guidance tied to agency budgeting and implementation planning. She also sees value in ongoing congressional attention as lawmakers consider the future of the program through the upcoming reauthorization process.
The conversation also explores how FedRAMP fits into the Pentagon's cloud environment. Dunne notes that the Pentagon has previously used FedRAMP Moderate as a baseline for broader security discussions, but says questions remain about how evolving defense requirements, FedRAMP 20x, and existing Rev. 5 investments will align. She points out that proposed changes to the Federal Acquisition Regulation and references to existing standards create additional uncertainty as organizations decide where to invest.
Looking ahead, Dunne returns to one of FedRAMP's original goals: reusability. She says agencies will always make risk-based decisions for their own environments, but they should be able to rely on a common security baseline rather than repeatedly evaluating the same information. That approach, she says, reduces costs for cloud service providers while helping agencies adopt secure cloud technologies more efficiently. Even with many moving parts still to address, Dunne says the upcoming reauthorization debate will be an important opportunity to strengthen the program for the future.
