There is a legitimate debate over the burden FedRAMP places on cloud service providers, particularly small businesses attempting to enter the federal market. Authorization can be expensive, technically demanding and difficult to navigate, and those concerns are supported by more than simple anecdotes. In 2024, the Government Accountability Office (GAO) identified six key challenges faced by selected agencies and cloud service providers pursuing FedRAMP authorizations, including insufficient resources, difficulty meeting technical and process requirements, problems finding agency sponsors and inconsistent experiences with third-party assessment organizations [1]. GAO also separately found that estimated authorization costs ranged from tens of thousands to millions of dollars, while cautioning that inconsistent cost-tracking methods made actual costs difficult to determine [2].
Those findings support the argument that FedRAMP needs reform. However, they do not establish that FedRAMP is unnecessary. The more important question is what part of the process should become easier, because reducing administrative friction is not the same thing as reducing the security discipline required to operate a cloud service for the federal government.
Documentation Is Operational Infrastructure
Much of the criticism directed at FedRAMP treats documentation as though its primary purpose is to satisfy an assessor. That framing confuses documentation produced solely for an assessment with documentation required to operate a sustainable security program: policies establish expectations and accountability; procedures describe how those expectations are carried out; system security plans define boundaries, architecture and control implementation; configuration baselines identify the state from which changes and deviations can be measured; and risk assessments identify key risks to the business. Taken together, those artifacts create the organizational structure that allows a security program to function consistently rather than depend on individual memory.
That distinction is especially important for small businesses, where security, compliance, engineering and administrative responsibilities may be concentrated among a handful of employees. A company may operate effectively while the people who designed its environment remain in place, but undocumented knowledge becomes a material risk when those employees leave, change roles or simply forget why a decision was made. If only one administrator understands why a firewall rule exists, if only one engineer knows where federal information flows or one security manager knows how an incident must be escalated, the organization has not created institutional knowledge. It has created dependency on particular individuals.
FedRAMP Must Address What Happens After Authorization
Congress established FedRAMP as a government-wide program providing a “standardized, reusable approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies,” [3]. While assessment is certainly part of that model, authorization is only one point in the life of a cloud service. Accounts change, employees depart, software is updated, vulnerabilities emerge, new integrations are introduced and configurations drift. A system that satisfies an assessment at one moment can begin moving away from its approved security posture almost immediately afterward.
A mature assurance program therefore requires three related elements: documentation that defines the intended environment, implementation that puts those requirements into operation and evidence showing that the implementation continues to function as intended. Removing documentation weakens the first element just as surely as weak technical controls weaken the second. Continuous monitoring cannot establish whether a system has drifted unless the organization has first defined the state from which drift is being measured.
FedRAMP 20x Should Strengthen That Relationship
FedRAMP 20x is important because it offers a way to reduce the cost of demonstrating security without abandoning the governance structure necessary to maintain it. FedRAMP describes 20x as “a new approach to cloud security assessment and authorization” focused on security decisions, continuous measurement and progressively increasing commitments to government-specific needs [4]. The program has finalized its 20X rules for Classes A, B and C, while Class D remains a later phase of the program [5].
These classes also illustrate an important point about proportionality. FedRAMP describes Class A as an entry path for cloud services with mature security and compliance programs, Class B as appropriate for fairly common small-scale or lighter-use services, and Class C as intended for common enterprise services likely to be used across an agency or to support important government services [5]. The distinction is based on the level of assurance and the expected federal use of the service, not on whether the company providing it qualifies as a small business.
The Key Security Indicators underlying 20X reinforce rather than eliminate the need for documentation. They address matters such as incident-response procedures, configuration management, changes to services, training, account management, vulnerability detection and the persistent verification of security outcomes [6]. These mechanisms do not replace governance; they provide better ways to determine whether the documented governance model is reflected in the live environment. Automation can identify drift, but there must first be an established state from which drift can be measured.
OMB’s 2024 modernization memorandum M-24-15 makes the relationship particularly clear. It directs FedRAMP to automate the intake and processing of “machine-readable security documentation, continuous monitoring data, and other relevant artifacts” and states that doing so should reduce participant burden and accelerate cloud adoption [7]. Elsewhere, the memorandum directs FedRAMP to receive authorization and continuous-monitoring artifacts as machine-readable data through APIs to the extent feasible [8]. Modernization, in other words, does not require choosing between documentation and automation. It changes the form in which security information can be maintained, exchanged and evaluated.
Reduce Redundancy, Not Discipline
There is substantial room to make FedRAMP less burdensome for small businesses. Evidence that already exists should not be manually recreated simply because an assessment process expects a different format. Machine-generated information should be reusable, assessment expectations should be consistent, and automated evidence should replace repetitive manual collection where automation produces better information. The FedRAMP Consolidated Rules for 2026 bring rules, definitions, timelines, stakeholder guidance, and source material into a common public reference and provide machine-readable source data for automation services and other tools [9].
Nevertheless, none of those reforms change the underlying requirement for an organization to understand and govern its own security environment. A small cloud provider should not need a large compliance department merely to explain how its security program operates. It should nevertheless be able to identify where federal information resides, who can access it, how systems are configured, how vulnerabilities are addressed, how incidents are escalated, and who owns each security responsibility.
When an organization cannot answer those questions consistently, FedRAMP has not created the weakness by requiring documentation. It has exposed a weakness that already existed.
The strongest promise of FedRAMP 20x is therefore not a future in which documentation disappears; it is a model in which documentation defines the security program, engineering implements it, and increasingly automated evidence shows whether the organization continues to operate as designed. That approach can make FedRAMP less expensive and less repetitive without confusing ease of assessment with adequacy of security.
For small businesses seeking federal work, that distinction matters. The process can and should become easier to navigate – the obligation to maintain a defensible security program should not.
References
[1] U.S. Government Accountability Office, Cloud Security: Federal Authorization Program Usage Increasing, but Challenges Need to Be Fully Addressed, GAO-24-106591, Jan. 18, 2024, “What GAO Found,” table “Key Challenges Faced by Agencies and Cloud Service Providers (CSP) When Pursuing FedRAMP Authorizations.”
[2] GAO-24-106591, “What GAO Found,” finding that FedRAMP authorization cost estimates “varied widely” and ranged from tens of thousands to millions of dollars; GAO attributed part of that variation to differing methods of determining costs.
[3] 44 U.S.C. § 3608, second sentence, establishing FedRAMP as a government-wide program providing a standardized, reusable approach to security assessment and authorization for cloud services processing unclassified agency information.
[4] FedRAMP, FedRAMP 20x: A Different Model for Cloud Assurance, introductory description of 20x and its emphasis on security decisions, continuous measurement and progressively increasing government-specific commitments.
[5] FedRAMP, FedRAMP 20x, “FedRAMP 20x is here,” including the current status and descriptions of Class A, Class B and Class C and the identification of Class D as Phase 4.
[6] FedRAMP Consolidated Rules for 2026, 20x Key Security Indicators and associated Class A–C certification rules.
[7] Office of Management and Budget, M-24-15, Modernizing the Federal Risk and Authorization Management Program (FedRAMP), July 25, 2024, discussion of “Streamlining processes through automation,” specifying machine-readable security documentation, continuous-monitoring data and other artifacts and linking automation to reduced participant burden.
[8] OMB M-24-15, § V, “Automation and Efficiency,” directing FedRAMP to receive authorization and continuous-monitoring artifacts as machine-readable data through APIs to the extent feasible.
[9] FedRAMP, Consolidated Rules for 2026, overview describing a common public reference containing rules, definitions, timelines, stakeholder guidance and source material, with separate machine-readable source data.