GSA seeks to boost understanding of FedRAMP 20x overhaul

Douglas Rissing/Getty Images

The cloud security program is looking to educate both agencies and private companies on the ways the revamped program differs from previous requirements.

The General Services Administration is seeking to communicate new FedRAMP rules to agencies and private companies, which the program’s security director said on Thursday are sometimes confused with legacy rules.

“A lot of people, instead of using an AI agent to go through the rules or to try to find their answer directly in the rules, they’re googling, or they’re relying on past advice … so we’re doing a lot of trying to message ‘hey, this is the new FedRAMP; this is how things work now,’” FedRAMP Security Director Nicole Thompson said at the GovCIO Media & Research Federal Cloud & Data Forum. 

FedRAMP now uses GitHub discussion boards, hosts community updates on a YouTube channel and has expanded its help desk to communicate with its stakeholders, according to a blog post updated Thursday. 

Thompson’s comments come as GSA is currently in phase three of a five-phase 20x rollout, a major reform effort designed to speed up the authorization of cloud services by cutting red tape and pushing companies to automate certain FedRAMP requirements. GSA’s push to clarify 20x rules matters because FedRAMP serves as a key market access point for cloud service providers doing business with agencies.

Through phases one and two of the 20x rollout, GSA has tested new cybersecurity rules with multiple cloud service providers.

“We were able to develop [20x processes] in real time, make adjustments to the rules that weren't clear, and so a lot of the very beginning was managing a lot of frustration about too much information happening all at one time,” Thompson said of 20x pilots.

“Over the last year and a half, people have adjusted,” Thompson added.

Now in phase three, GSA is formalizing FedRAMP 20x requirements from phases one and two while supporting new Class A, B and C certification types, according to the FedRAMP website. Phase four will pilot Class D certifications and phase five will end new certifications for legacy Rev5 offerings, the website says.

But agencies like the Centers for Medicare and Medicaid Services continue to have questions about the new FedRAMP regime. 

CMS has been asking FedRAMP questions to help speed up authorizations for cloud services it is sponsoring, Leslie Nettles, the agency’s acting deputy chief information security officer, said at the Thursday event.

“People are just hungry for what is the ground truth? Like, what do I need to pay attention to? Because Google [search] is full of complaints from old FedRAMP guidance,” Thompson said.

Thompson’s emphasis on 20x education is the latest public acknowledgement of the challenges the flagship cloud security program faces. The FedRAMP director recently told companies that are slow to patch known vulnerabilities they should not sell their cloud services to agencies, particularly after OpenAI models escaped a restricted testing environment and breached Hugging Face’s production infrastructure.

Amid the emerging challenges, some cloud service providers are reporting satisfaction with the security standards FedRAMP has set.

“Think about all the breaches that happen … most of the time, when it's those cloud systems, it's not the FedRAMP instance of that system that's getting breached,” Anish Patel, head of federal for Cloudflare, said Thursday. 

“In reality, if we could make a world where the FedRAMP stuff could be applied across the board, it would raise the floor for everything,” he added.