
Matt Chaiko
Lead Principal, Advisory Services, Coalfire
FedRAMP®


The FedRAMP Program has “opened the conversation” about potentially charging cloud service providers (CSPs) for undergoing the FedRAMP authorization process. In its blog post, “Exploring New Ways to Scale FedRAMP”, published on December 20, the FedRAMP Team acknowledged its current inability to meet the growing demand for FedRAMP authorizations and identified additional funding as a potential solution. The post outlines the benefits of new funding, such as hiring more reviewers, launching pilot programs, and increasing centralized oversight. To be clear, no decision has been made yet; the FedRAMP Team is in the early stages of exploring how a fee structure could be implemented fairly for CSPs of all sizes.
Let’s be honest. As a member of the FedRAMP CSP, Advisory, or 3PAO communities, your gut reaction to this proposal was likely, “Are you kidding me?” While this blog isn’t intended to outright dismiss the idea of charging CSPs, it would be disingenuous not to address the elephant in the room: Why should CSPs be held responsible for the FedRAMP Team failing to scale? Many CSPs, having navigated the initial authorization process, understand that the review system is slow and inefficient. However, expecting CSPs to fund these optimizations—despite the substantial investments already required in achieving and maintaining FedRAMP authorization—raises concerns.
The FedRAMP blog states, “For years now, federal agencies, companies, Congress, and a series of administrations have made clear they value what FedRAMP does and want to see the program scale and the marketplace grow well beyond what it is today.”
If this is true, why isn’t the federal government providing adequate funding to ensure the program runs efficiently? Companies (CSPs) are already making significant investments. According to an independent third-party study, the initial cost of FedRAMP authorization for a CSP averages $2 million. This includes expenses such as hiring specialized personnel, obtaining advisory services, security tool license costs, and third-party assessment costs. Growing investments in FedRAMP by CSPs is what pushed the program beyond its capacity in the first place. That leaves the agencies, Congress, and the current administration - What additional support will they be providing to help the FedRAMP Team scale?
The FedRAMP Team has asked the CSP community for feedback on designing a fair cost model. Here are my responses to two of the questions posed:
The cost model should be based not on business size but on the complexity of the cloud service offering (CSO) and the effort required for the FedRAMP Team to perform package reviews and continuous monitoring. Factors to consider include:
Whatever the cost model, it must be standardized and transparent to prospective CSPs.
The FedRAMP program has provided immense value since its inception and played a major role in enhancing the cybersecurity posture of the federal government. But I question whether additional funding and expansion of the FedRAMP Team is the best path forward. It may be time to reassess the current FedRAMP model entirely. In particular, the FedRAMP Team's package review process.
Does the FedRAMP Team review provide enough value to agencies to justify expanding the program? Or would the more efficient approach be to eliminate the FedRAMP Team review for agency authorizations?
Every agency is responsible for reviewing its CSPs' packages, assessing the associated risks, and issuing ATOs accordingly. As a result, each CSO undergoes an initial and annual assessment by an accredited 3PAO, detailed reviews by its agency customers, and a FedRAMP Team review.
Removing the FedRAMP Team review would align with the CMMC methodology, where the DoD CIO CMMC PMO provides oversight and defines program requirements but does not grant accreditations or conduct package reviews. This shift would allow the FedRAMP Team to focus on refining requirements, collaborating with agencies and CSPs, and enhancing continuous monitoring.
Additionally, this change could support the new FedRAMP Program Authorization model, where the FedRAMP Team directly authorizes CSPs without an agency partner. By limiting its reviews to CSPs pursuing a Program Authorization, FedRAMP could scale the program without requiring additional funding. CSPs might also be more receptive to a fee-based model for Program Authorizations, as it provides them with an opportunity to achieve FedRAMP authorization that would otherwise be unavailable without an agency sponsor.
The FedRAMP Team is seeking feedback from the industry to design a fair pricing model for CSPs of all sizes. This is an opportunity to influence the future of the FedRAMP program. Submit your feedback by February 28 using this Smartsheet form.
Join us at the PCI Community Meeting September 16-18, where Coalfire will be showcasing our latest advancements in cybersecurity and compliance.
Learn more