Federal Procurement Policies Governing Cloud Services
Federal agencies navigate overlapping policies to spend billions on cloud services.

Federal agencies spent roughly $16.7 billion on cloud contracts in fiscal year 2024, and that number is supposed to climb past $21 billion by fiscal year 2028. That money moves through a stack of overlapping policies, security gates, and contract vehicles, and vendors have to learn the whole stack at once or they end up filing paperwork for a program that quietly closed eighteen months ago. I've watched people make that exact mistake, more than once. This piece walks through the stack, layer by layer, starting with the policy shift that got us here.
One number worth sitting with before we go further: the government cloud market worldwide was valued at $32.01 billion in 2024, and it's supposedly headed toward $80.90 billion by 2030. The U.S. federal government isn't the whole market, but it's the single biggest customer in the room, and the rules it writes for itself tend to leak into everyone else's rulebook eventually.
The foundational policy shift from Cloud First to Cloud Smart
OMB's Cloud First mandate landed in 2010, and it was blunt on purpose: agencies had to consider cloud whenever it was feasible. That was the whole instruction, and it carried huge downstream consequences with almost no guidance on what happens after an agency says yes. It worked in the narrow sense that agencies started adopting cloud. Yet it also produced a pile of half-finished migrations and security bolted on as an afterthought, because considering cloud and doing cloud well are two very different jobs.
By 2019, OMB retired Cloud First and swapped in Cloud Smart. It sounds like a rebrand, but it isn't one. The substance actually moved: agencies went from a directive to adopt cloud toward a framework for adopting it without blowing themselves up. Cloud Smart rests on three legs: security, procurement, and workforce. That third leg is the tell, since this was as much an organizational mandate as a technology one, an admission that you can't buy your way into cloud maturity without also training the people who have to run the thing.
Cloud Smart came with five mandatory procurement requirements. Agency CIOs had to oversee modernization directly instead of handing it off and hoping. Agencies had to keep improving their internal policies instead of writing one document and calling it finished. Cloud SLAs needed standardizing, with steady attention to confidentiality, integrity, and availability, the CIA triad security people have leaned on since long before cloud existed. FedRAMP authorization became mandatory, which is the thread tying procurement policy to the security apparatus we get into next. Agencies also had to keep continuous eyes on their high-value assets, because you can't secure what you're not watching.
None of it had teeth until FITARA showed up. Enacted December 19, 2014, the Federal IT Acquisition Reform Act backed up the CIO's authority and tied the Federal Data Center Consolidation Initiative directly to cloud adoption. Cloud Smart is policy; FITARA is law. Together they're the bedrock everything downstream, every contract vehicle, every security requirement, gets built on top of.
FedRAMP as the mandatory security gate every cloud vendor must pass
Here's the question every cloud vendor eventually asks out loud, usually while on hold with somebody's procurement office: how does one company get cleared to sell to hundreds of federal agencies without redoing a security review each time? The answer is FedRAMP, the Federal Risk and Authorization Management Program, built on an "authorize once, use many" idea. A cloud provider gets vetted once, and any agency can then use that provider without starting the review over from page one.
For years FedRAMP lived as policy, not law, which meant it could bend with whoever happened to be running OMB that year. Congress closed that gap in December 2022, writing FedRAMP into law through the FedRAMP Authorization Act inside the FY 2023 NDAA. That's not a small change, since FedRAMP went from something OMB strongly nudged agencies toward to something agencies are now legally on the hook for.
The same law rebuilt how FedRAMP is governed, swapping the old Joint Authorization Board for a new FedRAMP Board. GSA formally shut down the JAB and stood up the Board in May 2024, almost eighteen months after the law passed. Worth noticing: that gap tells you something about how federal reorganizations actually move, which is rarely as fast as the press release implies.
The traditional path, now called Rev5, is thorough to the point of being glacial. Vendors have to meet NIST SP 800-53 Rev 5 controls, find a sponsoring agency willing to walk them through the process, and produce documentation the FedRAMP PMO reviews by hand. Low and Moderate authorizations historically took eighteen months or more, and High took longer still. In July 2024, OMB issued M-24-15, telling agencies to start reporting what FedRAMP authorization actually costs to pursue. Putting a dollar figure on it confirmed what a lot of people already suspected: the process was too slow and too expensive.
Here's the part that should genuinely worry a smaller vendor eyeing federal work. An eighteen-month wait is itself a wall, and a startup with six months of runway in the bank cannot sit around for a year and a half hoping for a green light. FedRAMP, in its original shape, ended up functioning as much like a bouncer as a security check, and the companies it kept out weren't always the risky ones. Sometimes they were just the broke ones.
FedRAMP 20x: what the 2025–2026 overhaul changes for vendors and agencies
GSA announced FedRAMP 20x on March 24, 2025, and it's the biggest structural shake-up the program has seen since it launched. The core idea: stop reading thousands of pages of manual documentation and start checking security controls automatically, using something GSA calls Key Security Indicators. The stated goal is automating at least 80% of FedRAMP's security requirements. Maybe that number holds up once it meets real vendors and real auditors, maybe it doesn't; either way, the direction is obvious. Less paperwork, more evidence a machine can check on its own.
If the pilot pathway holds, the timeline shift is dramatic. Low and Moderate authorizations that used to eat eighteen-plus months are targeted to run around three months under 20x. It's the same program name attached to what's nearly a different program.
A handful of structural changes are already locked in. The PMO stopped doing second-level reviews of authorization packages after March 2025, so agencies now make their own risk calls with no federal referee double-checking the homework behind them. Centralized continuous monitoring, which used to be a JAB job, ended that same month, and each agency now watches the providers it actually uses. Significant Change Requests, which took three to four months because a vendor had to ask permission before making a material change, got replaced by Significant Change Notifications, which let a vendor report changes after they've made them instead of waiting on a yes.
There's a quieter shift buried in here too: 20x drops the agency sponsorship requirement. That alone lowers the wall for vendors who never had a federal customer willing to sponsor them through Rev5 in the first place.
January 2026 brought six new Requests for Comment, numbered 0019 through 0024, aimed at finishing the modernization job. These introduce "FedRAMP Certified" and "FedRAMP Validated," splitting program-level authorization from an individual agency's Authority to Operate. That distinction actually matters, because "FedRAMP authorized" has been used loosely to mean three or four different things over the years, and separating the program's stamp from an agency's own risk call clears up confusion that's dogged the whole system for a while now.
The sunset dates matter as much as the launch date did. FedRAMP plans to retire the Rev5 Low and Moderate path by mid-FY27, and the High path by end of FY27. So vendors sitting in a Rev5 pipeline right now have roughly two to three years to decide: finish under the old system, or jump ship to 20x. For agencies, the bigger adjustment isn't the paperwork, it's the monitoring responsibility that used to sit with the JAB and now sits squarely on them. That's a staffing problem and a tooling problem before it's ever a checkbox on a form.
The FAR's cloud blind spots and why contracting officers work around them
Now for the part where the government's own rulebook admits it wasn't built for the thing everybody's trying to buy. The Federal Acquisition Regulation is the default legal framework for nearly all federal purchasing, and as of GAO's June 2026 report, the FAR still has no definition of cloud computing. Its definition of information technology is roughly two decades old, and its definition of a commercial product or service doesn't match how cloud actually gets sold.
That last gap is the expensive one. Cloud runs on subscription terms, usage-based billing, infrastructure shared across customers, the kind of arrangement that barely existed when the FAR's commercial item framework got written. Try shoving a SaaS subscription into a box built for buying forklifts, and you get exactly the friction you'd expect.
GAO's June 2026 recommendation is blunt: Congress should require the FAR to get updated with cloud-specific definitions. As of this writing, that gap sits there, documented and acknowledged and still wide open, because admitting a problem in a report and fixing it in statute run on very different clocks.
DoD didn't wait around for Congress. Defense procurement runs under DFARS Subpart 239.76, which spells cloud computing out explicitly: "a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or service provider interaction." It's a dense sentence, sure, but it's an actual definition, which is more than the FAR can currently claim. The catch: DFARS only covers Defense, and civilian agencies are still working out of a rulebook with a cloud-shaped hole punched through the middle of it.
So what do civilian contracting officers actually do with that hole? They route around it, leaning on contract vehicles built with cloud's quirks in mind instead of trying to jam a subscription model into a FAR clause that was never meant to hold it. Which is exactly where those vehicles come in.
The main contract vehicles agencies use to buy cloud services
The GSA Multiple Award Schedule, specifically its Cloud Special Item Number, is the widest door into the federal cloud market. It's open not just to federal agencies but to state, local, territorial, and tribal governments, plus eligible nonprofits, which makes it about the closest thing to a universal on-ramp anywhere in this system. Terms are pre-negotiated, which cuts the contracting burden on both sides, and FedRAMP authorization is baked into the SIN itself as a condition of entry. This is where the security layer and the procurement layer physically bump into each other: no FedRAMP, no seat at this table.
Government-wide Acquisition Contracts, GWACs, are IT-specific vehicles that let multiple agencies buy from one pre-vetted pool of vendors instead of each agency running its own competition from scratch. Executive Order 14240, signed March 20, 2025, told GSA to take over GWAC management across the government, pulling something that used to be scattered across several agencies into one place. GSA stood up an Office of Centralized Acquisition Services to run that transition.
GSA's OneGov Strategy, launched April 2025, pushes the same idea further: the government negotiates as one buyer for common IT needs instead of two hundred agencies each cutting their own separate deal. Since April, GSA has closed several high-impact agreements under OneGov, some knocking prices down dramatically on widely used commercial software. When the federal government shows up as a single customer instead of two hundred small ones, the leverage shows up right there in the invoice.
DoD runs its own operation through the Joint Warfighting Cloud Capability, a multi-vendor cloud vehicle that sits entirely outside GSA's civilian framework, though it still has to answer to FedRAMP and DFARS. JWCC is a good reminder that "the federal cloud market" is a misleading phrase, since it's really several markets wearing a shared set of rules like a trench coat.
Threading through all of it is Executive Order 14271, signed April 15, 2025, which tells agencies to buy commercially available products wherever practical instead of commissioning custom builds. Stack that next to GWAC centralization and OneGov, and a pattern shows up: the number of doors into the federal cloud market keeps narrowing, even while the dollars flowing through those remaining doors keep climbing.
How agency-level decisions layer on top of the government-wide framework
Everything above is the government-wide rulebook. What actually happens inside one agency is where the theory runs into the budget spreadsheet, and the two don't always shake hands.
Take the FedRAMP 20x monitoring shift. Government-wide policy now says agencies own continuous monitoring instead of leaning on a centralized JAB function, which is fine on paper. In practice, that means an agency's internal security staffing decides which vendors it can realistically support, because monitoring a cloud provider costs real people and real tools and real hours, and some agencies have that capacity while others are still trying to hire for it.
Budget behavior tells a similar story. Treasury's cloud services budget jumped from $515 million in FY 2023 to $2.2 billion in FY 2024, one agency's decision, large enough on its own to move the entire federal cloud spending total. Civilian agencies together requested $8.3 billion for cloud in the FY 2025 IT budget, but that single number flattens a lot of real variation in how individual agencies build their cloud portfolios and which vehicles they lean on.
Agencies also write their own guidance on top of the government-wide framework. The Interior Department's PAMOCIO memo from March 2025 is a decent example: it takes the broad Cloud Smart and FedRAMP requirements and translates them for Interior's specific situation, which looks nothing like, say, the Department of Labor's.
Small business participation is worth a second look here too. Small businesses accounted for roughly 5% of federal cloud spending in FY 2021 and climbed to nearly 21% by FY 2023, a jump driven partly by agency set-aside decisions and SBA programs sitting on top of the base procurement rules. That's real progress, but large vendors still dominate the infrastructure and platform layers, capturing 78% of IaaS spending and 70% of PaaS spending in FY 2023. An agency choosing IaaS over SaaS is quietly choosing which tier of vendor wins, whether it frames the decision that way or not.
Reading the current policy environment as a vendor or agency buyer
Walk back through each piece and the shape of the thing is actually pretty legible: Cloud Smart sets the procurement requirements, FedRAMP handles the security piece, the FAR and DFARS and the GWACs supply the contracting mechanism, and agency-level ATOs and monitoring close the loop. Each layer leans on the one under it.
The honest description of where things stand right now is mid-transition, and transitions rarely move in a straight line. Rev5 and FedRAMP 20x are running side by side, with Rev5 set to sunset for Low and Moderate by mid-FY27 and for High by end of FY27. The FAR's cloud definition gap is documented by GAO and still unclosed by Congress. Centralization under GSA, through EO 14240, OneGov, and GWAC consolidation, is underway but nowhere near finished. Anyone working in this space right now has to hold the old rules and the new ones in their head at the same time, which is its own kind of skill.
For vendors, the one question that actually matters is which FedRAMP pathway fits their offering and at what impact level, because the Rev5 clock is running whether or not a given company has noticed yet. For agency buyers, the monitoring responsibility 20x hands down is a staffing and tooling decision first, a paperwork change a distant second, and no amount of reading policy memos resolves that on its own.
The centralization trend is the one worth watching over a longer horizon. As GSA pulls in more GWAC management and pushes more OneGov agreements, the number of real entry points into the federal cloud market seems to be shrinking, even as total spending climbs toward that projected figure above $21 billion by FY 2028. Vendors routing through the Cloud SIN and GSA-managed vehicles look better positioned than the ones betting on standalone agency contracts that might get absorbed into the centralized structure down the road.
Meanwhile, the FAR gap is the quiet risk sitting under all of it. Cloud computing still has no real definition inside the FAR, so every civilian cloud contract carries a bit of interpretive fog, one that contracting officers currently navigate through workarounds rather than solid statutory ground. That kind of structural ambiguity breeds inconsistency between agencies, and every so often it produces a bid protest that a cleaner rulebook would have prevented outright. Given that the U.S. federal government sits at the center of a global cloud market headed toward $80.90 billion by 2030, how that ambiguity eventually gets resolved, or doesn't, matters well past the edges of federal procurement.


