Q&A: What VA's FedRAMP Shift Means for Federal Cloud Innovation
Key Takeaways
- What changed with VA's approach to FedRAMP?
VA clarified that cloud vendors do not need to already hold FedRAMP certification to bid on or win a contract. The security requirements remain, but the timing for meeting them has changed. - How does DSS Health Cloud help agencies and technology partners?
DSS Health Cloud provides a FedRAMP High certified foundation that can help agencies, ISVs, and integration partners bring secure cloud solutions into federal health care environments without starting from scratch. - What role does SBG Technology Solutions play?
SBG serves as the preferred onboarding and advisory partner for DSS Health Cloud, helping organizations navigate systems engineering. architecture, risk management framework requirements, integration, and the ATO process.
The Department of Veterans Affairs (VA) recently clarified its approach to FedRAMP requirements for cloud procurements, opening the door for vendors to compete for contracts without already holding FedRAMP certification. The security requirements have not gone away, but the timing has changed, creating new opportunities as well as new considerations for agencies and the companies that support them.
Against that backdrop, DSS has achieved FedRAMP High certification for its DSS Health Cloud, a secure cloud environment designed to support federal agencies, independent software vendors (ISVs), and other organizations bringing new technologies into government health care environments.
We spoke with Bruce Dickey, CEO of SBG Technology Solutions, a DSS, Inc. subsidiary, and Brion Bailey, MS, director business development, federal at DSS, Inc., about what VA's clarification means, how DSS Health Cloud can help organizations navigate this changing environment, and SBG's role in helping agencies and technology companies move securely from solution to deployment.
Q: The VA recently updated its guidance around FedRAMP and cloud procurements. For those who haven't followed the news, what has changed?
Bruce: The VA's CIO office issued a memorandum clarifying that cloud providers, independent software vendors, and other companies looking to do business with VA in a FedRAMP environment do not need to already hold FedRAMP certification to bid on or win a cloud contract. FedRAMP can instead become a post-award requirement, shifting when vendors need to meet those security and authorization requirements.
It's not really a new policy. It's a correction. For years, contracting officers, program managers, and OIT often treated FedRAMP certification as a pre-award gate, requiring vendors to have certification before they could bid or win a contract.
VA was explicit that this does not waive any security requirements. Once under contract, vendors still need to deliver the full security package, including assessment reports, architecture and data flow diagrams, asset inventories, vulnerability scans and testing, and FedRAMP evidence.
The security bar hasn't moved. What has changed is when vendors have to clear it.
Q: What are the biggest implications of this change for federal agencies and companies that support the VA?
Bruce: For federal agencies, it opens the aperture. VA is no longer limiting competition from emerging, smaller, or newer cloud vendors that may not have had the resources to pursue FedRAMP certification without a contract hand.
That should increase competition and create opportunities for better, more efficient, and more cost-effective solutions.
For companies like DSS and SBG, it also shifts the risk profile. The FedRAMP process now happens on the government's clock, post-award, rather than on the vendor's clock before an award or solicitation.
Program offices will need partners that can move quickly and get the security documentation right the first time because that work now takes place within the contract period of performance.
Q: DSS recently achieved FedRAMP High certification for DSS Health Cloud. How does that investment position DSS to support agencies and partners in this evolving environment?
Brion: DSS invested several years ago in establishing a FedRAMP infrastructure, doing the hard work well before this policy clarification. With the shift, vendors can now win VA contracts and initiate the FedRAMP High process post-award. DSS has already completed that work, which means agencies and integration partners working with DSS Health Cloud won't be waiting on us.
FedRAMP requirements remain firmly in place, particularly for environments handling protected health information or other sensitive data. The difference is that DSS Health Cloud already provides a FedRAMP High certified foundation, giving agencies and partners a head start in meeting those requirements.
It's not just a checkbox. DSS has already established the FedRAMP High certified environment needed to support existing solutions as well as new capabilities moving forward.
Q: SBG Technology Solutions serves as the preferred onboarding and advisory partner for DSS Health Cloud. What role does SBG play in helping agencies and software vendors successfully adopt secure cloud solutions?
Bruce: The DSS and SBG team helps translate this policy shift into something VA program offices and software vendors can actually execute against, helping them move innovate solutions into federal healthcare environments more efficiently.
DSS Health Cloud provides the authorized foundation, while SBG brings the systems and engineering, architecture, and Risk Management Framework experience needed to get solutions mapped, assessed, and through the ATO process without reinventing the wheel.
SBG has been supporting risk management framework efforts across VA and the Department of Defense for years, and we know where these packages can stall. Our job is to make sure they don't, so innovation can keep moving forward.
Q: Many organizations want to bring new healthcare technologies into federal agencies but face security, integration, and compliance challenges. How does the combination of DSS Health Cloud and SBG help simplify that journey?
Bruce: Most vendors looking to enter the VA market must solve several difficult problems at once. Is the platform secure enough? Will it integrate with VA's existing or planned systems? Can the vendor demonstrate compliance quickly enough to remain competitive?
Addressing those challenges separately can take years.
DSS Health Cloud addresses the security foundation with an environment that is already FedRAMP High certified. SBG brings experience navigating integration and compliance within the VA environment, helping vendors address those challenges more efficiently.
Together, DSS and SBG mean a vendor isn't stitching together three vendors three timelines. They've got one path in.
Q: Looking ahead, what role do you see secure cloud platforms playing as federal healthcare modernization continues to evolve?
Brion: Cloud technology is becoming the foundation for the next generation of federal health care capabilities, from AI-enabled clinical care coordination and interoperability across VA and Department of War health records to faster deployment of new tools for providers and Veterans. A secure, agile cloud environment can accelerate the delivery of innovative solutions while providing greater enterprise visibility across the technology environment.
Policy will continue to evolve as well, and VA's recent memo is a good example. I expect more of these course corrections as agencies look for ways to move faster without compromising security
The agencies and companies best positioned for that environment will be those that have already built a secure foundation that supports rapid innovation and agile solution delivery, rather than addressing security after the fact.
Building the Foundation for What Comes Next
VA's clarification may change when FedRAMP requirements enter the procurement process, but as Bruce and Brion point out, it does not change the importance of security, compliance, and operational readiness.
With DSS Health Cloud providing a FedRAMP High certified foundation and SBG helping organizations navigate systems engineering, integration, Risk Management Framework requirements, and the ATO process, DSS and SBG can help agencies and technology partners bring new capabilities into federal health care environments securely and efficiently.
Contact DSS today to learn more about how DSS Health Cloud and SBG Technology Solutions can help agencies and technology partners navigate secure cloud adoption, FedRAMP requirements and the path to ATO. Subscribe to our blog page to stay informed of the stores that matter to you.