惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
P
Privacy International News Feed
W
WeLiveSecurity
Spread Privacy
Spread Privacy
S
Schneier on Security
Google Online Security Blog
Google Online Security Blog
N
News and Events Feed by Topic
Forbes - Security
Forbes - Security
Cisco Talos Blog
Cisco Talos Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
L
Lohrmann on Cybersecurity
P
Privacy & Cybersecurity Law Blog
T
The Exploit Database - CXSecurity.com
C
CXSECURITY Database RSS Feed - CXSecurity.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
小众软件
小众软件
人人都是产品经理
人人都是产品经理
SecWiki News
SecWiki News
Schneier on Security
Schneier on Security
月光博客
月光博客
博客园_首页
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google DeepMind News
Google DeepMind News
Cyberwarzone
Cyberwarzone
www.infosecurity-magazine.com
www.infosecurity-magazine.com
AWS News Blog
AWS News Blog
WordPress大学
WordPress大学
AI
AI
酷 壳 – CoolShell
酷 壳 – CoolShell
Hacker News: Ask HN
Hacker News: Ask HN
Attack and Defense Labs
Attack and Defense Labs
IT之家
IT之家
P
Proofpoint News Feed
The Hacker News
The Hacker News
The Cloudflare Blog
Vercel News
Vercel News
Application and Cybersecurity Blog
Application and Cybersecurity Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Cloudbric
Cloudbric
C
Cisco Blogs
TaoSecurity Blog
TaoSecurity Blog
I
Intezer
Jina AI
Jina AI
雷峰网
雷峰网
阮一峰的网络日志
阮一峰的网络日志
Microsoft Azure Blog
Microsoft Azure Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
A
About on SuperTechFans
B
Blog

MeriTalk

Eliminating Silos in IT/OT Cybersecurity Is a Funding Challenge, Not a Technical One How More Tightly Focused Software Development Initiatives Will Unlock Innovation Across Government Transforming Federal Cybersecurity Through Private Sector Innovation Evolving Zero Trust and Embedded AI – Federal Government Cybersecurity Predictions for 2026 Unlocking AI’s Potential in High-Assurance Environments Accelerate Agentic AI in the Federal Government: Top Takeaways Why Congress Must Reauthorize the Technology Modernization Fund Make Cybersecurity a Key Ingredient of Modernization How Spectro Cloud’s PaletteAI Secure helps agencies scale AI securely, compliantly, and confidently Fix the Foundation: How Hybrid Cloud and Trusted Data Enable Government AI New Google Workspace Cost-Saving Offer Available for U.S. Federal Government Reinventing FedRAMP in the Age of AI Balancing Security and Efficiency: The Federal IT Dilemma in the AI Era Meeting Evolving State and Local Cyber Threats AI Is the Solution to Stop AI Data Theft Enhancing U.S. Government Operations with AI and Human-Centered Design How FinOps Can Help Agencies Slash Cloud Costs in 5 Steps Will Quantum Computing Weaken or Strengthen Cybersecurity of Federal Systems? Improving Citizen and Federal Employee Experience with Virtual AI Assistants Strategies for Securing the Federal Supply Chain Reframing the U.S. Government’s Approach to Cybersecurity Oversight Three Steps Agencies Can Take to Meet Government’s AI Requirements The Impact of NIST’s PQC Standardization on the Federal Cybersecurity Ecosystem Generative AI is Revolutionizing Federal Government Operations NIST’s new PQC Algorithms and What They Mean for Federal Agencies Addressing the U.S. Quantum Labor Shortage Before It’s Too Late How a Community Vigil Approach and Secure by Design are Critical to Software Cybersecurity Addressing the Talent Shortage: How Digital Government Improves Satisfaction, Retention Here’s What We Can Learn (and Do) About Cybercrime from FBI’s Latest Internet Crime Report Implementing AI Assurance Safeguards Before OMB’s December Deadline The Next AI Wave: Quantum AI CDM’s Evolution to Non-Traditional Technology: Why Now and How Will it Succeed? Customer Expectations Require Agencies to Raise the Bar on Customer Experience, Report Shows Applying for Government Benefits Shouldn’t Be Difficult When It Comes to Identity Verification Four Federal Software Supply Chain Security Trends to Watch FedRAMP Baseline Transition Points to OSCAL-Native Tools What Zero Trust Means for Modern Government: Best Practices for Key Tenets Four Ways to Handle the IT Funding Crunch Agencies Need to Get Creative to Fill the Cyber Workforce Gap Customer Identity trends report shows control trumps convenience Federal Agencies Making Strides Toward Sustainability and Climate Action Executive Order 14028 | Improving the Nation’s Cybersecurity Depends on Data | All Data is Security Data Applying Geospatial Intelligence, AI/ML to Climate Change Challenge My Cup of IT: Angry at Arthritis, Hunting for Cures How the Federal Government Can Help Combat a Fragmented Internet Accelerating Cybersecurity for US Critical Infrastructure Getting in on the Ground Floor of the ‘New Observability’ Comply-to-Connect is Key to Zero Trust for DoD How Will Upcoming Cryptocurrency Regulations Affect Industry? My Cup of IT: Cup Cake for Kushner? Launching a New Era of Government Cloud Security Managing IT Complexity in Federal Agencies Agencies Must Modernize Zero Trust Approaches to Achieve Optimal Protection Five Essential Metrics for Measuring Federal Government CX Unlocking the Benefits of 5G and Beyond The Federal Factory of the Future: How AI is Transforming Manufacturing The Quantum Impact on Cyber How Next-Gen Computers Will Transform What’s Possible for Federal Government Agencies Must Take an Authentic Approach to Synthetic Data Biometrics and Privacy: Finding the Perfect Middle Ground Two-Way Street: Why Officials and Constituents Are Equally Responsible for Securing the Midterms The “Programmable World” Will Bring the Best of the Virtual World Into the Physical One Cyberattacks are a Common Occurrence and the Costs are Higher Than Ever Increasing Equity Through Data and Customer Experience The AI Edge: Why Edge Computing and AI Strategies Must Be Complementary How Metaverses and Web3 can Reshape Government Four Emerging Technology Trends set to Impact Government Most 5G Enables AI at the Edge Plugging Cyber Holes in Federal Acquisition Resilient Critical Infrastructure Starts with Zero Trust The Evolution of Government Tech Procurement Under CMMC 2.0 Zero Trust Requires Continuous, Tested Security for Federal Agencies How Multi-INT Fusion Accelerates Mission Intelligence for Real-Time Decision Advantage Three Things to Consider for Responsible AI in Government Legislation, White House Orders Show Agencies Opportunity for Hybrid Cloud Creating an Effective Framework for DoD’s Software Factories Realizing Upsides for Digital Security in the Hybrid Workplace A Future With AI and ML: The Power of Workforce Education Five Tips to Begin MFA Integration and Embrace Zero Trust The Vital Intersection Between Equity and Digital Transformation Equity as a Platform: Applying a New Mindset to Scale Innovation Harnessing the Right Data for Evidence-Based Equity From EO to Action: Human Factors of Enabling a Cyber Safety Review Board For Equity in Government Services, It’s Time to Change the Paradigm Critical Questions to Ask When Considering Explainable AI (XAI) for Your Federal Agency The Telework Model for Government: COVID Lessons for Building an Effective Workforce DevSecOps: 4 Steps for Mitigating the Next Cyber Attack in Your Federal IT Environment Better Cyber Hygiene Helps, but Federal Security Needs SASE Lift DoD, Feds Plot Top Cyber, Cloud Priorities for 2022 Cloud-Native Government: How to Transform With Intention DoD and VA Health Networks Face Growing Threat From Medical-Device Vulnerabilities New Federal Cybersecurity Requirements: How Agencies Should Implement a Zero Trust Architecture Protecting Our Nation Through Big Data Analytics Three Ways COVID-19 Altered Federal, State IT Budget Allocations Ransomware is More Than a Cybersecurity Issue From Me to We: Take the Mission Further With Multiparty Systems Anywhere, Everywhere: Integrating Your Virtual Workplace ‘I, Technologist’: Empowering Innovators in the Federal Workforce Mirrored World: Digital Twins Report for Duty Across Government Stack Strategically: Rearchitecting Government for What’s Next
The FedRAMP High Supply Crisis Is a Federal Security Problem – Not a Procurement Footnote
Danielle Bar · 2026-03-25 · via MeriTalk

Federal agencies spent $11 billion on cloud services in 2024. Roughly 40 percent of that spending supported high-impact systems, platforms carrying national security operations, law enforcement coordination, emergency services, healthcare records, and financial infrastructure. The data on those systems cannot tolerate compromise. And yet the cloud market built to protect it is dangerously thin.

As of early 2025, the FedRAMP Marketplace listed approximately 80 cloud service offerings at the High impact level. Only 48 held full authorization. That gap between what agencies need and what the market can actually deliver at the required security tier is not an abstract compliance concern. It is a procurement bottleneck that is forcing real tradeoffs with the federal government’s most sensitive data.

What FedRAMP High Actually Requires

The FedRAMP program classifies cloud services at three impact levels: Low, Moderate, and High, based on the potential consequences of a security breach. FedRAMP High authorization requires 421 security controls drawn from NIST SP 800-53 Rev 5, nearly 30 percent more than the 325 controls at the Moderate baseline. Those additional controls are not bureaucratic overhead. They address advanced encryption requirements, physical access restrictions, enhanced personnel security vetting, and continuous monitoring capabilities calibrated for sophisticated adversaries.

The gap between Moderate and High is not a paperwork gap. It reflects a fundamentally different threat model, one designed for data that, if compromised, could endanger lives, disrupt national security operations, or undermine critical infrastructure.

Because High-authorized options don’t exist across many use cases, agencies often default to general-purpose productivity tools operating at the Moderate tier. That workaround may solve a procurement problem. It creates a security one.

The Threat Environment Agencies Are Actually Operating In

The argument for FedRAMP High-level security is no longer theoretical. The threat data from the past year makes the case in operational terms.

The CrowdStrike 2026 Global Threat Report documented an 89 percent increase in AI-enabled adversary attacks year-over-year, with the average eCrime breakout time dropping to just 29 minutes. Cloud-conscious intrusions rose 37 percent. Perhaps most concerning, 82 percent of all detections were malware-free, meaning traditional signature-based defenses are insufficient against the methods adversaries are now using routinely. State-nexus actors, particularly China-aligned groups, increased targeting of edge devices by 38 percent, using valid credentials and native tools to blend into normal operations while moving laterally toward sensitive data.

For agencies operating at the High impact level, these are adversaries specifically targeting the types of data that FedRAMP High was designed to protect. The 2026 World Economic Forum Global Cybersecurity Outlook reinforces the picture: 65 percent of large organizations now identify third-party and supply chain vulnerabilities as their greatest barrier to cyber resilience, up from 54 percent the prior year. When agencies exchange sensitive data across fragmented platforms operating at different authorization levels, every seam between those systems becomes an attack surface.

General-purpose cloud tools authorized at the Moderate tier were not designed for this threat environment. Deploying them for high-impact workloads is a structural mismatch that no configuration policy can fully close.

The CMMC Dimension: A Defense Industrial Base in Distress

FedRAMP High’s significance extends well beyond federal agencies. For the defense industrial base, the authorization gap creates a compounding compliance crisis.

CMMC Level 2 requires defense contractors to demonstrate 110 security practices derived from NIST SP 800-171. FedRAMP High’s 421 controls map directly to those requirements, and when a vendor achieves FedRAMP High authorization, its customers inherit those validated controls rather than building and validating each one independently. That inheritance can compress CMMC compliance timelines by 50 percent or more. Given the state of DIB readiness, that compression is urgently needed.

A survey of 209 defense industrial base organizations found that only 46 percent consider themselves prepared for CMMC Level 2 certification. Fifty-seven percent have not completed a NIST 800-171 gap analysis. Sixty-two percent lack adequate governance controls. The CyberSheath 2025 State of the DIB report puts the broader picture in even starker terms: only 1 percent of defense contractors feel fully prepared for CMMC audits, down from 4 percent the previous year. The median SPRS score across the DIB sits at 60, a full 50 points below the required threshold of 110.

Critical controls remain widely undeployed. Seventy-nine percent of DIB organizations lack vulnerability management capabilities. Seventy-eight percent lack patch management. Seventy-four percent lack data loss prevention. Seventy-three percent have not implemented multi-factor authentication. These are not edge cases; they are the majority of organizations now operating under CMMC requirements embedded in active defense contracts.

FedRAMP High control inheritance does not solve every problem in this picture. But it changes the compliance calculus fundamentally, converting a multi-year infrastructure build into an architecture decision.

The Multi-Framework Compliance Argument

Federal agencies and defense contractors in 2026 are not confronting a single regulatory obligation. They are managing simultaneous compliance deadlines across CMMC 2.0 for defense contracts, HIPAA for healthcare data, PCI DSS 4.0 for payment processing, and ISO 27001 as a global baseline, among others. Addressing each framework independently multiplies cost, timeline, and implementation risk.

At the control level, the overlap is substantial. An encryption architecture validated for FedRAMP High simultaneously satisfies CMMC encryption practices, HIPAA’s technical safeguards, PCI DSS cryptographic requirements, and ISO 27001 Annex A controls. A platform that unifies these controls under a single architecture eliminates the redundancy inherent in framework-by-framework compliance programs. Survey data supports the operational difference this makes: organizations with completed gap analyses follow documented encryption standards at nearly twice the rate of those without, 77 percent versus 42 percent.

According to a 2025 data workflows survey, 75 percent of government respondents require FedRAMP for their data exchanges, and 69 percent use FIPS 140-3 validated cryptographic modules. When a single platform’s control inheritance satisfies requirements across multiple frameworks simultaneously, multi-framework compliance shifts from a program management problem to an architecture decision.

The FedRAMP 20x Factor: Why Waiting Is a Strategy With Real Costs

The FedRAMP program is undergoing significant modernization through the FedRAMP 20x initiative, and the timeline has direct implications for agencies and contractors making cloud security decisions today.

Phase 1 completed with a Low baseline pilot demonstrating authorization in under two months. Phase 2, active through Q1 2026, involves a Moderate pilot with 13 participants. Wide-scale adoption for Low and Moderate authorizations is expected in Phase 3, targeting Q3 through Q4 2026. But the FedRAMP 20x High baseline pilot is not expected until Q1 through Q2 2027, with the legacy Rev 5 authorization pathway expected to sunset in Q3 through Q4 2027.

Organizations that delay action are not waiting for a better option. They are accepting a multi-year gap in high-security cloud capabilities during the period when adversary activity is accelerating most rapidly.

What Agencies and Contractors Should Do Now

Audit your FedRAMP authorization landscape. Identify which cloud services your agency or organization relies on, at which impact levels they are authorized, and where mission-critical data flows through platforms operating below the High threshold. If your most sensitive data exchange is running through Moderate-authorized tools, you have a structural architecture gap, not a configuration problem.

Map framework overlaps before building framework-specific programs. Organizations pursuing CMMC, HIPAA, PCI DSS, and ISO 27001 simultaneously should identify control overlaps early and invest in platforms that satisfy multiple frameworks from a single implementation.

Evaluate FedRAMP High In Process providers now. The FedRAMP authorization journey moves through Ready, In Process, and Authorized stages. “In Process” is not a planning status. It signals that controls have been implemented, independently assessed by a certified third-party assessment organization, and are under active federal review. Agencies and contractors that engage providers during the In Process stage gain architecture lead time. Waiting for the Authorized designation means competing for capacity alongside every organization that also waited.

Consolidate data exchange channels under unified governance. With 82 percent of detections now malware-free, attackers are exploiting gaps between systems rather than targeting individual platforms. Every separate tool for email, file sharing, SFTP, and managed file transfer is a seam in your security architecture. Unified governance under a single policy engine and audit log is not an administrative preference; it is an operational security requirement.

The compliance clock is not slowing down. CMMC requirements are embedded in contracts now. DORA enforcement began in January 2025. HIPAA penalties exceed $100 million annually. The federal agencies and defense contractors that act on FedRAMP High inheritance today will be the ones positioned to compete, win contracts, and demonstrate the security posture their missions and regulators demand. The others will still be building.

Danielle Barbour is Senior Director of Product Marketing, Compliance at Kiteworks. She brings experience across medtech, insurance, and software industries and holds an MBA from Saint Mary’s College of California.