July 27, 2026 open public meeting agenda
| Time | Topic | Speaker(s) |
|---|
| 1–1:05 p.m. | Welcome, Call to Order, Roll Call, and Meeting Logistics | Ryan Hoesing, DFO |
| 1:05–1:10 p.m. | Chair Remarks and Meeting Objectives | Larry Hale, FSCAC Chair |
| 1:10–1:40 p.m. | Agency Adoption & Reuse Data Briefing - Growth of FedRAMP Certifications over time - Agency authorization and reuse trends - Top agencies by authorization activity - Continuous vs. time-bound ATOs - SaaS, PaaS, and IaaS trends - Age of certifications vs. agency adoption - FedRAMP 20x adoption outlook | FedRAMP PMO |
| 1:40–2:15 p.m. | Committee Discussion: Agency Adoption & Reuse - Barriers to reuse - Opportunities to improve agency confidence and trust - Agency best practices - Potential FSCAC work products and recommendations | FSCAC Members (facilitated by the Chair and DFO) |
| 2:15–2:20 p.m. | Break | |
| 2:20–2:50 p.m. | Discussion: Future of the FedRAMP Authorization Act - Review current statutory language related to reuse - Identify opportunities to strengthen reuse provisions - Discuss recommendations for future reauthorization efforts | FSCAC Members (facilitated by the Chair and DFO) |
| 2:50–3 p.m. | Public Comments (limited to 3 minutes per speaker) and Closing Remarks | Members of the Public/Larry Hale/Ryan Hoesing |
Meeting opening and administrative items
Ryan Hoesing opened the public meeting at 1:02 p.m. ET and confirmed that it was being conducted as an open public meeting under the Federal Advisory Committee Act. The meeting was recorded, closed captioning was available through Zoom, and public comment was reserved for the end of the meeting.
Membership updates
Ryan welcomed four members whose terms began on July 27, 2026:
- Vu Nguyen - Department of Justice, federal agency CISO representative
- Sean Flowers - Department of Commerce, federal agency CISO representative
- Irfan Nawaz - Salesforce
- Hemant Baidwan - Knox Systems
Ryan also recognized an incoming member whose term begins August 1, 2026, and thanked former members Josh Krueger, Michael Vacirca, and Lamont Yarborough for their service and continued interest in the committee.
Quorum and attendance
Ryan conducted roll call. Ten of the committee’s fourteen appointed members were present, exceeding the quorum requirement of eight members. Quorum was confirmed.
Ryan reminded participants that the committee had two remaining public meetings scheduled for 2026: August 31 and November 2.
Chair’s opening remarks and meeting objectives
Larry Hale welcomed the new and returning members and framed the July meeting as the next step following the committee’s June discussion. He emphasized that the committee should use available data to narrow its work rather than attempt to address every reuse challenge at once.
Larry identified the desired outcomes for the meeting:
- Identify a small number of barriers to adoption and reuse that are actionable for FSCAC
- Select one or more achievable work products or areas of focus
- Identify members willing to advance the work through working sessions before the August 31 meeting
- Review the reuse provisions of the FedRAMP Authorization Act and consider whether future reauthorization could strengthen reuse while preserving agency responsibility for risk decisions
Agency adoption and reuse data briefing
Pete Waterman was briefly unavailable at the start of the presentation because of an urgent conflict. Ryan stated that he was temporarily setting aside his DFO role and presenting in his separate capacity as FedRAMP Chief of Staff. Pete rejoined later in the briefing and discussion.
Data limitations
Ryan cautioned that the data reflected agency ATO letters and related information reported to FedRAMP. Agencies do not always submit the required information consistently, so the dataset is useful for identifying patterns but is incomplete and should not be treated as a perfect measure of production use.
Certification and authorization baseline
- 590 unique FedRAMP Certified services tracked over the full period presented
- 6,004 historical agency ATOs on record
- 3,320 ATOs treated as active based on information supplied to FedRAMP
- An average of 5.6 active ATOs per certified service, although the distribution is highly uneven
- 140 new services certified during the prior year and 79 additional services certified fiscal year-to-date
Ryan emphasized that some services have hundreds of recorded ATOs, while others have only one or none, so the average is not representative of a typical service.
Authorization trends
Recorded ATO activity peaked in fiscal year 2024 and remained relatively level through fiscal year 2025. Fiscal year 2026 activity was substantially lower with approximately two months remaining. Ryan identified several possible contributors, including reductions in the federal workforce, contract reductions and consolidation, the government shutdown, and incomplete agency reporting. The discussion did not establish a single cause.
Agency concentration and lifecycle reporting
A comparatively small group of agencies accounted for a large share of the ATOs reported to FedRAMP. Members viewed this concentration as both a measurement issue and a potential opportunity to learn from agencies that have institutionalized repeatable adoption processes.
Among the 3,320 active ATOs:
- 1,908 ATOs, or 57 percent, had no definitive expiration date
- 1,412 ATOs, or 43 percent, had a specific expiration date
Both approaches create maintenance challenges when agencies do not report terminations, renewals, or other lifecycle changes to FedRAMP.
Service type and age of certification
Software-as-a-Service offerings substantially outnumbered Platform-as-a-Service and Infrastructure-as-a-Service offerings in the certification inventory. Ryan also compared certification age with active agency ATOs:
- 374 services certified within the past five years accounted for 1,255 active ATOs
- 216 older services, generally certified in 2020 or earlier, accounted for 2,057 active ATOs
The committee discussed this as evidence that agency adoption often accumulates over time and that FSCAC could help identify ways to shorten the adoption curve for newer services.
FedRAMP 20X outlook
Ryan explained that the production FedRAMP 20X certification path had only recently opened. Class A was scheduled to open August 3, and Classes B and C were scheduled to open August 31. Visible agency ATO activity for newly certified 20X services was therefore expected to emerge over subsequent procurement and risk-decision cycles, rather than immediately. Pete cautioned that some known agency uses might not appear in FedRAMP data because agencies had not yet reported them.
Clarification of certification, agency ATO, adoption, and reuse
During questions, Ryan and Pete clarified that each agency remains responsible for issuing its own authorization or risk decision for its use of a cloud service. An agency uses the FedRAMP Certification package and reusable assessment materials to support that decision; it does not simply adopt another agency’s ATO.
The committee also distinguished the prior Rev. 5 agency authorization path from FedRAMP 20X. Under the prior path, an agency ATO often preceded the FedRAMP Certification. Under 20X, a cloud service provider receives a FedRAMP Certification first, and agencies then use that certification package as the basis for their own authorization decisions.
Committee discussion: barriers to agency adoption and reuse
Education, Awareness, and Agency Responsibilities
Members repeatedly identified a need for clearer, audience-specific education. Agencies, cloud service providers, assessors, acquisition officials, and oversight organizations may not share a consistent understanding of what a FedRAMP Certification establishes, what agencies remain responsible for, and how FedRAMP 20X changes the prior operating model.
Mapping FedRAMP 20X KSIs to Existing Baselines
Victoria Yan Pillitteri proposed a practical roadmap or delta that would help agencies understand the relationship between FedRAMP 20X Key Security Indicators and the familiar Rev. 5 Moderate or related NIST control baselines. Lawrence Marnelli and Carlton Harris supported clearer mapping or explanatory material that could help agencies understand the level of abstraction, risk implications, and potential effects on reciprocity with other frameworks.
Measurement, Demand, and Direct Agency Input
Rex Booth questioned whether the available data was sufficient to conclude that adoption itself was deficient and suggested comparing agency system inventories and overlapping authorizations to identify where greater reuse could reduce duplication. Hemant Baidwan and Branko Bokan emphasized the need to understand agency demand, internal agency ATOs, and the reasons agencies choose internal or alternative paths. Members recommended hearing directly from agency officials about the specific barriers, additional reviews, and resource constraints they encounter.
Tooling, Automation, and Reporting
Irfan Nawaz noted that agencies may not have the tooling or automation capacity to ingest and use higher volumes of machine-readable FedRAMP information. He recommended identifying best practices for integrating FedRAMP reporting into existing agency ATO and governance processes rather than adding a separate reporting burden. Members also discussed the need to improve the completeness and maintenance of agency authorization data reported to FedRAMP.
Risk Acceptance, Timelines, and Impact-Level Gaps
Vu Nguyen and Hemant Baidwan discussed the importance of transparency into agency-specific risk acceptance, additional mitigations, and the division of responsibilities among the cloud service provider, a sponsoring or initial agency, and subsequent using agencies. Members also noted that differences between a service’s certification class and an agency’s required impact level can prevent adoption even when a certified offering exists.
Reciprocity and Broader Framework Alignment
Carlton Harris asked how the program’s shift toward outcome-oriented KSIs and automation would affect trust and reciprocity with other security and compliance frameworks. The committee viewed this as closely related to the education and baseline-mapping work.
Working group decision and volunteers
Ryan summarized two barriers that had received broad support as actionable FSCAC focus areas:
- Lack of awareness, education, and shared understanding of responsibilities
- Lack of agency tooling and automation to support efficient use and reporting
The committee agreed to establish working sessions focused on agency adoption and reuse. The group would refine the problem statement and determine the most useful near-term work product rather than locking a final deliverable during the public meeting.
Members who volunteered during the meeting were:
- Carlton Harris
- Irfan Nawaz
- Hemant Baidwan
- Victoria Yan Pillitteri
- Vu Nguyen
Ryan stated that he would follow up with the full committee, include other interested or absent members, schedule the working sessions, and invite the incoming member after the member’s term began on August 1.
Ryan and Larry clarified that working sessions may develop draft material outside a public meeting, but the full committee must deliberate on and approve any advice or recommendations during an open public meeting.
Future of the FedRAMP authorization act
After a short break, Ryan led a focused discussion of the reuse-related provisions of the FedRAMP Authorization Act. The discussion was limited to reuse because that was the topic identified in the published meeting notice.
Statutory concepts reviewed
- Agencies should check whether an existing FedRAMP authorization or certification is available before initiating a new authorization process
- Agencies should use existing assessments and authorization materials to the extent practicable
- An agency that finds an existing package wholly or substantially deficient should document that determination
- Agencies should provide authorization decisions and supporting information to GSA/FedRAMP
- FedRAMP materials are subject to a statutory presumption of adequacy, while agencies retain responsibility for their own risk decisions
Discussion themes
Members discussed whether future reauthorization should clarify the operational meaning of the presumption of adequacy, what constitutes a demonstrable agency need for additional review, and how agencies should focus incremental analysis on their specific use case, integration, data, and mission risk rather than repeat controls that have already been assessed.
Branko Bokan emphasized that the committee needed a consistent understanding of statutory intent and legal terminology before recommending language. Carlton Harris connected the statutory discussion to the need to explain how KSIs support agency risk decisions and reciprocity. Irfan Nawaz noted that the decline and incompleteness in ATO reporting may indicate a gap between statutory reporting expectations and implementation.
Status of the discussion
The committee did not establish a separate working group or approve a recommendation on the Authorization Act. Members were encouraged to review the statutory materials individually, consult their agency or company General Counsel and Congressional Affairs teams as appropriate, and return with potential recommendations for the August 31 meeting. Ryan agreed to explore whether the committee could receive additional legal or legislative-context support without promising that such support would be available.
Ryan also noted that a material change to the August 31 agenda or meeting duration would require sufficient lead time for a Federal Register notice.
Public comment
Dillon Fuller asked whether the committee could support additional guidance or standardization for how agencies evaluate continuous monitoring evidence under the Consolidated Rules for 2026, with the goal of avoiding duplicative reviews and speeding reuse. Ryan explained that the committee would not respond to the comment during the meeting but would take it under consideration and share it with the members.
Closing and next steps
Larry summarized that the committee had selected specific focus areas, identified volunteers for working sessions, and expected draft work to return to the full committee at the August 31 public meeting. He also noted that the Authorization Act discussion required further study and consultation.
Ryan committed to follow up with all committee members, confirm working group participation, schedule working sessions, and circulate materials. The next FSCAC public meeting was scheduled for Monday, August 31, 2026, from 1:00 to 3:00 p.m. ET, followed by the final scheduled 2026 meeting on November 2. The recording concluded at approximately 2:59 p.m. ET during the closing remarks; the transcript does not include a separate explicit adjournment statement.
Concise takeaway
The July 27, 2026 FSCAC meeting moved the committee from broad issue identification to a defined working phase. The committee focused its near-term work on two linked barriers: stakeholder education and agency tooling/automation. Five members volunteered for working sessions, with additional members to be invited. A practical first deliverable is expected for public discussion on August 31. The committee also began reviewing the reuse provisions of the FedRAMP Authorization Act but deferred any recommendation until members could obtain a clearer legal and legislative understanding.