Series: Modernizing Federal Cloud Compliance
Part 1: The New Era of FedRAMP: How OMB M-24-15 Redefined Cloud Security
For more than a decade, FedRAMP operated under its original 2011 foundational guidelines. These rules successfully accelerated secure cloud adoption across the federal government. Yet, given the rapid evolution of modern cyber threats and cloud technologies, the program ultimately needed a significant structural overhaul.
The Catalyst: The FedRAMP Authorization Act of 2022
The transformation began in late 2022 with the passage of the FedRAMP Authorization Act. This landmark legislation formally established FedRAMP in law as a government-wide program housed within the General Services Administration (GSA). It mandated a standardized, reusable approach to cloud security assessments and modernized program governance by creating a FedRAMP Board.
A New Program Under the Same Name: OMB M-24-15
To guide the government-wide implementation of this new law, the Office of Management and Budget (OMB) issued Memorandum M-24-15 in July 2024. This was not a routine policy update; it formally rescinded the 2011 memo and replaced the program in its entirety. According to official FedRAMP documentation, M-24-15 effectively created “a new program with the same name but an entirely different set of authority and responsibilities”. It updated the program’s vision and scope, formally designating FedRAMP as the central authority and introducing core policy mechanisms:
- The Presumption of Adequacy: Mandates that once a Cloud Service Offering (CSO) is authorized, federal agencies must presume the security assessment is sufficient for their own Authority to Operate (ATO), eliminating redundant agency-by-agency re-testing.
- Governance Realignment: Retired the legacy Joint Authorization Board (JAB) and transferred strategic oversight to the FedRAMP Board and Technical Advisory Group (TAG)
- The Push for Automation: Mandated that continuous monitoring and authorization artifacts transition to machine-readable formats.
From Policy Mandate to Operational Execution
Retiring the 2011 memo marked the beginning of a modernized era for FedRAMP. However, policy is only as effective as its implementation. Driven by OMB’s mandate for continuous monitoring and automated validation via OSCAL (Open Security Controls Assessment Language), the FedRAMP PMO set out to completely rewrite the assessment playbook
Coming up in Part 2: How M-24-15’s policy vision became today’s operational reality with FedRAMP 20x and the Consolidated Rules for 2026 (CR26), and what cloud providers must do to prepare.