Mr. Speaker, if this bill sounds familiar to Members, there is good reason for that. Once again, the House of Representatives is debating a bipartisan bill to secure Federal agency use of modern cloud computing services.
However, this time we are doing it as H.R. 8956, the Federal Secure Cloud Improvement and Jobs Act. Formerly named the FedRAMP Authorization Act, this was the first bill the House passed this Congress, as H.R. 21, on January 5, 2021.
We also passed the same legislation as part of this year's House version of the National Defense Authorization Act.
This is such an important issue that we are here again to send an improved bill back to the Senate for final passage.
Cybersecurity and technology modernization are both vital issues to ensure this government runs efficiently, effectively, and safely. We need this legislation to address the continued onslaught of cyberattacks that have compromised both the private and public sectors' critical information systems.
Cloud computing is an important innovation.
It allows users to tap into extra resources to meet spikes in demand, like what agencies saw when trying to deliver COVID-relief assistance.
It also allows them to access modernized applications without the need for them to also invest in their own data storage equipment.
While cloud computing is the norm in the private sector, we still need to encourage agencies to adopt this technology when it makes sense. We also must ensure cloud computing services are secure. That is where the Federal Risk and Authorization Management Program comes in.
FedRAMP, run by the General Services Administration, is the main Federal program focused on helping agencies procure secure cloud computing systems. It provides a consistent process to ensure agencies know a given cloud service meets Federal cybersecurity standards. It also provides clarity for vendors, so they understand the requirements to ensure their products are secure enough for Federal agency use.
Shifting to the cloud is more cost effective, allows for better citizen services and mission-based solutions, and provides more responsive technology capabilities overall. These improved efficiencies have led to significant cost savings.
At the end of fiscal year 2021, the GSA estimated that over the FedRAMP program's 10-year lifespan, it had helped agencies avoid $716 million in individual security review costs. So while agencies are not required to buy FedRAMP-approved services, it makes sense to encourage them to do so.
After passing the earlier version, H.R. 21, the Senate also made changes that improved the bill we are considering today.
Such updates include striking the unnecessary authorization of $20 million in appropriations and requiring better oversight of the industry costs associated with becoming FedRAMP certified. This will help ensure both small and large businesses can participate in the program.
In addition, this version also seeks to identify and avoid bottlenecks that slow approval. It also takes steps to secure the software supply chain from threats by foreign bad actors, the likely source of the 2020 SolarWinds attack that targeted numerous private sector companies and Federal agencies.
Codifying this successful program into law is an important step towards encouraging Federal agencies to take full advantage of this program and all the security benefits it offers.
Mr. Speaker, I urge my colleagues to support this bill, and I reserve the balance of my time.
Mrs. CAROLYN B. MALONEY of New York. 8956.
Mr. Speaker, protecting our public's valuable information is something we can all agree on. I hope we can continue to do our job and work together on improving the Federal Government cybersecurity and adoption of modern technology.
Mr. Speaker, I encourage my colleagues to support this bill, and I yield back the balance of my time.
Mrs. CAROLYN B. MALONEY of New York.
Mr. Speaker, I urge passage of H.R. 8956 and yield back the balance of my time.
BREAK IN TRANSCRIPT