National Defense Authorization Act for Fiscal Year 2027

Floor Speech

Date: July 22, 2026
Location: Washington, DC

BREAK IN TRANSCRIPT

Mr. WALKINSHAW. Mr. Chair, I rise today in support of Amendment No. 309 to the FY2027 National Defense Authorization Act. My amendment would establish a pilot program to enable the Department of Defense (DoD) to more efficiently deploy modern cybersecurity solutions by accelerating the security verification of solutions that have already received FedRAMP High certification.

FedRAMP is a standardized approach to certifying and assessing the security of cloud computing technologies used across federal agencies, and a FedRAMP High certification is the strictest cloud security authorization level within FedRAMP.

This level of certification ensures compliance with the standards needed to securely handle and process the federal government's most sensitive unclassified information and data.

FedRAMP seeks to create a ``certify once, reuse many times'' model for cloud products and services that provides a secure and cost- effective approach to federal cloud service adoption.

The idea behind this concept of ``certify once, reuse many times'' or ``reciprocity'' as I like to refer to it, is that if a cloud service's security controls have already been certified at a basic level, multiple federal agencies should be comfortable with adopting the service for their own purposes.

For years, DoD has relied on its own assessment and verification process for cloud-based services, separate and distinct from FedRAMP-- however, both DoD's and FedRAMP's assessment and verification processes rely on the same NIST standards and have the same goal, which is to certify that a cloud-based product meets security standards for federal use.

What this means in practice is that both the government and our private sector partners must invest significant time and resources to verify security controls for cloud service deployment not just once, but twice if they hope to make that service available to both Federal Civilian and DoD customers.

Additionally, maintaining two parallel certification pathways has created bottlenecks in deploying modern commercial cloud capabilities, including critical cybersecurity tools, within the DoD--even when those solutions have already been certified for civilian agency use under the same NIST standards through the FedRAMP program.

This amendment would save the federal government time and resources by encouraging reciprocity between the parallel FedRAMP and DoD cloud security assessment processes.

It establishes a pilot program to accelerate the DoD's assessment of cloud-based cybersecurity solutions that have already been authorized under the same underlying NIST standards that the Department's existing assessment process relies on.

In doing so, this pilot will help deliver innovative commercial cybersecurity capabilities to the warfighter more quickly, at a time when cyber threats from our adversaries are growing more sophisticated.

I urge my collegues to support this amendment. The Acting CHAIR. The question is on the amendments en bloc offered by the gentleman from Alabama (Mr. Rogers).

The en bloc amendments were agreed to. Amendment No. 316 Offered by Mr. Grothman

BREAK IN TRANSCRIPT


Source
arrow_upward