All sections
STOP 7Addresses V-7, SA-5, SE-8

Stop: Using standards compliance as a barrier to entry

The bottom line

Compliance gates keep capable builders out.

See the thinking

Security and compliance standards are currently positioned as gates vendors must pass before work begins: FedRAMP authorization, NIST attestations, state-specific overlays, each documented before a line of production code runs. This structure keeps capable builders out, keeps compliance-document specialists in, and provides less actual security than it appears to, because point-in-time paperwork assessments are weak predictors of operational security. The standards themselves can be out of date the moment they are written.

The alternative: move standards assessment out of the procurement gate and into the authority to operate. Let vendors build and demonstrate in production-like sandboxed environments with synthetic data at low barrier, and require them to prove their security posture in the context of the actual environment before sensitive data is processed. Assessment against real, running systems is both more rigorous and less exclusionary than assessment of documents.

And for genuine robustness, replace point-in-time attestation with the open review mechanism described in C3: before production authorization, solutions are published for nationwide review across accessibility, privacy, security vulnerabilities, and better existing alternatives, with findings triaged publicly. A solution that has survived motivated public scrutiny has passed a stronger test than any standards checklist provides, and the test never goes stale, because the reviewers never stop.

We have drafted this open-review mechanism in the proposed legislation linked below. For FedRAMP specifically (question V-7), reciprocity plus environment-context demonstration would streamline authorization far more effectively than additional baseline harmonization. S12 extends this same model from a point-in-time, open-review demonstration to a continuously demonstrated security capability, checked automatically with every production deployment.

Supporting Content

Rate CMS progress

How well is CMS acting on this recommendation? Cite your evidence in the discussion below.

Community average: Not yet rated

Sign in to rate CMS

CMS progress & evidence

Comments about CMS action on this recommendation. The original recommendation discussion is below.

No CMS progress comments yet.

Sign in to share CMS progress or evidence.

Sign in to comment

Recommendation discussion

Public comments on the recommendation itself. Anyone can read them; signing in is required to post.

No comments yet. Be the first to weigh in.

Add your comment

Add nuance, a state example, a disagreement, or language you would want CMS to see.
Sign in to comment

You can still post anonymously — your email is never shown.

Sign in to rate CMS progress.