Pegasystems' expansion of its FedRAMP Class D certification for Pega Cloud for Government marks a significant development in federal cloud procurement, enabling agencies to deploy AI-driven workflow automation within a compliant cloud environment. Concurrently, IBM's Maximo Application Suite achieved FedRAMP Moderate authorization, broadening secure SaaS options for federal asset management. These certifications reflect a federal push toward secure, AI-enabled cloud modernization, while state-level initiatives like Tennessee's tax platform migration underscore growing multi-vendor cloud adoption.
Market Analysis
Federal and state governments are accelerating cloud adoption with a focus on security compliance and operational modernization. Key observations include:
Pegasystems' FedRAMP Class D Expansion: This positions Pega Cloud as a competitive AI-powered workflow automation platform for federal agencies, supporting IT modernization and compliance with federal security standards.
IBM Maximo's FedRAMP Moderate Authorization: Enables federal agencies to adopt a secure, cloud-based asset and facilities management SaaS, with TRM providing specialized migration and advisory services.
Tennessee's Statewide Cloud Migration: Led by Tyler Technologies and involving AWS, Rackspace, and others, this initiative exemplifies large-scale SaaS adoption and integrated cloud architectures in state government.
DSS Health Cloud's FedRAMP High Certification: As the first VA integrator to achieve this, DSS Health Cloud meets the highest federal cloud security standards, opening opportunities in sensitive health IT deployments.
Frequently Asked Questions
What does Pegasystems' FedRAMP Class D certification mean for federal cloud procurement?
Pegasystems' expanded FedRAMP Class D certification allows federal agencies to adopt its AI-driven Pega Cloud platform with confidence in compliance and security. This certification supports agencies seeking to modernize workflows and decision-making processes while meeting federal security mandates, making Pega a viable prime contractor for cloud-based automation solutions.
How does IBM Maximo's FedRAMP Moderate authorization impact federal asset management contracts?
IBM Maximo's FedRAMP Moderate status authorizes federal agencies to use its cloud-based asset and facilities management SaaS for mission-critical operations. Procurement officers should consider IBM Maximo for contracts requiring FedRAMP Moderate compliance, especially where hybrid cloud solutions and secure modernization of infrastructure assets are priorities.
What opportunities arise from Tennessee's statewide cloud migration?
Tennessee's migration of its tax and assessment platform to a unified cloud architecture highlights demand for integrated cloud infrastructure and SaaS solutions at the state level. Vendors with expertise in multi-vendor cloud deployments, SaaS modernization, and public sector digital transformation can find strategic opportunities in similar state and local government projects.
Why is DSS Health Cloud's FedRAMP High certification significant?
DSS Health Cloud's FedRAMP High certification, the highest federal cloud security level, qualifies it for sensitive health IT deployments, particularly within the Department of Veterans Affairs. This certification is critical for contractors targeting federal health sector cloud services requiring stringent security and compliance standards.
How should procurement professionals approach cloud vendors with new FedRAMP certifications?
Procurement professionals should evaluate vendors' FedRAMP certification levels relative to agency security requirements and mission needs. New certifications like those of Pegasystems, IBM Maximo, and DSS Health Cloud indicate readiness to support federal cloud modernization efforts, especially in AI, asset management, and health IT domains. Partnering with certified vendors can mitigate compliance risks and accelerate cloud adoption.
☁️
Cloud Services
🔒
Cybersecurity
💻
Information Technology
🛡️
Defense & Military
Federal agencies are accelerating IT modernization efforts by adopting automated, secure, and compliant infrastructure solutions to support hybrid and multicloud environments. These initiatives address critical challenges such as manual provisioning, configuration drift, and governance gaps, particularly in air-gapped and zero trust security contexts. Industry leaders including IBM HashiCorp and Broadcom are providing technologies and strategic guidance to enable private cloud adoption and AI-driven cybersecurity enhancements, aligning with FedRAMP continuous monitoring requirements and federal zero trust mandates.
Federal procurement professionals should prioritize solutions that automate infrastructure provisioning and enforce compliance to meet evolving security mandates like FedRAMP and zero trust.
The demand for private cloud and hybrid cloud solutions indicates growing opportunities for vendors specializing in secure, scalable cloud platforms and AI-enabled cybersecurity tools.
Agencies are focusing on integrating continuous monitoring and governance capabilities, suggesting procurement strategies should emphasize lifecycle security and compliance management.
Contractors with expertise in cloud modernization, infrastructure automation, and federal security frameworks can leverage these trends to align offerings with agency modernization roadmaps.
☁️
Cloud Services
🤖
Artificial Intelligence
💻
Information Technology
Pegasystems has expanded its FedRAMP Class D certification for its Pega Cloud for Government platform, enabling federal agencies to deploy AI-powered workflow automation and decisioning tools compliant with stringent federal security standards. This expansion supports agencies in modernizing IT systems, improving operational efficiency, and enhancing constituent services through advanced cloud-based AI solutions hosted on AWS GovCloud. The development positions Pegasystems as a competitive provider in the federal digital transformation market alongside major vendors such as Salesforce and Microsoft.
Federal procurement professionals should note Pegasystems' enhanced FedRAMP authorization, which facilitates acquisition of secure AI-enabled cloud services for sensitive government workloads.
This expansion signals growing federal demand for AI-driven automation and cloud migration, creating opportunities for contractors specializing in secure cloud platforms and AI integration.
Agencies aiming to modernize legacy systems can leverage Pega's certified platform to meet compliance requirements while advancing digital workflows.
Contractors and vendors should evaluate competitive positioning as Pegasystems strengthens its foothold amid established cloud service providers in the federal sector.
DSS, Inc. has achieved FedRAMP High (Class D) certification for its DSS Health Cloud, marking it as the first solutions provider and integrator to the Department of Veterans Affairs (VA) to reach this highest-tier federal cloud security standard. This certification enables DSS to offer secure, scalable health IT solutions that comply with stringent federal cloud security mandates, supporting VA's cloud-first modernization strategy and facilitating broader adoption across federal agencies and commercial healthcare sectors.
Why this matters: Procurement professionals should note that DSS Health Cloud now meets the most rigorous FedRAMP security requirements, making it a qualified option for sensitive federal health IT deployments.
This certification aligns with federal mandates emphasizing cloud security and modernization, particularly within the VA and other health-focused agencies.
Contractors and vendors in health IT and cloud services can leverage this certification to position offerings for federal health sector opportunities requiring FedRAMP High compliance.
Agencies seeking secure cloud solutions for healthcare data management may consider DSS Health Cloud as a compliant, scalable platform supporting improved patient care and operational efficiency.
☁️
Cloud Services
🔒
Cybersecurity
💻
Information Technology
🛡️
Defense & Military
The General Services Administration's FedRAMP program is advancing federal cloud security by transitioning from the Rev5 framework to the FedRAMP 20x initiative, which mandates continuous, automated vulnerability detection, reporting, and machine-readable evidence of security controls. FedRAMP Director Pete Waterman has emphasized that technology vendors unable to rapidly remediate critical vulnerabilities, especially those driven by AI-accelerated cyber threats, should not pursue federal contracts. Congress is preparing to reauthorize FedRAMP in 2027, aiming to strengthen program resources and maintain rigorous cybersecurity standards amid evolving threats. Federal agencies and contractors must adapt to accelerated compliance timelines, integrate continuous monitoring capabilities, and prepare for increased automation in security authorization processes. This shift also influences commercial sectors adopting FedRAMP as a security benchmark beyond government procurement.
Why this matters: FedRAMP 20x fundamentally changes federal cloud procurement by requiring continuous security assurance rather than periodic audits, increasing demand for automated compliance solutions.
Vendors with FedRAMP authorization gain competitive advantage in both federal and regulated commercial markets, while those lacking authorization risk exclusion.
Procurement professionals should prioritize cloud service providers demonstrating rapid vulnerability remediation and AI-specific cybersecurity safeguards.
Organizations must plan for accelerated patching requirements, integration of AI-assisted threat detection, and evolving legislative frameworks impacting cybersecurity standards and vendor eligibility.
Connor Moucka, a Canadian hacker, pleaded guilty in U.S. federal court to orchestrating a major 2024 cyberattack that compromised Snowflake Inc's cloud infrastructure, resulting in data theft from over 165 customers including AT&T, LendingTree, and Ticketmaster. The breaches caused more than $9.5 million in losses and over $2.5 million in ransom payments. Moucka faces sentencing on October 27, 2026, with potential decades in prison. This case highlights the critical need for enhanced cybersecurity measures such as multi-factor authentication and credential monitoring for organizations relying on cloud services.
Why this matters: The prosecution underscores federal commitment to combating sophisticated cloud-based cyber threats affecting government and commercial cloud environments.
Agencies and contractors using cloud platforms should prioritize implementing advanced security controls to mitigate risks from credential theft and ransomware.
Procurement professionals should evaluate vendor cybersecurity postures and require compliance with best practices to protect sensitive data.
Organizations may benefit from increased demand for cybersecurity services focused on cloud infrastructure protection and incident response readiness.
The Department of Veterans Affairs (VA) issued a clarifying memo addressing misconceptions about cloud security vendor requirements. The memo explicitly states that vendors do not need to have FedRAMP certification before responding to VA solicitations or requests for information related to cloud security. This guidance aims to assist VA contracting officers and program managers in accurately understanding certification prerequisites, ensuring that potential vendors are not prematurely excluded from procurement opportunities based on FedRAMP status.
Why this matters: Procurement professionals should note that FedRAMP certification is not a mandatory prerequisite for initial vendor engagement in VA cloud security solicitations, potentially broadening the pool of eligible vendors.
VA contracting officers and program managers can use this memo to refine solicitation language and evaluation criteria to avoid unnecessary barriers.
Vendors interested in VA cloud security contracts should consider responding to solicitations even if they have not yet obtained FedRAMP certification.
This clarification may influence procurement planning and vendor outreach strategies within the VA cloud services domain.
The Department of Veterans Affairs (VA) has updated its cloud procurement policy to no longer require existing FedRAMP certification as a prerequisite for cloud service contractors. Instead, vendors must comply with VA-specific security requirements and obtain a VA Authorization to Operate (ATO), which can be granted within 60 days. This policy change aims to accelerate acquisition timelines and reduce barriers for cloud technology adoption while maintaining rigorous security and privacy standards tailored to VA's operational needs.
Why this matters: Procurement professionals should note that VA cloud solicitations now allow participation from vendors without prior FedRAMP certification, expanding the competitive vendor pool.
The VA Authorization to Operate process provides a streamlined, VA-specific security assessment alternative to FedRAMP, enabling faster contract awards and technology deployment.
Contractors interested in VA cloud opportunities must prepare to meet VA-specific security and privacy requirements and engage with the VA ATO process.
This approach reflects VA's balance between accelerating cloud modernization and maintaining strict cybersecurity controls, signaling potential shifts in federal cloud procurement practices.
☁️
Cloud Services
🔒
Cybersecurity
✅
Regulatory Compliance
💻
Information Technology
🏗️
Construction & Infrastructure
IBM has achieved FedRAMP Moderate Authorization for its Maximo Application Suite SaaS as of August 2026, enabling U.S. federal agencies to adopt this secure, cloud-based asset and facilities management solution for mission-critical operations. This authorization affirms IBM's capability to provide compliant hybrid cloud services tailored to federal security standards. TRM, an IBM Maximo partner based in Alexandria, Virginia, supports federal clients with migration, implementation, and advisory services to facilitate secure cloud modernization aligned with these requirements.
Why this matters: Federal agencies now have a FedRAMP-authorized SaaS option for asset management, enhancing secure cloud adoption for infrastructure and operational assets.
Procurement professionals should consider IBM Maximo for upcoming asset management contracts requiring FedRAMP Moderate compliance.
TRM’s partnership offers specialized support services, presenting opportunities for contractors in cloud migration and advisory roles.
This development signals increased federal emphasis on secure modernization of facilities and asset management systems, influencing future procurement priorities.
🔒
Cybersecurity
🤖
Artificial Intelligence
✅
Regulatory Compliance
💻
Information Technology
💼
Professional Services
Federal agencies are actively addressing challenges posed by the rapid pace of technological change, particularly in AI and cybersecurity, which outstrip traditional acquisition cycles. Efforts include GSA's updates to AI contract clauses and the OneGov initiative to accelerate procurement, as well as the VA's revised FedRAMP requirements to streamline security authorizations. Meanwhile, oversight bodies like GAO have raised concerns about reported savings in DoD health IT contracts and highlighted workforce planning issues at FEMA, underscoring the need for improved acquisition agility and strategic resource management.
Agencies such as GSA, VA, DHS, and DoD are implementing modernization initiatives to shorten procurement timelines and enhance technology adoption.
Procurement professionals should note evolving contract clauses and expanded authorities aimed at accelerating acquisition of emerging technologies.
Contractors can explore opportunities supporting streamlined security authorizations, AI and cybersecurity solutions, and workforce management services.
Budget constraints and legislative uncertainties continue to influence acquisition strategies, requiring adaptive planning and engagement with policy developments.
NASA has revised its Earth Science Research Overview (ROSES-25 A.1) effective August 4, 2026, to mandate that all proposals involving NASA high-end computing resources explicitly include associated usage costs in their budgets. This update extends the previously applied $0.09 per Service Billing Unit (SBU) charge from the NASA Center for Climate Simulation to all NASA high-end computing facilities supporting Earth Science projects. The change reflects NASA's response to increased constraints on computational resources and aims to ensure transparent budgeting and cost recovery for these services.
Procurement professionals should note that Earth Science proposals must now budget for high-end computing resource usage, impacting overall project cost estimates.
Contractors and researchers planning to utilize NASA's computational facilities need to incorporate these charges into their financial planning to avoid proposal deficiencies.
This update signals NASA's emphasis on resource management and cost accountability, which may influence future solicitations and contract negotiations involving computational services.
For billing inquiries, David Considine at NASA is the designated contact, reachable via david.b.considine@nasa.gov.