Founder narrative
Anya Petrova10 min read108 views

The month FedRAMP turned out to have an expiry date at 77K MRR

A composite founder diary. Everyone treats FedRAMP as a property of your product. In September 2026 I found that only the buying agency may decide whether it applies, and that every section of the FedRAMP Authorization Act carries a note repealing itself on 23 December 2027.

Updated on September 28, 2026

Flat vector illustration on off-white. A thin horizontal rule runs from the left, solid charcoal for most of its length, then continuing as a pale grey dashed line to the right edge. A short charcoal tick crosses the solid part. Below an empty band, a terracotta bar ends right of the tick.
Flat vector illustration on off-white. A thin horizontal rule runs from the left, solid charcoal for most of its length, then continuing as a pale grey dashed line to the right edge. A short charcoal tick crosses the solid part. Below an empty band, a terracotta bar ends right of the tick.
In this story
“Only a federal agency can determine if their use case for a cloud service falls within the scope of FedRAMP.”

That sentence is on the programme's own website, and I did not read it until week six. A civilian agency had asked for our FedRAMP package in July. We did not have one. We were at 77,000 dollars a month, eleven people, and the deal in front of us was worth about a fifth of our annual revenue, so I did what you do: I found a checklist, priced an assessor, and started building a plan around a thing I assumed was a property of my software. It is not a property of my software. And the statute underneath it has a date on it.

Quick answer (2026). This diary is a composite, assembled from patterns across several small software companies, with names, numbers and timeline changed. The legal material is not composite: every quotation below is verbatim from the linked page and was read on 28 September 2026. Three things surprised me. First, whether FedRAMP applies is not a fact about your product at all, and you are not the party who gets to decide it. Second, the FedRAMP Authorization Act repeals itself: every section from 44 U.S.C. 3607 to 3616 carries a note making the repeal effective five years after 23 December 2022. Third, the word "exempt" appears zero times in that chapter, and the three places small businesses are mentioned are a report topic, a committee agenda item and two seats on that committee.

The question I was not allowed to answer

I had been trying to answer the do-we-need-FedRAMP question the way you answer any other compliance question: read the scope, compare it to what we do, decide. That is the wrong shape of question, and the programme says so directly. Its 2026 scope guidance states that "Agencies are solely responsible for determining if their use of a cloud service falls within the scope of FedRAMP." Not the provider. The agency.

It goes further, and this is the part that reorganised my thinking. The guidance says "a single cloud service may even be within or outside the scope of FedRAMP depending on the use case" and adds, in a parenthesis, that FedRAMP therefore "does not supply a list of cloud services that are always outside the scope of FedRAMP for this precise reason". The same product, unchanged, is in scope for one buyer and out of scope for another. Scope is a fact about the deal, not about the code.

What the scope page actually says

There are real exclusions. Single agency systems, social media, search engines, widely available commercial information services, and ancillary services of negligible risk are all listed as outside the scope. The guidance even says that "Many agency use cases are exempted from the scope of FedRAMP", especially agency specific applications that will not be reused elsewhere.

Read that sentence again with the subject in mind. Agency use cases are exempted. Not vendors. Not small vendors. The exclusion is real, it is generous, and it belongs to somebody else to invoke. The page is explicit that providers "may reference this when considering whether to pursue a FedRAMP Certification but the specific agency use case for adoption is what matters, not the service itself".

So my honest position in August was that I could not tell you whether I needed the thing I was about to spend a year buying, and neither could my lawyer, and the only people who could were the ones who would not sign until I had it.

The date nobody put on the checklist

Then I read the statute, which I recommend, because it takes twenty minutes and no checklist will do it for you.

44 U.S.C. 3608 is the section that creates the programme. It says the Administrator "shall establish a Government-wide program that provides a standardized, reusable approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies". One paragraph. Then, underneath it, a note headed Repeal of Section, recording that Congress "provided that the repeal of this section is effective on the date that is 5 years after" 23 December 2022.

I assumed that was a quirk of one housekeeping section. I checked all ten sections of the chapter, 3607 through 3616. The note is on every one of them. Ten of ten. The Act that codified FedRAMP was written to delete itself on 23 December 2027.

What actually expires

This is where I nearly wrote something false, so let me be careful. FedRAMP is older than the Act. It ran from 2011 under an OMB memorandum, and it currently runs under OMB Memorandum M-24-15 as well as the statute. The programme's own site lists both as its authority. If the chapter repeals on schedule, the programme very probably continues on executive authority, exactly as it did for eleven years before Congress touched it.

What does not obviously continue is the guarantee. 44 U.S.C. 3613(e) is the reuse promise, and it is the entire commercial case for the spend: "The assessment of security controls and materials within the authorization package for a FedRAMP authorization shall be presumed adequate for use in an agency authorization to operate cloud computing products and services." Do it once, sell it many times. That presumption is a creature of the statute. Policy can be rewritten by whoever holds the pen next; a statutory presumption cannot. The thing with the expiry date is not the programme. It is the promise that the work travels.

The carve-out inside the guarantee

The presumption also has a hole in it, and the hole is drafted with more care than the promise.

Subsection (e)(2)(B) preserves "the authority of the head of any agency to make a determination that there is a demonstrable need for additional security requirements beyond the security requirements included in a FedRAMP authorization for a particular control implementation". No standard for "demonstrable". No appeal. No clock.

Now put it beside subsection (b), one screen up. If an agency concludes your package is "wholly or substantially deficient", then "the head of the agency shall document as part of the resulting FedRAMP authorization package the reasons for this determination". Rejecting you wholesale creates a paper trail. Asking you for one more control, on a Tuesday, for a demonstrable need nobody defines, creates nothing at all.

The statute polices the rare catastrophic refusal and leaves the routine one unrecorded. Every founder I know has met the second one. None has met the first.

I went looking for the small business door

By this point I was doing what I always do, which is grep for my own escape. I ran the terms across the operative text of all ten sections, 32,676 characters. De minimis: zero. Small entity: zero. Annual revenue: zero. Number of employees: zero. Revenue threshold: zero. Waiver: zero. Expedited: zero. Hardship: zero. Exempt: zero.

"Small business" does appear. Three places.

It is a topic the Director must report on annually, as "The unique costs and potential burdens incurred by cloud computing companies that are small business concerns". It is an agenda item for an advisory committee, which must examine "Measures to increase the number of FedRAMP authorizations for cloud computing products and services offered by small businesses concerns". And it is two chairs: the committee must include "At least 5 representatives from unique businesses that primarily provide cloud computing services or products, including at least 2 representatives from a small business concern".

A report about my costs, a discussion of my problem, and two seats. Not a threshold, not a reduced control set, not a fee waiver, not a shorter path. The word cost appears five times in the chapter and every single one is an instruction to study, review or report on cost. None of them reduces one.

The committee that was exempted from the wrong sunset

One more piece of grammar, because it is the tell.

Section 3616(e) says "Section 14 of the Federal Advisory Committee Act" shall "not apply to the Committee". Section 14, now at 5 U.S.C. 1013, is the provision that makes an advisory committee "terminate not later than the expiration of the 2-year period beginning on the date of its establishment unless" it is renewed, or "its duration is otherwise provided for by law".

So Congress deliberately switched off the two year sunset on the body whose job includes making this easier for companies my size, and then put a five year repeal on the section that creates it. It swapped a short renewable clock for a long unrenewable one. The committee must hold "not fewer than 3 meetings in a calendar year", which across the whole life of the statute is at least fifteen meetings, and the small business question is item (iii) of four, under one of three stated purposes.

The arithmetic

I did not need a price for this one, which is just as well, because I could not source one.

The statute ran from 23 December 2022 to 23 December 2027. That is 1,826 days. On the day I am writing, 28 September 2026, there are 451 days left, which is 14.8 months. Seventy five point three per cent of the statute's life is already gone.

Here is the part I find genuinely difficult. Section 3615 requires the Director to report annually on, among other things, "The average length of time to issue FedRAMP authorizations." Congress mandated the measurement of how long this takes. Congress also fixed the date the chapter dies. Nothing in the chapter relates the two numbers to each other, and I could not find the published figure from a source I was willing to cite, so I am not going to tell you whether an authorization begun today finishes before the statute expires. I will only say that the statute requires somebody to know.

What I got wrong

Three things, and the first is the big one.

I spent an evening convinced I had found that FedRAMP ends in 2027. It does not. The repeal is of the codified Act, not of the programme, and the programme predates the Act by eleven years. If I had published the dramatic version I would have been wrong, and the precise version is more interesting anyway.

I also assumed the rule of construction attached to the Act would say something about what happens to existing authorizations. It does not. The only construction note preserves "the authorities of the Director of the Office of Management and Budget or the Secretary of Homeland Security". It protects the agencies' powers. It says nothing about the providers' authorizations.

And I assumed, for six weeks, that scope was mine to determine. It was the cheapest error and the most expensive one.

What actually happened

Scroll to see more

What I assumedWhat the text says
I can work out whether FedRAMP applies to us"Agencies are solely responsible for determining if their use of a cloud service falls within the scope of FedRAMP."
Scope is a property of the product"a single cloud service may even be within or outside the scope of FedRAMP depending on the use case"
The exclusions are for small vendors"Many agency use cases are exempted from the scope of FedRAMP"
The statute is permanentRepeal note on 10 of 10 sections, effective "5 years after" 23 December 2022
One authorization is reusable, full stopPresumed adequate, subject to any agency's "demonstrable need for additional security requirements"
There is a small business on-rampA report topic, an agenda item, and two committee seats

Limits

I read the United States Code as rendered by Cornell's Legal Information Institute on 28 September 2026, and the scope guidance on the programme's own site the same day. I did not survey pending legislation, and a sunset is an easy thing for Congress to extend, so treat 23 December 2027 as the date currently written down rather than a prediction. I did not price an assessment, and I have deliberately quoted no authorization timeline, because I could not source one I trusted. I looked at the federal regime only. I make no claim about state or defence equivalents, and the CMMC story is a different animal that I wrote about separately.

The one thing I would tell you

Before you budget for a permission, read the statute that creates it, and read it for two things nobody puts on a checklist: who decides that you need it, and how long the thing you are buying is guaranteed to be worth something.

I had assumed both answers were boring. One of them was a sentence saying the decision is not mine. The other was a note, repeated ten times, with a date on it.

A

Written by

Anya Petrova

Frequently asked questions

Is this a real founder's diary?

It is a composite. These diaries are built from patterns across several small software companies, with the numbers, names and timeline changed, so no single story here is any one real company. The legal material is not composite: every statute and guidance passage quoted is quoted verbatim from the linked page and was read on 28 September 2026.

When is FedRAMP required?

Not on a test you are allowed to apply. The programme's 2026 scope guidance says agencies are solely responsible for determining whether their use of a cloud service falls within scope, and that a single cloud service may be within or outside scope depending on the use case. FedRAMP deliberately publishes no list of services that are always out of scope. Scope is a fact about the agency's use case, not about your product.

Does the FedRAMP Authorization Act really expire?

The codified chapter does. Every section from 44 U.S.C. 3607 to 3616 carries a Repeal of Section note recording that Congress made the repeal effective five years after 23 December 2022, which is 23 December 2027. I checked all ten sections and the note is on ten of ten.

Is there a small business exemption from FedRAMP?

No. Across the operative text of all ten sections the terms de minimis, small entity, annual revenue, number of employees, revenue threshold, waiver, expedited, hardship and exempt each occur zero times. Small business appears three times: as a topic the Director must report on, as an item an advisory committee must examine, and as two seats on that committee.

Is a FedRAMP authorization reusable across agencies?

By statute, presumptively yes, and that presumption is the commercial case for the spend. 44 U.S.C. 3613(e) says the assessment and materials in an authorization package shall be presumed adequate for use in an agency authorization to operate. But the same subsection preserves each agency head's authority to find a demonstrable need for additional security requirements, with no defined standard and no appeal.

Does the repeal mean FedRAMP shuts down in 2027?

Almost certainly not, and I nearly got this wrong. FedRAMP predates the Act by eleven years, ran from 2011 under an OMB memorandum, and currently also runs under OMB Memorandum M-24-15. What has a date on it is the statutory floor, including the reuse presumption. A policy can be rewritten by whoever holds the pen; a statutory presumption cannot.

Founder narrative

The month DORA compliance arrived in someone else's contract, at 75K MRR

A composite founder diary. A payments customer sent an eleven page DORA addendum with a one percent of turnover penalty clause. Four days of reading the regulation showed that no EU regulator could fine us at all, that the size relief is reserved for regulated firms, and that the real cost was free incident support written into the contract.

10 min read98
Founder narrative

The month my bank was allowed not to read the name, at 82K MRR

A composite founder diary at 82K MRR. When a payment order names one person and numbers another, the receiving bank may pay on the number and need not check the name. The escape the statute gives a non bank originator is deleted by a signature, and the right to chase the stranger follows the loss.

10 min read33