Tyler Tech Podcast from Tyler Technologies

Cloud Compliance in Government: FedRAMP vs. GovRAMP

Episode Summary

This episode of the Tyler Tech Podcast, recorded live at Tyler Connect 2026 in Las Vegas, features a conversation with John Smail, U.S. federal security and compliance lead at Amazon Web Services (AWS), and Clay Thomas, vice president of cloud strategy at Tyler Technologies, on the differences between FedRAMP and GovRAMP and why the distinction matters for government organizations evaluating cloud solutions. The discussion explores the purpose and scope of each framework, common misconceptions about cloud compliance, and the relationship between compliance and cybersecurity. John and Clay also share practical guidance for government IT, security, and procurement leaders on evaluating risk and data sensitivity, balancing compliance requirements with cost and innovation, and aligning cloud decisions with their organization’s specific needs.

Episode Notes

In this episode of the Tyler Tech Podcast, John Smail, U.S. federal security and compliance lead at Amazon Web Services (AWS), and Clay Thomas, vice president of cloud strategy at Tyler Technologies, explore the differences between FedRAMP and GovRAMP and why the distinction matters for government organizations evaluating cloud solutions. Recorded live at Tyler Connect 2026 in Las Vegas, the conversation breaks down the purpose of each framework, who they serve, and how they relate to broader cloud security and compliance efforts.

John and Clay discuss common misconceptions surrounding cloud compliance, including why FedRAMP and GovRAMP are often treated as interchangeable despite serving different levels of government and addressing different requirements. They also examine the relationship between compliance and cybersecurity, highlighting why compliance frameworks should be viewed as tools for providing assurance rather than direct measures of security.

The episode concludes with practical guidance for government IT, security, and procurement leaders. From evaluating risk and data sensitivity to balancing compliance requirements with cost, innovation, and operational goals, John and Clay emphasize the importance of aligning cloud decisions with an organization’s specific needs rather than defaulting to the most stringent compliance standard.

This episode also highlights an upcoming webinar on cloud strategy in government, featuring research-backed insights and real-world public sector experiences.

This episode also highlights emerging strategies for building efficiency in the public sector, with insights into how agencies are using technology and process improvements to do more with existing resources.

And learn more about the topics discussed in this episode with these resources:

Listen to other episodes of the podcast.

Let us know what you think about the Tyler Tech Podcast in this survey!

Episode Transcription

Josh Henderson: Before we dive into today’s episode of the Tyler Tech Podcast, I want to let you know about a conversation that you do not want to miss. On August 25th, join Tyler Chief Technology Officer Russell Gainford, a guest speaker from Forrester, and government leaders from Peoria County, Illinois, and the city of Mobile, Alabama, for a discussion on why cloud for government is fundamentally different. You’ll hear research-backed insights alongside real-world examples of government organizations putting cloud strategies into practice. Registration is free, and you can reserve your spot using the link in this episode’s show notes. Now let’s get to today’s episode of the Tyler Tech Podcast.

Clay Thomas: Good decision-making just starts with being clear on the outcome that you’re trying to achieve that’s going into an actual procurement request and not just starting with compliance first and foremost. The first question should really be what data are we talking about? How sensitive is it? What are the risks associated with that data in this specific context of the use case?

Josh Henderson: From Tyler Technologies, this is the Tyler Tech podcast. I’m your host, Josh Henderson. Today’s episode tackles a frequently misunderstood topic in government technology: cloud compliance.

For public sector organizations evaluating cloud solutions, terms like FedRAMP and GovRAMP often surface in procurement discussions, security reviews, and vendor requirements.

But despite their similar names, these frameworks serve different purposes, apply to different levels of government, and aren’t always as interchangeable as they may seem. Recorded live at Tyler Connect 2026 in Las Vegas, my guests are John Smail, U.S. federal security and compliance lead at Amazon Web Services — or AWS — and Clay Thomas, vice president of cloud strategy here at Tyler. 

Between them, they bring extensive experience helping government organizations navigate cloud security, compliance requirements, and technology modernization initiatives. We explore where confusion often arises, how compliance relates to security, and what government IT and procurement teams should consider when evaluating cloud solutions.

There is a lot to unpack, so let’s get started.

Alright, John, Clay. Thank you so much for joining me today on the Tyler Tech Podcast. Today, we’re going to dive into a topic that generates a lot of questions across government IT, that distinction between GovRAMP and FedRAMP. So, to set the stage, let’s start with the basics. Can you give us a quick orientation? What are GovRAMP and FedRAMP? Who do they apply to, and how do they relate to each other?

John Smail: I’ll start with FedRAMP because, essentially, FedRAMP is the baseline of how cloud services get authorized, and it is codified in what’s called the federal FedRAMP Authorization Act. So, they it was passed by congress. It was inserted into the National Defense Authorization Act, and it applies to all federal agencies and any CSPs that want to provide cloud services to those federal agencies. So, if they’re going to process, store, or transmit federal information in a cloud service, then it’s pretty much going to have to be FedRAMP authorized.

The GovRAMP is a 501(c)(6) organization that organized around state, local, tribal, and higher education organizations that were looking for, hey. How do we baseline these authorization programs and how can we represent those small governments back to the CSPs? So, it’s a big benefit because they can standardize the review of security information for these small, you know, state, local governments. You know, how they relate is really if you look at it, they’re both based on what’s called NIST SP 800-53, the security controls catalog, and they build on top of each other. So GovRAMP builds on top of FedRAMP. And if you, you know, once you achieve FedRAMP, if you’re a vendor, then you can take that authorization and get GovRAMP.

Josh Henderson: Thank you for laying that out. I feel like that’s a great context setting for the rest of the conversation. So, and one thing I want to make sure listeners understand, GovRAMP and FedRAMP are competing alternatives, right, that an agency chooses between. They serve different levels of government. So where does the confusion actually come from? Why do so many agencies and vendors talk about these as if they’re interchangeable?

Clay Thomas: I mean, part of the confusion purely comes in how they’re named and just being similarly named. Oftentimes, they are used interchangeably is what we found. But ultimately, as John mentioned, they serve different levels of government, and they also have different types of scope and legal authority between the different segments of the market.

GovRAMP was established to follow the same characteristics and the same playbook that FedRAMP established in the sense of using independent audits and using continuous security monitoring and following NIST-based controls. Where they differ in focus is ultimately around state and local and education organizations ultimately having different types of circumstances, resources, data requirements, and risk associated compared to the federal government.

And historically, there just hasn’t been a standardized risk management framework that has been specifically targeted at the state and local market, and that’s where GovRAMP was established. And sometimes it’s we see it trickle into being included for RFP requirements interchangeably with FedRAMP. I do want to call out that an important detail to understand about GovRAMP, John mentioned it, it is a nonprofit organization that was established and is not actually directly affiliated with FedRAMP or the United States government. And so, but it is comprised of as a member organization of government officials, cloud service providers, policymakers. And so, there’s sort of a combination of members within the nonprofit organization.

Josh Henderson: Good to know. Now, John, let’s go a little bit deeper on FedRAMP specifically. You know, it was created by the federal government. It’s been around since 2011.

How is it structured? What does it actually provide in terms of compliance assurance, and what agencies does it actually apply to?

John Smail: Yeah. You’re right. You’re right. So, it has been around since 2011, and I would say, you know, for a long time, it didn’t change too much.

So, it stayed fairly consistent for a long time. As I mentioned, based on NIST 853 control catalog, and it has essentially three levels of authorization. They did have a FedRAMP ready.

Now they’ve taken that away, but they have FedRAMP low, FedRAMP moderate, and FedRAMP high. And as you step up those levels of authorization, you’re stepping up the amount of evidence if you’re a CSP, like AWS, that we provide to the federal government to show them, you know, our compliance with these controls. So, you know, so for low, it’s somewhere around 100 controls.

For moderate, you’re stepping way up to about 325 controls. And then for high, you’re over 400 controls. So, you know, quite a quite a big bar there. As Clay mentioned, brings standardization.

So, all CSPs are on the same level. So, whether you’re Microsoft, AWS, Google, we’re all achieving the same standard. That gives our customers and the federal agencies so all U.S. federal government agencies have to use FedRAMP-authorized services.

They know that if they see that FedRAMP moderate authorization, what that cloud service achieved. What they what they evidenced and what they achieved. So that’s the level of risk.

It gives them a baseline for if I’m using that service, I get to inherit those 325 controls, and then I’m responsible for the ones on top of it.

Josh Henderson: Now, Clay, from the Tyler side, how do you see these distinctions show up in real conversations with public sector clients? Where do things tend to get lost in in translation?

Clay Thomas: I think a lot of the confusion just purely starts when procurement language gets reused across agencies or copied from prior RFPs, without actually being calibrated to the underlying use case or the risk associated with the data for the specific procurement ask. And we find that in many cases, agencies are trying to do the right thing and ask for the strongest level of possible security posture, but that can often lead to frameworks being treated as interchangeable.

And we find that that often leads to even poorer outcomes when we talk about frameworks are designed for very specific jurisdictions, types of requirements that they’re solving, and specific types of outcomes. And so, there’s additional challenges when it comes to conversations jumping straight into the compliance label before aligning on necessarily what the specific problem needs to be actually solved, what data is in scope, and what level of assurance is actually required.

And that’s certainly where we help clients just walk through and navigate what is actually policy, what is specific to their use case, and just help them understand what is the best solution for them. And I do want to call out, and John likes to talk about this quite a bit, is that security and compliance are two distinct things but are complementary. And you can think of cybersecurity as actually the practice of physically and logically securing data systems operations from external threats, whereas compliance is very focused on providing evidence for very specific people, process, and technology controls that are aligned to very specific outcomes. And so, I like to say that compliance, you could be compliant, but you could also have security gaps, and you could also have strong security practices that go above and beyond what a specific compliance framework actually is designed to achieve. So, it’s sort of complementary in two different things.

Josh Henderson: And now can you walk us through what GovRAMP actually does provide and how it relates to FedRAMP authorization in practice? For example, does having a FedRAMP authorization get a vendor part of the way there with GovRAMP?

John Smail: Yeah. Absolutely. So GovRAMP, you know, as I said, it so I’ll specifically talk about AWS sometimes in this. 

So, we achieve our FedRAMP authorizations. And for a vendor, for all vendors, if you achieve that FedRAMP authorization, you have all the evidence and what you need to do to provide to GovRAMP to get added to their approved product list. 

So, you know, what is that? Well, to get a FedRAMP authorization, you have to complete the documentation of all 325 controls for moderate and say and you document those in your system security plan. Then you hand that to a third-party assessment organization that’s FedRAMP certified, and they review those 325 controls. 

So, they do a security assessment plan, a security assessment report, and then they write a letter of attestation. And we, as a CSP, we provide all of that to GovRAMP. Alright? So GovRAMP then reviews all of that information, and if it’s all there, it’s all solid, then they will add you to their approved products list.

And so that’s getting on the approved products list. But you also have further commitments to GovRAMP. You commit that I am going to continue to provide our continuous monitoring data, which is vulnerability scanning, patching, making sure we’re meeting our service level agreements.

If we don’t, we have challenges, we develop a plan of actions and milestone, what we call a POAM, and GovRAMP watches those for all the state local governments that are members of GovRAMP. So, they know that they have an organization that they’re part of that’s actually watching, you know, those big CSPs or small CSPs because it’s all in the same state.

Josh Henderson: Stay tuned. We’ll be right back with more of the Tyler Tech Podcast.

Every day, government leaders are being asked to do more with less, manage growing workloads, meet rising expectations, and address staffing and budget challenges.

Jade Champion: And while efficiency is a priority for nearly every organization, today’s challenges require a different approach. It’s not just about improving individual processes; it’s about expanding capacity without adding resources.

Josh Henderson: That means connecting systems, simplifying workflows, reducing manual work, and giving staff more time to focus on the services that matter most.

Jade Champion: Across the country, public sector agencies are improving operations through automation, artificial intelligence, integrated systems, and smarter ways of working.

Josh Henderson: Discover how agencies are reducing complexity, freeing up staff time, and creating more capacity to serve their communities. Visit the link in our show notes and download our free eBook, How Governments Build Efficiency at Scale, to learn from real-world examples, client stories, and expert insights.

Jade Champion: Now let’s get back to the Tyler Tech Podcast.

Josh Henderson: And now what kinds of compliance can state and local agencies achieve with a commercial cloud environment that doesn’t have GovRAMP authorization? Then what does support from AWS look like in that regard?

John Smail: So, I’ll give you a little bit of history on the FedRAMP program and some of the changes that have been made and then how we, you know, worked into our current GovRAMP relationship and where we are on their approved products list. So FedRAMP in mid-2024, they had what was called a joint authorization board. Right? And CSPs would submit their evidence to that joint authorization board, and they would review it and then grant FedRAMP authorization.

Well, they dissolved the Joint Authorization Board, you know, known as the JAB. They dissolved that, and for big CSPs like AWS, we were assigned to the Department of Defense as our FedRAMP lead agency. And so, we already had a good relationship with Department of Defense because they have essentially their own authorization program that also builds on FedRAMP, which we call the Department of Defense file service provider security requirements guide. And so, you take your FedRAMP authorization, and then they add additional requirements to what they call impact levels. So, most people that operate in federal government do business with the Department of Defense too because they’re very large.

And so, we did have a relationship with them. And so, when we were assigned over there to Department of Defense, they were our lead agency. It was pretty smooth. 

And they took us on. And so, we were getting our Department of Defense impact level authorizations, and they were giving our FedRAMP authorizations through reciprocity. So, I tell you all that because there was a period that some people in the industry and some people in government, once they dissolved the JAB, thought it was the Wild West.

Meaning that, oh my goodness, the CSPs are just out there doing whatever they want. Right? And I’m sure there are some cases where, you know, some things slip through the cracks. But companies like AWS that were always working with Department of Defense, let me tell you, they do not lower their standards.

And they didn’t miss anything. So, there was no gap for AWS. So, we continue that.

And then when government came to us and said, hey, you know, we had worked in StateRAMP before, you know, the predecessor to GovRAMP. You know, we’re thinking about how we bring you guys in without the JAB, and they established what’s called the Hyperscale Inheritance Authority.

Okay, so because of all the work we do with the Department of Defense, that’s a long time to get authorized by them. It’s a lot of paperwork, a lot of evidence, a lot of continuous monitoring data that we share with them. What could we do? And they developed that hyperscale inheritance authorization for organizations like AWS, and we provide all of that same data back to GovRAMP, and that’s how we got put on the authorized product list. Now we continue to provide the same continuous monitoring that we do to the Department of Defense to GovRAMP so they can tell their members, hey. They’re continuing to, you know, meet the high bar. 

Josh Henderson: Fantastic. And now, Clay, I’m guessing you field a lot of requests where an agency is asking for GovRAMP, out of caution rather than out of strict requirement. How do you have that conversation? How do you help them, you know, think through whether GovRAMP is actually necessary for their use case? 

Clay Thomas: And, really, the first thing we look to do is just to understand the why behind the request.

Ultimately, we ask is GovRAMP being driven by a formal state requirement or policy? Is it out of a procurement language that’s being copied? Is it out of a general sense of just caution and a perception that compliance leads to increased levels of security outcomes. So really, these are all just questions that we have in partnership with our clients that are going through a procurement process, asking for a specific compliance program associated with an ask.

And there from there, we really just try to separate a combination of things. So, we can think of mandatory things that are associated with actually assessed impact or risk associated with a data or use case or understand if it may be preference or coming from sort of boilerplate language that is reused between RFPs. And by all means, our intent is not to push back on compliance asks, but it’s really to understand what is the specific need that we can recommend to our clients to ultimately lead to increased security outcomes without overcomplicating, in some cases, by tacking on compliance requirements.

So, it’s a combination of things.

John Smail: Yeah. I think I think that’s a great point. You know, a key of all of this is do once, use many, right? And so, on the government side and on the vendor side, you don’t want to redo the same thing over and over again.

Josh Henderson: Yeah. So now when government isn’t strictly required, what are some of the real-world trade offs if an agency or vendor chooses it anyway? Things like cost, the pace of future releases, or operational complexity, things like that.

Clay Thomas: Yeah. I mean, the biggest trade off is certainly around cost. GovRAMP and other compliance programs carry real value through transparency and assurance that clients and procurement officers value, but it also carries a significant amount of investment on behalf of vendors and CSPs to actually go and implement a lot of the controls and operational and people controls that go into that. And so that can certainly show up in influencing pricing and specifically procurement outcomes related to costs.

Now, secondly, the second tradeoff is certainly around speed and flexibility. When you have an environment that’s in scope of a specific compliance program that carries just by necessity an additional amount of change management that goes into controlling the level of change activity that goes into that environment, and so oftentimes when you’re releasing new features, you may release them at a quicker pace into an environment that is not in scope of a specific compliance program, whereas it may take time to trickle into those environments that are in scope of the compliance program to get the additional authorization for what’s been included.

And so, we oftentimes see that that can lead to slower delivery for features in some cases or reduce the pace of innovation if a compliance program is sometimes associated with it. That’s not always the case. In some case, there can be sort of an increased pace once a compliance environment is established. And it’s not to say that GovRAMP is necessarily the wrong choice for any given solution, but we want to make sure that it is the right fit based on the actual risk associated with the data, and the underlying cost is actually truly needed for a specific situation.

Josh Henderson: And now, John, from AWS’s perspective, why does innovation tend to move faster in standard commercial cloud environments? Is that something that’s by design? 

John Smail: It is not by design. And so, it first, understand this that, you know, so we have what we call GovCloud. You know? So, we built, you know, for the U.S. government.

So, you do and they and they have they have a lot of good use cases that they have to use it for. Typically, they’re around U.S. persons and, you know, being on U.S. soil and things like that. And we have our commercial regions, and, you know, they’re both authorized. And that the honest truth is they’re built exactly the same.

So, the way when we when AWS builds a cloud service, it doesn’t build one version for GovCloud, one version for commercial, it builds the cloud service, and then we deploy it to regions. And then, you know, so if you look at our regions, I mean, they’re very standardized, and that’s what the government wants.

They want commercial cloud services.

And, you know, the quickest way to do that is take those commercial services.

So, they’re on the same infrastructure. They’re built the same way. AWS does security the same for both of them, a very high bar, you know, that has, you know, encryption, physical security. We have what we call Nitro architecture that really gets down to protecting and encrypting data all across the stack.

And so, it’s built the same way. So why do we see cloud services in commercial much earlier than we do in GovCloud or, you know, getting FedRAMP authorized? It has to do with the authorization process.

It’s the collecting of that information from the service teams.

You do all of the paperwork we need to do. We need to run it through a third-party assessment test of those FedRAMP controls.

They’re typically already implemented, but they implemented them as part of AWS security, and we turn them into language that we need to do for FedRAMP or GovRAMP or the Department of Defense.

Wrap all that together. We ship it off to Department of Defense, and they spend a long time reviewing that.

And the whole time, it’s not authorized. So, people think, well, what’s going on in GovCloud? We’re just kind of we’re waiting for that process to finish. And then once that process finishes, then it’s authorized. So, you’re getting the same service, but it’s licensed, essentially.

Josh Henderson: So, as we start to wrap up the conversation and knowing all of the things that we’ve just discussed throughout, how can government IT teams and procurement leaders make smarter, more confident decisions when it comes to cloud selection and compliance? What does good decision-making look like here?

Clay Thomas: I mean, I think good decision-making just starts with being clear on the outcome that you’re trying to achieve that’s going into an actual procurement request and not just starting with compliance first and foremost. The first question should really be what data are we talking about? How sensitive is it? What are the risks associated with that data in this specific context of the use case? And then once you have a good understanding of that, you can have a much more grounded conversation when it comes to the level of security assurance that is actually appropriate based on the regulatory environment, the policy that’s associated with it, the risks, and all of the things that go into that. Now I also think it’s important for agencies not to assume that the highest compliance threshold is always the safest and smartest choice.

More compliance does not necessarily mean that you have better security in an environment if it’s not aligned to the actual data, a sensitivity and profile or risk associated with it. In fact, it can actually lead to increased levels of, we talked about some of these tradeoffs, cost, increase to sort of the challenges for, innovation and things like that. So over-specifying compliance can drive a cost, and it definitely narrows the field of viable solutions too. The higher levels of compliance you go, the higher tradeoffs you have for cost and so on. Okay. I mean, so to me, decision making is really just about aligning the compliance requirement to the mission and the problem and outcomes you’re looking to solve.

Josh Henderson: And now, obviously, we’ve tried to make a very complex issue a little bit more accessible in this conversation.

But if you want one key takeaway if you want the listeners to take away one thing from this conversation with GovRAMP and FedRAMP, what would that be and why?

John Smail: Yeah. I think Clay’s touched on this a lot is, you know, I would encourage government members, state and local governments, yeah, in higher education, resist the temptation to layer on custom security controls and requirements, especially those that duplicate what’s already been assessed at the federal level. It’s a very rigorous process, you know, trust that process and spend your time working on your side of customer responsibility matrix. There’s a lot to do over there. There’s a lot of innovation you can do. Spend that time building your product, spend that time securing your side of the responsibility matrix, and trust that, you know, the federal FedRAMP authorization is rigorous. That way you can really lean into that do once use many purposes of both FedRAMP and GovRAMP.

Clay Thomas: And then for me, I would say that both are important, but they have their very specific problems that they’re targeting to solve, and they serve different portions of government. Honestly, compliance decisions are complicated. We’ve talked about a lot of jargon and technical pieces of during this conversation alone. And so ultimately, I would recommend agencies and our clients to ultimately just reach out and partner with us to help unpack a lot of these complexities, help you typically work and sort of understand the why and provide recommendations into the best solution in terms of not only compliance, but how our products are designed and operated when it comes to security practices. So really start with sort of the why and work backwards from there.

Josh Henderson: I think that’s a great place to wrap things up. I think this is going to be very helpful for folks to kind of identify what is needed, what isn’t needed, with all the very complex compliance measures, in place here. So really appreciate you both taking the time. I think this was a fantastic conversation.

Thank you so much.

As we heard today, cloud compliance is rarely a one size fits all decision.

While frameworks like FedRAMP and GovRAMP provide important standards for security assurance and transparency, the right approach depends on an organization’s unique data, risk profile, regulatory obligations, and operational goals.

John and Clay emphasize that compliance and security are related, but they’re not the same thing. Effective decision-making starts with understanding the problem you’re trying to solve, the sensitivity of the data involved, and the level of assurance that’s actually required. Rather than treating compliance frameworks as interchangeable, agencies can achieve better outcomes by aligning security requirements with their mission, risks, and procurement objectives.

If you’d like to learn more about the topics discussed in this episode, be sure to check out the show notes for additional resources. We’d also love to hear your feedback. Fill out the listener survey linked in the notes or reach out anytime at podcast@tylertech.com. And be sure to subscribe, rate, and review the show so you never miss an episode. For Tyler Technologies, I’m Josh Henderson. Thanks for listening to the Tyler Tech Podcast.