logoalt Hacker News

cuuupidyesterday at 9:19 PM2 repliesview on HN

> Not criticizing FedRAMP

Think it's very important to criticize FedRAMP. The FedRAMP board is extremely slow moving and continuously disregards industry feedback. As a result, FedRAMP is essentially a Palantir tax, where nearly every startup hoping to sell to government (including larger ones like Anthropic, xAI, Cognition AND OpenAI) is forced to pay Palantir to deploy in their FedRAMP enclave. This has a sticker price of 200-500k/y before we get into compute premiums.

Going through FedRAMP yourself requires a staff who is willing to put in a dedicated effort on the compliance paperwork (not the controls, which you could knock out in ~1mo easily, just the paperwork) for 6-8mo before getting into a line to hopefully get a 3PAO audit and then remediations followed by another audit which is followed by needing to get agency sponsorship for a FedRAMP board review. This costs $2-3M minimum including the amount of security software needed for evidencing and policy, which rules out nearly every small business. This process also can easily take 2-3 years of waiting, which forces out enterprise. So anyone entering the ecosystem is essentially forced to pay Palantir (or 2F which is a distant 2nd) a tax that is entirely enforced by government regulation.

They are not any kind of 'Federal Cyber Experts' either as that work is primarily outsourced to Schellman etc.


Replies

bigfatkittentoday at 4:55 AM

> FedRAMP is essentially a Palantir tax, where nearly every startup hoping to sell to government (including larger ones like Anthropic, xAI, Cognition AND OpenAI) is forced to pay Palantir to deploy in their FedRAMP enclave

Having been through FedRAMP twice, I can this is absolute fiction. What does Palantir have to do with anything?

firesteelraintoday at 3:16 AM

> Going through FedRAMP yourself requires a staff who is willing to put in a dedicated effort on the compliance paperwork

But couldn’t you say the same for CMMC 2.0, NIST 800-171, RMF, JSIG, STIG, etc?