Key Takeaways
- GAO found that outdated regulations and conflicting guidance are still hindering federal cloud procurements.
- Eighteen CFO Act agencies (75%) lacked established guidance on cloud service level agreements, complicating cost and vendor management.
- GAO recommended statutory updates, clearer technical direction, and modernized acquisition practices to avoid vendor lock-in.
Federal cloud adoption remains under scrutiny as the Government Accountability Office (GAO) calls on Congress and federal entities to address persistent acquisition and regulatory obstacles. The findings, based on a July 2024 review, arrived during a period when agencies are accelerating modernization efforts but often encounter uneven policy, restrictive licensing rules, and cost management hurdles.
These persistent challenges will be a core focus at the Potomac Officers Club’s 2026 FedCiv Summit on Oct. 29, where industry and government leaders will discuss AI deployment, cybersecurity, and infrastructure modernization. Cloud acquisition strategies are expected to dominate the agenda as agencies balance policy requirements with technology shifts.
In its review of 24 Chief Financial Officers (CFO) Act agencies, GAO found that 18 agencies (75%) had not established guidance on cloud service level agreements (SLAs). This lack of documentation persists despite White House requirements for cloud procurement. Without established baselines, officials frequently struggle to manage service expectations and maintain cost transparency.
Agencies specifically identified cloud cost management as a significant barrier. GAO warned that restrictive licensing practices, such as requiring agencies to repurchase licenses for cloud use, charging additional fees to run software on another provider’s infrastructure, and levying conversion fees to migrate on-premises software, have consistently increased costs and limited agency choice of cloud providers.
Conflicting software and cloud guidance from federal oversight organizations continues to create uncertainty around procurement decisions. While the Federal Cloud Computing Strategy ("Cloud Smart") directs agencies to modernize acquisition practices and avoid vendor lock-in, GAO found implementation uneven across major agencies.
Federal acquisition regulations and outdated policy frameworks further complicate procurements. GAO reported that outdated acquisition rules and inconsistent procurement guidance are materially slowing federal cloud adoption. Hyperscale cloud providers such as Amazon Web Services, Microsoft Azure, and Google Cloud Platform, as well as acquisition vehicles managed by the General Services Administration (GSA), are directly affected by these SLA and licensing constraints.
A related GAO report via CIO Dive underscored the impact of repurchase requirements and conversion fees on cloud migrations, validating agency concerns that modern cloud services map awkwardly to existing legacy acquisition categories.
The regulatory challenges extend to federal cybersecurity expectations, particularly for systems categorized as high-value assets. Nearly 33% of federal agencies lacked guidance to ensure continuous visibility into high-value assets in cloud environments. According to a separate MeriTalk summary of GAO’s findings, this lack of visibility undermines federal cybersecurity and resilience goals.
Many agencies have attempted to address cloud cost management, staffing, and access to authorized services independently. However, the structural challenges of conflicting software guidance and unclear acquisition rules slow broader modernization. Without centralized procurement clarity, agencies risk policy misalignment when attempting to adopt multi-vendor cloud architectures.
To establish technical baselines, agencies increasingly reference National Institute of Standards and Technology (NIST) frameworks. NIST’s cloud computing standards, including Special Publication (SP) 500-292 on cloud definitions and SP 800-145 on cloud characteristics, are widely consulted. Furthermore, federal Zero Trust Architecture principles outlined in NIST SP 800-207 serve as critical guidelines for securing these modern environments.
GAO has urged Congress and federal agencies to address these regulatory and operational barriers by modernizing statutory definitions and procurement models. Correcting restrictive software licensing and establishing consistent SLA guidance will be critical for agencies attempting to scale secure, cost-effective cloud infrastructure.
⬇️