Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> It’s mostly an easy button for procurement officers

I know. I have never had an issue with FedRAMP as a single marketplace. The issue has always been arbitrary compliance requirements

> Startups are always problematic for government procurement

Absolutely, and ensuring that they are within a verified marketplace such as that which FedRAMP intended to make is good.

The issue is the upfront cost to become FedRAMP compliant is so high, that most vendors do not even try until extremely late in their lifecycle.

Furthermore, a lack of vendors does lead to extremely suboptimal pricing. There is some cost to recoup from going through FedRAMP compliance hurdles, but a lot of it is also because once you are FedRAMP compliant, depending on the tooling, you have a captive market with maybe 1 or 2 competitors.

> Startups are always problematic for government procurement, and unless you play in a space that is setup to handle small vendors, your business is going through partners anyway

I'm not talking about SIs or MSSPs. I'm talking about specific FedRAMP compliance partners. They provide no value except checkboxing, but all of vendors need to partner with them.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: