A Government Accountability Office report published June 23, 2026 found that the federal government spends more than $10 billion annually on cloud services while operating under a procurement framework that contains no statutory definition of “cloud computing,” relies on an information technology definition written more than a decade ago, and leaves agencies navigating conflicting guidance from the Office of Management and Budget and the National Institute of Standards and Technology. GAO examined 24 CFO Act agencies, documented six categories of procurement challenges, and issued recommendations directed at GSA, DHS, CISA, and the Federal CIO Council, along with two matters for congressional consideration.
Background
Federal cloud spending grew from $2.3 billion to more than $10 billion annually over the past decade as agencies migrated workloads from on-premise infrastructure to commercial cloud platforms. That growth has outpaced the legal and regulatory framework governing how agencies buy those services.
The Federal Acquisition Regulation contains no definition of “cloud computing.” Its information technology definition has not been updated since the Federal Information Technology Acquisition Reform Act—FITARA—set it in statute more than a decade ago. The FAR’s definitions for commercial products and services also do not reflect the subscription-based, consumption-priced delivery models common to cloud computing, creating legal ambiguity for contracting officers applying standard acquisition procedures to cloud buys. The FAR’s commercial item provisions were designed for tangible goods and fixed deliverables; they do not accommodate the elasticity, shared-responsibility models, and metered pricing that define cloud services today.
Agencies also operate under software guidance from OMB and NIST that conflicts in ways GAO described as creating “unnecessary burdens” on procurement and cloud operations. The Federal Procurement Data System—Next Generation, FPDS-NG, the government’s primary contract spending database, has been officially retired. Yet 22 of the 24 agencies GAO reviewed still used it to track cloud obligations. GAO found those figures imprecise: IT product and service codes in FPDS do not map cleanly to cloud service categories, so agencies cannot accurately capture cloud spending in the system regardless of effort.
Key Details
GAO’s review of all 24 CFO Act agencies produced a frequency count of each challenge category across the government:
Fifteen agencies reported that outdated FAR definitions directly hindered cloud procurements. A separate 15 agencies struggled to obtain FedRAMP-authorized cloud solutions for their requirements. Seventeen agencies said they needed to overhaul IT management practices to control cloud costs—a discipline known as FinOps—but lacked a government-wide mandate requiring it. Seventeen agencies also reported confusion from conflicting OMB and NIST software guidance, including guidance on software bills of materials, or SBOMs. Eleven agencies encountered technical complexity managing multi-vendor cloud environments. Ten agencies cited resource constraints in building and maintaining cloud-skilled workforces.
All recommendations from this report remain open. GAO noted that the FPDS challenge is particularly acute for oversight: Congress and inspectors general rely on FPDS data to track federal IT spending trends, and inaccurate cloud obligation figures undermine that function across the government.
GAO presented two matters for congressional consideration: updating the statutory definitions of commercial products and services to accommodate modern cloud delivery models and establishing a federal definition of “cloud computing” aligned with NIST standards, while also updating information technology definitions in regulation to be consistent with FITARA. On the executive side, GAO directed GSA to mandate FinOps practices and benefit reporting across agencies—though GSA disagreed with this recommendation—directed DHS to have CISA issue SBOM implementation guidance to resolve the OMB-NIST conflict, and directed the Federal CIO Council to document and disseminate best practices for managing multi-vendor cloud environments.
What It Means for Contractors
The regulatory gaps GAO identified carry direct consequences for companies competing in the federal cloud market.
The absence of a FAR definition for “cloud computing” surfaces in inconsistent solicitation structures, uneven application of commercial item procedures, and disputes over which standard clauses apply to subscription-priced services. Cloud service providers that built their federal practices on the assumption that contracting officers will consistently apply commercial item streamlining are operating on a foundation the current FAR does not reliably support. Until Congress acts on the matters GAO identified, expect continued variation in how agencies structure cloud solicitations and which terms they flow down to vendors.
The FedRAMP authorization backlog compounds the access problem. Fifteen agencies told GAO they struggled to obtain FedRAMP-authorized solutions. For cloud providers, that reflects sustained demand pressure on the authorization pipeline and ongoing risk that agencies will pursue workarounds—buying cloud services through existing IT contract vehicles without discrete authorization assessments. That approach creates compliance exposure for vendors and security risk for the government.
Imprecise FPDS obligation data degrades market intelligence. Cloud companies rely on procurement database spending figures to map agency demand, track competitor awards, and project opportunity pipelines. When obligation data is miscoded because IT product and service codes do not align with cloud categories, those market projections carry compounding error. Until a successor system with cloud-specific coding is deployed and agencies migrate their data, historical FPDS cloud spending figures should be treated as directional estimates rather than reliable baselines.
For prime contractors managing multi-vendor cloud environments on agency contracts, the absence of government-wide best practices means each agency works out its own coordination procedures at performance time. When interoperability requirements go unresolved at the solicitation stage, the prime and its cloud subcontractors absorb the integration complexity. The Federal CIO Council’s charge to document and disseminate multi-vendor best practices should reduce that friction over time, but contractors should not count on near-term regulatory relief.
GSA’s anticipated FinOps mandate will reshape how cloud task orders are structured if ultimately implemented. If FinOps reporting becomes a contract deliverable rather than an internal agency function, primes and cloud subcontractors should expect new cost-optimization reporting requirements and potentially performance metrics tied to measurable savings. Companies that have not built FinOps capabilities into their federal delivery models should treat this recommendation as an early signal to invest.
The SBOM guidance conflict directly affects software vendors in federal cloud supply chains. Once DHS and CISA issue implementation guidance resolving the OMB-NIST conflict, it will set baseline software composition transparency requirements for components entering federal cloud environments—standards vendors will need to meet to stay competitive on security-sensitive task orders.