Executive Summary
Purpose
Federal leaders do not need another cloud mandate; they need a defensible way to decide where each workload belongs. This paper synthesizes fifteen years of federal cloud policy, the U.S. Government Accountability Office (GAO) audit record, peer-reviewed scholarship, and 2024–2026 developments in egress-fee waivers, the EU Data Act, FedRAMP 20x, the Department of Defense (DoD) Joint Warfighting Cloud Capability (JWCC) follow-on, and AI workloads. It provides a workload-suitability screen, a five-year lifecycle cost model, and a governance roadmap for selecting the architecture that best supports mission delivery, compliance, security, and predictable cost.
Key Findings
Federal cloud decisions now carry greater financial and architectural consequences. FedRAMP 20x is scaling automated authorization, the JWCC follow-on is embedding financial operations into the acquisition vehicle, and AI spending has become a first-order architecture driver. Together, these developments make workload-level suitability, lifecycle economics, and day-one telemetry executive responsibilities rather than downstream technical concerns.
- Cloud economics are contingent, not automatic. Across three GAO reports (2019, 2022, 2026), agencies could not consistently measure cloud spending or savings; 17 of 24 needed IT-management changes to control cloud costs.
- Lock-in has changed shape. Major providers waived exit data-transfer fees in 2024, with conditions. The binding constraints now are refactoring cost, data gravity, workforce skills, and operational data-transfer charges; recurring production egress remains billable (Sections 2.3–2.4, Figure 1).
- Compliance is becoming an engineering discipline. FedRAMP 20x is shifting authorization toward automated, machine-readable evidence for the Low and Moderate baselines; other workloads remain on traditional paths (Section 3.4).
- AI workloads are the new economic center of gravity. AI cost management has moved to the center of cloud financial practice (Section 2.3), and accelerated compute carries its own commitment economics (Section 3.5). Architect and budget for AI as a first-class workload category.
- Suitability beats ideology. A gated, scoreable six-dimension screen and a three-scenario, five-year cost model replace trend-based decisions with measurable criteria (Sections 4.1.1, 4.1.2).
Strategic Recommendations
- Screen every candidate workload with the gated suitability assessment before writing a business case, and publish the scores with it.
- Model five-year costs across on-premises refresh, lift-and-shift, and refactor scenarios, with data movement and AI growth explicit.
- Stand up FinOps governance before migration, not after the first budget surprise.
- Engineer for evidence-based compliance under FedRAMP 20x where eligible and zero trust mandates across the estate.
- Treat AI workloads as a distinct architecture and cost class with day-one telemetry.
Spry Perspective: Modernizing an Evidence-Management Platform
Consider an agency evidence-management platform with continuous cross-boundary ingest, stable demand, FedRAMP High requirements, extensive legacy coupling, partial modularity, and a developing cloud workforce. Lift-and-shift may offer the lowest initial migration cost, yet recurring data movement, AI inference, security tooling, cross-boundary traffic, and logging can make it the highest-cost option over five years. This outcome is illustrative; agencies should validate it through workload telemetry and the lifecycle cost model in Section 4.1.2.
Decision standard. Advance a workload only when its suitability score, five-year lifecycle cost, authorization pathway, funding strategy, and operational telemetry collectively support the target architecture. When these indicators conflict, retain or pilot the workload until measured evidence resolves the disagreement.
Immediate Actions for Federal Agencies
Agencies can begin within ninety days without waiting for a new enterprise migration program. First, inventory recurring data movement across authorization boundaries and place every metered flow in the lifecycle cost model. Second, select the next modernization business case, complete the suitability screen, and validate the indicated outcome through three five-year cost scenarios. Third, require tagging, obligation guardrails, and quarterly cost-architecture reviews for workloads already in the cloud. In parallel, engage contracting to address exit-egress and commitment terms and security teams to plan the applicable authorization path.
PROBELM & ANALYSIS
Scope and Analytical Frame
A number of modernization business cases fail for one simple reason: they compare procurement costs instead of operating economics. Cloud computing can deliver elasticity, pay-per-use economics, and a transfer of infrastructure risk to the provider (Armbrust et al., 2010; Mell & Grance, 2011), and federal policy has tracked that promise from Cloud First (2010) to Cloud Smart (Office of Management and Budget [OMB], 2019). The accumulated evidence supports a disciplined middle position: cloud is not inherently cheaper, on-premises is not inherently obsolete, and cloud benefits are contingent on organizational context and structured cost modeling (Venters & Whitley, 2012; Khajeh-Hosseini et al., 2012).
This is a narrative synthesis, not a systematic review: GAO reports and policy instruments anchor the federal evidence, foundational scholarship supplies the concepts, and 2024–2026 developments rest on primary publications and named trade reporting. Thresholds in the suitability screen (Section 4.1.1) are engagement-derived heuristics; calibrate them against agency data before use.
This paper is intended to support architecture and acquisition discussion, not to substitute for agency-specific engineering, legal, contracting, or budget determinations. Its recommendations should be validated against each agency’s workload telemetry, authorization boundary, appropriation structure, and contract vehicle before use in a decision memorandum, proposal, or implementation plan.
Source currency note. Claims about FedRAMP 20x, JWCC timing, survey results, egress-fee terms, and EU Data Act implementation reflect sources available as of July 2026; revalidate before reuse.
Current State Assessment
Early federal business cases promised lower cost, elastic capacity, less infrastructure management, and faster delivery: each achievable, none automatic (Table 1).
| Assumption | What the Evidence Shows |
|---|---|
| Cloud reduces cost | GAO found agencies realized benefits but could not consistently track spending or savings; figures were likely underreported (GAO, 2019). In 2026, GAO reported federal procurement data could not determine precise cloud obligations (GAO, 2026). |
| Elasticity controls spending | Cost control is not automatic: 17 of 24 major agencies told GAO that controlling cloud costs required changes in their IT management approaches (GAO, 2026). |
| CapEx-to-OpEx improves budgeting | Multi-year appropriations complicate operating-expense volatility; GAO names cost and savings tracking among four persistent challenges (GAO, 2022). |
| Lift-and-shift accelerates ROI | Migration without redesign preserves legacy inefficiencies; the literature distinguishes migration types by the architectural adaptation each requires (Jamshidi et al., 2013). |
| Agencies can exit providers easily | Providers announced exit-fee waivers in 2024, with provider-specific conditions (Sawers, 2024); lock-in persists through proprietary standards, data gravity, and workforce skill concentration (Opara-Martins et al., 2016). |
| Infrastructure burden disappears | Responsibility shifts to governance, automation, identity, and monitoring (GAO, 2022). |
Cloud platforms amplify both strong and weak architectural decisions; migration without disciplined cost modeling produces the cost-visibility failures GAO has documented for seven years (GAO, 2019, 2022, 2026).
Drivers and Trends
AI has changed both the demand curve and the governance problem. In the FinOps Foundation’s 2026 practitioner survey, 98% of respondents reported managing AI spending, up from 31% two years earlier, and AI cost management ranked as the most-needed new skill (FinOps Foundation, 2026b). The survey is a self-selected sample, but the direction is clear: AI concentrates scarce accelerated compute, data gravity, and high-volume movement between storage, training, and inference.
The rules around switching providers have also changed. Google, AWS, and Microsoft waived exit data-transfer fees in 2024, with provider-specific conditions (Sawers, 2024), and the EU Data Act (European Parliament & Council of the European Union, 2023) requires cost-based switching charges from September 2025, banning them after January 12, 2027, though it binds the European market, not U.S. federal contracts. Lock-in now operates through proprietary services, data gravity, operational data-transfer charges, and workforce skill concentration (Opara-Martins et al., 2016).
Compliance is shifting from document-heavy periodic assessment toward automated, evidence-based validation under FedRAMP 20x for eligible baselines (General Services Administration [GSA], 2026), while zero trust mandates (Exec. Order No. 14028, 2021; OMB, 2022) reshape identity, segmentation, and telemetry expectations.
Challenges and Risks
The total-cost-of-ownership literature found early that cloud decisions are frequently ad hoc and hidden costs systematically underestimated (Walterbusch et al., 2013), and recent syntheses find comprehensive assessment methods still scarce and cost transparency still the gating problem (Heinrich et al., 2023). Three drivers dominate.
Data egress and recurring movement. Recurring egress arises from cross-region replication, government-to-commercial transfers, analytics exports, public dissemination, and movement across authorization or provider boundaries (Figure 1). The 2024 exit-fee waivers generally do not reach these flows; they remain metered and belong, flow by flow, in the lifecycle cost model.
Figure 1: Recurring Data Movement in a Hybrid Federal Estate
Note. Original figure. Flows marked $ are metered operational egress; the 2024 exit-fee waivers do not apply to them.
Elasticity without governance. Cloud enables rapid provisioning and, without guardrails, silent overspending: oversized instances, idle managed databases, persistent development environments, and autoscaling without budget thresholds. On-premises estates fail differently, overprovisioning for peak (Armbrust et al., 2010). Measured service (Mell & Grance, 2011) is an accountability tool only if consumption is metered and reviewed; 22 of 24 agencies still rely primarily on historical procurement data (GAO, 2026).
Migration strategy. The chosen approach determines long-term operating cost. Lift-and-shift minimizes upfront change but often preserves legacy inefficiencies and higher steady-state costs. Refactoring requires greater initial engineering investment but can substantially reduce long-term operational expense by modernizing the application rather than simply relocating it (Figure 2). The literature classifies these migration types and supplies structured decision support for this choice (Jamshidi et al., 2013; Khajeh-Hosseini et al., 2012).
Figure 2: Migration Strategy and the Cost Trade

Note. Original figure. Illustrative relative magnitudes, not measured data; model each scenario per Section 4.1.2.
Consequences of Inaction
The consequences are on the federal record (GAO, 2019, 2026; Table 1). Consumption billing misaligned with fiscal-year boundaries can create budget-execution risk and, where obligations exceed available appropriations or approved controls, potential Anti-Deficiency Act exposure. Autoscaling and commitments may increase that exposure depending on obligation controls; hybrid estates without mature governance combine the weaknesses of both models, and lock-in deepens with every year a decision is deferred.
Lessons from Government and Industry
The defense enterprise illustrates the institutional response. JWCC, DoD’s multi-vendor enterprise cloud contract, generated more than $3 billion in task orders by mid-2025 (Harper, 2025); its successor, reported as JWCC Next and the JWCC Unified Cloud Marketplace, published draft acquisition materials in mid-2026, with awards expected from 2027 and embedded financial-operations visibility (Easley, 2026a, 2026b). Major federal buyers now treat financial governance as an architectural requirement.
Industry practice points the same way: FinOps has become an executive function in cloud-mature organizations, with 78% of surveyed practices reporting to the CTO or CIO (FinOps Foundation, 2026b); financial engineering belongs alongside technical engineering from the start.
ARCHITECTURE
Architecture placement is a mission and economic decision, not a referendum on cloud. Each workload should run where its latency, data movement, security classification, authorization boundaries, resilience needs, workforce capacity, and five-year cost profile produce the strongest mission outcome. A common governance and telemetry discipline must span the resulting hybrid estate.
Future State Vision
Cloud-first does not mean cloud-only (OMB, 2019). Retention may be sound where workloads are stable, data movement is heavy and continuous (the decisive variable is movement pattern, not stored volume), latency is strict, refresh cycles are funded, or classified and disconnected environments apply. The mirror-image conditions weigh toward cloud with equal force: demand variability that fixed capacity must overprovision to absorb (Armbrust et al., 2010), provider-scale security telemetry, multi-region continuity, and staffing scarcity. Most agencies will run hybrid estates; without mature governance, hybrid combines the weaknesses of both models; with it, the strengths of each.
Reference Architecture Overview
Figure 3 presents a vendor-neutral reference: a classification-aware hybrid in which sovereign, government, and disconnected cloud form factors can serve workloads that historically defaulted to on-premises retention. The compliance knockout (Section 4.1.1) determines whether those form factors are viable for a given workload.
Figure 3: Sovereign and Disconnected Cloud Form Factors in a Classification-Aware Hybrid

Note. Original figure; a vendor-neutral composite of capabilities major providers now offer.
Core Components
- On-premises core. Stable, data-heavy, or high-compliance systems, refreshed in place and operated with cloud practices.
- GovCloud production. Mission workloads operating within FedRAMP authorization boundaries.
- Commercial or government cloud enclave. Analytics and AI environments where elasticity, managed services, and approved authorization boundaries carry the strongest economics.
- Sovereign and disconnected form factors. Classified, air-gapped, and tactical-edge missions, resolved through the compliance knockout.
- Zero trust fabric. Identity-centric segmentation spanning all environments, with centralized audit and telemetry pipelines.
- FinOps layer. Cost-allocation tagging, budget guardrails, and consumption metering across every boundary.
Security and Governance Considerations
Cloud redistributes security responsibility rather than eliminating it: continuous monitoring, identity engineering, centralized audit pipelines, and infrastructure-as-code governance, multiplied across hybrid boundaries. GAO names cybersecurity among agencies’ four persistent cloud challenges (GAO, 2022). Contractors handling controlled unclassified information face DFARS 252.204-7012, NIST SP 800-171, and CMMC obligations that constrain which cloud services and enclaves may hold that data.
FedRAMP 20x. FedRAMP is now statutory, codified by the FedRAMP Authorization Act (2022) at 44 U.S.C. §§ 3607–3616 and implemented through OMB Memorandum M-24-15 (OMB, 2024). Announced in March 2025, 20x moves eligible authorization toward automation-based validation of Key Security Indicators and machine-readable evidence, with broader adoption targeted for the Low and Moderate baselines (GSA, 2026); other workloads remain on traditional paths, so plan for dual-track compliance. FedRAMP authorization does not eliminate the agency-level authorization to operate, whose cost and schedule belong in the business case (Section 4.1.2).
Zero trust. Executive Order 14028 directed agencies toward zero trust (Exec. Order No. 14028, 2021); NIST SP 800-207 defines the architectural model (Rose et al., 2020), the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model provides the staged adoption path (CISA, 2023), OMB set government-wide goals (OMB, 2022), and the DoD strategy targets FY2027 outcomes (U.S. Department of Defense, 2022). Cloud-native services can simplify identity enforcement, telemetry collection, and policy automation compared with many legacy environments, but the benefit depends on service configuration, integration quality, and operational maturity; count that difference as a modernization benefit in the cloud-side cost model only when the agency can substantiate it.
AI Workloads as a Distinct Cost Class
AI changes the estate’s unit economics in three ways, each an architectural input. First, accelerated compute is supply-constrained and commitment-priced: reserved GPU capacity trades utilization risk for availability, while on-demand capacity trades price for flexibility; the crossover depends on training cadence, inference load, availability requirements, and utilization. Second, training concentrates data gravity: co-locate approved training corpora with compute when repeated cross-boundary movement would create material cost, latency, or security overhead. Third, inference is latency- and egress-sensitive: place it near authorized consumers and meter it per unit of work. Day-one telemetry should include:
- GPU-hours per job.
- Committed-capacity utilization.
- Cost per training run.
- Cost per thousand inferences.
- Model and accelerator type.
- Data-transfer volume.
- Energy or facility costs where material.
- Service-level performance.
Track these measures against the five-year model (Section 4.1.2) and normalize applicable cloud billing data to FOCUS (Section 4.5).
Operational Model
Cloud success requires financial engineering alongside technical engineering: cost-allocation tagging, budget guardrails, rightsizing, commitment optimization, idle-resource detection, and quarterly cost-architecture reviews (FinOps Foundation, 2026b); the federal record shows why (GAO, 2026; Table 1). FinOps stands up before migration, not after the first budget surprise.
AI Workloads as a Distinct Cost Class
Expected outcomes should be verified through the governance metrics in Section 4.5: fewer unallocated or unexplained cloud charges; approved five-year lifecycle models that expose data movement and AI growth; shorter, evidence-supported authorization cycles where FedRAMP 20x applies; AI unit costs and utilization visible from day one; and documented workload-placement decisions traceable to suitability, cost, security, and mission evidence.
ROADMAP & GOVERNANCE
Implementation Roadmap
The roadmap runs through four controlled phases: assess workload suitability, design the lifecycle cost model and target architecture, pilot against the approved model, and scale only after governance controls perform as intended. Each phase ends with an auditable decision gate: screening approval, architecture and funding approval, pilot validation, and scale authorization. These artifacts keep decisions defensible as workload facts, prices, and policy change.
Phase 1 – Assess
Before any migration business case, screen the workload across six dimensions (Table 2), extending peer-reviewed decision-support models (Khajeh-Hosseini et al., 2012; Martens & Teuteberg, 2012) with engagement-derived anchors tuned to agency data. One gating question precedes any score: does a contract vehicle, a funding line, and an authorization pathway exist? The screen belongs jointly to the program office and the CIO shop, with contracting engaged early (Figure 4).
Table 2: Suitability Dimensions and Rating Anchors
| Dimension | 1 (Favors Cloud) | 2 (Intermediate) | 3 (Favors Retention/Hybrid) |
|---|---|---|---|
| Data volume & movement | Light recurring movement; typically under ~10 TB | Moderate movement; ~10–100 TB | Heavy, continuous cross-boundary movement; over ~100 TB |
| Workload variability | Highly variable or bursty | Seasonal or cyclical | Stable and predictable |
| Compliance complexity | Single FedRAMP Low/Moderate boundary | FedRAMP High, or two unclassified boundaries | Three or more boundaries, any classified enclave, or air-gapped |
| Integration surface | Limited, modern interfaces | Moderate coupling | Extensive legacy coupling |
| Refactor feasibility | Straightforward (modular, documented) | Partial (mixed architecture) | Hard (monolithic, poorly documented) |
| Workforce cloud maturity | Mature (cloud engineering & FinOps) | Developing | Minimal |
Scoring. Rate each dimension 1–3 (1 favors cloud; 3 favors retention or hybrid), sum the ratings (6–18), and read the preliminary band from Table 3. The screen is a triage instrument, not a final architecture decision: equal weighting is acceptable only for initial screening, and the engagement-derived anchors require calibration against agency data. One rating is non-compensable: compliance = 3 directs the workload to retention or an eligible sovereign or disconnected form factor regardless of total. Scores within one point of a band boundary are indeterminate. In every case, the Phase 2 cost model, authorization analysis, and engineering assessment validate the indicated outcome and govern when the evidence conflicts. Security modernization benefit is not scored here; Section 3.4 evaluates it for inclusion in the cloud-side cost model only when the agency can substantiate the benefit.
Table 3: Score Bands and Indicated Outcomes
| Total | Indicated Outcome |
|---|---|
| 6–9 | Cloud-native recommended: refactor to managed services; consumption governance from day one. |
| 10–12 | Phased refactor plus cloud: migrate in tranches, highest-variability components first. |
| 13–15 | Hybrid, retain core: keep stable, data-heavy, or high-compliance cores; extend with cloud analytics and burst capacity. |
| 16–18 | On-premises modernization: refresh in place; adopt cloud operating practices without relocation. |
Figure 4: The Suitability Screening Flow

Note. Original figure. The gate and the compliance knockout override the summed score; the cost model governs on disagreement.
Worked example. An agency evidence-management platform: ~400 TB continuous cross-boundary ingest (3); stable workload (3); FedRAMP High plus one boundary (2); extensive legacy coupling (3); partially modular (2); developing workforce (2). Total 15: hybrid, retain core. Keep the chain-of-custody core, extend analytics into a compliant cloud enclave, and rescore as the facts change.
Phase 2 – Design
First-year savings rarely reflect steady state; formal total-cost-of-ownership models exist to surface hidden cost categories (Walterbusch et al., 2013; Heinrich et al., 2023). Model three scenarios over five years; Table 4 and Figure 5 show the comparison structure for the Section 4.1.1 worked example:
- Scenario A, on-premises refresh: hardware lifecycle, supply-chain lead times, licensing, staffing, security and continuity provisioning, facility overhead, and refresh timing.
- Scenario B, lift-and-shift: consumption net of commitment discounts, operational data transfer, assessment-and-authorization cost and schedule, and expanded security tooling, with sensitivity analysis on utilization, commitments, and pricing.
- Scenario C, refactored cloud-native: higher upfront development, reduced steady-state footprint, automation gains, refactor schedule risk, and authorization cost for the re-architected system.
Table 4: Notional Five-Year Cost Comparison for the Worked Example
| Cost Category (5-Year Totals, $M, Notional) | A: On-Premises Refresh | B: Lift-and-Shift | C: Refactor |
|---|---|---|---|
| Upfront investment (refresh, migration, or refactoring) | 6.0 | 3.5 | 9.0 |
| Steady-state infrastructure and consumption | 16.0 | 19.5 | 12.5 |
| Recurring data movement | 0.5 | 3.0 | 1.8 |
| Assessment and authorization | 0.6 | 1.4 | 1.6 |
| Operations staffing | 7.5 | 6.0 | 4.5 |
| Five-year total | 30.6 | 33.4 | 29.4 |
Figure 5: Five-Year Cost Comparison for the Evidence-Management Modernization Scenario
Note. Notional figures for illustration; they show the structure of the comparison, not measured costs. The indicated hybrid outcome combines Scenario A for the core with a refactored analytics enclave; the cost model prices that combination directly.
Model integrity depends on transparent assumptions. For each scenario, document the price basis, utilization profile, labor rates, data-transfer volumes, authorization schedule, refresh timing, discount commitments, inflation treatment, and AI-growth forecast. Run sensitivity tests on the variables most likely to change the indicated outcome, and retain the assumptions with the decision record.
Funding mechanics belong in the model. An on-premises refresh may draw procurement appropriations, refactoring may constitute development work, and steady-state consumption may draw operations and maintenance funds, subject to agency-specific purpose, time, and amount determinations. Consumption billing must respect fiscal-year boundaries and bona fide need. Defense funds are programmed roughly two years ahead, so agencies should use the model as a budget-formulation input and evaluate the Technology Modernization Fund, working capital funds, or other available authorities for refactor capital. Contracting and financial-management officials should structure commitment discounts as obligation strategies consistent with the governing appropriation and vehicle.
Phase 3 – Pilot
Migrate in tranches, highest-variability components first. Validate pilot consumption against the Phase 2 model, not first-year invoices; steady state is the test. Prove out tagging, guardrails, and compliance-evidence pipelines on the pilot, and use its telemetry to calibrate the suitability anchors for the next tranche.
Phase 4 – Scale
Scale under the governance proven in the pilot: commitment discounts structured with contracting (Section 4.1.2), authorization maintained per Section 3.4, and rescoring as workforce maturity, refactoring investment, and provider capabilities change the facts. Each new workload enters through the same screen, model, and telemetry discipline.
Governance Framework
Governance rests on three instruments. First, the gated suitability screen: no business case proceeds without a contract vehicle, funding line, and authorization pathway, and published scores accompany every proposal. Second, the five-year cost model: it governs whenever a score is indeterminate or disputed. Third, FinOps controls: tagging, guardrails tied to obligations, commitment optimization, idle-resource detection, and quarterly cost-architecture reviews (FinOps Foundation, 2026b).
Roles and Responsibilities
- Program office. Owns the screen jointly with the CIO shop, supplies workload facts, publishes scores with the business case.
- CIO shop. Co-owns the screen, maintains the cost model and rating anchors, operates telemetry and evidence pipelines.
- Contracting. Engaged early; negotiates exit-egress and commitment terms and confirms flow-down at task-order award (Sections 4.1.2 and 5.3).
- FinOps function. Reports to the CTO or CIO; runs tagging, guardrails, and quarterly cost-architecture reviews.
- Security and compliance. Maintains dual-track authorization plans and zero trust alignment (Section 3.4).
Organization Adoption
Workforce cloud maturity is a scored dimension, not an afterthought: minimal cloud engineering and FinOps skills weigh a workload toward retention until investment changes the facts. Train and hire against the target operating model, rescore as maturity develops, and let adoption pace follow demonstrated capability.
Metrics and Performance Measurement
GAO’s seven-year record shows what happens without measurement (GAO, 2019, 2026). The CIO shop and FinOps function should maintain a performance baseline for each workload and report, at least quarterly, consumption allocated by tags; unit costs against the five-year model; recurring egress volume and cost by boundary; commitment coverage and utilization; idle-resource burn; authorization cycle time under applicable pathways; and AI compute telemetry from day one. Normalize applicable provider billing data to the FinOps Open Cost and Usage Specification (FOCUS, version 1.4; FinOps Foundation, 2026a) so unit costs remain comparable across providers. The governance board should define thresholds that trigger rightsizing, commitment changes, architectural review, or workload rescoring.
RECOMMENDATIONS
The recommendations below convert the paper’s findings into four approval conditions. Every workload must have a published suitability score, a validated five-year lifecycle model, an identified authorization and funding path, and operational telemetry with named owners. These conditions apply whether the indicated outcome is cloud-native refactoring, phased migration, hybrid placement, or on-premises modernization.
Strategic Recommendations
- Screen every candidate workload and publish scores with the business case; every case scored within two quarters.
- Model five-year costs across refresh, lift-and-shift, and refactor, with data movement and AI growth explicit; nothing advances on first-year pricing.
- Stand up FinOps before migration: tagging, guardrails, and quarterly reviews before the first workload moves.
- Let suitability and the cost model, not policy trend, direct each workload; retention in place is a legitimate outcome: measure decisions scored, not migrated.
Technical Recommendations
- Engineer for evidence-based compliance: machine-readable evidence and automated validation under FedRAMP 20x where eligible, zero trust telemetry designed in.
- Treat AI as a distinct cost class: screen accelerated compute separately, weigh data gravity before consolidating training data, require day-one telemetry.
- Design hybrid boundaries around data movement; meter recurring cross-boundary flows.
- Adopt cloud operating practices everywhere: infrastructure as code, telemetry, tagging.
Executive Takeaway
The question facing federal leaders is no longer whether cloud works. It does. The question is whether each workload belongs there. Agencies that answer that question with measurable economics rather than assumptions will modernize faster, spend more predictably, and avoid the next decade of technical debt.
Acquisition Considerations
Exit-fee waivers do not reach operational egress: press for exit-egress terms at the vehicle or BPA level with flow-down at task-order award, and structure commitment discounts as multi-year strategies across true-consumption and prepaid patterns. Watch the JWCC Unified Cloud Marketplace (Easley, 2026a, 2026b); fund refactoring via the Technology Modernization Fund or working capital funds.
Conclusion
Fifteen years of policy and a consistent audit record support one conclusion: federal cloud economics are contingent, not automatic, and delay compounds technical and financial exposure. Within ninety days, an agency can inventory recurring data movement, screen its next modernization business case, build the three-scenario lifecycle model, and establish tagging and obligation guardrails. Leaders should require that evidence before approving workload placement. When suitability, cost, security, and mission data are recorded together, the modernization decision becomes faster to defend, easier to govern, and more resilient as technology and prices change.
ABOUT THE AUTHOR
This paper was prepared by the Enterprise Modernization & Cloud Strategy Practice at Spry Methods, Inc. It abridges a full APA edition available on request, and its empirical claims are supported by the cited sources. Spry provides services aligned to the framework, including suitability screening, lifecycle cost modeling, refactor-feasibility analysis, hybrid architecture, technical workshops, pilots, and FinOps governance. The framework and its decision criteria are published so agencies can evaluate and apply them independently. Contact: sprymethods.com | [email protected] | LinkedIn: Spry Methods.
REFERENCES
Armbrust, M., Fox, A., Griffith, R., Joseph, A. D., Katz, R., Konwinski, A., Lee, G., Patterson, D., Rabkin, A., Stoica, I., & Zaharia, M. (2010). A view of cloud computing. Communications of the ACM, 53(4), 50–58. https://doi.org/10.1145/1721654.1721672
Cybersecurity and Infrastructure Security Agency. (2023). Zero trust maturity model (Version 2.0). https://www.cisa.gov/resources-tools/resources/zero-trust-maturity-model
Easley, M. (2026a, March 24). Pentagon wants greater visibility into cloud spending with JWCC Next overhaul. DefenseScoop. https://defensescoop.com/2026/03/24/jwcc-next-cloud-spending-dod-cio-kirsten-davies/
Easley, M. (2026b, June 1). Pentagon’s JWCC follow-on would create cloud marketplace, expand AI and edge computing. DefenseScoop. https://defensescoop.com/2026/06/01/pentagon-jwcc-ucm-draft-performance-of-work-statement/
European Parliament & Council of the European Union. (2023). Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data (Data Act). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2023/2854/oj
Exec. Order No. 14028, 86 Fed. Reg. 26633 (2021). Improving the nation’s cybersecurity. https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity
FedRAMP Authorization Act, Pub. L. No. 117-263, § 5921, 136 Stat. 2395 (2022) (codified at 44 U.S.C. §§ 3607–3616).
FinOps Foundation. (2026a). FinOps Open Cost and Usage Specification (FOCUS), Version 1.4. https://focus.finops.org/
FinOps Foundation. (2026b). State of FinOps 2026. https://data.finops.org/
General Services Administration. (2026). FedRAMP 20x. FedRAMP. https://www.fedramp.gov/20x/
Harper, J. (2025, August 7). Pentagon officials gearing up for JWCC Next enterprise cloud program solicitation. DefenseScoop. https://defensescoop.com/2025/08/07/jwcc-next-enterprise-cloud-program-dod-solicitation-plans/
Heinrich, S., Kreft, N., Schuster, T., & Volz, R. (2023). A total cost of ownership model for cloud computing infrastructure. In Proceedings of the 56th Hawaii International Conference on System Sciences. https://hdl.handle.net/10125/103337
Jamshidi, P., Ahmad, A., & Pahl, C. (2013). Cloud migration research: A systematic review. IEEE Transactions on Cloud Computing, 1(2), 142–157. https://doi.org/10.1109/TCC.2013.10
