Federal cyber experts had significant concerns about the security of Microsoft's Government Community Cloud High (GCC High) but approved it anyway, despite the company's inability to provide adequate documentation and evidence of its security measures. The approval was made after the product was already being used across the government and defense industry. This decision has raised questions about the effectiveness of the Federal Risk and Authorization Management Program (FedRAMP) in ensuring the security of cloud services used by the government. The program has been criticized for being slow and ineffective, with some arguing that it has become a rubber stamp for industry.