
FedRAMP: What It Is, Who Needs It, and Where to Start
Emily Bonnie
Senior Content Marketing Manager
Rob Gutierrez
Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP
FedRAMP sets the gold standard for cloud security, and achieving certified status can open up significant growth opportunities in both government and private sectors. Understanding and navigating FedRAMP compliance, however, can be complex and full of questions.
Does your organization need to be FedRAMP compliant? Even if you’re not legally required to comply, what are the benefits of achieving FedRAMP authorization? What does the authorization process entail, and how do you get started? How much resources, time, and money will it take to get FedRAMP compliant?
This article demystifies FedRAMP authorization and offers practical guidance and best practices for organizations considering compliance.
What is FedRAMP?
The Federal Risk and Authorization Management Program (FedRAMP) is designed to ensure that all cloud services used by US federal agencies meet strict security requirements, mitigating the risk of data breaches and cyber threats. It provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud technologies.
FedRAMP was introduced in 2011 and enacted into law in December 2022 as part of the US National Defense Authorization Act. In 2025 and 2026, the program underwent its most significant redesign since its creation: FedRAMP 20x replaced the paperwork-heavy legacy model with automated, machine-readable validation, and the Consolidated Rules for 2026 (CR26) brought every requirement into a single ruleset. Under CR26, "FedRAMP Authorized" became "FedRAMP Certified," and the familiar Low, Moderate, and High impact levels became Certification Classes B, C, and D.
The result is a program that remains one of the most rigorous cloud security standards in the world, with a certification path that is faster and more accessible than it has ever been.
What is the purpose of FedRAMP?
As federal agencies began to replace traditional software with cloud-based solutions, cloud service providers (CSPs) were required to prepare an authorization package for each agency they wanted to work with. Much like vendor security questionnaires, requirements for these authorization packages were inconsistent, resulting in significant manual and duplicate work for both cloud solutions creating the authorization packages and the agencies reviewing them.
FedRAMP offers a consistent, standardized approach to streamline this process. By using a "do once, use many" framework, FedRAMP enables CSPs and federal agencies to reuse existing security assessments, saving significant time and reducing duplicated efforts.
Benefits of FedRAMP certification
Cloud service providers with a FedRAMP Certification are listed in the FedRAMP Marketplace, which government agencies use to find cloud-based solutions that already meet federal security requirements. A Marketplace listing makes you much more likely to win business from government agencies, since it's easier for an agency to adopt a certified product than to start the process with a new vendor. The Marketplace has grown dramatically since FedRAMP 20x launched, with more than 650 cloud services listed as of mid-2026, nearly double the count from two years earlier.
Beyond access to the federal market, a FedRAMP Marketplace listing can also give you a significant competitive advantage in the private sector. FedRAMP is a rigorous and respected security standard, so authorization can give current and potential customers the highest confidence in your commitment to meeting stringent cloud security standards.

The Ultimate Guide to Federal Frameworks
Get an overview of the most common federal frameworks, who they apply to, and what their requirements are.
Who needs to be FedRAMP compliant?
All cloud service providers that process or store federal data must be FedRAMP certified.
This requirement extends to organizations that handle federal data, directly or indirectly, through cloud computing environments. It's not only the CSPs that need to be concerned with FedRAMP; federal agencies and state and local governments that use cloud services must also ensure their providers are compliant. In addition, businesses seeking to enter the federal marketplace must achieve FedRAMP certification.

FedRAMP requirements
What FedRAMP requires of you now depends on which certification path you take. Under the Consolidated Rules for 2026, there are two: the modern 20x path built on automated validation, and the legacy Rev5 path, which accepts new applications until June 11, 2027.
FedRAMP 20x requirements: Key Security Indicators
The 20x path replaces control-by-control narrative documentation with 46 Key Security Indicators (KSIs) organized into 10 families:
- Cloud Native Architecture
- Service Configuration
- Identity and Access Management
- Monitoring, Logging, and Auditing
- Policy and Inventory
- Change Management
- Recovery Planning
- Incident Response
- Supply Chain Risk
- Cybersecurity Education
Each KSI is a specific, measurable security outcome that maps back to NIST 800-53 controls, and providers demonstrate them through automated, machine-readable evidence rather than written descriptions. Many KSIs must be validated "persistently," meaning continuously verified from the production environment rather than checked once at assessment time. For a full breakdown, see our guide to FedRAMP Key Security Indicators.
FedRAMP Rev5 requirements: NIST 800-53 baselines
The Rev5 path is a derivative of NIST Special Publication 800-53 and uses its control baselines, adding FedRAMP-specific parameters and additional control requirements. The baselines were historically labeled Low, Moderate, and High; under CR26, those became Certification Classes B, C, and D, with Class B having the fewest controls and Class D the most controls and strictest parameters.
There is also a privacy control baseline applied to systems of every class. If a CSP processes personally identifiable information (PII), for instance, it must implement controls assigned to the privacy control baseline.
Rev5 requirements are broken down into 18 control families based on NIST 800-53 Rev. 5:
- Access Control
- Awareness and Training
- Audit and Accountability
- Security Assessment and Authorization
- Configuration Management
- Contingency Planning
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Physical and Environmental Protection
- Planning
- Personnel Security
- Risk Assessment
- System and Services Acquisition
- System and Communication Protection
- System and Information Integrity
- Supply Chain Risk Management (new with Revision 5)
Recommended reading
FedRAMP 20x: Goals, Timeline, and the 2026 Consolidated Rules
Recommended reading
FedRAMP 20x Continuous Monitoring Requirements: What’s Changed, What Hasn’t, and Where Teams Can Get Stuck
Tips for getting started with FedRAMP compliance
Embarking on the journey to FedRAMP compliance can be a daunting task, but learning about the process and following best practices can make compliance much more manageable.
Here are some essential tips and best practices for organizations that are just getting started with FedRAMP compliance:
Thoroughly understand requirements for your certification path
Familiarize yourself with the Consolidated Rules for 2026, which define every FedRAMP requirement in plain MUST and MUST NOT language and are published as machine-readable data on GitHub. If you're pursuing 20x, study the 46 Key Security Indicators and the NIST 800-53 controls they map to. If you're on the Rev5 path, focus on the NIST SP 800-53 baseline for your target class.
Perform a gap analysis to understand how your current environment aligns with FedRAMP
This gap analysis should cover all aspects of your cloud service, from data encryption and user authentication to incident response and risk management practices. The outcome will provide a clear roadmap for bridging any gaps and ensuring your services are fully compliant with FedRAMP standards.
Secure support and commitment across your organization
Achieving FedRAMP compliance is a significant endeavor that requires a concerted effort across your organization. It's essential to garner support and commitment from both the executive leadership and the technical teams responsible for implementing the necessary changes. It can be a costly endeavor, so we recommend doing a budget and resource analysis to ensure feasibility and preparedness for the assessment and process.
This involves educating stakeholders about the value and implications of FedRAMP compliance, including the potential for expanded business opportunities within the federal market and the overall enhancement of your security posture. Establishing a cross-functional team dedicated to achieving compliance can facilitate collaboration and ensure that all efforts are aligned with your organization's goals.
Decide whether you need an agency sponsor
One of the biggest changes under FedRAMP 20x is that an agency sponsor is no longer required. Providers on the 20x path apply directly through Program Certification, which removes what was historically the single hardest prerequisite for smaller CSPs entering the federal market.
An agency sponsor is still required on the Rev5 path. If that's your route, partnering with a federal agency that currently uses your service or is committed to adopting it can significantly streamline the process, provide insight into agency-specific security concerns, and add credibility to your application. Engage early and often with potential agency partners to build the relationship and secure commitment.
Even on the 20x path, building agency relationships matters: agencies make the final decision about using your service, and the certification model expects direct, ongoing communication with your agency customers through quarterly reporting and reviews.
Carefully define your system boundaries
A critical step in the FedRAMP compliance process is accurately defining the boundaries of your cloud system. This includes:
- Internal Components: Identifying all elements within your cloud service, from infrastructure and applications to data storage and processing units, ensuring that security controls are uniformly applied.
- External Service Connections: Cataloging all connections to external services and third-party providers, assessing the security implications of these integrations, and ensuring they do not compromise your compliance posture. If you don't have on-premise components and rely on cloud services such as AWS, Azure, or Google Cloud Platform, there may be areas of shared responsibility or inheritance for controls.
- Data and Metadata Flows: Mapping out the flow of data and metadata within and outside your system to understand potential vulnerabilities and apply appropriate security measures. This comprehensive understanding of your system's boundaries is essential for implementing effective security controls and for documenting your security posture in your certification package. FedRAMP’s Minimum Assessment Scope rules, formalized during the 20x rollout, give providers clearer guidance for narrowly defining information resource boundaries while still capturing all necessary components.
Approach FedRAMP as an ongoing commitment
FedRAMP compliance is not a one-time achievement. It’s an ongoing, continuous commitment to maintaining high security standards. It requires regular monitoring, updating security controls, and periodic reassessments to adapt to evolving threats and changes in your cloud services and threat landscape.
Under CR26, quarterly Ongoing Certification Reports, annual independent assessments, and continuous vulnerability monitoring are standing requirements for every certified provider. Adopting a mindset that treats FedRAMP as an integral part of your operational processes will help you stay compliant and secure over time.
Use FedRAMP resources
The FedRAMP Program Management Office (PMO) remains an essential resource, though how you engage with it has changed. FedRAMP has revived help.fedramp.gov as its central repository of guidance, FAQs, and articles, and it is shifting intake from the shared info@fedramp.gov inbox toward structured request forms that route questions more consistently. Retired templates and legacy guidance are preserved at fedramp.gov/legacy for reference, while current requirements live in the Consolidated Rules at fedramp.gov/2026.
Engaging with these resources early and often can help you navigate the process, avoid common pitfalls, and develop a successful strategy for achieving and maintaining certification. FedRAMP also runs public community working groups and monthly community updates, which are the best window into how requirements are being interpreted in practice.
FedRAMP Compliance Checklist
Get a step-by-step checklist to walk you through the process of preparing for FedRAMP authorization.
How to streamline FedRAMP compliance with automation + AI
Because it's a rigorous standard, achieving FedRAMP certification requires a significant amount of time and resources. On the 20x path, you'll need to stand up automated evidence collection, validate your Key Security Indicators, and maintain machine-readable certification data. On the Rev5 path, you'll complete a gap analysis and readiness work, implement NIST 800-53 controls for your target class, and collect documentation and evidence for your assessor. And once certified, every provider maintains compliance through quarterly reporting, continuous monitoring, and annual assessments.
Cybersecurity platforms like Secureframe Defense can significantly cut down on the amount of time and effort it takes to complete these manual tasks, freeing up your team to focus on strategic objectives.
Here are a few reasons organizations choose Secureframe as their partner for achieving and maintaining compliance with federal frameworks:
- Government and federal compliance expertise: Secureframe achieved FedRAMP 20x certification through both the Phase One (Low) and Phase Two (Moderate) pilots, so our platform and guidance reflect direct experience with the new model.
- Integrations with federal cloud products: Secureframe integrates with your existing tech stack, including AWS GovCloud, to automate infrastructure monitoring and evidence collection.
- Trusted 3PAO partner network: Secureframe has strong relationships with certified Third Party Assessment Organizations like Schellman and Prescient Assurance, and can support FedRAMP and other federal audits such as CMMC and CJIS.
- Cross-mapping across frameworks: FedRAMP and NIST 800-53 have many overlapping requirements with NIST 800-171, CJIS, and other federal frameworks. Instead of starting from scratch, our platform can help map what you’ve already done for FedRAMP to other frameworks so you’re never duplicating efforts.
- Continuous monitoring: By monitoring your tech stack 24/7 to alert you of non-conformities, Secureframe makes it easier to maintain continuous compliance and a strong security posture. You can specify test intervals and notifications for required regular tasks to maintain FedRAMP compliance. You can also use our Risk Register and Risk Management capabilities to support your continuous monitoring efforts and POA&M maintenance.
To learn more about how Secureframe can help you comply with FedRAMP and other federal frameworks, schedule a demo with a product expert.
Note: This post was originally published in February 2024 and has been updated for accuracy.
Use trust to accelerate growth
FAQs
What is FedRAMP in simple terms?
FedRAMP is a government-wide program that sets security standards for cloud services used by the U.S. government. You can think of it as a security checkpoint that cloud services must pass to work with federal government agencies.
What does FedRAMP stand for?
FedRAMP stands for the Federal Risk and Authorization Management Program.
Is FedRAMP mandatory?
FedRAMP authorization is mandatory for cloud service providers (CSPs) that want to work with federal agencies.
Who needs to be FedRAMP certified?
Cloud service providers that offer services to U.S. federal agencies need to be FedRAMP certified. This can include Software-as-a-Service (SaaS), Infrastructure-as-a-Service (IaaS), and Platform-as-a-Service (PaaS) providers that handle government data.
Is FedRAMP only for government?
While FedRAMP is designed for government use, its rigorous standards are often adopted by private sector companies seeking to enhance their cloud security posture, especially those wishing to do business with the government.
Who governs FedRAMP?
FedRAMP is governed by the FedRAMP Board, established in 2024 to replace the Joint Authorization Board. Its members include chief information officers from the Department of Homeland Security (DHS), Department of Defense (DoD), Department of Veterans Affairs, Department of the Air Force, Cybersecurity and Infrastructure Security Agency (CISA), Federal Deposit Insurance Corporation (FDIC), and General Services Administration (GSA). The General Services Administration administers the program.
What is the difference between NIST and FedRAMP?
NIST (National Institute of Standards and Technology) creates a wide range of security standards and guidelines, including those for cybersecurity. FedRAMP is a program that applies NIST's security standards specifically to cloud services used by the federal government, adding a layer of requirements and processes for authorization and continuous monitoring. Essentially, FedRAMP builds on NIST standards to ensure cloud services meet the specific needs of federal agencies.
What are the three levels of FedRAMP?
FedRAMP historically used three impact levels: Low, Moderate, and High.
Under the Consolidated Rules for 2026, those became Certification Classes B, C, and D respectively, joined by Class A, a new time-limited entry tier for providers with a recent SOC 2 Type II or GovRAMP assessment.
Is GovCloud required for FedRAMP certification?
Only for Class D (the former High baseline). Many organizations pursuing Class C (formerly Moderate) use GovCloud because they want to or because their agency customers require it. GovCloud is not required for Class B.
What is FedRAMP 20x?
FedRAMP 20x is the modernized certification path introduced in 2025 and formalized in the Consolidated Rules for 2026. It replaces narrative documentation and point-in-time audits with 46 Key Security Indicators validated through automated, machine-readable evidence, and it requires no agency sponsor. It is the recommended path for cloud-native providers and will eventually replace the legacy Rev5 process entirely.
What's the difference between FedRAMP Authorized and FedRAMP Certified?
They describe the same status under different names. The Consolidated Rules for 2026 retired "FedRAMP Authorized" in favor of "FedRAMP Certified" for every provider in the Marketplace, with no change to controls or boundaries. The rename clarifies that a FedRAMP Certification is FedRAMP's validation of a provider's security information, distinct from the Authority to Operate that each agency issues for its own use of the service.

Emily Bonnie
Senior Content Marketing Manager
Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.

Rob Gutierrez
Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP
Rob Gutierrez is an information security leader with nearly a decade of experience in GRC, IT audit, cybersecurity, FedRAMP, cloud, and supply chain assessments. As a former auditor and security consultant, Rob performed and managed CMMC, FedRAMP, FISMA, and other security and regulatory audits. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including NIST 800-171, NIST 800-53, FedRAMP, CMMC, SOC 2, and ISO 27001.