Skip to main content

🔔 Notifications Hub: See compliance updates in one place

Federal Risk and Authorization Management Program (FedRAMP)

FedRAMP is the government-wide program that standardizes security assessment and authorization for cloud services used by federal agencies. Introduced in 2011, codified into law in December 2022 (FedRAMP Authorization Act, Title 5 Subtitle B of the FY23 NDAA). Cloud service providers achieve FedRAMP authorization once, and any federal agency can reuse that authorization. The program is managed by GSA with JAB (Joint Authorization Board) oversight for the highest-visibility authorizations.

FedRAMP Baselines

  • FedRAMP Low: ~125 NIST SP 800-53 controls. For cloud services where a breach would have limited adverse effect.
  • FedRAMP Moderate: ~325 controls. The most common baseline. For services where a breach would have serious adverse effect on operations or assets.
  • FedRAMP High: ~421 controls. For services handling the most sensitive unclassified government data.

Baseline selection uses FIPS 199 security categorization (Low/Moderate/High) based on confidentiality, integrity, and availability impact. Control counts adjust across Rev 4 and Rev 5 baselines; the numbers above are approximate.

Authorization Paths

  • Joint Authorization Board (JAB) P-ATO: Review by DoD, DHS, and GSA representatives. Results in a Provisional ATO that any agency can leverage. The JAB prioritizes cloud services with broad government-wide demand.
  • Agency Authorization: A sponsoring federal agency issues the authorization. Any other agency can reuse it. Most FedRAMP Authorized services went through this path.

The 3PAO

A Third-Party Assessment Organization (3PAO) is an accredited independent firm that performs the security assessment. The 3PAO is the FedRAMP equivalent of a CMMC C3PAO: accredited, independent of the CSP, and responsible for producing the Security Assessment Report (SAR) used during authorization.

Continuous Monitoring

FedRAMP authorization is not one-and-done. Authorized CSPs submit monthly vulnerability scans (POA&M updates, deviation requests), perform annual assessments, and notify their authorizing official of significant changes. Missing continuous monitoring obligations can lead to authorization revocation.

FedRAMP 20x

FedRAMP 20x (launched 2024/2025) is the program's modernization effort. The goals are to cut authorization time dramatically through automation, streamline documentation, and shift from static packages to machine-readable continuous monitoring. Community working groups are shaping the technical and process changes. If you're pursuing FedRAMP authorization now, expect the program you encounter at the end of the process to look different from the one you started with.