# FedRAMP Marketplace | Secureframe

> The FedRAMP Marketplace lists Authorized, In Process, and Ready cloud services. How agencies leverage existing authorizations and how status levels differ.

canonical: https://secureframe.com/glossary/fedramp-marketplace

The FedRAMP Marketplace at marketplace.fedramp.gov is the official directory of cloud services that have been authorized, are actively pursuing authorization, or have been designated as FedRAMP Ready. Federal agencies use the Marketplace to find authorized cloud services and leverage existing authorizations without duplicating assessments. If you run a cloud service that wants federal business, Marketplace listing is how you become visible to buyers.

### What the Marketplace Lists

- Service name, provider, and brief description.
- Authorization status: FedRAMP Authorized, In Process, or Ready.
- Authorization type: JAB P-ATO or Agency Authorization.
- Impact level: Low, Moderate, or High.
- Service model: IaaS, PaaS, SaaS.
- Sponsoring agency and authorization date.
- 3PAO that performed the assessment.

### Authorization Status Meanings

- **FedRAMP Ready: **A 3PAO has attested the service can likely achieve authorization. No assessment yet. The offering is marketing itself to agencies willing to sponsor.
- **In Process: **An authorization is underway, either with the JAB or a sponsoring agency. 3PAO assessment may be in progress or complete.
- **FedRAMP Authorized**: Authorization has been issued. Any federal agency can leverage it.

### How Agencies Use the Marketplace

A contracting officer evaluating a cloud service for agency use checks the Marketplace first. FedRAMP Authorized status with appropriate impact level means the security posture is already vetted to the standard the agency needs. The agency can issue its own ATO leveraging the existing authorization, which is faster and cheaper than a fresh assessment.

### FedRAMP Marketplace vs DoD Cloud Services Catalog

The FedRAMP Marketplace is the primary catalog for civilian federal cloud services. The DoD maintains separate requirements through the Cloud Computing SRG. DoD-specific authorizations (IL4, IL5, IL6) are listed on the DISA Cloud Service Catalog. Many commercial cloud providers appear on both, particularly for services that serve both civilian and defense customers.
