FedRAMP

A U.S. government program that standardizes the security assessment, authorization, and continuous monitoring of cloud services so federal agencies can adopt them with confidence.

What is FedRAMP?

FedRAMP (the Federal Risk and Authorization Management Program) is a U.S. government-wide program that standardizes how cloud services are assessed, authorized, and continuously monitored for use by federal agencies. It was launched in 2011 to solve a real problem: before FedRAMP, every agency evaluated the same cloud product separately, producing duplicate reviews and inconsistent decisions. Its guiding principle is “do once, use many times,” so a service is assessed once against a standard set of requirements and then reused across government.

How does FedRAMP relate to FISMA and NIST 800-53?

These three terms are often confused but fit together cleanly:

  • FISMA: The federal law requiring agencies to protect their information systems.
  • NIST SP 800-53: The catalog of security and privacy controls agencies use to meet FISMA.
  • FedRAMP: The cloud-specific implementation of both, tailoring 800-53 controls to cloud services.

What are the impact levels?

A cloud service is categorized using FIPS 199 based on the sensitivity of the data it handles, then must meet the matching control baseline:

  • Low: Limited impact if data is compromised.
  • Moderate: The most common level, covering roughly 80 percent of authorizations.
  • High: For the most sensitive data, where compromise could be severe.

How does authorization work?

  • Document controls: The provider writes a System Security Plan describing how each control is met.
  • Independent assessment: A FedRAMP-accredited third-party assessment organization (3PAO) tests the system and produces a Security Assessment Report.
  • Authorization: A federal agency reviews the package and issues an Authorization to Operate (ATO).
  • Continuous monitoring: The provider must keep proving security every month through scanning, reporting, and POA&M updates. FedRAMP is not a one-time certification.

What is FedRAMP 20x?

  • A major modernization: Announced by the GSA in March 2025, FedRAMP 20x is a ground-up redesign focused on automation, machine-readable packages, and continuous validation rather than static documentation and manual review.
  • Faster entry: It introduced Key Security Indicators and pilot pathways to speed up authorization, starting with the Low baseline.
  • New terminology: Under 2026 consolidated rules, a service approved by the program office but without an agency sponsor is now called “FedRAMP certified,” reducing confusion about what authorization covers.

Why does FedRAMP matter?

  • Gateway to federal business: For cloud providers, authorization is often a prerequisite for selling to federal agencies.
  • Uniform protection: It ensures government data in the cloud is protected to a consistent, rigorous standard across agencies.