What is FedRAMP?
FedRAMP (the Federal Risk and Authorization Management Program) is a U.S. government-wide program that standardizes how cloud services are assessed, authorized, and continuously monitored for use by federal agencies. It was launched in 2011 to solve a real problem: before FedRAMP, every agency evaluated the same cloud product separately, producing duplicate reviews and inconsistent decisions. Its guiding principle is “do once, use many times,” so a service is assessed once against a standard set of requirements and then reused across government.
How does FedRAMP relate to FISMA and NIST 800-53?
These three terms are often confused but fit together cleanly:
- FISMA: The federal law requiring agencies to protect their information systems.
- NIST SP 800-53: The catalog of security and privacy controls agencies use to meet FISMA.
- FedRAMP: The cloud-specific implementation of both, tailoring 800-53 controls to cloud services.
What are the impact levels?
A cloud service is categorized using FIPS 199 based on the sensitivity of the data it handles, then must meet the matching control baseline:
- Low: Limited impact if data is compromised.
- Moderate: The most common level, covering roughly 80 percent of authorizations.
- High: For the most sensitive data, where compromise could be severe.
How does authorization work?
- Document controls: The provider writes a System Security Plan describing how each control is met.
- Independent assessment: A FedRAMP-accredited third-party assessment organization (3PAO) tests the system and produces a Security Assessment Report.
- Authorization: A federal agency reviews the package and issues an Authorization to Operate (ATO).
- Continuous monitoring: The provider must keep proving security every month through scanning, reporting, and POA&M updates. FedRAMP is not a one-time certification.
What is FedRAMP 20x?
- A major modernization: Announced by the GSA in March 2025, FedRAMP 20x is a ground-up redesign focused on automation, machine-readable packages, and continuous validation rather than static documentation and manual review.
- Faster entry: It introduced Key Security Indicators and pilot pathways to speed up authorization, starting with the Low baseline.
- New terminology: Under 2026 consolidated rules, a service approved by the program office but without an agency sponsor is now called “FedRAMP certified,” reducing confusion about what authorization covers.
Why does FedRAMP matter?
- Gateway to federal business: For cloud providers, authorization is often a prerequisite for selling to federal agencies.
- Uniform protection: It ensures government data in the cloud is protected to a consistent, rigorous standard across agencies.