FedRAMP, the Federal Risk and Authorization Management Program, is the federal government’s standardized framework for evaluating the security of commercial cloud services before agencies use them to handle government data. Any cloud provider that wants to sell to a federal agency has to go through it. Congress codified the program in December 2022 through the FedRAMP Authorization Act, so it is now a statutory requirement rather than a policy that a future administration could rescind.1Office of the Law Revision Counsel. 44 USC 3607 – Definitions In practice, FedRAMP tells providers which security controls to implement, requires an independent assessment of those controls, results in an Authorization to Operate (ATO) issued by an agency or by FedRAMP itself, and then obligates the provider to keep monitoring and reporting for as long as the service holds its authorization.
Who Runs FedRAMP and Under What Authority
The program sits inside the General Services Administration. Its governing statute is at 44 U.S.C. §§ 3607–3616, and it builds on the Federal Information Security Modernization Act (FISMA) along with the NIST Risk Management Framework. FISMA and FedRAMP draw from the same NIST SP 800-53 catalog of security controls, but FedRAMP tailors that catalog for commercial cloud providers, dropping requirements meant only for government-operated systems and adding controls appropriate for private companies hosting federal data.2FedRAMP Help Center. Is a Federal Information Security Modernization Act FISMA Authority To Operate ATO Sufficient To Meet FedRAMP Requirements
The 2022 Act replaced the old Joint Authorization Board with a seven-member FedRAMP Board of federal technology executives selected by the Federal Chief Information Officer at OMB. The Board sets policy and works to expand the government’s capacity for authorizing cloud services; it no longer reviews individual authorization packages the way the JAB did.3FedRAMP. FedRAMP Governance A Technical Advisory Group of federal practitioners advises on risk assessments, and the Federal Secure Cloud Advisory Committee gives industry and third-party assessors a public forum to weigh in.4The White House. M-24-15 Modernizing the Federal Risk and Authorization Management Program
The Three Security Impact Levels
Before a provider does anything else, the cloud service has to be categorized by the impact a breach would have on the data it holds. This categorization drives the entire process: which controls apply, how rigorous the assessment is, and how long authorization takes. FIPS 199 sets three levels based on potential harm to confidentiality, integrity, and availability.5National Institute of Standards and Technology. FIPS 199 – Standards for Security Categorization of Federal Information and Information Systems
- Low: A breach would cause limited harm. Collaboration tools handling non-sensitive information often fall here.
- Moderate: A breach could cause serious harm, such as significant financial loss or major operational disruption. This is the most common level for services handling controlled but unclassified federal data.
- High: A breach could cause severe or catastrophic harm, including threats to human life, critical infrastructure, or national security.
NIST SP 800-60 provides the methodology for mapping specific types of federal information to these categories.6Computer Security Resource Center. NIST SP 800-60 Rev 2 Initial Working Draft – Guide for Mapping Types of Information and Systems to Security Categories Categorizing too low leaves data underprotected. Categorizing too high adds cost and complexity that can push authorization out by months.
A narrower path exists for software-as-a-service products handling only low-impact data. FedRAMP Tailored for Low-Impact SaaS (Li-SaaS) requires fewer controls and has historically taken four to eight weeks. To qualify, the service must be fully operational, meet the NIST definition of SaaS, hold no personally identifiable information beyond login fields (username, email, password), and run on FedRAMP-authorized infrastructure or infrastructure the provider controls.7FedRAMP. FedRAMP Tailored Security Requirements for Low Impact-Software as a Service LI-SaaS Cloud Services Any additional PII disqualifies the service from this path.
How a Provider Gets Authorized
The FedRAMP Authorization Act and OMB Memo M-24-15 replaced the old binary choice between JAB provisional authorization and agency authorization with three paths.
Agency Authorization
This is still the most common route. A cloud provider partners with a specific federal agency, and that agency’s authorizing official reviews the security package and issues the ATO. The process starts with a kickoff meeting to align on security expectations and system boundaries. Once the authorizing official signs the letter, the provider can host that agency’s data and the authorization goes into the FedRAMP Marketplace for other agencies to reuse. Agencies can also collaborate on joint authorizations. The path typically takes six to eighteen months from kickoff, though simpler systems at lower impact levels move faster.
Program Authorization
For cloud services without an agency sponsor, M-24-15 created a program authorization path. The FedRAMP Director signs the authorization instead of an individual agency’s authorizing official, so a provider can achieve FedRAMP authorization without first finding a federal customer willing to lead the review.4The White House. M-24-15 Modernizing the Federal Risk and Authorization Management Program
FedRAMP 20x
FedRAMP 20x is the newest and fastest path, rolling out in phases through 2026. Where the legacy Rev 5 process typically required years of preparation, pilot participants in 20x have received authorization in under two months. Phase 1 produced an initial 12 low-impact authorizations from 26 submissions. The core idea is to replace extensive written narratives with automated demonstration of secure configurations. Providers do not need an agency sponsor, and once authorized they can maintain and improve their service without seeking advance permission for each change. The 2026 roadmap expands automated validation to moderate-impact systems and formalizes the full set of low and moderate requirements.8FedRAMP. FedRAMP 20x
Whichever path a provider takes, the FedRAMP PMO gives feedback across multiple review cycles, flagging gaps in control implementations or insufficient evidence, and the provider has to respond within set timeframes to stay in the pipeline.
What the Authorization Package Contains
The authorization package is the body of evidence a provider submits to prove its system meets federal security requirements. Most of the time and money in FedRAMP goes into producing these documents.
System Security Plan
The System Security Plan (SSP) is the primary document. It defines the system boundary (which components and data flows are covered), lists the security controls, and explains how each is implemented. Controls come from NIST SP 800-53 and cover access management, encryption, incident response, physical security, and more.9National Institute of Standards and Technology. NIST SP 800-53 Rev 5 – Security and Privacy Controls for Information Systems and Organizations FedRAMP publishes standardized templates that map each control to the requirements set during categorization. The SSP also has to include a complete hardware and software inventory of the cloud environment and a contingency plan with defined recovery time objectives.
Independent Assessment
The Security Assessment Plan (SAP) describes how the controls will be tested. The Security Assessment Report (SAR) documents the results, including every vulnerability found and the risk it poses. Both must be produced by an accredited third-party assessment organization (3PAO), not the provider. That independence is non-negotiable.
A 3PAO must be accredited by the American Association for Laboratory Accreditation (A2LA) under ISO/IEC 17020, with a favorable annual review and a full on-site reassessment every two years.10FedRAMP. 3PAO Obligations and Performance Standards Initial 3PAO assessments for a moderate-impact system commonly run between $50,000 and $400,000 depending on the size and complexity of the environment, with annual reassessments in a similar range.
Cryptographic Modules
Any encryption protecting federal data has to use a validated cryptographic module. The governing standard is FIPS 140-3, which superseded FIPS 140-2 in 2019; NIST stopped accepting new FIPS 140-2 submissions on April 1, 2022.11National Institute of Standards and Technology. FIPS 140-3 Transition Effort Existing FIPS 140-2 validations remain usable while active, but new modules must meet FIPS 140-3.
Moving to Machine-Readable Submissions
FedRAMP is shifting authorization packages from narrative PDFs to structured data using the Open Security Controls Assessment Language (OSCAL). Under OMB Memo M-24-15, GSA was to begin receiving authorization artifacts through automated, machine-readable means by July 2025, and agencies must be able to produce and ingest OSCAL artifacts by July 2026.12FedRAMP Documentation. M-24-15 Section IX Implementation
What Happens After Authorization
Getting authorized is not the finish line. Maintaining an authorization requires continuous monitoring for the life of the service.
Vulnerability Scanning and POA&M Deadlines
Providers must scan operating systems, web applications, and databases every month and share the results with their authorizing officials and consuming agencies.13FedRAMP. FedRAMP Documentation – Vulnerability Scanning Findings go into a Plan of Action and Milestones (POA&M) with fixed remediation deadlines: 30 days for critical and high-risk findings, 90 days for moderate, and 180 days for low.14FedRAMP Documentation. Plan of Action and Milestones POA&M FedRAMP will not grant or maintain authorization while open high-risk findings remain unresolved. A 3PAO also has to perform a full annual security assessment.
FedRAMP 20x uses a slightly different framework, weighing each vulnerability’s potential adverse impact, whether the system is internet-reachable, and whether the vulnerability is likely to be exploited. Under that framework, the highest-severity internet-facing vulnerabilities at the high-impact level must be at least partially mitigated within 12 hours of evaluation.15FedRAMP Documentation. Vulnerability Detection and Response
Handling Significant Changes
Major changes to an authorized system have to go through a formal process. FedRAMP sorts them into three types:16FedRAMP Documentation. Significant Changes
- Routine recurring: Day-to-day maintenance, patching, and operational changes. These do not require authorizing official approval.
- Adaptive: Changes that add functionality or modify features without fundamentally altering the system’s risk profile. Most non-routine changes fall here and need authorizing official review and approval.
- Transformative: Rare changes that alter the risk profile and require significant new testing and documentation. These require authorizing official approval and typically trigger a broader reassessment.
For adaptive and transformative changes, the provider submits a Significant Change Request with a security impact analysis, the 3PAO develops an assessment plan for the affected controls, and the authorizing official approves both before implementation. After the change, the assessor tests the affected areas and issues a report. If the authorizing official accepts the results, the POA&M is updated with any conditions; if not, the provider must remediate or roll back.
Incident Reporting
The tightest deadlines in FedRAMP apply to security incidents. Providers must report confirmed or suspected incidents to FedRAMP, to every affected agency customer, and (when the incident matches a CISA-listed attack vector) to CISA within one hour of identifying the incident.17FedRAMP Documentation. Incident Communications Procedures After the initial notification, providers send updates at least once per calendar day until the incident is fully resolved. That one-hour clock starts on identification, not on completed investigation, so pre-established communication channels and contact lists for every agency customer are essential.
Reuse Across Agencies: Presumption of Adequacy
One of the most consequential provisions of the FedRAMP Authorization Act is the legal requirement that agencies reuse existing authorizations. Under 44 U.S.C. § 3613(e), if a cloud product already holds a FedRAMP authorization at a given impact level, agencies must presume that the security assessment in the authorization package is adequate for issuing their own ATO at or below that level.18Office of the Law Revision Counsel. 44 USC 3613 – Roles and Responsibilities of Agencies
An agency can overcome that presumption only if it has a demonstrable need for security requirements beyond what the existing package covers, or if the package is substantially deficient for the intended use. When an agency does additional authorization work, it must document why the previous package was found deficient and report to the FedRAMP PMO, where the FedRAMP Director decides whether the extra work was justified.4The White House. M-24-15 Modernizing the Federal Risk and Authorization Management Program
The provision matters for both sides of the transaction. Before the Act, agencies routinely demanded their own full security reviews of products that already held a JAB provisional authorization or another agency’s ATO, duplicating months of work and hundreds of thousands of dollars in assessment costs. The presumption of adequacy does not eliminate all additional agency requirements, but it shifts the burden: the agency has to justify why the existing authorization is not good enough, rather than the provider proving it again from scratch.
The FedRAMP Marketplace
The FedRAMP Marketplace is the public database where federal agencies find cloud services that have engaged with the authorization process. Every listing carries one of three status labels:19FedRAMP. Marketplace Products
- FedRAMP Ready: The provider has completed a readiness assessment showing it is likely to succeed in full authorization. Not an authorization, but a signal to potential agency sponsors.
- FedRAMP In Process: The provider is actively under review through one of the authorization paths.
- FedRAMP Authorized: The service holds a full authorization and is available for government-wide procurement. This is where the presumption of adequacy engages for other agencies considering the same product.
Agencies use the Marketplace to compare authorized services, review security packages, and identify solutions that fit their mission. For providers, appearing there as Authorized is the gateway to selling cloud services across the federal government.