What Is FedRAMP (Federal Risk and Authorization Management Program)?

Related problems: A federal agency customer requires a FedRAMP-authorized cloud service; Not sure what a provider's FedRAMP listing actually covers; Need cloud tools that can hold controlled unclassified information for a defense contract; Hearing both impact levels and new FedRAMP classes and not sure how they compare

The Federal Risk and Authorization Management Program (FedRAMP) is the US government program that standardizes how the security of cloud services is assessed and monitored for use by federal agencies. A provider goes through one assessment, and agencies can reuse that package rather than each running its own full review. FedRAMP status has also become a common benchmark outside federal agencies, for example for cloud services that hold defense contract data. This entry is general information, not legal advice; confirm requirements with the contracting agency, counsel or your assessor.

At a glance

  • FedRAMP covers cloud service offerings (SaaS, PaaS and IaaS) used by federal agencies.
  • Status applies to a specific service offering, not to a provider’s whole company or every product it sells.
  • Most statuses rely on an assessment by an independent assessor recognized by FedRAMP, and providers are monitored on an ongoing basis after approval.
  • Certification baselines are labeled Class A through D: B covers the former LI-SaaS and Low baselines, C covers Moderate and D covers High, while A is a new entry class.
  • Agencies still make their own decision to use a service after reviewing its FedRAMP package.

What problem it solves

Before FedRAMP, each agency evaluated each cloud service on its own, which was slow, expensive and inconsistent. Providers repeated similar audits for every agency, and agencies had no common standard for comparing them.

FedRAMP replaces that with a single, government-wide approach: one set of requirements based on NIST security controls, one assessment, and a package that many agencies can reuse. For buyers outside government, a FedRAMP listing offers a well-understood signal of a provider’s security program, provided it covers the service actually being bought.

How it works

Categorize. Agencies categorize their own systems by impact level, following federal standards, and providers pursue the certification class that fits the customers and data they expect.

Assess. For most classes, an independent assessor recognized by FedRAMP tests the service’s controls. Under the newer 20x process, more of this validation is automated.

Review and list. Approved services are listed on the FedRAMP Marketplace, along with their status and level or class.

Agency use. An agency reviews the package and decides whether the service can be used for its systems, adding its own controls where needed.

Continuous monitoring. Providers report vulnerabilities, changes and incidents on an ongoing basis and are reassessed periodically.

Transition. FedRAMP is moving from the older Rev5 certification type, which includes the legacy agency-sponsored path, to the 20x type. Both use the same class labels and may appear on listings during the transition, so check the current rules.

Impact levels and certification classes

Agencies assign impact levels (Low, Moderate, High) to their own systems based on data sensitivity. FedRAMP certification classes label how much assurance a cloud service has demonstrated, and they replace the old baseline names rather than sitting alongside them. FedRAMP cautions that classes are not one-for-one substitutes for an agency’s impact level. The program is in transition, so confirm current rules on the FedRAMP website.

Class Former baseline Rev5 certification 20x certification Typical evidence
Class A None; a new entry class Not offered Based on a certification completed within the past year under an accepted framework (FedRAMP Rev5 including FedRAMP Ready, SOC 2 Type II, or GovRAMP); a fresh independent assessment is optional Marketplace listing
Class B LI-SaaS and Low Assessment under the class’s independent verification rules, through the agency or program path Fresh assessment by a FedRAMP Recognized assessor plus automated validation Marketplace listing, certification package
Class C Moderate Independent assessment, through the agency or program path Fresh assessment by a FedRAMP Recognized assessor plus more automated validation Marketplace listing, certification package, continuous monitoring reports
Class D High Independent assessment with the most extensive requirements Being introduced in stages and not yet generally available Marketplace listing, certification package, continuous monitoring reports

The agency path, where an agency sponsors the review, is a legacy path available only for Rev5. FedRAMP still reviews and approves packages on either path.

When it matters for buyers

  • When you sell to or work for federal agencies. Cloud services in your solution may need FedRAMP status.
  • When a defense contract includes DFARS 252.204-7012. External cloud providers that store, process or transmit covered defense information are expected to meet security requirements equivalent to the FedRAMP Moderate baseline; other CUI contracts depend on their own clauses.
  • When a provider markets “FedRAMP” broadly. Check that the exact offering, region or tenant you would use is the one listed.
  • When comparing providers for regulated workloads. FedRAMP packages give detailed security evidence beyond a summary report.
  • When state or local agencies are involved. They may look for GovRAMP status instead of, or alongside, FedRAMP.

Our public cloud overview covers how providers separate government-focused offerings from their commercial services.

Questions to ask vendors

  • Which FedRAMP certification class (or former baseline, such as Moderate) do you hold, and for which exact service offering?
  • Is it a Rev5 or a 20x certification, through which path, and what is its current status?
  • Is the service we would buy, including region and tenant type, inside that boundary?
  • Can we see the package, or a summary, through the proper FedRAMP channels?
  • What is your customer responsibility matrix, and which controls stay with us?
  • How will the program transition affect your status and our use of the service?

How it differs from GovRAMP

GovRAMP, formerly StateRAMP, is a separate nonprofit program aimed at state, local and other public-sector buyers. It is modeled on FedRAMP and uses similar NIST-based requirements, and GovRAMP can review existing FedRAMP materials, but a status in one program does not automatically equal status in the other. FedRAMP sits under the broader federal security law, FISMA, and is often discussed alongside CMMC and NIST Special Publication 800-171 for defense contractors. A SOC 2 report is a commercial attestation, not a government authorization, though it is broader cloud security evidence many buyers also ask for.

Frequently Asked Questions

Does FedRAMP status mean an agency can use a service without its own review?
No. FedRAMP gives agencies a reusable security package, but each agency still decides whether the service fits its own systems and risk, and documents that decision.
What do FedRAMP Low, Moderate and High mean?
They are impact levels, or security categories, based on how much harm a loss of confidentiality, integrity or availability would cause; agencies assign them to their own systems. FedRAMP now labels its certification baselines as classes: Class B covers the former LI-SaaS and Low baselines, Class C the Moderate baseline and Class D the High baseline. FedRAMP cautions agencies not to treat classes as one-for-one substitutes for impact levels when deciding what a service can be used for.
Is FedRAMP required for private companies?
Not directly. It applies to cloud services used by federal agencies. Private companies meet it indirectly, for example when a Defense Department contract includes DFARS 252.204-7012 and an external cloud provider stores, processes or transmits covered defense information: that clause expects the provider to meet security requirements equivalent to the FedRAMP Moderate baseline. Other contracts involving controlled unclassified information depend on their own agency clauses.
How do we check a provider's FedRAMP status?
Look the service up on the FedRAMP Marketplace, which lists each cloud service offering with its status and level or class. Make sure the listing names the exact service you plan to buy.
Is FedRAMP changing?
Yes. FedRAMP now has two certification types: the older Rev5 approach, based mainly on documented plans, and the newer FedRAMP 20x approach, with more automated validation. Both use certification classes, Rev5 continues during a transition period, and parts of 20x, such as Class D, are still being introduced. Check the FedRAMP website for current rules and dates.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.