What Is FedRAMP? A Practical Definition
Glossary · enterprise · 5 min read · last verified 2026-07-21
FedRAMP — the Federal Risk and Authorization Management Program — is a United States government program that standardizes how cloud services are security-assessed, authorized, and continuously monitored for use by federal agencies.
What FedRAMP is
FedRAMP applies to cloud service offerings sold to US federal agencies. It was established in 2011, is administered through the General Services Administration, and draws its security controls from NIST Special Publication 800-53. The program exists so that one rigorous assessment can be reused across agencies instead of every agency running its own independent review of the same product.
Three details define the scope precisely:
- It is federal. FedRAMP governs federal agency use of cloud services. It is not a general commercial certification, and non-federal buyers are not required to ask for it.
- Authorization is granted by a government authorizing official, not by an auditor and not by the vendor. An agency can issue an Authority to Operate (ATO) for its own use, and the program also operates a central authorization route whose resulting package other agencies can reuse. The governance of that central route was reorganized following the FedRAMP Authorization Act, so confirm the current path against fedramp.gov rather than against older secondhand descriptions.
- Scope is set by impact level. The Low, Moderate, and High baselines correspond to the potential impact of a compromise on confidentiality, integrity, and availability, categorized under FIPS 199. Each baseline carries a different control set and a materially different assessment burden.
The unit of authorization is a defined system boundary — a specific offering, in a specific configuration, with specific dependencies — not a company and not a product family.
Why FedRAMP matters
For a vendor selling into federal agencies, FedRAMP functions as a gate rather than a differentiator. An agency generally cannot put an unauthorized cloud service into production, so the absence of an authorization ends the conversation regardless of product quality. Its presence does not win the deal; it only makes the deal possible.
The offsetting benefit is reuse. An authorization package listed in the FedRAMP Marketplace can be leveraged by other agencies, which is the entire economic argument for the effort. The cost is real and recurring: third-party assessment, documentation, remediation, and then continuous monitoring that never ends. Published figures for cost and elapsed time vary widely by impact level, system complexity, and starting security posture, and the program does not set a fixed price or a guaranteed timeline — treat any single number quoted at you as one vendor's experience rather than a benchmark.
How FedRAMP works
The sequence stays broadly consistent even as program governance evolves:
- Categorize. Determine the impact level appropriate to the federal data the system will hold.
- Choose a path. Either a sponsoring agency drives authorization for its own use, or the vendor pursues the program's central authorization route.
- Implement and document. Controls are implemented and described in a System Security Plan that maps each control to how the system actually satisfies it.
- Assess independently. An accredited Third Party Assessment Organization (3PAO) tests the controls and produces a Security Assessment Report. Self-assessment does not substitute.
- Authorize. A government authorizing official reviews the package and accepts the residual risk. Open items are tracked in a Plan of Action and Milestones (POA&M).
- Monitor continuously. Recurring vulnerability scanning, POA&M upkeep, annual assessment, and formal review of significant changes. Continuous monitoring is where most of the long-run cost sits, and it is the part that surprises vendors who budgeted for a project.
Common misconceptions
- "We are FedRAMP certified." There is no certification. A system is authorized, and by whom and at what impact level are the questions that matter. Marketplace statuses such as "ready" or "in process" describe progress, not authorization.
- "FedRAMP replaces SOC 2 or ISO 27001." They answer different questions for different audiences, and a commercial reviewer will still ask for the report they know how to read. See SOC 2 vs ISO 27001.
- "Moderate means moderately secure." Impact level reflects the consequence of compromise for the data in scope. It is not a ranking of engineering quality.
- "Running on authorized infrastructure means we inherit authorization." Building on an authorized cloud platform lets a vendor inherit some controls, which reduces work meaningfully. It does not authorize the application layer above it.
- "FedRAMP settles our data location questions." Location, personnel screening, and citizenship terms come from specific controls and agency contract language, and they should be confirmed as separate line items rather than assumed — see data residency requirements.
- "Defense works the same way." Department of Defense workloads add requirements under the DoD Cloud Computing Security Requirements Guide and its own impact levels.
FedRAMP in practice
The decision is a revenue question wearing security clothing. Before committing, look for evidence that federal demand is specific rather than aspirational: a named agency willing to sponsor, a funded requirement, a contract vehicle the agency can actually buy through, and a defensible estimate of how many agencies would reuse the package.
Then price the whole obligation, not just the assessment:
- A named internal owner for the authorization boundary, not a part-time assignment layered onto an existing role.
- Engineering capacity for control implementation and, more durably, for change control that slows routine dependency and release work.
- A separate deployment and often separate operations staffing, since the federal boundary usually cannot share tooling, access patterns, or third-party services with the commercial environment.
- Monitoring, reporting, and annual assessment funded as a permanent line item rather than a one-time project cost.
Vendors with thin federal pipelines frequently conclude that the better move is to defer — partner with or resell through an already-authorized provider, or stay out of federal until a sponsor materializes. That is a legitimate answer, and it is more honest than an indefinite "in process" status that sales teams begin quoting as if it were an authorization.
Keep federal answers separate from commercial ones. Pasting FedRAMP language into a commercial security questionnaire confuses reviewers evaluating a different risk model and invites follow-up questions no one on the commercial side is equipped to answer.