FedRAMP
Definition
FedRAMP
FedRAMP is the United States programme that standardises security assessment and authorisation for cloud services sold to federal agencies. One authorisation is meant to be reused across agencies, which is the whole economic argument for running the programme at all.
Reuse is the promise, and it is also the measure of whether the programme works.
Without it, every agency would assess every cloud service independently, and every provider would be assessed dozens of times against the same controls — the programme exists to do that work once.
Whether one assessment genuinely satisfies the next agency has always been the open question — and it is the question the current modernisation is aimed at.
Key takeaways
- FedRAMP standardises cloud security authorisation for United States federal agencies.
- The marketplace listed 531 FedRAMP Certified Services at the time of writing.
- FedRAMP 20x is a current modernisation adding certification classes A to D.
- Security control baselines are drawn from the NIST catalogue rather than invented separately.
How it works
A cloud provider is assessed against a security baseline, an agency authorises it, and other agencies are then meant to reuse that authorisation rather than repeat the work. Impact levels of low, moderate and high determine how demanding the baseline is.
The control baselines come from the NIST catalogue — specifically Security and Privacy Controls for Information Systems and Organizations, which supplies the underlying requirements rather than FedRAMP writing its own.
The public marketplace is the place to check a claim. It lists 531 total FedRAMP Certified Services alongside 30 certified under the newer programme, and it names the authorising agencies.
The programme is changing substantially. FedRAMP 20x is described as a new approach to cloud security assessment and authorization that moves beyond traditional compliance to focus on the security decisions that matter most.
The criticism of the old model is unusually candid for a government programme. The same source characterises the legacy approach as compliance-focused audits to check a box, and says 20x replaces static yearly manual assessments with continuous measurement.
| Element | What it means for a buyer |
|---|---|
| Impact level | Low, moderate or high, matching data sensitivity |
| Authorising agency | Who sponsored the assessment |
| Reuse | Whether another agency can rely on it |
| 20x class | A to D, under the newer certification route |
| Marketplace listing | The only place to verify a claim |
Check the marketplace rather than the sales deck. “FedRAMP ready”, “in process” and “authorised” are different states, and only one of them means the work is finished.
Examples
Cloud authorisation claims are made loosely and verified rarely, which is why the public listing matters more than the brochure. Each arrangement here was priced before anyone checked what the obligation required.
A provider markets itself as FedRAMP ready. That indicates readiness for assessment rather than completion of one, and the marketplace distinguishes the two.
An agency reuses another agency’s authorisation for a collaboration tool. That is the programme functioning as designed, and it removes months from the procurement.
A commercial buyer requires FedRAMP from a provider despite having no federal work. The baseline is rigorous, so this is defensible, though compliance outsourcing teams should know they are buying a federal standard.
A provider holds authorisation for one service and implies it covers its whole platform. Authorisation attaches to a defined service boundary, exactly as data center outsourcing scope does.
Related terms
Federal cloud security sits among general security services, standards and the roles that operate them. Every term below is pinned to one sense and separated from the one beside it.
- Government outsourcing: public sector contracting generally, of which cloud is one category.
- Cybersecurity outsourcing: buying security capability, rather than obtaining a federal authorisation.
- Data center outsourcing: the infrastructure arrangement an authorisation boundary describes.
- Compliance outsourcing: delegating regulatory work as a service line.
- Information security analyst: the role operating the controls an assessment tests.
- Security operations outsourcing: delegating monitoring and response, which continuous authorisation assumes.
- ISO 27001: an international certification, structurally unlike a federal authorisation.
FAQ
What does FedRAMP authorisation actually cover?
A defined cloud service boundary at a stated impact level. It does not extend automatically to a provider’s other services or platforms.
What is the difference between ready, in process and authorised?
Ready indicates preparedness for assessment, in process means an assessment is underway, and authorised means an agency has granted authorisation.
What is FedRAMP 20x?
A modernisation of the programme that moves away from static annual audits toward continuous measurement, introducing certification classes A to D.
Can a commercial buyer require FedRAMP?
Yes, and some do. The baseline is demanding, though it is designed for United States federal data rather than commercial needs.
Where do the security controls come from?
From the NIST catalogue of security and privacy controls, which FedRAMP draws baselines from rather than maintaining a separate control set.
How do I verify a provider’s claim?
Through the public marketplace, which lists authorised services and the sponsoring agencies. Do not rely on the provider’s own description.
Start at Outsource Accelerator and work out whether you are buying the authorization or inheriting it.







Independent




