FedRAMP

Also known as: Federal Risk and Authorization Management Program

framework · cybersecurity · regulatory-standard

US government program standardizing security assessment and authorization for cloud services.

The Federal Risk and Authorization Management Program (FedRAMP) is the US government program established by OMB Memorandum M-11-29 (December 2011) to provide a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. The program addresses the challenge that without standardization, every federal agency would individually assess each cloud provider against FISMA requirements — an enormously duplicative process. FedRAMP creates 'do once, use many times' authorizations: a cloud service provider achieves FedRAMP authorization once, and federal agencies can then leverage that authorization for their own use. The program has three impact levels (aligned with FIPS 199 categorization): Low (limited adverse impact); Moderate (serious adverse impact); High (severe or catastrophic impact). FedRAMP uses NIST 800-53 controls tailored to each impact level, with FedRAMP-specific control parameter values and additional FedRAMP-specific controls. Two authorization paths: Agency Authorization to Operate (P-ATO from sponsoring agency) and Joint Authorization Board (JAB) authorization (from DoD, DHS, GSA representatives — discontinued in 2024). FedRAMP authorization is a substantial undertaking — typically 12-24 months of preparation and assessment, with costs from hundreds of thousands to millions of dollars depending on impact level and CSP complexity. The program is administered by GSA's FedRAMP Program Management Office. Substantial recent developments include the FedRAMP Authorization Act (2022, codified into law) and ongoing modernization efforts to address scaling and pace concerns.

Originators

Office of Management and Budget (OMB); General Services Administration (GSA); CIO Council; Joint Authorization Board (JAB); broader federal cybersecurity community high

Year / Decade

2011 (OMB Memo M-11-29); 2012 (program operational); 2022 (FedRAMP Authorization Act); ongoing high

Primary sources

OMB Memorandum M-11-29 (2011), FedRAMP Program Management Office (ongoing). FedRAMP documentation and templates, FedRAMP Authorization Act (2022), FedRAMP Marketplace and continuous publications high

Core components

Primary use case

Authorization for cloud services used by US federal agencies; foundation for federal cloud-first policy implementation; reference framework for state and local government cloud authorization (some states reference FedRAMP); basis for substantial commercial cloud-service authorization industry; foundation for substantial federal cloud-vendor business; integration with broader federal cybersecurity governance (FISMA, RMF); foundation for some industry cloud-security certifications.

Common criticisms

Lineage

Siblings
NIST Risk Management Framework, CMMC