FedRAMP
Also known as: Federal Risk and Authorization Management Program
US government program standardizing security assessment and authorization for cloud services.
The Federal Risk and Authorization Management Program (FedRAMP) is the US government program established by OMB Memorandum M-11-29 (December 2011) to provide a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. The program addresses the challenge that without standardization, every federal agency would individually assess each cloud provider against FISMA requirements — an enormously duplicative process. FedRAMP creates 'do once, use many times' authorizations: a cloud service provider achieves FedRAMP authorization once, and federal agencies can then leverage that authorization for their own use. The program has three impact levels (aligned with FIPS 199 categorization): Low (limited adverse impact); Moderate (serious adverse impact); High (severe or catastrophic impact). FedRAMP uses NIST 800-53 controls tailored to each impact level, with FedRAMP-specific control parameter values and additional FedRAMP-specific controls. Two authorization paths: Agency Authorization to Operate (P-ATO from sponsoring agency) and Joint Authorization Board (JAB) authorization (from DoD, DHS, GSA representatives — discontinued in 2024). FedRAMP authorization is a substantial undertaking — typically 12-24 months of preparation and assessment, with costs from hundreds of thousands to millions of dollars depending on impact level and CSP complexity. The program is administered by GSA's FedRAMP Program Management Office. Substantial recent developments include the FedRAMP Authorization Act (2022, codified into law) and ongoing modernization efforts to address scaling and pace concerns.
Core components
- Three impact levels: Low, Moderate, High (FIPS 199 alignment)
- NIST 800-53 controls with FedRAMP-specific tailoring
- Two authorization paths (Agency P-ATO
- JAB authorization, discontinued 2024)
- 'Do once, use many times' authorization reuse
- Continuous monitoring requirements
- FedRAMP Marketplace listing of authorized cloud services
- Third-Party Assessment Organizations (3PAOs) for assessments
- FedRAMP Program Management Office at GSA
- Connection to FISMA and federal cybersecurity policy
- FedRAMP Authorization Act (2022) statutory basis
Primary use case
Authorization for cloud services used by US federal agencies; foundation for federal cloud-first policy implementation; reference framework for state and local government cloud authorization (some states reference FedRAMP); basis for substantial commercial cloud-service authorization industry; foundation for substantial federal cloud-vendor business; integration with broader federal cybersecurity governance (FISMA, RMF); foundation for some industry cloud-security certifications.
Common criticisms
- Authorization process is slow and expensive — typical 12-24 months and substantial cost create barriers for smaller cloud service providers
- the slow pace contradicts cloud-native rapid-iteration practice
- authorization scope (the System Security Plan) has tendency to grow over time as cloud services evolve, requiring frequent re-authorization work
- tendency toward checklist compliance rather than substantive security improvement
- commercial 3PAO quality varies substantially
- FedRAMP-specific control tailoring creates differences from NIST 800-53 implementations elsewhere, creating duplicative compliance work
- continuous monitoring requirements are substantial and costly
- the program's complexity creates barriers to entry that may inadvertently consolidate federal cloud market around large incumbents
- agencies sometimes use FedRAMP authorization as a procurement screen even where lower impact levels would be appropriate
- integration with state and local government cloud authorization is incomplete despite informal use
- recent Authorization Act and modernization efforts respond to longstanding concerns but implementation is ongoing
- FedRAMP 'In Process' status is sometimes used commercially in ways that overstate authorization progress.
Lineage
- Siblings
- NIST Risk Management Framework, CMMC