FedRAMP: requirements, process, and how to automate it
FedRAMP, the Federal Risk and Authorization Management Program, is the standardized process the U.S. federal government uses to assess, authorize, and continuously monitor the security of cloud products before an agency can put federal data in them. Any cloud service provider selling infrastructure, platform, or software as a service into a federal agency eventually runs into a FedRAMP requirement, whether that means pursuing an authority to operate sponsored by an agency, a listing on the FedRAMP Marketplace, or a reseller relationship built on an already-authorized cloud.
What FedRAMP is
FedRAMP standardizes how the federal government assesses, authorizes, and continuously monitors the security of cloud services before those services can host federal data. Rather than letting each of the federal government's many agencies run its own independent security review of the same cloud product, FedRAMP centralizes the assessment once so that a single package, reviewed under a shared set of NIST SP 800-53 control catalog baselines, can support authorization decisions across the government.
The program is run by the FedRAMP Program Management Office, housed inside the General Services Administration, working alongside the Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology. Congress gave FedRAMP a statutory foundation with the FedRAMP Authorization Act, enacted as part of the fiscal year 2023 National Defense Authorization Act in December 2022, which formalized the program's authority and pushed the PMO toward the modernization effort known as FedRAMP 20x.
Every FedRAMP package is built against one of three impact levels under the current FedRAMP baselines: Low, Moderate, and High. Low covers cloud services where a breach would cause limited harm; Moderate is where most federal business systems land, including systems that process controlled unclassified information; High is reserved for the smallest slice of systems, the ones where a security failure could cause severe or catastrophic damage to operations, assets, or people, such as law enforcement and emergency response systems. A lighter-weight path, FedRAMP LI-SaaS, exists for low-impact software as a service products with a narrow data footprint.
Who needs FedRAMP
FedRAMP applies to any cloud service provider, meaning any company offering infrastructure, platform, or software as a service, that stores, processes, or transmits federal data, or that a federal agency intends to use in the course of its mission. That reaches three overlapping groups in practice.
- Commercial SaaS and PaaS vendors selling directly to a federal program office, where the agency itself becomes the sponsor and eventual authorizing official.
- Cloud infrastructure providers, the compute, storage, and networking layer other authorized systems are built on, which need their own authorization before anything hosted on top of them can inherit it.
- Resellers and system integrators that package a FedRAMP-authorized product into a larger federal solution, and need to understand which controls they inherit and which remain their own responsibility.
It also reaches organizations that do not think of themselves as cloud vendors at all: a state agency running a federally funded program, a research institution handling federal grant data in a cloud tool, or a healthcare vendor whose product touches both commercial and federal customers and needs the HIPAA Security Rule and FedRAMP to coexist in the same environment. The trigger is always the same question: does federal data, or a federal mission function, touch this system? If the answer is yes, some FedRAMP-shaped requirement is coming, whether that means full authorization, inheritance of an already-authorized boundary, or a security review modeled on the same control set.
FedRAMP requirements, by baseline and control family
FedRAMP does not invent its own control catalog. Every baseline is built directly on the NIST SP 800-53 control catalog, organized into roughly twenty control families covering access control, audit logging, configuration management, incident response, and supply chain risk, among others. FedRAMP adds its own parameters and overlays on top of the NIST baseline, tightens some controls, layers in continuous monitoring requirements that NIST alone does not specify, and requires a level of evidence detail (configuration exports, policy documents, architecture diagrams) that a generic NIST assessment does not.
| Impact level | Who it is for | Relative control burden |
|---|---|---|
| Low | Cloud services with a narrow footprint and limited potential harm from a breach | Smallest control set of the three baselines |
| Moderate | Most federal business systems, including systems handling controlled unclassified information | The baseline most cloud service providers authorize against |
| High | Law enforcement, emergency response, and other systems where compromise could cause severe or catastrophic harm | Largest control set and the most third-party assessment work |
In practice, the control families that consume the most authorization effort are access control, audit and accountability, configuration management, system and communications protection, and system and information integrity, because these are where a 3PAO tests the most technical evidence: how access is provisioned and revoked, how logs are collected and retained, how configuration baselines are enforced and drift is detected, how data is encrypted in transit and at rest, and how vulnerabilities are found and remediated on a defined clock.
The FedRAMP authorization process, step by step
A FedRAMP authorization is not a single audit; it is a sequence of gates, each with its own artifact and its own reviewer. The path below reflects an agency-sponsored authorization, the most common route for a cloud service provider without an existing federal customer relationship.
- Readiness assessment: A 3PAO or advisory partner evaluates whether the environment and its documentation are mature enough to enter the process, typically four to eight weeks.
- Secure an agency sponsor: The CSP finds a federal agency willing to sponsor its authorization, since agency authorization is the primary FedRAMP path today; timing depends entirely on the relationship and can run from a few weeks to several months.
- Build the System Security Plan: The CSP documents every control implementation, data flow, and the authorization boundary in the SSP, usually the single largest authoring effort in the package, commonly eight to twelve weeks.
- Independent 3PAO assessment: An accredited third-party assessment organization tests the implemented controls and produces the Security Assessment Report, typically eight to twelve weeks depending on baseline and system complexity.
- Remediate findings: The CSP works through the Plan of Action and Milestones for anything the 3PAO flagged, closing high-risk findings before authorization can proceed, commonly four to eight weeks.
- Agency review and authorization decision: The sponsoring agency's authorizing official reviews the full package and issues the authority to operate, typically four to eight weeks after a clean package is submitted.
- Listing on the FedRAMP Marketplace: Once authorized, the package is listed on the FedRAMP Marketplace, making the authorization eligible for reuse and inheritance by other agencies.
- Continuous monitoring: Monthly vulnerability scanning, annual assessments, and significant change requests keep the authorization current; this phase does not end, and it is where most authorizations are eventually put at risk if evidence goes stale.
How long does FedRAMP take and what does it cost?
Timelines and costs vary by baseline, system complexity, and how ready the environment is on day one, but the ranges below hold for a typical cloud service provider pursuing agency authorization.
Most FedRAMP authorizations take twelve to eighteen months from a standing start, assuming an agency sponsor is in place early. A well-prepared Low-impact or LI-SaaS effort can close in nine to ten months, while a complex High baseline system, especially one that needs multiple rounds of 3PAO remediation, can run well past twenty-four months.
Third-party assessment fees, paid to the 3PAO, commonly run $100,000 to $250,000 for a Moderate baseline and can exceed $300,000 for High, driven by system size and the number of components inside the authorization boundary. Advisory and SSP-authoring support, if the CSP does not build the package in-house, typically adds another $75,000 to $200,000. Ongoing continuous monitoring, including the annual assessment and monthly scanning support, commonly runs $50,000 to $150,000 a year after authorization. None of these figures include the internal engineering time spent remediating findings, which is frequently the largest hidden cost in the process.
ACTA's own pricing is licensed per environment, and every engagement starts with a conversation. The deterministic artifact generation described later on this page is aimed at the SSP-authoring and evidence-collection costs above, not the 3PAO's independent testing fee, which ACTA does not and cannot replace.
Common failure points
Most FedRAMP delays trace back to a small set of recurring mistakes, and they show up whether the CSP is authorizing for the first time or renewing a package that has been live for years.
- An authorization boundary drawn too loosely, pulling systems and data flows into scope that do not need to be there, which inflates both the control burden and the assessment cost.
- Evidence collected once for the SSP and never refreshed, so by the time the 3PAO tests it the screenshots and configuration exports no longer match the live environment.
- POA&M items that describe a fix without a verifiable completion date, which authorizing officials read as an open risk rather than a closed one.
- Continuous monitoring treated as a compliance afterthought instead of an operational discipline, so vulnerability scan results pile up and the authorization slides into remediation mode within the first year.
- Underestimating how much of the assessment is inherited-control paperwork: proving what a cloud infrastructure provider already covers, rather than reproving controls from scratch.
How ACTA automates FedRAMP
ACTA's federal policy pack library includes FedRAMP, and like every pack in the library, it ships with every license: there is no separate FedRAMP add-on tier or per-framework fee. The pack is editable YAML, so a program can tune control narratives and evidence mappings to its own environment rather than working from a static template.
Because ACTA runs on goRapide, BMD's deterministic causal engine, with no LLMs, no agents, and no probabilistic components anywhere in the compliance path, the same environment run through the same journey twice produces identical artifacts, identical scores, and identical evidence both times, and every control decision carries an inspectable causal chain back to the evidence that produced it. That determinism is the kind of consistency a 3PAO's repeatable testing depends on: a package that means the same thing every time it is produced.
From a live environment, ACTA generates the System Security Plan, Security Assessment Report, POA&M, Risk Assessment Report, control narratives, and evidence binder, the core of a FedRAMP package, and can provision the underlying cloud environment as code on AWS commercial, AWS GovCloud, Azure, Google Cloud, Microsoft GCC High, or bare metal, with a small environment standing up in roughly 25 minutes.
After authorization, ACTA's continuous monitoring tracks credential health, evidence freshness, endpoint posture, and drift from previously passing controls, the exact areas where FedRAMP authorizations quietly go stale between annual assessments. A stale posture refreshes to current in two clicks, the same cATO capability that underpins continuous authorization work generally. Evidence never leaves the customer's boundary: the standard deployment phones home only for a license heartbeat, and the air-gapped build does not phone home at all.
FedRAMP and adjacent frameworks
FedRAMP's control catalog is not standalone. It is built directly on the NIST SP 800-53 control catalog, which functions as the substrate underneath most other federal security programs, so work done to satisfy FedRAMP maps cleanly onto NIST-based assessments elsewhere in an agency's portfolio, and vice versa.
SOC 2 is the reciprocity question that comes up most often. A SOC 2 Type 2 report and a FedRAMP package overlap in places, particularly around access control, change management, and monitoring, because both ultimately trace back to similar security principles. But there is no formal reciprocity between the two: a SOC 2 report cannot substitute for a FedRAMP authorization, and a 3PAO will still test FedRAMP-specific controls, evidence formats, and continuous monitoring obligations that SOC 2 does not require. What a mature SOC 2 program buys a CSP is a head start on evidence collection and control maturity, not a shortcut through the authorization itself.
CMMC assessments sit in a different lane: FedRAMP governs cloud services agencies use directly, while CMMC governs how defense contractors protect controlled unclassified information in their own environments, often environments built on a FedRAMP-authorized cloud underneath. A defense contractor pursuing CMMC frequently ends up relying on an already-authorized FedRAMP cloud as part of its own boundary rather than seeking FedRAMP authorization itself.
StateRAMP extends a comparable model to state and local government, using a similar baseline structure and assessment approach but run by its own program office, independent of the federal PMO. A cloud service provider targeting both federal and state buyers typically has to pursue both authorizations separately today, though the two programs share enough structure that prior FedRAMP evidence meaningfully shortens the StateRAMP effort. Explore the rest of the compliance framework library for how FedRAMP relates to the wider control landscape.
Frequently asked questions
How long does FedRAMP take?
Most FedRAMP authorizations take twelve to eighteen months from a standing start, assuming an agency sponsor is in place early. A well-prepared Low-impact or LI-SaaS effort can close in nine to ten months, while a complex High baseline system, especially one that needs multiple rounds of 3PAO remediation, can run well past two years.
How much does FedRAMP cost?
Budget $100,000 to $250,000 in 3PAO assessment fees for a Moderate baseline, more for High, plus $75,000 to $200,000 in advisory or SSP-authoring support if you are not building the package in-house, and $50,000 to $150,000 a year afterward for continuous monitoring. Internal remediation time is usually the largest cost nobody budgets for.
What is the difference between FedRAMP Moderate and High?
Moderate is where most federal business systems land, including systems handling controlled unclassified information, and it is the baseline most cloud service providers authorize against. High is reserved for systems where a security failure could cause severe or catastrophic harm, such as law enforcement or emergency response systems, and it carries the largest control set and the most third-party assessment work.
Can I reuse my SOC 2 for FedRAMP?
Partially. A SOC 2 Type 2 report overlaps with FedRAMP in areas like access control and change management, and a mature SOC 2 program gives you a head start on evidence and control maturity. But there is no formal reciprocity: a 3PAO still has to independently test FedRAMP-specific controls and continuous monitoring obligations that SOC 2 does not cover.
Do I need a 3PAO?
Yes. A FedRAMP authorization requires an accredited third-party assessment organization to independently test and validate the implemented controls before an agency can issue an authority to operate. The 3PAO also performs the readiness assessment and, after authorization, supports the annual assessment that keeps the authorization current.
What is FedRAMP Ready?
FedRAMP Ready is a preliminary designation on the FedRAMP Marketplace, issued after a 3PAO reviews a cloud service offering's documentation and concludes it is mature enough to enter a full authorization process. It signals readiness to potential agency sponsors, but it is not itself an authorization.
Who authorizes a FedRAMP package?
Authorization comes from an authorizing official at the sponsoring federal agency for an agency authorization, the most common path today. FedRAMP also maintains a Joint Authorization Board process for a smaller number of widely reusable cloud offerings, though most cloud service providers pursue the agency path.
What is the FedRAMP Marketplace?
The FedRAMP Marketplace is the public registry showing every cloud service in the FedRAMP process, including its designation of In Process, Ready, or Authorized, its impact level, its sponsoring agency, and the 3PAO that assessed it. Agencies use it to find authorizations they can reuse instead of starting from scratch.
What is FedRAMP 20x?
FedRAMP 20x is the PMO's ongoing modernization effort, aimed at making authorization faster and less document-heavy by leaning on automation and machine-readable evidence rather than lengthy narrative documents. It builds on the authority Congress gave the program in the FedRAMP Authorization Act, and it is still evolving, so specifics should be confirmed against current FedRAMP.gov guidance.