Back to blog
US & Americas

FedRAMP authorization: what selling cloud to US federal agencies takes

FedRAMP is the standardised authorization process for cloud services used by US federal agencies. The paths to authorization, the impact levels, the documentation burden, and the continuous monitoring that never stops.
GRC Copilot Team
FedRAMP authorization: what selling cloud to US federal agencies takes

FedRAMP is the US government programme that standardises security assessment and authorization for cloud services sold to federal agencies. It is built on NIST SP 800-53, and it is widely regarded as one of the most demanding compliance programmes a commercial cloud provider can undertake - in effort, in documentation, and in the ongoing obligation after you achieve it.

Why it exists

Without it, every agency would assess every cloud service independently. FedRAMP's premise is "do once, use many": a service is authorized once, and other agencies can reuse that authorization package rather than starting over.

Impact levels

Your level follows the sensitivity of the data the service will handle, and it determines how many controls apply:

  • Low - limited adverse effect if compromised. Includes a tailored baseline for low-risk software-as-a-service.
  • Moderate - the most common level, covering the majority of federal data that is not public.
  • High - for data where compromise would have severe or catastrophic effect: law enforcement, emergency services, financial and health systems.

The control count rises steeply with level, and moving up later is a substantial re-assessment rather than an increment.

Paths to authorization

  • Agency authorization - you partner with a federal agency that sponsors and issues the authority to operate. The more common route, and it requires finding an agency willing to invest in you.
  • Programme-level authorization - a more centralised review path historically associated with the Joint Authorization Board, prioritising services with broad government demand.

The programme has been evolving, including modernisation efforts around automation and reuse. Confirm current paths and requirements with the FedRAMP programme before planning - the process has changed more than most compliance regimes.

Build the control evidence once

GRC Copilot maps NIST 800-53 and FedRAMP baselines onto your existing controls - so ISO 27001 and SOC 2 work you already did counts toward the package rather than being repeated.

What the package contains

The documentation burden is the part that surprises people:

  • System Security Plan (SSP) - the central artefact, describing how every applicable control is implemented in your specific system. It runs to hundreds of pages.
  • Supporting plans - configuration management, incident response, contingency, and more.
  • Security assessment by an accredited third-party assessment organisation (3PAO) - independent testing, not self-attestation.
  • Plan of Action and Milestones (POA&M) - tracked open findings with remediation dates.
  • A boundary diagram and data flow documentation that must match reality precisely.
The authorization boundary is the decision that shapes everything. Draw it too wide and you inflate the control scope enormously; draw it inaccurately and the assessment stalls. Settle it before writing the SSP.

Continuous monitoring - the part that never ends

Authorization is not the finish line. Ongoing obligations include monthly vulnerability scanning with defined remediation timeframes by severity, monthly reporting to the authorizing official, POA&M maintenance, significant change requests before major architectural changes, and annual assessment.

That "significant change" requirement is a genuine operating constraint: architectural changes need approval, which is a different rhythm from continuous delivery.

Is it worth it?

Only if US federal business is a real target. It is a major, sustained investment - and the ongoing monitoring obligation is a permanent operational commitment, not a project that completes. Where federal revenue is strategic, it is also a strong moat: competitors face the same barrier.

Related programmes worth knowing: StateRAMP for state and local government, and SP 800-171 for contractors handling controlled unclassified information - both lower barriers to public-sector work.

Frequently asked questions

How long does FedRAMP take?

Typically a year or more end to end, dominated by documentation, remediation and finding an agency sponsor rather than by the assessment itself.

Does SOC 2 or ISO 27001 help?

Yes, substantially - the underlying controls and evidence overlap. Neither substitutes for the FedRAMP package, but they reduce the remediation work considerably.

Can we use a FedRAMP authorized cloud provider and inherit their authorization?

You inherit controls at the infrastructure layer, which is a real advantage, but your own service still requires its own authorization. Inheritance reduces scope; it does not remove it.

What is a 3PAO?

An accredited third-party assessment organisation that independently tests your controls. Self-assessment is not sufficient.

Key takeaways

  • Built on NIST 800-53, with impact level driving control count.
  • The authorization boundary decision shapes the entire effort.
  • Independent 3PAO assessment is mandatory.
  • Continuous monitoring is a permanent operating commitment, not a project.
#fedramp #authorization #cloud #federal #continuous-monitoring