GRCCopilot
Sign In
U.S. General Services Administration (GSA) / FedRAMP Programme Management Office

FedRAMP Security Assessment Framework

The U.S. government's standardised cloud security authorisation programme — mandatory for federal agency cloud adoption

Start Assessment Create Free Account
14
Controls
42
Questions
Active
Status
May 2029
Expires

About this Framework

The Federal Risk and Authorization Management Program (FedRAMP) provides a standardised approach to security assessment, authorisation and continuous monitoring for cloud products and services used by U.S. federal agencies. Based on NIST SP 800-53 controls, FedRAMP authorisations (ATO) are reusable across agencies — a single assessment serves all 400+ federal agencies. Cloud providers must achieve FedRAMP authorisation before selling cloud services to the U.S. federal government.

Key Control Domains

Access Control
Audit & Accountability
Configuration Management
Contingency Planning
Identification & Authentication
Incident Response
Media Protection
Physical Protection
Risk Assessment
System & Communications Protection
System & Information Integrity
Supply Chain Risk Management

Who Needs This?

  • Cloud service providers selling to U.S. federal agencies
  • Federal agencies selecting cloud solutions
  • DoD, civilian and intelligence community contractors
  • SaaS/IaaS/PaaS providers pursuing government cloud market

Compliance Benefits

  • Mandatory requirement for federal cloud sales — opens a $100B+ market
  • Reusable ATO accepted by all 400+ federal agencies
  • Significantly reduces per-agency security assessment burden
  • Foundation for global government cloud security recognition

Official Reference

FedRAMP Official Programme Site
https://www.fedramp.gov/

Assessment Details

Issuer / AuthorityU.S. General Services Administration (GSA) / FedRAMP Programme Management Office
FrameworkFedRAMP Security Assessment Framework
Controls14
Questions42
StatusActive
Assessment Start25 May 2026
Assessment Expires25 May 2029

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/fedramp-security-assessment-framework

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.