Compliance

FedRAMP,explained

7 min read · Updated June 2026

FedRAMP is the US government programme that standardises how cloud services are assessed and authorised for federal use. It is built on NIST 800-53 baselines, requires assessment by an accredited 3PAO, and imposes ongoing continuous monitoring. It is an authorisation granted by the government, not a self-declared certificate.

What FedRAMP is

FedRAMP, the Federal Risk and Authorization Management Program, gives US federal agencies a consistent way to adopt cloud services securely. Rather than each agency assessing a cloud product from scratch, FedRAMP provides a standard process and a reusable authorisation.

It is aimed squarely at cloud service providers that want to sell to the US federal government, so it is a go-to-market requirement for that market rather than a general best practice.

Baselines and impact levels

FedRAMP uses NIST 800-53 controls organised into baselines at low, moderate, and high impact, with FedRAMP-specific parameters. There is also a tailored baseline for low-impact software-as-a-service. The baseline you target depends on the sensitivity of the data your service will handle.

Authorisation and assessment

A cloud service is assessed by an accredited third-party assessment organisation (a 3PAO), which tests the controls and documents the results. Authorisation is then granted by the government, either by an individual agency issuing an Authorisation to Operate, or through the FedRAMP process. The provider does not authorise itself.

Continuous monitoring

FedRAMP does not stop at authorisation. Providers must maintain continuous monitoring: regular vulnerability scans, a plan of action and milestones to track and close weaknesses, and ongoing reporting to the authorising official. Staying authorised is an ongoing obligation.

How to approach it

  1. 1Confirm the impact level and baseline your service needs.
  2. 2Implement the 800-53 baseline controls and document them in a system security plan.
  3. 3Engage a 3PAO for assessment and remediate findings.
  4. 4Pursue an agency authorisation or the FedRAMP process.
  5. 5Operate the continuous-monitoring programme to stay authorised.

Frequently asked questions

Is FedRAMP a certification?

It is more precisely an authorisation. After a 3PAO assessment, the government grants an authorisation to operate, either by an agency or through the FedRAMP process. It is not a certificate a provider issues to itself.

How does FedRAMP relate to NIST 800-53?

FedRAMP baselines are built from NIST 800-53 controls with FedRAMP-specific parameters and continuous-monitoring requirements. If you have done 800-53 work, much of it carries directly into a FedRAMP effort.

Who needs FedRAMP?

Cloud service providers that want to sell to US federal agencies. It is generally not required for purely commercial customers, so providers pursue it when the federal market is a target.

Do this in a fraction of the time

Diligio centralises your approved answers, drafts each response grounded in your sources, and independently verifies it before you review. RFPs, DDQs, and security questionnaires, answered from one knowledge base.

Related guides

Due diligence

What is a DDQ (due-diligence questionnaire)?

Due diligence

DDQ vs RFP: what is the difference?

RFPs

RFP vs RFI vs RFQ: what is the difference?

RFPs

The RFP response process: a step-by-step guide

RFPs

How to build an RFP content library

RFPs

The bid/no-bid decision: when to respond to an RFP

Security questionnaires

How to respond to security questionnaires faster

Security questionnaires

SIG vs CAIQ vs VSAQ: the security questionnaires explained

Security questionnaires

Vendor security assessment checklist

Compliance

SOC 2 vs ISO 27001: what is the difference?

Compliance

ISO 27001 readiness checklist: how to prepare for certification

Compliance

SOC 2 for startups: a practical guide

Compliance

GDPR compliance for SaaS: a practical guide

Compliance

HIPAA compliance for software vendors

Compliance

PCI DSS compliance, explained

Compliance

The NIST Cybersecurity Framework, explained

Compliance

ISO 42001, the AI management standard, explained

Compliance

ISO 27017 and ISO 27018: cloud security and privacy, explained

Compliance

ISO 22301 and business continuity, explained

Compliance

DORA, explained

Compliance

Cyber Essentials, explained

Compliance

The CCPA and CPRA, explained

Compliance

NIST 800-53, explained

Compliance

NIST 800-171 and CMMC, explained

Compliance

HITRUST CSF, explained

Financial regulation

BSA/AML, explained

Financial regulation

The FATF 40 Recommendations, explained

Financial regulation

MiFID II and MAR, explained

Financial regulation

Consumer credit and fair lending, explained

Due diligence

Third-party risk management (TPRM): a practical guide

Putting FedRAMP into practice? See Diligio Compliance for FedRAMP.