Questions / Answer
How Long Does a FedRAMP Authorization Take?
Your board wants a date, and FedRAMP does not publish one. That is the honest answer, and it comes straight from FedRAMP's own process documents. FedRAMP stands for the Federal Risk and Authorization Management Program. It is the federal standard for checking that cloud products are safe to use.
What is the official answer?
FedRAMP publishes no fixed calendar for authorization. Its process documents describe the authorization process, not a timeline. (FedRAMP authorization process) An authorization certifies that a cloud product's security has been assessed and is adequate for federal use. (FedRAMP authorization process) The process follows the steps in the Risk Management Framework, NIST SP 800-37. (FedRAMP authorization process) NIST is the National Institute of Standards and Technology, the agency behind many federal security standards. OMB, the Office of Management and Budget, replaced the 2011 FedRAMP memo with M-24-15 in July 2024. (M-24-15)
How long does it actually take?
At the start of FY25, final authorization times were exceeding one year, sometimes approaching two. (FedRAMP FY25 review) New services without an agency sponsor faced an anticipated timeline of 2 to 3 years. (FedRAMP FY25 review) FY25 is FedRAMP's fiscal year 2025, the period it used to measure its backlog. After FedRAMP cleared its backlog in FY25, it reported final review time under 30 days. (FedRAMP FY25 review)
Which authorization paths exist?
FedRAMP describes three paths to authorization. (FedRAMP authorization process) Agency Authorization is signed by the agency's authorizing official. It means the agency assessed the provider's security against FedRAMP guidelines and accepted it. (FedRAMP authorization process) An authorizing official is the person who accepts the risk and signs the authorization. CSP stands for cloud service provider, the company seeking authorization. Program Authorization is signed by the FedRAMP Director for products without an agency sponsor. FedRAMP says Program authorization replaced the old Joint Authorization Board (JAB) authorizations. (FedRAMP FY25 review) A third category covers other paths approved by the FedRAMP Board. (FedRAMP authorization process)
What happens after authorization?
Agencies use the FedRAMP package to issue their own authorization to operate (ATO). (FedRAMP authorization process) They can also issue an authorization to use (ATU). (FedRAMP authorization process) Agencies must presume the package is adequate for their use at or below its assessed impact level. (FedRAMP authorization process) FIPS 199 is the federal standard that defines impact levels. The presumption lasts only while the authorization is maintained through ongoing monitoring. (FedRAMP authorization process)
What is FedRAMP 20x?
FedRAMP 20x tests an automated approach to authorization. It assesses security with Key Security Indicators (KSIs) and machine-readable validation. (20x pilot) The Phase 1 pilot covered FedRAMP Low authorization and ended in September 2026. (20x pilot) FedRAMP announced a Phase Two pilot aimed at Moderate authorizations. (FedRAMP FY25 review) It anticipates opening a formal 20x path to the public by the end of FY26 Q2. (FedRAMP FY25 review)
Is PolicyCortex FedRAMP authorized?
PolicyCortex is not FedRAMP authorized. Its 33 collectors read live Azure configuration and evaluate it against NIST 800-53 and NIST 800-171. It is strongest in commercial Azure, and AWS, Amazon Web Services, is covered too. It produces SSP, SAR, and POA&M output from collected evidence, and re-verifies controls after remediation. SSP is a System Security Plan and SAR is a Security Assessment Report. POA&M is a Plan of Action and Milestones.
Sources
- FedRAMP M-24-15 authorization process, FedRAMP documentation (M-24-15 Section IV, The FedRAMP Authorization Process)
- OMB Memorandum M-24-15, Modernizing the Federal Risk and Authorization Management Program, July 25, 2024
- FedRAMP FY25 review, FedRAMP Built a Modern Foundation in FY25, September 30, 2025
- FedRAMP 20x Phase 1 pilot, FedRAMP documentation
Next step
FedRAMP authorizations run on evidence, and the best evidence comes from your live cloud. PolicyCortex reads your live Azure configuration and turns it into package-ready evidence. See what it can collect for you