Questions / Answer
What Is FedRAMP, in Plain Words?
FedRAMP is the government's way of checking cloud products. The name is short for Federal Risk and Authorization Management Program. One review can serve many agencies.
What does FedRAMP actually do?
It sets one security standard for cloud products. A cloud vendor proves it meets the standard once. Agencies reuse that proof instead of testing from scratch. (FedRAMP authorization process)
Before FedRAMP, every agency ran its own review. Vendors faced the same audit many times. FedRAMP replaced that with a shared process.
The program covers security assessment, authorization, and continuous monitoring for cloud products and services. (FedRAMP) Assessment means checking the controls. Authorization means approving the product. Monitoring means keeping the proof fresh.
Who needs FedRAMP?
Cloud vendors who sell to federal agencies. If your product holds federal data, agencies will ask about it. No authorization often means no contract.
Agencies can require a FedRAMP authorization as a contract condition in some cases. (FedRAMP authorization process)
It does not apply to software installed on your own servers. It is a cloud program from start to finish. Private companies with no federal customers can ignore it.
What are the Rev 5 baselines?
Baselines are the sets of security controls a vendor must meet. Rev 5 defines three impact levels. The control counts are:
- Low: 156 controls.
- Moderate: 323 controls.
- High: 410 controls.
These baselines are built from NIST SP 800-53 Rev 5, the federal control catalog. (FedRAMP) NIST stands for the National Institute of Standards and Technology.
Low is for the least sensitive systems. High is for the most sensitive. Moderate, the most common one, sits between them.
Agencies pick the level by rating how bad a breach would be. That rating decides which baseline applies.
What are the two paths to authorization?
The program supports two main paths to a FedRAMP authorization. (FedRAMP authorization process)
Agency Authorization: a federal agency's authorizing official reviews the vendor's security package and signs off. (FedRAMP authorization process) Other agencies can then reuse that package.
Program Authorization: the FedRAMP Director reviews the package and signs off. (FedRAMP authorization process) This path replaced the old Joint Authorization Board authorizations. (FedRAMP FY25 update)
Both paths end in a FedRAMP authorization listed in the Marketplace. (FedRAMP) The Marketplace is the public list of authorized cloud services.
What does "presumption of adequacy" mean?
If a cloud product has a FedRAMP authorization, agencies must presume the security assessment is adequate for their use. (FedRAMP authorization process) That is the "do once, use many times" idea. It is why one authorization can serve many agencies.
An agency can still ask for more if it has a proven need. But it cannot start from zero just because it wants to.
Is authorization a one-time event?
No. The authorization must be actively maintained with ongoing monitoring. (FedRAMP authorization process) Vendors keep proving the controls work over time.
The review covers documentation and tests of the controls. It can even include expert-led red team assessments. (FedRAMP authorization process) Letting monitoring lapse puts the authorization at risk.
Does FedRAMP endorse products?
No. The program states clearly that an authorization is not an endorsement of a product or service. (FedRAMP authorization process) It means the security posture was assessed and found adequate. Nothing more.
PolicyCortex is not FedRAMP authorized. It reads live Azure configuration and maps evidence to NIST 800-171 controls for teams working toward CMMC.
Sources
- FedRAMP.gov
- FedRAMP authorization process under OMB M-24-15
- FedRAMP FY25 update: program authorization replaced JAB authorizations
Next step
Eyeing federal work? Start building the evidence habit now, because every authorization path rewards it.