FedRAMP compliance: requirements, impact levels, and how to get authorized

FedRAMP compliance: requirements, impact levels, and how to get authorized

Santerra Holler October 09, 2026

FedRAMP compliance: requirements, impact levels, and how to get authorized

FedRAMP compliance means a cloud service offering meets the Federal Risk and Authorization Management Program’s security requirements, which are built on NIST SP 800-53 controls, and holds an authorization that lets U.S. federal agencies use it. It applies to any cloud service provider (CSP) selling Infrastructure as a Service (IaaS), Platform as a Service (PaaS) or Software as a Service (SaaS) that processes federal data. The industry often calls it the gold standard of U.S. government compliance certifications. This guide reflects the authorization rules as of October 2026. It covers what FedRAMP requires, how the impact levels differ, the steps to authorization and where CSPs most often fail.

Key takeaways

  • ✓FedRAMP combines a NIST SP 800-53 control baseline, a full documentation package, an independent Third Party Assessment Organization (3PAO) assessment and monthly continuous monitoring.
  • ✓A CSP’s FIPS 199 impact level of Low, Moderate or High decides how many controls it must implement and how much evidence it must produce.
  • ✓Most new authorizations go through an agency sponsor, because the Joint Authorization Board (JAB) provisional pathway was retired in favor of agency authorizations overseen by the FedRAMP Board.
  • ✓Unclear system boundaries, weak documentation and immature continuous monitoring cause more failed assessments than missing technical controls do.
  • ✓Authorized services are listed on the FedRAMP Marketplace, where other agencies can reuse the package instead of starting from scratch.

What FedRAMP compliance requires

FedRAMP requires an implemented control baseline, documentation that proves it, an independent assessment and ongoing monitoring after authorization. It sits alongside other cloud security compliance frameworks, but it is the strictest about evidence.

Technical requirements

  • ✓Implement the NIST SP 800-53 Rev. 5 baseline for your impact level, including access control (AC), audit and accountability (AU), configuration management (CM), incident response (IR) and system integrity (SI).
  • ✓Use FIPS 140-validated cryptography for data in transit and at rest.
  • ✓Enforce multi-factor authentication (MFA) for privileged and network access.
  • ✓Maintain secure configuration baselines, such as CIS Benchmarks or DISA STIGs, and track drift from them.
  • ✓Run an incident response capability that reports to the agency and to CISA through the US-CERT channel.

Documentation requirements

The core of the package is the System Security Plan (SSP), which describes the authorization boundary, data flows and how every control is implemented. Its attachments include policies and procedures, the Configuration Management Plan, the Incident Response Plan, the Contingency Plan, the Customer Responsibility Matrix (CRM) and the inventory workbook.

Assessment and continuous monitoring

A 3PAO accredited by A2LA writes a Security Assessment Plan (SAP), tests your controls and reports the results in a Security Assessment Report (SAR). After authorization, continuous monitoring (ConMon) becomes the ongoing obligation, and FedRAMP’s continuous monitoring approach mirrors the security assessment requirements of DORA and NIS2.

Cadence ConMon obligation
Monthly Authenticated scans of operating systems, databases, web applications and container images; updated Plan of Action and Milestones (POA&M); updated asset inventory
Remediation deadlines 30 days for High, 90 days for Moderate and 180 days for Low vulnerabilities
Annually 3PAO assessment of a subset of controls, plus penetration testing
Before major changes Significant Change Request approved before deployment

FedRAMP impact levels explained

FedRAMP impact levels are Low, Moderate and High, and you set yours with FIPS 199. You rate the potential harm to confidentiality, integrity and availability if the system is compromised, and the highest of the three ratings becomes your overall level, known as the high-water mark.

Impact level Typical data and systems Baseline depth
Low (including Li-SaaS) Public-facing or non-sensitive data, such as collaboration tools holding no personally identifiable information (PII) beyond login details Smallest baseline; Li-SaaS uses a tailored, lighter assessment
Moderate Controlled Unclassified Information (CUI) and PII, covering most agency SaaS, PaaS and IaaS Several hundred controls; the most common level
High Law enforcement, emergency services, financial and health data where a breach could cause severe or catastrophic harm Largest baseline, with stricter logging, encryption and personnel controls

Moderate or High? Agencies must match the level to their data, so a health or law enforcement workload cannot run on a Moderate service. Target the level your agency buyers actually need, because moving from Moderate to High later means adding controls and going through another assessment.

How to get FedRAMP authorized, step by step

You get FedRAMP authorized by preparing for readiness, finding an agency sponsor, building the package, passing a 3PAO assessment and earning an Authority to Operate (ATO).

  1. Readiness and gap analysis. Define the authorization boundary and build on FedRAMP-authorized infrastructure, such as AWS GovCloud, Azure Government or Google Cloud’s Assured Workloads, to inherit controls. Then run a gap analysis against the baseline.
  2. Readiness Assessment Report (RAR). A 3PAO checks whether you are ready. The RAR is optional for most CSPs but required for a FedRAMP Ready designation.
  3. Agency sponsorship. Secure an agency willing to authorize you and hold a kickoff with the agency and the FedRAMP PMO.
  4. Package development. Your compliance lead writes the SSP, attachments and CRM.
  5. Full assessment. The 3PAO executes the SAP, runs a penetration test and produces the SAR. You open POA&M items for findings.
  6. Authorization. The agency authorizing official reviews the risk and issues an ATO. The FedRAMP PMO then reviews the package and lists the service as Authorized on the Marketplace.
  7. Continuous monitoring. Your operations team delivers monthly ConMon evidence, and other agencies can reuse the package to issue their own ATOs.

Before engaging a 3PAO, have a draft SSP, boundary and data flow diagrams, an asset inventory, a CRM, the IR, CM and contingency plans, and at least one month of clean authenticated scan results.

Timelines, costs, and team roles

FedRAMP authorization usually takes many months to more than a year, and cost depends mostly on your impact level and how much you can inherit. The main drivers are:

  • Inheritance: building on an authorized IaaS removes physical and environmental controls from your scope.
  • Boundary size: every service, region and third-party integration inside the boundary adds controls to evidence.
  • Remediation debt: a large vulnerability backlog delays a clean assessment.
  • External help: advisory consultants, 3PAO fees and infrastructure rebuilt in a gov region all add cost.

A working team needs an executive sponsor, a compliance or program lead who owns the SSP, cloud and security engineers who implement controls, and an operations owner who produces ConMon evidence every month. The FedRAMP 20x initiative is pushing toward automated, machine-readable evidence, which favors teams that already generate evidence continuously instead of collecting it by hand.

Common pitfalls and when you are not ready

When CSPs struggle, the cause is usually weak process discipline rather than missing technology.

  • ✗Unclear boundaries: leaving shared services, CI/CD pipelines or support tools out of the diagram when they touch federal data.
  • ✗Unsupported inheritance: claiming controls that your IaaS provider’s CRM marks as the customer’s responsibility.
  • ✗Generic documentation: SSP narratives that restate the control instead of describing your implementation.
  • ✗Immature ConMon: scans that miss assets, or POA&M items that pass their deadlines.
  • ✗No executive sponsor: engineering time gets pulled back to feature work mid-assessment.

You are probably not ready if you lack an agency buyer, cannot produce an accurate asset inventory, or still patch critical vulnerabilities ad hoc. Applying cloud security best practices such as least privilege, infrastructure as code and centralized logging first makes the baseline far cheaper to meet.

How Upwind supports FedRAMP continuous monitoring

Upwind helps FedRAMP teams keep up with ConMon by showing what is actually running inside the authorization boundary. Monthly scans produce long finding lists that compete for the same remediation deadlines. Upwind’s lightweight eBPF sensors add runtime context to those lists, showing which vulnerabilities are loaded and reachable, which identities are used and which APIs carry sensitive data. Upwind is a runtime security platform rather than a GRC tool, so you will still need a separate tool or process to write and maintain the SSP. When choosing a cloud security platform for a FedRAMP boundary, Upwind covers:

  • ✓CSPM and Kubernetes posture checks to track configuration baselines and drift.
  • ✓Vulnerability prioritization by runtime exposure to work down the POA&M within deadlines.
  • ✓CIEM that shows which identities are actually used, supporting least privilege.
  • ✓Cloud detection and response, with AI agents that investigate threats for incident response.

Choosing your path to authorization

Pursue FedRAMP when you have a committed agency buyer, a clearly defined boundary and the operational maturity to produce monthly evidence without slipping. Authorization makes you eligible for federal procurement and gives you a package other agencies can reuse. It also earns more trust from public sector buyers and strengthens your commercial security posture. Set your impact level, map what you can inherit, and treat continuous monitoring as the core of FedRAMP compliance rather than a step that comes after the ATO.

FAQ

What is FedRAMP compliance?

FedRAMP compliance means a cloud service offering meets the Federal Risk and Authorization Management Program security requirements based on NIST SP 800-53 controls and has an authorization that allows U.S. federal agencies to use it.

Who needs FedRAMP authorization?

Any cloud service provider selling IaaS, PaaS, or SaaS to U.S. federal agencies and processing federal data needs FedRAMP authorization.

What are the FedRAMP impact levels?

FedRAMP has three impact levels: Low, Moderate, and High. They are set using FIPS 199 based on the potential harm to confidentiality, integrity, and availability if the system is compromised, and the highest rating becomes the overall level.

How do you get FedRAMP authorized?

A provider prepares its boundary and gap analysis, may complete a Readiness Assessment Report, secures an agency sponsor, builds the documentation package, passes a 3PAO assessment, and receives an Authority to Operate from the agency.

What happens after a FedRAMP authorization is granted?

After authorization, the provider must perform continuous monitoring, including monthly authenticated scans, POA&M updates, inventory updates, annual 3PAO testing of selected controls, penetration testing, and approval for significant changes before deployment.

Contents
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS