FedRAMP
A US government authorization required for any cloud or AI service that handles federal agency data.
A US government authorization required for any cloud or AI service that handles federal agency data.
Basic
FedRAMP (Federal Risk and Authorization Management Program) is the US government's standard security assessment for cloud services. It has three impact levels: Low, Moderate, and High. FedRAMP Moderate is the baseline for most civilian agencies. FedRAMP High is required for critical agencies (DoD, IRS, etc.). AI providers pursuing federal contracts need FedRAMP authorization, which typically takes 12-24 months.
Deep
FedRAMP is governed jointly by GSA, DoD, and DHS. Authorization is granted either by a Joint Authorization Board (JAB) or an individual agency. The assessment draws from NIST SP 800-53 controls, with 125+ controls at Moderate and 425+ at High. Cloud providers (AWS GovCloud, Azure Government, Google Cloud for Government) host FedRAMP-authorized AI endpoints. OpenAI offers FedRAMP Moderate through Azure OpenAI Government. Anthropic runs Claude through AWS GovCloud for federal contracts. FedRAMP authorization is a multi-year project · providers without one cannot legally process federal data.
Expert
FedRAMP authorization requires a 3PAO (Third Party Assessment Organization) audit against NIST SP 800-53 Rev 5 baselines. The process yields an Authorization to Operate (ATO) package: System Security Plan, Security Assessment Report, POA&M, and Continuous Monitoring. Provisional ATO via JAB is most efficient; individual agency ATOs are faster but less portable. Impact Levels map to FIPS 199 categorization. Data residency constraint: FedRAMP data must stay within US borders and be handled by US persons for most controls.
Depending on why you're here
- ·FedRAMP = US fed cloud authorization
- ·Three levels: Low, Moderate, High
- ·Draws from NIST SP 800-53 control families
- ·Need FedRAMP for any federal contract handling agency data
- ·Use AWS GovCloud, Azure Government, or Google GovCloud
- ·Authorization is multi-year · plan accordingly
- ·FedRAMP authorization unlocks $100B+ federal AI market
- ·Barrier to entry is real · 18-24 month authorization timeline
- ·Only 3-4 frontier AI providers currently authorized
- ·A US government seal of approval for cloud services
- ·Without it, you can't sell AI to federal agencies
- ·Three tiers based on how sensitive the data is
FedRAMP is a 2-year project and a multi-billion-dollar key to the US federal AI market. OpenAI and Anthropic are already through the door.