Government cloud authorization

FedRAMP & GovRAMP (formerly StateRAMP)

FedRAMP (federal) and GovRAMP — the state and local program formerly called StateRAMP — standardize how cloud services are security-assessed and authorized before government agencies may use them to handle government data.

Official source (opens in a new tab): FedRAMP (federal) / GovRAMP, formerly StateRAMP (state & local)

Scope

Who it applies to.

FedRAMP applies to companies selling cloud computing products and services — infrastructure, platform, or software as a service — that create, collect, process, store, or maintain federal information on behalf of a federal agency. The obligation sits on the cloud service provider, which must earn and maintain the certification. It reaches agencies as a procurement constraint: an agency must ensure any in-scope cloud service it uses is certified. GovRAMP, formerly StateRAMP, plays a parallel role for state, local, tribal, and education buyers.

Certification paths
FedRAMP now uses “FedRAMP Certified” as its program term for a cloud service offering that satisfies the statutory concept of authorization. The Joint Authorization Board was replaced by the FedRAMP Board in 2024, and the program has moved away from separate JAB and agency tiers toward a single designation. A legacy agency-sponsored path remains for Rev 5 packages and still requires FedRAMP review.
Impact levels & certification classes
Under the Consolidated Rules for 2026, offerings are certified in classes A through D, each carrying progressively more assurance. FedRAMP says these classes loosely align with the Low, Moderate, and High impact levels that FIPS 199 defines by the harm from losing confidentiality, integrity, or availability — but that there is no one-to-one correlation. The agency categorizes its own data.
NIST SP 800-53 baseline
Security expectations trace to NIST SP 800-53, and to the control baselines in NIST SP 800-53B, tailored by FedRAMP for cloud implementations. Because NIST publications are U.S. government works, the underlying control catalog is public. An agency’s own information system stays subject to FISMA and the NIST Risk Management Framework regardless of which cloud services it buys.
Independent assessment (3PAO)
An independent assessor — historically called a Third Party Assessment Organization, or 3PAO — analyzes, validates, and attests to the security materials a provider submits. FedRAMP has shifted to “independent assessor” to match the statute’s wording. Assessors perform initial and annual assessments, plus out-of-cycle assessments after significant changes, and must preserve chain of custody for the evidence they produce.
Continuous monitoring
Certification is a lifecycle, not a one-time event. Certified providers supply an Ongoing Certification Report to agency customers under FedRAMP’s collaborative continuous monitoring rules, and undergo annual reassessment. Agencies remain responsible for monitoring the service and their own integration of it. Letting a certification lapse can strand an agency customer that depends on it.
Scope limits
OMB Memorandum M-24-15 limits FedRAMP’s scope to cloud products and services that handle federal information on an agency’s behalf, and expressly places several categories outside it — including search engines and single-agency systems not offered as a shared service. For anything outside that scope, the memo states that “a FedRAMP authorization is not required.”

The vendor & sub-processor obligation

What it puts on you.

If you process government data in the cloud, the service generally must hold the appropriate authorization, and you must verify and continuously monitor that status — tying your compliance to a provider’s authorization package.

How self-hosting addresses it

Remove the third party, remove the burden.

Running the workload on your own infrastructure keeps the data off external cloud services altogether, so a FedRAMP or GovRAMP authorization is not something you have to inherit or monitor for that processing.

How FileFerret applies

FileFerret runs on hardware inside your own network, so it is not a cloud service offering supplied to an agency and generally falls outside FedRAMP’s scope. That is not a FedRAMP certification and is not a substitute for one. The agency’s own system still inherits its FISMA and NIST SP 800-53 obligations. See how it’s built →

Full, current text is maintained at the official source: FedRAMP (federal) / GovRAMP, formerly StateRAMP (state & local).

Enforcement

Who enforces it, and how.

FedRAMP is a procurement and authorization regime, not a fine regime — there is no civil penalty for lacking certification. It bites commercially: agencies must ensure the in-scope cloud services they use are certified, so an uncertified offering is effectively unsellable to federal buyers. The FedRAMP Authorization Act supplies the counterweight, directing that an authorization package’s security assessment “shall be presumed adequate” for reuse by another agency — a presumption an agency may overcome only on a demonstrable need.

Common questions

Questions firms ask.

Does software we run on our own servers need FedRAMP?

Generally no. FedRAMP certifies cloud service offerings — packaged products a provider supplies to customers. Software you buy and operate on your own infrastructure is not a cloud service offering being sold to the government, so there is nothing for FedRAMP to certify. Your agency’s own system still carries its FISMA and NIST SP 800-53 obligations, and those do not go away.

Can one agency rely on another agency’s FedRAMP package?

Largely, yes — that is the point of the statutory presumption of adequacy. Once an offering is certified at a given FIPS 199 impact level, another agency is to presume the assessment adequate for its own authorization to operate at or below that level. The agency still issues its own authorization, and may add requirements where it documents a demonstrable need.

Is StateRAMP still called StateRAMP?

StateRAMP announced a rebrand to GovRAMP in 2025, reflecting state, local, tribal, and education participation; the original legal entity name was retained while the organization operates under the GovRAMP brand. It is an independent nonprofit, not a government program, and its verification tiers build on NIST SP 800-53 controls. Requirements are set by the buying jurisdiction, so check the specific solicitation.

Modern software, kept inside your walls.

Tell us about your organization and the data you need to protect. We’ll help you put capable, modern tools to work on a private system we ship, install, and support — with nothing ever leaving your network.