Skip to content

FedRAMP

What is FedRAMP?

The Federal Risk and Authorization Management Program, a US government programme that standardises security assessment and authorisation for cloud services used by federal agencies.

Cloud

What the standards actually require on fedramp

Requirements naming fedramp across 6 standards, quoted from the control text.

FedRAMP Rev 512 controls

FedRAMP defines four baselines based on FIPS 199 system impact level: (a) LI-SAAS (Low Impact SaaS) - low-impact SaaS with no sensitive data + 156 controls + accelerated authorization path; (b) LOW (Low Impact) - 156 controls;

FedRAMP-Baselines · FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters
FISMA4 controls

FISMA + FedRAMP coordination for cloud services. FEDRAMP (Federal Risk and Authorization Management Program) operationalizes FISMA for CLOUD SERVICES used by federal agencies (established by OMB Memorandum M-11-30 + modernized by M-24-15 of July 2024).

FISMA-FedRAMP-Cloud-Coordination · FedRAMP for Cloud Services + 800-37 ATO Integration
MARS-E3 controls

Coordinate MARS-E compliance with adjacent federal programmes and audit regimes. IRS Publication 1075 (Safeguarding Federal Tax Information) compliance for Federal Tax Information (FTI) processing under IRC Section 6103 + Safeguard Procedures Report (SPR) ever...

MARS-E-Cross-Program-Coordination-IRS-Pub-1075-FedRAMP-CMS-ARS-HHS-OIG-Joint-Audit-3PAO · MARS-E Cross-Program + IRS Pub 1075 + FedRAMP + CMS ARS + HHS OIG + Joint Audit + 3PAO
ISMAP (Japan)2 controls

ISMAP Assessment positions ISMAP within the comprehensive Japanese and international cloud security regulatory landscape. (1) External Assessment by ISMAP-Approved Auditor: CSP must undergo annual third-party assessment by ISMAP-approved audit organisation inc...

ISMAP-Assessment-ExternalAuditor-AnnualReview-CustomerTransparency-Coord-FedRAMP-IRAP-GCloud-PIPA-ISO27017 · ISMAP Assessment - External ISMAP-Approved Auditor + Annual Review + Customer Information and Transparency + Coordination FedRAMP/UK G-Cloud/Australia IRAP/Singapore MTCS + ISO 27017 + PIPA + Japan Digital Agency
FedRAMP High110 controls

Detect network services not authorized; audit or alert FedRAMP-defined personnel.

SI-4(22) · Unauthorized Network Services

Questions people ask about fedramp

What is FedRAMP?
The Federal Risk and Authorization Management Program, a US government programme that standardises security assessment and authorisation for cloud services used by federal agencies.
Why is FedRAMP important for compliance?
FedRAMP is a key concept in Cloud. Understanding fedramp helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to FedRAMP?
Key concepts related to FedRAMP include Cloud Security. Understanding these interconnected concepts provides a more comprehensive view of Cloud requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address FedRAMP?
FedRAMP appears in the requirement text of FedRAMP Rev 5, IRS Publication 1075, FISMA, MARS-E, ISMAP (Japan). Across these standards we have identified 136 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about FedRAMP?
Explore our compliance framework pages to see how fedramp applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how FedRAMP applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.