Authorization program · Last verified

Federal Risk and Authorization Management Program

FedRAMP is the U.S. federal cloud authorization program run by GSA under the FedRAMP Authorization Act — agencies grant authorizations, not certificates. It was established by Public Law 117-263 in December 2022, and cloud providers are assessed by third-party assessment organizations.

Class
Authorization program
Owner
U.S. General Services Administration (GSA)
Who asks for it
Public procurement
Public register
Not confirmed at our last check
Last verified

What it is

FedRAMP is a U.S. government authorization program, not a commercial certification scheme. It was established on 23 December 2022 by Section 5921 of Public Law 117-263, which added sections 3607–3616 to chapter 36 of title 44 of the United States Code; the statute states, "This section may be cited as the FedRAMP Authorization Act," and names the program in section 3608 as the "Federal Risk and Authorization Management Program".

A note on terminology: FedRAMP's own website currently mixes two words. The statute and the process language say authorization ("cloud security assessment and authorization"; providers "received pilot authorizations"), while the homepage counters and product names say certified ("Total FedRAMP Certified Services"; "Class A Certifications"). This page uses the statutory term and quotes the owner's wording where it differs.

Who owns it

The program is run by the U.S. General Services Administration (GSA) under the FedRAMP Authorization Act (44 U.S.C. §§ 3607–3616).

Who assesses it

FedRAMP's homepage uses the phrase "FedRAMP recognized assessors" for the assessment side, and its 20x material describes independent assessments performed by third-party assessment organizations (3PAOs). How 3PAO recognition itself is run was not verified in the sources reviewed as of 29 August 2026.

Levels

  • Class A (Pilot) — "Class A Certifications are for cloud services with mature security and compliance programs that are looking to enter the federal marketplace." (fedramp.gov/20x, 29 August 2026)
  • Class B (Low) — "Class B Certifications are for cloud services that provide fairly common small-scale or light use services." (fedramp.gov/20x, 29 August 2026)
  • Class C (Moderate) — "Class C Certifications are for cloud services that provide common enterprise services that are likely to be used in systems across an entire agency or that provide important government services." (fedramp.gov/20x, 29 August 2026)

Who asks for it

Federal agencies buying cloud services are the demand side: the Marketplace lists "FedRAMP certified cloud services, authorizing agencies, and FedRAMP recognized assessors". The program's reach is federal procurement, not the wider economy — no obligation on non-federal buyers was identified in the sources reviewed as of 29 August 2026; confirm against GSA/OMB guidance.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Federal Risk and Authorization Management Program." Certifidex, FutureTechnologies. Last verified 29 August 2026. https://certifidex.com/frameworks/fedramp

All frameworks & audits →