Authorization program · Last verified
Federal Risk and Authorization Management Program
FedRAMP is the U.S. federal cloud authorization program run by GSA under the FedRAMP Authorization Act — agencies grant authorizations, not certificates. It was established by Public Law 117-263 in December 2022, and cloud providers are assessed by third-party assessment organizations.
- Class
- Authorization program
- Owner
- U.S. General Services Administration (GSA)
- Who asks for it
- Public procurement
- Public register
- Not confirmed at our last check
- Last verified
What it is
FedRAMP is a U.S. government authorization program, not a commercial certification scheme. It was established on 23 December 2022 by Section 5921 of Public Law 117-263, which added sections 3607–3616 to chapter 36 of title 44 of the United States Code; the statute states, "This section may be cited as the FedRAMP Authorization Act," and names the program in section 3608 as the "Federal Risk and Authorization Management Program".
A note on terminology: FedRAMP's own website currently mixes two words. The statute and the process language say authorization ("cloud security assessment and authorization"; providers "received pilot authorizations"), while the homepage counters and product names say certified ("Total FedRAMP Certified Services"; "Class A Certifications"). This page uses the statutory term and quotes the owner's wording where it differs.
Who owns it
The program is run by the U.S. General Services Administration (GSA) under the FedRAMP Authorization Act (44 U.S.C. §§ 3607–3616).
Who assesses it
FedRAMP's homepage uses the phrase "FedRAMP recognized assessors" for the assessment side, and its 20x material describes independent assessments performed by third-party assessment organizations (3PAOs). How 3PAO recognition itself is run was not verified in the sources reviewed as of 29 August 2026.
Levels
- Class A (Pilot) —
"Class A Certifications are for cloud services with mature security and compliance programs that are looking to enter the federal marketplace." (fedramp.gov/20x, 29 August 2026)
- Class B (Low) —
"Class B Certifications are for cloud services that provide fairly common small-scale or light use services." (fedramp.gov/20x, 29 August 2026)
- Class C (Moderate) —
"Class C Certifications are for cloud services that provide common enterprise services that are likely to be used in systems across an entire agency or that provide important government services." (fedramp.gov/20x, 29 August 2026)
Who asks for it
Federal agencies buying cloud services are the demand side: the Marketplace lists "FedRAMP certified cloud services, authorizing agencies, and FedRAMP recognized assessors". The program's reach is federal procurement, not the wider economy — no obligation on non-federal buyers was identified in the sources reviewed as of 29 August 2026; confirm against GSA/OMB guidance.
Sources
- FedRAMP — statutory authority (GSA) ↗ — accessed
- FedRAMP — homepage (Marketplace definition and the owner's "certified" wording) ↗ — accessed
- FedRAMP 20x (Class A/B/C, Rev5 closing date) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.