A U.S. federal compliance program standardizing security assessment, authorization, and continuous monitoring for cloud products and services.
For a government agency, using a FedRAMP moderate-authorized service ensures that the vendor meets a standardized level of security that has already been vetted. For a business, achieving this status is essentially the "gold standard" requirement to sell software or cloud services to federal civilian agencies.
Perform a gap assessment of our current processes against the requirements of FedRAMP Moderate (underway).
Develop a remediation plan and implement to address any gaps.
Undergo an audit to verify compliance with FedRAMP, target is late 2027.
FedRAMP Moderate is one of the three security impact levels defined by the Federal Risk and Authorization Management Program (FedRAMP). It is the most common authorization level for Cloud Service Providers (CSPs) seeking to do business with the U.S. federal government, as it covers approximately 80% of current cloud service applications.
The "Moderate" impact level is designated for systems where a security breach would result in serious (but not catastrophic) harm. This typically involves:
To achieve a FedRAMP Moderate authorization, a service provider must implement a baseline of security controls derived from NIST Special Publication 800-53.
The program uses a "low-moderate-high" scale to match security rigor with the sensitivity of the data being hosted: