code/+/trust primary logo full color svg

FedRAMP

Definition

FedRAMP is the U.S. government's standardized security authorization program for cloud services used by federal agencies, reusable across agencies once granted.

Before FedRAMP, every federal agency independently assessed cloud vendors -- the same vendor might conduct 50 separate security assessments for 50 agencies. FedRAMP establishes a "authorize once, use many" model: one authorization from a Sponsoring Agency or the JAB (Joint Authorization Board) is recognized across all federal agencies.

FedRAMP authorization levels

  • Low -- systems where breach impact is limited; rare for cloud services
  • Moderate -- covers most civilian agency use cases; 325 security controls
  • High -- law enforcement, financial, health data; 421 controls; highest cost and effort

FedRAMP authorization paths

Agency-sponsored path: a federal agency agrees to sponsor your authorization. JAB path (FedRAMP Connect): compete for a slot on the JAB prioritization list. Agency path is faster if you have a federal customer willing to sponsor. The 3PAO (Third Party Assessment Organization) conducts the independent security assessment regardless of path.

Related terms

See how we implement this

Need help implementing this in your business?

Code and Trust translates AI concepts like fedramp into working implementations, starting with a workflow audit that shows exactly where it creates ROI.

Schedule AI Audit →