Skip to main content

Understand FedRAMP: An informational guide to the Federal Risk and Authorization Management Program

A plain-language guide to how cloud services earn the security authorization required to be used across the U.S. federal government.

Start with the basics Search the docs

Explore the documentation

New to FedRAMP? These sections walk from the big picture down to the details of getting a cloud service authorized.

  • What is FedRAMP?

    The program, why it exists, and the "do once, use many times" idea behind it.

  • Authorization paths

    How a cloud service gets its authorization, and who grants it.

  • Impact levels

    Low, Moderate, and High — how systems are categorized and what changes.

  • The process

    From readiness through assessment, authorization, and continuous monitoring.

  • Roles & responsibilities

    Cloud providers, assessors, agencies, the PMO, and the FedRAMP Board.

  • FAQ & resources

    Common questions, key documents, and links to official material.

  • Contact

    Reach the maintainers, or find official FedRAMP support channels.

A quick definition

FedRAMP — the Federal Risk and Authorization Management Program — is a government-wide program that standardizes how the security of cloud products and services is assessed, authorized, and continuously monitored so agencies can adopt them with confidence.

Learn more