Understand FedRAMP: An informational guide to the Federal Risk and Authorization Management Program
A plain-language guide to how cloud services earn the security authorization required to be used across the U.S. federal government.
Start with the basics Search the docsExplore the documentation
New to FedRAMP? These sections walk from the big picture down to the details of getting a cloud service authorized.
-
What is FedRAMP?
The program, why it exists, and the "do once, use many times" idea behind it.
-
Authorization paths
How a cloud service gets its authorization, and who grants it.
-
Impact levels
Low, Moderate, and High — how systems are categorized and what changes.
-
The process
From readiness through assessment, authorization, and continuous monitoring.
-
Roles & responsibilities
Cloud providers, assessors, agencies, the PMO, and the FedRAMP Board.
-
FAQ & resources
Common questions, key documents, and links to official material.
-
Contact
Reach the maintainers, or find official FedRAMP support channels.
A quick definition
FedRAMP — the Federal Risk and Authorization Management Program — is a government-wide program that standardizes how the security of cloud products and services is assessed, authorized, and continuously monitored so agencies can adopt them with confidence.
Learn more