Skip to main content

Authorization paths

A cloud service earns FedRAMP authorization through an agency sponsor. Here's how that works, how it has changed, and what "FedRAMP Authorized" actually means.

What an authorization is

A FedRAMP authorization is a formal decision that a cloud service's security risk is acceptable for federal use. The core artifact is an Authorization to Operate (ATO) — a signed statement from an agency official accepting the risk of using the system.

The main path: Agency authorization

The primary route to FedRAMP authorization is the Agency ATO path:

  1. A cloud service provider (CSP) partners with a federal agency that wants to use the service.
  2. The CSP completes the full FedRAMP security assessment with an accredited third-party assessor (a 3PAO).
  3. The sponsoring agency's Authorizing Official (AO) reviews the security package and, if satisfied, issues an ATO.
  4. The completed package is added to the FedRAMP Marketplace, where other agencies can review and reuse it to grant their own ATOs.

Because the assessment is standardized, a service authorized by one agency can be adopted by others without starting over — the "do once, use many times" model in action.

From the JAB to the FedRAMP Board

Historically, FedRAMP also offered a JAB Provisional ATO (P-ATO), granted by the Joint Authorization Board — the CIOs of DoD, DHS, and GSA. The FedRAMP Authorization Act of 2022 replaced the JAB with the FedRAMP Board, and the program has since centered on the agency authorization path. Governance details continue to evolve — confirm the current model on fedramp.gov.

FedRAMP Ready and In Process

Authorization is a journey, and the Marketplace reflects several designations along the way:

Common Marketplace designations for cloud services
DesignationWhat it means
FedRAMP ReadyA 3PAO has attested, via a Readiness Assessment Report (RAR), that the service is likely to achieve authorization. An optional but common starting point.
FedRAMP In ProcessThe service is actively pursuing authorization with an agency sponsor and is undergoing full assessment.
FedRAMP AuthorizedThe service has a completed security package and an active ATO. Other agencies can reuse the package.

Modernization: FedRAMP 20x

FedRAMP has been pursuing a major modernization effort — often referred to as FedRAMP 20x — aimed at making authorization faster and more automated, with a stronger emphasis on machine-readable security data and continuous validation rather than point-in-time paperwork. If you are planning a real authorization, check the latest guidance, because the specifics of these newer pathways are changing.

Reciprocity and reuse

Once a service is authorized, its package can be reused:

  • Agency reuse — another agency reviews the existing package and issues its own ATO, rather than commissioning a new assessment.
  • DoD and other frameworks — the Department of Defense layers additional requirements (Impact Levels 4/5/6 under its Cloud Computing SRG) on top of FedRAMP. A FedRAMP authorization is often a prerequisite, not a replacement.

Where to go next