Roles & responsibilities
FedRAMP works because several parties each play a distinct role — the provider being assessed, the independent assessor, the agency accepting the risk, and the bodies that govern the program.
The parties involved
At a glance
- CSP — builds and operates the cloud service being authorized.
- 3PAO — independently tests the service's security.
- Agency — sponsors and accepts the risk via an ATO.
- PMO — runs the program day to day.
- FedRAMP Board — provides governance and direction.
- NIST — authors the underlying standards.
Cloud Service Provider (CSP)
The company that owns and operates the cloud service seeking authorization. The CSP is responsible for:
- Implementing the required security controls.
- Documenting them in the System Security Plan (SSP).
- Remediating findings and maintaining the POA&M.
- Running continuous monitoring once authorized.
Third-Party Assessment Organization (3PAO)
An independent, accredited assessor that tests whether the CSP's controls actually work. 3PAOs are accredited under a recognized program (via the American Association for Laboratory Accreditation, A2LA) to ensure they meet FedRAMP's competence and independence standards. The 3PAO produces the RAR, SAP, and SAR.
Independence matters: the 3PAO must not be the same party that built the system, so the assessment is objective.
Federal agency & the Authorizing Official (AO)
The agency that wants to use the service is the sponsor. Within it, the Authorizing Official (AO) is the senior official who reviews the security package, weighs the residual risk, and signs the Authorization to Operate (ATO). Without an agency sponsor and an AO's signature, there is no authorization.
FedRAMP Program Management Office (PMO)
Housed within the General Services Administration (GSA), the PMO runs FedRAMP day to day:
- Maintains templates, baselines, and guidance.
- Operates the FedRAMP Marketplace and the secure repository of packages.
- Supports agencies, CSPs, and 3PAOs through the process.
The FedRAMP Board
Established by the FedRAMP Authorization Act of 2022 (replacing the former Joint Authorization Board), the FedRAMP Board provides governance and strategic direction — setting priorities, guiding policy, and overseeing the program's evolution.
NIST
The National Institute of Standards and Technology doesn't run FedRAMP, but it writes the standards FedRAMP depends on — FIPS 199, SP 800-53 (the control catalog), and SP 800-37 (the Risk Management Framework).
Who does what, by stage
| Stage | Lead |
|---|---|
| Document the system (SSP) | CSP |
| Independent assessment (SAR) | 3PAO |
| Authorization decision (ATO) | Agency / AO |
| Continuous monitoring | CSP (reviewed by agency) |
| Program governance | PMO & FedRAMP Board |
Where to go next
- The process — how these roles interact step by step.
- Authorization paths — how the authorization decision is structured.