Skip to main content

Roles & responsibilities

FedRAMP works because several parties each play a distinct role — the provider being assessed, the independent assessor, the agency accepting the risk, and the bodies that govern the program.

The parties involved

At a glance

  • CSP — builds and operates the cloud service being authorized.
  • 3PAO — independently tests the service's security.
  • Agency — sponsors and accepts the risk via an ATO.
  • PMO — runs the program day to day.
  • FedRAMP Board — provides governance and direction.
  • NIST — authors the underlying standards.

Cloud Service Provider (CSP)

The company that owns and operates the cloud service seeking authorization. The CSP is responsible for:

  • Implementing the required security controls.
  • Documenting them in the System Security Plan (SSP).
  • Remediating findings and maintaining the POA&M.
  • Running continuous monitoring once authorized.

Third-Party Assessment Organization (3PAO)

An independent, accredited assessor that tests whether the CSP's controls actually work. 3PAOs are accredited under a recognized program (via the American Association for Laboratory Accreditation, A2LA) to ensure they meet FedRAMP's competence and independence standards. The 3PAO produces the RAR, SAP, and SAR.

Independence matters: the 3PAO must not be the same party that built the system, so the assessment is objective.

Federal agency & the Authorizing Official (AO)

The agency that wants to use the service is the sponsor. Within it, the Authorizing Official (AO) is the senior official who reviews the security package, weighs the residual risk, and signs the Authorization to Operate (ATO). Without an agency sponsor and an AO's signature, there is no authorization.

FedRAMP Program Management Office (PMO)

Housed within the General Services Administration (GSA), the PMO runs FedRAMP day to day:

  • Maintains templates, baselines, and guidance.
  • Operates the FedRAMP Marketplace and the secure repository of packages.
  • Supports agencies, CSPs, and 3PAOs through the process.

The FedRAMP Board

Established by the FedRAMP Authorization Act of 2022 (replacing the former Joint Authorization Board), the FedRAMP Board provides governance and strategic direction — setting priorities, guiding policy, and overseeing the program's evolution.

NIST

The National Institute of Standards and Technology doesn't run FedRAMP, but it writes the standards FedRAMP depends on — FIPS 199, SP 800-53 (the control catalog), and SP 800-37 (the Risk Management Framework).

Who does what, by stage

Primary responsibility across the lifecycle
StageLead
Document the system (SSP)CSP
Independent assessment (SAR)3PAO
Authorization decision (ATO)Agency / AO
Continuous monitoringCSP (reviewed by agency)
Program governancePMO & FedRAMP Board

Where to go next