Skip to main content

The process

Getting authorized is a lifecycle, not a one-time test. It runs from readiness, through a full assessment and authorization decision, into ongoing continuous monitoring.

The lifecycle at a glance

  1. Preparation & readiness

    The cloud service provider (CSP) documents its system and, optionally, works with a 3PAO to produce a Readiness Assessment Report (RAR). A successful RAR earns the FedRAMP Ready designation and signals the service is a strong candidate for authorization.

  2. Full security assessment

    The CSP writes a detailed System Security Plan (SSP) describing how it meets every control in its baseline. An independent, accredited 3PAO then tests the system against a Security Assessment Plan (SAP) and documents the results in a Security Assessment Report (SAR).

  3. Authorization decision

    The agency's Authorizing Official reviews the complete package — SSP, SAR, and a Plan of Action & Milestones (POA&M) for any open findings — and weighs the residual risk. If acceptable, they issue an Authorization to Operate (ATO).

  4. Continuous monitoring (ConMon)

    Authorization is not the finish line. The CSP continuously monitors its security posture — submitting monthly vulnerability scans, keeping the POA&M current, reporting incidents, and undergoing an annual assessment — so the authorization stays valid over time.

The key documents

Core artifacts in a FedRAMP security package
DocumentPurposeWho produces it
RAR Readiness Assessment Report — early attestation that the service can likely be authorized. 3PAO
SSP System Security Plan — the detailed description of how each control is implemented. CSP
SAP Security Assessment Plan — the methodology and scope for testing the system. 3PAO
SAR Security Assessment Report — the findings from the independent assessment. 3PAO
POA&M Plan of Action & Milestones — the tracked plan to remediate open findings. CSP

How long it takes

There's no single answer. A well-prepared service with an engaged agency sponsor might move through assessment in several months; less-prepared efforts can take much longer. The biggest accelerators are:

  • Strong documentation — a clear, complete SSP saves enormous back-and-forth.
  • An engaged agency sponsor — the authorization can't be issued without one.
  • A mature security posture — fewer open findings means a faster decision.

FedRAMP's modernization work (FedRAMP 20x) aims to compress these timelines by automating evidence collection and validation.

Where to go next