Start with Identity
← Glossary
Compliance

FedRAMP

Federal Risk and Authorization Management Program. The US government cloud services authorization framework. Levels: Low, Moderate, High. Required for SaaS used by federal agencies. Authorization timelines run 12-24 months.

FedRAMP is a market gate more than a security ceiling: it determines which identity vendors a federal agency can buy at all, which is why the authorized list is much shorter than the vendor landscape. Authorization timelines measured in months to years also shape the product, because vendors freeze the authorized boundary and ship new capability outside it. Check what is actually in the boundary, not just that the vendor holds an authorization.

See also: compliance guides, SOC 2, NIST 800-63, identity for government article

Last reviewed By SWI Community TeamSuggest a correctionHow we research