Back to Frameworks
Industry

FedRAMP

FedRAMP standardizes how cloud service providers get authorized to handle US federal government data, so each agency doesn't have to run its own security assessment from scratch.

It's built on the NIST 800-53 control catalog at Low, Moderate, or High impact levels, and authorization comes either through a sponsoring agency (an Agency Authorization) or the Joint Authorization Board (a JAB Provisional Authorization), followed by continuous monitoring obligations.

See how LumiGRC handles FedRAMP

Get a Demo
3

Impact levels

0%
Typical certification profile
Audit Rigor67%
Time to Certify69%
Surveillance Burden65%
Issued & Enforced By

GSA / FedRAMP PMO

FedRAMP, built on NIST SP 800-53

Key Points

  • Built on the NIST 800-53 control catalog
  • Low / Moderate / High impact authorization levels
  • Agency or JAB-sponsored authorization path
  • A prerequisite for selling cloud services to US federal agencies