FedRAMP standardizes how cloud service providers get authorized to handle US federal government data, so each agency doesn't have to run its own security assessment from scratch.
It's built on the NIST 800-53 control catalog at Low, Moderate, or High impact levels, and authorization comes either through a sponsoring agency (an Agency Authorization) or the Joint Authorization Board (a JAB Provisional Authorization), followed by continuous monitoring obligations.
Impact levels
GSA / FedRAMP PMO
FedRAMP, built on NIST SP 800-53