Glossary

FedRAMP

FedRAMP is the US federal government’s standardized program for authorizing cloud services: assess once against NIST 800-53 baselines, reuse the authorization across agencies. If you sell cloud software to federal agencies, FedRAMP authorization isn’t a differentiator — it’s the entry ticket.

What it takes, honestly

FedRAMP is a different weight class from commercial compliance: hundreds of controls at the Moderate baseline, a third-party assessment organization (3PAO), continuous monitoring with monthly deliverables, and a documentation corpus measured in hundreds of pages. Traditional timelines ran a year-plus and seven figures all-in; the program’s recent modernization (FedRAMP 20x) is working to compress that with automation-first assessment, and newer entrants have moved faster — but “fast” remains relative.

The strategic question

FedRAMP makes sense when federal revenue justifies a program, not a project — the continuous-monitoring obligations are permanent operating cost. Common intermediate steps: selling through a FedRAMP-authorized platform’s marketplace, targeting agencies via authorized resellers, or starting with CMMC-adjacent defense contractors where the bar is 800-171, not full FedRAMP.

Where your commercial program helps

A mature SOC 2/ISO control set with clean evidence discipline is the right launching point — the control overlap is substantial, and the evidence-automation habits transfer directly. What doesn’t transfer is the documentation depth; budget for that as its own workstream.

Related Terms

CMMC — CMMC is the DoD's cybersecurity certification for contractors — three levels, anchored to NIST 800-171, now appearing in defense contracts and flow-downs.

CUI (Controlled Unclassified Information) — CUI is US government information that's sensitive but not classified — export data, defense technical data, and more. Handling it triggers NIST 800-171 and CMMC.

NIST 800-53 — NIST 800-53 is the US government's control catalog — hundreds of controls across 20 families — underlying FedRAMP, FISMA, and federal procurement.