Page Info
Description: Welcome to providers and a general overview of the expectations for FedRAMP and how to navigate this entire section.
Purpose: Providers will know how to navigate the consolidated rules for 2026.
Cloud Service Providers¶
FedRAMP is a security framework for businesses to set security goals for themselves, continuously validate the effectiveness of the capabilities used to meet those goals, measure their performance against those goals, and ensure security and engineering teams have the resources necessary to meet those goals. It should not be treated like a traditional compliance framework.
To be listed in the FedRAMP Marketplace and qualify for FedRAMP Certification, cloud services must have one of the following government-wide use cases:
-
Direct Government-Wide Use: The service will be used directly by multiple federal agency customers for integration into federal information systems that fall within the scope of 44 USC ยง 3506.
-
Indirect Government-Wide Use: The service will be used as a third-party information resource in other cloud services that have direct government-wide use.
FedRAMP does not apply to services used by the Defense Industrial Base.
The Department of War established the Cybersecurity Maturity Model Certification (CMMC) to enhance cybersecurity protections for sensitive unclassified information within the Defense Industrial Base (DIB). CMMC requirements apply to private companies that do business with the Department of War and establishes requirements that are only relevant to the Department of War.
All questions about "FedRAMP Equivalency" or the application of FedRAMP Certification requirements for CMMC should be directed to the Department of War. FedRAMP does not support the Certification of services for this use case in any way.
-
First time?
Learn where to start, how to find an advisor, choose a certification profile, and start your journey.
-
Previously "authorized?"
Things are changing and you'll need to do things differently from here on out.
-
FedRAMP 20x Rules!
Dig into the approach and expectations for FedRAMP 20x, a new cloud-native approach that encourages cloud services to demonstrate the outcomes of their security decisions using automation.
-
FedRAMP Rev5
Learn more about the newly balanced and modernized FedRAMP Rev5 approach for cloud services that run their own infrastructure or will be used for the most mission-critical government services where the risk of catastrophic harm must be mitigated.