U.S. flag

An official website of the United States government

Requests for Comment

RFC-0032 Offerings By Government

Summary

Cloud service offerings that are provided by federal government agencies as a shared service for use by other federal agencies are different from cloud service offerings provided by private companies: they are subject to all statutory and policy requirements for federal information systems and must receive an agency authorization to operate following agency-specific requirements.

The FedRAMP Certification process is designed to establish a standardized process for commercial cloud services operated by private companies to provide agencies with sufficient information to make risk-based decisions when using the cloud service. This process is generally unnecessary for a cloud service that is operated by a federal agency under existing federal requirements.

The Offerings By Government ruleset allows cloud service offerings that are overseen by federal authorizing officials to obtain a FedRAMP Certification following their own agency process without needing to adopt all FedRAMP rules that are designed for private companies. This pathway allows FedRAMP to rely on the authorization, assessment, and ongoing oversight performed by the Agency Provider while preserving the minimum government-wide information and activities necessary to support reuse by customer agencies.

These rules do not constitute a government-wide authorization to operate. Each customer agency remains responsible for determining whether the cloud service offering is appropriate for its use and for authorizing the federal information systems in which the offering will be used.


Applicability

These rules apply to a cloud service offering when:

  1. The cloud service offering is operated by a federal agency;
  2. The offering is made available for direct use by one or more other federal agencies;
  3. The operating agency maintains responsibility for the security, privacy, assessment, their own authorization, and ongoing monitoring of the offering; and
  4. The responsible Agency Authorizing Official (AO) formally requests use of the Offerings by Government pathway.

For purposes of this ruleset, an Agency Provider is a federal agency responsible for operating a cloud service offering that is made available for use by other federal agencies.


General FedRAMP Responsibilities

These rules apply to FedRAMP for granting FedRAMP Certification to cloud services provided by agencies.

OBG-FRP-ELG - Offerings by Government Eligibility

FedRAMP MUST apply the Offerings by Government rules only when the responsible Agency Authorizing Official (AO) confirms through official government channels that the cloud service offering meets the applicability requirements of this ruleset.

OBG-FRP-EFR Exemption from FedRAMP Rules

FedRAMP MUST exempt agency providers from FedRAMP Rules except those in the Offerings By Government ruleset if requested by an agency Authorizing Official during an application for FedRAMP Certification of an agency provided cloud service offering.

OBG-FRP-CLS FedRAMP Certification Class Mapping

FedRAMP MUST grant FedRAMP Certification at the appropriate agency requested Certification Class UNLESS the request exceeds the FIPS-200 Information System Impact Level in the agency authorization to operate, as follows:

  1. Low Impact ATO: Class B
  2. Moderate Impact ATO: Class C
  3. High Impact ATO: Class D

OBG-FRP-DEC - Certification Decision

FedRAMP MUST review the Offerings by Government Certification Package for completeness and grant FedRAMP Certification when:

  1. The Agency Provider meets the eligible requirements;
  2. The agency Authorization to Operate is current and active;
  3. The package contains the minimum information required by this ruleset; and
  4. The package is available to FedRAMP and customer agencies

General Agency Provider Responsibilities

These rules apply to federal agencies providing cloud services to other federal agencies who wish to obtain or maintain FedRAMP Certification.

OBG-AGP-ATO Authorization to Operate

Agency Providers MUST obtain and maintain an agency authorization to operate for the service offering.

OBG-AGP-NAS Notification of Authorization Status

Agency Providers MUST notify FedRAMP and customer agencies promptly when the agency authorization to operate is:

  1. Allowed to expire;
  2. Suspended;
  3. Revoked;
  4. Replaced by an interim authorization;
  5. Subject to new material conditions; or
  6. Otherwise no longer sufficient to support the existing FedRAMP Certification

OBG-AGP-CPO Certification Package Overview

Agency Providers MUST supply an Agency Certification Package, using any format determined appropriate by the agency, that includes at least the following information:

  1. Agency Authorization to Operate letter that includes the FIPS-199 Information System Impact Level
  2. Agency System Security Plan
  3. Agency Plans of Action & Milestones
  4. Agency Privacy Threshold or Impact Assessment
  5. Agency Security Assessment

OBG-AGP-MKT Marketplace Listing

Agency Providers MUST supply the necessary information required by CDS-CSO-PUB to maintain a listing in the FedRAMP Marketplace.

OBG-AGP-CCM Collaborative Continuous Monitoring

Agency Providers SHOULD establish at least quarterly collaborative continuous monitoring meetings to review ongoing security decisions and risks with their customer agencies.

OBG-AGP-UTC Use of Trust Centers

Agency Providers MAY use any appropriate trust center or similar sharing mechanism to make the Agency Certification Package available to agency customers and FedRAMP.