Skip to content
Sunday, August 23, 2026
Engevity NewsScience & health
Research · Learning · Evidence
Science News

FedRAMP: How a Cloud Service Gets Federal Authorization

The certification is central; the authority to operate is not. A step-by-step look at what a FedRAMP package proves, what the statute obliges agencies to reuse, and where the process still stalls.

FedRAMP: How a Cloud Service Gets Federal Authorization

A FedRAMP authorization does not, by itself, put a cloud service inside a federal agency. It certifies a security assessment that agencies must then treat as a starting point: under 44 U.S.C. § 3613(e)(1), the assessment of security controls in a FedRAMP authorization package "shall be presumed adequate" for an agency's own authorization to operate. The agency still signs the ATO.

What does a FedRAMP authorization actually certify?

It certifies the provider's security package — not any particular agency's use of it. The package documents how a cloud service implements a control baseline, assessed by a third party and reviewed centrally. What it does not cover is the configuration an agency selects, the identity integration it wires up, the logging it turns on, or the data it decides to put inside the boundary.

That gap is where most program offices lose time. FedRAMP's published guidance for agencies is blunt about the sequencing: "Do not begin by copying a provider's security controls!" Agencies are told to categorize their own system under FIPS 199 and FIPS 200, select controls from NIST SP 800-53B, and only then compare certified services against that list, checking service boundaries and assessment results against the agency's own risk tolerance. Read in reverse — picking the product first, then reverse-engineering the paperwork — the process produces an authorization that describes the vendor rather than the system the agency is actually running.

Why does the presumption of adequacy matter?

Because it moves the burden of proof. Reuse of cloud security assessments was federal policy for a decade before it was federal law; the FedRAMP Authorization Act, codified at 44 U.S.C. § 3613, made it a statutory duty. Agencies must check the governmental mechanism for an existing authorization "before beginning the process of granting a FedRAMP authorization," and must use existing assessment materials "to the extent practicable."

The presumption is a floor, not a ceiling. Section 3613(e)(2) preserves an agency's authority to impose additional controls where there is "a demonstrable need for additional security requirements beyond the security requirements included in a FedRAMP authorization." That clause is where reuse quietly erodes. An agency that layers on its own overlay is back to bespoke assessment work — the exact cost the reuse duty was written to avoid — and the statute does not require it to defend the overlay to anyone outside its own risk executive. The incentive runs one way: no security officer is ever criticized for adding a control.

How does an agency authorization actually run?

In five published steps, and only the last one produces the signature. The sequence below is FedRAMP's own process for an initial agency authorization; the artifacts named in it — system security plan, assessment reports, plan of action and milestones — are the deliverables a program office will be asked for.

  1. Define the use and the required protections. Describe the work, the users, and the federal information involved; categorize the system under FIPS 199 and FIPS 200; select controls from NIST SP 800-53B.
  2. Compare certified services. Review certification packages against the business need, checking service boundaries, security capabilities, and assessment results.
  3. Confirm the provider supports the planned implementation. Read the provider's secure configuration guide and verify identity integration, logging, administrative controls, and data protection settings. FedRAMP's guidance recommends a limited pilot "when it will reduce uncertainty."
  4. Configure and assess the agency's use. Implement the service, the agency's own controls, and the integrations; test functionality; document it in the agency system security plan.
  5. Authorize the agency system. Complete assessment reports and risk documentation, then issue an authorization that identifies approved use, information, boundary, required configurations, restrictions, and conditions for continued use. Notify FedRAMP and begin ongoing monitoring.

One durable constraint sits inside step five: FedRAMP advises agencies not to authorize a Class A certified service for more than 12 months unless the provider is pursuing a higher certification. That is a renewal clock, and it starts at authorization, not at procurement award.

Where does the process stall?

At sponsorship and at compliance drift, according to the last comprehensive federal audit of the program. In GAO-24-106591, published January 18, 2024, the Government Accountability Office found that the 24 CFO Act agencies increased their number of authorizations by about 60 percent between July 2019 and April 2023 — while nine agencies reported using cloud services that were not FedRAMP-authorized, contrary to OMB requirements.

GAO made three recommendations: two to the Office of Management and Budget, including that it ensure agencies consistently track and report the costs of sponsoring an authorization and that it finalize and implement proposed new FedRAMP guidance, and one to the General Services Administration on cryptographic requirements. GAO recorded all three as closed and implemented by July 2024.

The cost-tracking finding names the structural problem plainly. A traditional agency authorization requires a sponsor — a specific agency willing to spend staff time and assessment money so that a service enters the marketplace every other agency can then reuse. The benefit is governmentwide; the bill is not. That asymmetry, more than any single vendor's readiness, is what historically set the queue length.

What did FedRAMP 20x change?

It changed what gets assessed, not who signs. FedRAMP 20x replaces long narrative control documentation with key security indicators that, in the program's framing, "can demonstrate security posture in near real time, replacing static yearly manual assessments," and sorts providers into certification classes rather than a single path. The agency ATO obligation is untouched; what shrinks is the package the agency inherits and the interval at which it is refreshed.

The rollout has been staged as a series of pilots rather than a cutover:

PhaseWindowScope
Phase OneApr–Sep 2025Low baseline pilot; 26 submissions
Phase TwoNov 2025–Mar 2026Moderate baseline pilot; 14 submissions
Phase ThreeJul–Sep 2026Formalizing rules, opening the submission pipeline
Phase FourFY27 Q1–Q2 (estimated)Class D pilot
Phase FiveFY27 Q3–Q4 (estimated)Rev5 sunset

The program's own throughput claims are worth reading as claims. GSA announced on August 11, 2025 that "In July, FedRAMP reached a record 114 authorizations for fiscal year 2025 — more than double the number completed in FY 2024," that it "authorized four new cloud services through its innovative FedRAMP 20x Phase One pilot," and that it had "reduced the time for authorizations to approximately five weeks." Those are the sponsor agency's figures, self-reported, and they measure the central certification step — not the agency-side work in steps one through five, which no central clock covers.

What to watch next in the process

Three things, all procedural. First, whether Phase Three's formalized rules survive contact with the 12-month Class A renewal limit — a shorter certification life shifts recurring effort back onto agencies. Second, whether OMB's guidance keeps the sponsorship cost visible now that GAO has closed its recommendation; the finding was closed, but the underlying free-rider problem is a budgeting fact, not an audit item. Third, whether the nine agencies GAO found using unauthorized services show up in later inventories, because the presumption of adequacy only saves work for agencies that use the marketplace in the first place.

For a related policy news perspective, read A Game-Changing Platform for Independent Writers.

Sources

  1. 44 U.S.C. § 3613, Roles and responsibilities of agencies (Office of the Law Revision Counsel)
  2. FedRAMP, Initial Agency Authorization (Consolidated Rules for 2026)
  3. U.S. Government Accountability Office, GAO-24-106591, Cloud Security: Federal Authorization Program Usage Increasing, but Challenges Need to Be Fully Addressed
  4. FedRAMP, FedRAMP 20x
  5. U.S. General Services Administration news release, GSA Celebrates Major Milestones in FedRAMP Cloud Authorization Reform, August 11, 2025