Federal Risk and Authorization Management Program (FedRAMP)
The Federal Risk and Authorization Management Program (FedRAMP), codified at 44 U.S.C. 3607-3616 and housed in GSA, provides a standardized, reusable approach to security assessment and authorization for cloud products and services that process unclassified federal information.
The FY 2023 NDAA made FedRAMP statutory, adding sections 3607 through 3616 to title 44 and placing the program office in GSA. The statute's charge is reuse: one assessment and authorization of a cloud product, relied on across agencies, instead of each agency re-reviewing the same service. OMB Memorandum M-24-15 (July 2024) rebuilt the program's structure and governance around that mandate.
The 20x initiative is replacing the Rev 5 process. Providers submit machine-readable Key Security Indicators for automated validation rather than static documentation packages, certification classes A, B, and C set the baseline, and an agency sponsor is no longer required. Phase 3 wide-scale adoption is underway, with the submission pipeline opening in the fourth quarter of FY26.
Two things practitioners miss. A FedRAMP authorization is not an ATO; each agency still makes its own authorization decision for its own use of the service. And the statutory sections sunset on December 23, 2027 unless Congress reauthorizes them.
Regulatory Reference
44 U.S.C. 3607-3616; OMB Memorandum M-24-15; FAR Case 2026-001 (proposed FAR Part 40)
RFO Status
FedRAMP is statutory and sits outside the FAR, but FAR Case 2026-001 (proposed June 23, 2026) writes it into proposed Part 40, requiring cloud services that hold CUI to meet security equivalent to the FedRAMP Moderate baseline and excusing FedRAMP-authorized providers with incident-reporting procedures from duplicate CUI incident reporting.
Category
Programs & Pathways
How AcqBot Helps
AcqBot checks whether a proposed cloud service holds a current FedRAMP authorization at the needed baseline, pulls the reuse case from the marketplace record, and drafts the solicitation's cloud security requirements so the contracting officer is not re-authorizing what the program already covers.
Related glossary entries
SBIR/STTR (Small Business Innovation Research)
SBIR and STTR are congressionally mandated programs requiring federal agencies with large R&D budgets to fund small business innovation through phased awards — feasibility (Phase I), development (Phase II), and commercialization (Phase III), which carries sole-source follow-on authority.
8(a) Business Development Program
The 8(a) Business Development Program, authorized by Section 8(a) of the Small Business Act, gives SBA-certified firms owned by socially and economically disadvantaged individuals a nine-year term of access to sole-source and competitive set-aside federal contracts under 13 CFR Part 124.
HUBZone Program
The HUBZone program, created by the HUBZone Act of 1997 and run by SBA, steers federal contracts to small businesses that keep their principal office in a historically underutilized business zone and draw at least 35 percent of employees from HUBZone residents.
Women-Owned Small Business Program (WOSB/EDWOSB)
The Women-Owned Small Business (WOSB) program, created by section 8(m) of the Small Business Act, lets contracting officers set aside contracts, and make limited sole-source awards, to SBA-certified women-owned small businesses in NAICS codes where SBA finds women-owned firms underrepresented.