Federal Risk and Authorization Management Program (FedRAMP)

The Federal Risk and Authorization Management Program (FedRAMP), codified at 44 U.S.C. 3607-3616 and housed in GSA, provides a standardized, reusable approach to security assessment and authorization for cloud products and services that process unclassified federal information.

The FY 2023 NDAA made FedRAMP statutory, adding sections 3607 through 3616 to title 44 and placing the program office in GSA. The statute's charge is reuse: one assessment and authorization of a cloud product, relied on across agencies, instead of each agency re-reviewing the same service. OMB Memorandum M-24-15 (July 2024) rebuilt the program's structure and governance around that mandate.

The 20x initiative is replacing the Rev 5 process. Providers submit machine-readable Key Security Indicators for automated validation rather than static documentation packages, certification classes A, B, and C set the baseline, and an agency sponsor is no longer required. Phase 3 wide-scale adoption is underway, with the submission pipeline opening in the fourth quarter of FY26.

Two things practitioners miss. A FedRAMP authorization is not an ATO; each agency still makes its own authorization decision for its own use of the service. And the statutory sections sunset on December 23, 2027 unless Congress reauthorizes them.

Regulatory Reference

44 U.S.C. 3607-3616; OMB Memorandum M-24-15; FAR Case 2026-001 (proposed FAR Part 40)

RFO Status

FedRAMP is statutory and sits outside the FAR, but FAR Case 2026-001 (proposed June 23, 2026) writes it into proposed Part 40, requiring cloud services that hold CUI to meet security equivalent to the FedRAMP Moderate baseline and excusing FedRAMP-authorized providers with incident-reporting procedures from duplicate CUI incident reporting.

Category

Programs & Pathways

How AcqBot Helps

AcqBot checks whether a proposed cloud service holds a current FedRAMP authorization at the needed baseline, pulls the reuse case from the marketplace record, and drafts the solicitation's cloud security requirements so the contracting officer is not re-authorizing what the program already covers.