← ALL FRAMEWORKS

FedRAMP

Cloud Security

Issued by U.S. General Services Administration (GSA)

FedRAMP is the US government's standardized process for security assessment, authorization, and continuous monitoring of cloud products used by federal agencies, built on NIST SP 800-53 controls. It applies to cloud service providers selling to federal agencies, and to vendors whose product touches federal data as a subcontractor. On June 25, 2026, FedRAMP finalized its Consolidated Rules for 2026 (CR26) — the largest structural overhaul in over a decade, replacing the Low/Moderate/High baseline labels with new Certification Classes (A–D) and retiring "FedRAMP Authorized" in favor of "FedRAMP Certified." Mandatory compliance takes effect January 1, 2027, with existing Rev 5 authorizations transitioning out through mid-2027.

Get notified the moment FedRAMP actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

minor

FedRAMP opened a new Request for Comment (RFC) titled 'Offerings By Government,' posted to the FedRAMP changelog on 2026-08-06, inviting stakeholder input on potential changes to FedRAMP offerings.

VIEW SOURCE ↗

▸ 6 EARLIER UPDATES IN THE FULL HISTORY

The complete change log for FedRAMP — every confirmed update, with severity and source — is included in every account, free ones too.

Sign up free to see the full history