Interweave Technologies
Oct 8

FedRAMP Requirements and What Federal Contractors Should Know

FedRAMP is the United States government's standardized program for assessing, authorizing, and continuously monitoring the security of cloud products and services that hold federal data. The FedRAMP requirements break into five parts: a set of NIST SP 800-53 security controls matched to the sensitivity of the data, an independent assessment by a recognized third-party assessment organization, a documented security package, an authorization decision from the government, and continuous monitoring that runs for as long as the service holds federal data.

One distinction decides how the rest of this applies to you. FedRAMP authorizes the cloud service provider, not your company. Your company cannot earn a FedRAMP credential, but your contract can require you to prove that every cloud platform touching federal data holds one. That proof obligation sits with you.

Below we cover where the controls come from, how impact levels and the new Certification Classes work, who the rules bind, what DFARS and CMMC add on top, what FedRAMP Moderate equivalency actually demands, and the logging, backup, and software inventory evidence you have to produce year-round.

What Are the FedRAMP Requirements?

The FedRAMP requirements are a baseline of NIST SP 800-53 security controls set by data sensitivity, an independent assessment by a FedRAMP-recognized third-party assessment organization, a complete security documentation package, a government authorization decision, and ongoing continuous monitoring. Each piece depends on the one before it. Controls get implemented, the assessment tests them, the documentation records both, the authorization accepts the result, and monitoring keeps the result honest.

Continuous monitoring is the part contractors underestimate. An authorization is a snapshot of a system on an assessment date, and systems drift. FedRAMP answers drift with monthly vulnerability scanning, annual assessment, significant change reporting, and incident reporting. A cloud service that stops producing that evidence can be placed in remediation or removed from the FedRAMP Marketplace entirely.

Scale explains why the program exists in this shape. The FedRAMP Marketplace listed 537 certified cloud service offerings as of October 5, 2026, up from roughly 350 authorized services across the program's first ten years. Reuse is what multiplies that work: FedRAMP Marketplace data shows 350 reuse authorizations in fiscal year 2025 against 131 new ones, meaning one security package served agencies over and over instead of each agency repeating the review. That reuse model is the practical reason a single compliance program can lean on authorized platforms rather than rebuilding security evidence per contract.

Is FedRAMP Based on NIST Standards?

Yes, FedRAMP is based on NIST standards. The control catalog comes from NIST Special Publication 800-53, and the sensitivity categories that decide which controls apply come from Federal Information Processing Standard 199. NIST SP 800-53 Revision 5 supplies the full catalog, and FedRAMP selects a subset of it for each baseline.

That subset is not arbitrary. FedRAMP adds cloud-specific parameters and assessment expectations that NIST leaves open, such as scan frequencies, boundary definitions, and the evidence a third-party assessment organization has to collect. The catalog is NIST, the cloud interpretation is FedRAMP, and both travel together in the authorization package.

What Are the Key Differences Between NIST 800-53 and FedRAMP?

The key differences between NIST 800-53 and FedRAMP are scope and authority. NIST SP 800-53 is a control catalog that applies to federal information systems broadly, with no authorization attached to it. FedRAMP is a program that selects controls from that catalog, requires an independent assessment against them, and issues a government decision on a specific cloud service offering.

Put plainly, 800-53 tells you what good security controls look like. FedRAMP decides which of those controls a cloud service must implement, who gets to test the implementation, and whether the result is accepted. A platform can align with 800-53 and still hold no FedRAMP standing. The difference between the two carries real weight for anyone running federal data on commercial SaaS platforms.

Who Needs to Comply With NIST 800-53?

Federal agencies and the information systems they operate need to comply with NIST 800-53, under the Federal Information Security Modernization Act. Contractors inherit the standard indirectly rather than directly. A defense contractor storing Controlled Unclassified Information on its own network follows NIST SP 800-171, which defines 110 security requirements across 14 families and derives from 800-53.

The inheritance path matters for scoping. Your internal systems answer to 800-171 through your contract clauses, and the cloud services inside your data boundary answer to 800-53 through FedRAMP. Those two obligations run side by side, and treating them as one requirement is how gaps open. Clear separation of the two is where NIST compliance scoping usually starts.

What Are the FedRAMP Impact Levels and Certification Classes?

FedRAMP impact levels are Low, Moderate, and High, and under the Consolidated Rules for 2026 those labels become Certification Classes B, C, and D, with a new Class A entry tier added. The mapping is direct. Class B covers what was Low, including the LI-SaaS variant, Class C covers what was Moderate, and Class D covers what was High.

The level is set by consequence, not by company size. A cloud system is categorized by how much damage a loss of confidentiality, integrity, or availability would cause the government. Limited damage lands at Low, serious damage at Moderate, and severe or catastrophic damage at High. Most federal work sits in the middle: FedRAMP Marketplace data shows roughly 80 percent of certified offerings hold the Moderate baseline, now Class C.

What Are the Key Differences Between FIPS and FedRAMP?

The key differences between FIPS and FedRAMP are function and sequence. FIPS 199 is the standard that categorizes a system's sensitivity, and FedRAMP is the program that authorizes the system once that category sets the control baseline. FIPS comes first and answers how bad a breach would be. FedRAMP comes second and answers whether the service is secure enough for that answer.

A second FIPS standard shows up in the control detail. FIPS 140 validation governs the cryptographic modules a cloud service uses, and FedRAMP baselines require validated cryptography for data in transit and at rest. One FIPS standard sizes the problem, the other certifies part of the solution.

How Many Controls Does Each FedRAMP Baseline Require?

Each FedRAMP baseline requires a different control count: 156 controls at Low, 323 at Moderate, and 410 at High. The FedRAMP Rev5 baselines, drawn from NIST SP 800-53 Revision 5, set those figures, and all three pull from the same 17 control families. Depth separates them rather than breadth. Older sources still circulate counts of 125, 325, and 421, which came from the earlier Revision 4 baselines and no longer match what an assessment tests against.

Legacy Impact LevelCertification Class (CR26)Approximate ControlsData It CoversNot applicableClass AEntry tierNew transitional baseline that replaces FedRAMP Ready at a lower barLow (with LI-SaaS)Class B156Public-facing or limited-risk federal informationModerateClass C323Controlled Unclassified Information and most federal workloadsHighClass D410Sensitive unclassified data where a security failure causes severe harm

Your class is decided by your contract, not by preference. Contract language referencing DFARS 252.204-7012 or Controlled Unclassified Information points at the Moderate baseline, now Class C, as the floor. Work involving defense installations, critical infrastructure, or operational sequencing data pushes to Class D.

Is FedRAMP Required for Government Contractors?

FedRAMP is required for government contractors indirectly. Your company does not get FedRAMP authorized, but your contract requires that any cloud service storing, processing, or transmitting federal data holds FedRAMP authorization or a recognized equivalent. The authorization attaches to the platform. The responsibility for selecting and proving the platform attaches to you.

Scope exclusions exist and are worth checking before anyone starts a project. OMB Memorandum M-24-15 names categories that fall outside FedRAMP, including search engines, social media platforms used under agency social media policy, single-agency systems not offered as shared services, commercially available information services that handle no federal data, and low-risk ancillary services. Everything else that touches federal data in the cloud is in scope. Scoping that question early is the first thing we work through with government contractors.

Timing is what makes the difference in cost. Huntsville's concentration of primes, subcontractors, and defense suppliers means this question usually arrives mid-project, after a platform is already in production and a flow-down clause surfaces. A cloud inventory built at the proposal stage answers it in an afternoon.

Do Subcontractors and SaaS Vendors Need FedRAMP Authorized Cloud Services?

Yes, subcontractors and SaaS vendors need FedRAMP authorized cloud services whenever the service holds federal data. The obligation follows the data, not the tier of the contract. A sub-tier supplier that receives Controlled Unclassified Information from a prime carries the same cloud requirement the prime carries, because the clause flows down with the work.

Three delivery models fall in scope: Software as a Service that stores or processes federal data, Platform as a Service used to build applications that support federal operations, and Infrastructure as a Service that hosts the systems. A vendor that sells to federal contractors rather than to agencies directly is still in scope the moment federal data lands in its environment, which is the single most common misread of the rule.

Can You Use a Non-FedRAMP Cloud Service for Federal Data?

No, you cannot use a non-FedRAMP cloud service for federal data when your contract requires the FedRAMP baseline. The alternatives are narrow. You can select an authorized service, accept a provider's documented equivalency and validate it yourself, isolate federal data in a separate compliant enclave, or host the system internally and carry the full control burden under NIST SP 800-171 instead.

Internally hosted systems leave FedRAMP's scope because FedRAMP governs external cloud providers. That shift does not reduce the work. It transfers every control, every piece of documentation, and every assessment obligation onto your own team, with no authorization package available to inherit. Most small and mid-size organizations find the authorized-platform route cheaper and faster to defend, which is why cloud selection and cloud systems planning belong at the start of a federal project rather than the middle.

What Is the FedRAMP Certificate Requirement?

There is no FedRAMP certificate in the sense most people mean. FedRAMP grants an Authority to Operate, issued by a federal agency, and under the Consolidated Rules for 2026 the program's output is now called a FedRAMP Certification rather than a FedRAMP Authorization. Neither is a certificate your company hangs on a wall. Both attach to a specific cloud service offering, usually a government edition of a commercial product.

Precision here protects you during an audit. A vendor claiming its company is "FedRAMP certified" has told you nothing about which offering holds standing, at what class, or whether the modules you plan to use fall inside the authorized boundary. Authorization attaches to the offering and the boundary, never to the brand.

What Changed Under the Consolidated Rules for 2026?

The Consolidated Rules for 2026 changed FedRAMP's vocabulary, its baseline labels, and its timeline, without changing the underlying controls. FedRAMP released the rules on June 24, 2026, they took effect July 4, 2026, and they become mandatory for all stakeholders on January 1, 2027. The class structure traces back to notice NTC-0004, published February 25, 2026.

Three changes affect contractor decisions right now. Authorization became Certification, so a service still marketed as "FedRAMP Authorized" is using retired wording. Impact levels became Certification Classes A through D, with existing authorizations carrying forward automatically at the matching class and the same control set. And the legacy Rev5 path is closing: FedRAMP stops accepting new Rev5 applications on June 11, 2027, with existing Rev5 certifications sunsetting December 31, 2028.

That sunset is a procurement question, not just a program detail. A platform you select in 2026 on a Rev5 certification has a migration ahead of it, and asking a vendor about its transition plan now costs nothing. The newer path moved fast in the pilots: GSA reported 114 authorizations in fiscal year 2025, more than double the prior year, with average agency review time falling to roughly five weeks.

What Are the Rules and Regulations for Federal Contractors?

The rules and regulations for federal contractors handling sensitive federal data are DFARS 252.204-7012, NIST SP 800-171, Supplier Performance Risk System scoring, and the Cybersecurity Maturity Model Certification program. DFARS 252.204-7012 carries the cloud requirement directly: if a contractor uses an external cloud service provider to store, process, or transmit covered defense information, the contractor must require that the provider meets security requirements equivalent to the FedRAMP Moderate baseline.

NIST SP 800-171 governs your own systems with its 110 requirements, and SPRS records your self-assessed score against them. Those three obligations are contractual, which means a shortfall is a performance issue rather than a regulatory fine. That framing is exactly why documented DFARS compliance carries weight during award and option exercise.

What Is the Difference Between FedRAMP and CMMC?

The difference between FedRAMP and CMMC is what each one certifies. FedRAMP certifies the cloud platforms you use, assessing the provider's controls, monitoring, and incident response. CMMC certifies your organization, assessing how your company protects Controlled Unclassified Information across its people, policies, and systems.

The two meet at the data boundary. When an assessor maps everywhere Controlled Unclassified Information is created, stored, processed, or transmitted, every cloud platform inside that boundary has to demonstrate it meets the NIST SP 800-171 security requirements. A FedRAMP authorized platform supplies that demonstration directly. A platform without one shifts the burden back to you, and you carry it with your own documentation and testing. The relationship between the two is covered in depth in our CMMC certification primer.

What the CMMC Phase 2 Suspension Did Not Change

The CMMC Phase 2 suspension did not change DFARS 252.204-7012, NIST SP 800-171, or SPRS reporting. On July 13, 2026, the Department of War suspended the Phase 2 transition that would have made third-party C3PAO assessment a condition of award starting November 10, 2026, under publication case 26-P-1023. Class Deviation 2026-O0025, Revision 3, signed September 3, 2026, made the suspension binding by directing contracting officers to remove Phase 2 language from solicitations and contracts.

Level 1 and Level 2 self-assessments can still be required where a contract carries them, and the baseline obligation to implement NIST SP 800-171 stayed exactly where it was. Many published guides still describe third-party assessment as the live gate, which is now out of date.

For cloud decisions the suspension raises the stakes rather than lowering them. With the third-party assessment gate paused, the FedRAMP Moderate equivalency requirement in DFARS 252.204-7012 is the clearest cloud obligation still fully in force, and it has been in force the entire time. Contractors who treated CMMC as the deadline and the cloud requirement as a downstream detail now have the order reversed.

What Does FedRAMP Moderate Equivalent Mean?

FedRAMP Moderate equivalent means a cloud service offering has achieved 100 percent compliance with the FedRAMP Moderate security control baseline through an assessment conducted by a FedRAMP-recognized third-party assessment organization, with the documentation delivered to the contractor. A Department of Defense memorandum dated December 21, 2023 set that standard. There is no partial credit in it.

The documentation package is specific: a System Security Plan, a Security Assessment Plan, a Security Assessment Report prepared by the recognized assessor, and a Plan of Action and Milestones showing that findings were corrected and validated. A provider claiming equivalency without that body of evidence has made a marketing claim, not a compliance one. Reviewing a provider's System Security Plan is the fastest way to tell the two apart.

Equivalency also moves work onto your side of the table. An authorized service carries a public listing that serves as evidence on its own. An equivalent service has no listing, so you collect the four documents, confirm the assessment happened within the last year, and retain all of it for your own audit. That collection and validation effort is the hidden cost of the equivalency route, and it is worth pricing into a risk assessment before signing.

How Do You Verify a Cloud Service on the FedRAMP Marketplace?

You verify a cloud service on the FedRAMP Marketplace by checking the listing against five specific details rather than by trusting a vendor badge. Work through them in order:

  1. Confirm the status is a live authorization or certification, not "In Process" and not the legacy "FedRAMP Ready" designation, which does not satisfy a contract requirement.
  2. Match the class or impact level to your contract. A Class B listing does not cover a Class C obligation.
  3. Check the exact cloud service offering named on the listing, because authorization attaches to one offering and most vendors list a government edition rather than the commercial product.
  4. Verify that the modules and features you plan to use sit inside the authorized boundary, since partial-product authorizations are common.
  5. Capture the evidence, including the listing itself, the authorization date, the authorizing agency, and vendor confirmation that your tenant runs in the authorized environment.

Watch for three patterns that fail an audit: equivalency claimed with no supporting documentation package, a vendor "working toward" authorization, and an authorization that covers a different product than the one being sold to you. Each one looks reassuring in a sales conversation and collapses under assessor review.

What Are FedRAMP Logging Requirements?

FedRAMP logging requirements sit in the audit and accountability control family and require centralized, tamper-resistant logging that captures user activity, system events, and security-relevant occurrences, retained long enough to support investigation and reviewed continuously rather than on demand. Logs are the raw material every other compliance claim is built from.

Three properties decide whether a logging setup holds up. Coverage means every component inside the authorization boundary writes logs, including identity systems, storage, and administrative actions. Integrity means logs are centralized where the people being logged cannot alter them. Review means someone or something examines them continuously, which in practice means a security information and event management platform rather than a folder nobody opens.

FedRAMP's modernized path makes the continuous part explicit. The Key Security Indicator covering monitoring, logging, and analysis requires centralized tamper-resistant logging and persistent infrastructure and configuration scanning so that evidence is produced on an ongoing basis, not assembled before an audit. Continuous evidence is also where network monitoring and compliance stop being separate projects.

How Do You Meet FedRAMP Requirements for Backups?

You meet FedRAMP requirements for backups through the contingency planning control family, which requires backups of user-level data, system-level information, and security documentation, protected with the same controls as the live system and tested on a defined schedule. Encryption applies to backup media, and access to backups follows the same least-privilege rules as production.

Testing separates a compliant backup from an assumed one. The controls expect documented restoration testing, defined recovery time and recovery point objectives, and alternate storage that is geographically separated from the primary site. A backup nobody has restored is an untested control, and assessors treat it that way.

How Do You Comply With the FedRAMP SBOM Requirement?

You comply with the FedRAMP SBOM requirement by obtaining a Software Bill of Materials for third-party commercial software components, keeping it current as releases ship, and confirming that those software providers hold a Secure Software Development Attestation with CISA. FedRAMP's Key Security Indicator covering third-party resources sets that expectation as part of supply chain risk management.

The requirement sits in the modernized path rather than in the legacy Rev5 baselines, where a Software Bill of Materials supports component inventory controls without being named outright. Contractors feel it secondhand. When your cloud provider has to produce component inventories and upstream vulnerability monitoring, that discipline flows into the questions you answer about your own data boundary. Starting the conversation with suppliers early, and writing delivery expectations into vendor agreements, costs far less than reconstructing a software inventory under assessment pressure.

Does FedRAMP Require Continuous Monitoring?

Yes, FedRAMP requires continuous monitoring. Authorized cloud services must perform ongoing vulnerability scanning, undergo annual assessment, report significant changes, and report security incidents, with the results reviewed by the authorizing agency. Authorization is a starting condition rather than a finished state.

Your side of that arrangement is continuous too. A platform authorized when you selected it can enter remediation, let an assessment lapse, or be removed from the FedRAMP Marketplace, and nothing notifies you automatically. Checking the Marketplace once at procurement leaves you exposed for the entire contract period that follows. Re-verification belongs on a schedule.

This is where a reactive technology model breaks down structurally. Break-fix support arrives after something has already gone wrong, and compliance evidence has to exist before anyone asks for it. We built our model around preemptive, all-inclusive managed cybersecurity for that reason, with monitoring, documentation, and evidence collection running continuously rather than being assembled under deadline.

Evidence collected continuously also costs less than evidence reconstructed. Scans, logs, policy updates, and platform re-verification produced on a steady cadence turn an audit into a retrieval exercise instead of a scramble, which is the same discipline that keeps contract requirements satisfied between reviews.

What Happens If You Use a Non-Compliant Cloud Platform?

If you use a non-compliant cloud platform, the practical outcomes are an assessment finding, a corrective action plan, platform replacement, and data migration, usually on someone else's timeline. Agencies can restrict tool usage mid-project, and contracting officers can delay approvals while alternatives get implemented.

Prevention is straightforward and almost entirely front-loaded. Inventory every cloud platform that will hold federal data before the work starts, confirm each one's standing and class against the contract, document the verification, and re-verify on a schedule. Catching a mismatch during planning costs a procurement conversation. Catching it during an assessment costs a migration and rebuilt device relationships across every system that touched the old platform.

What Are the Main Security Frameworks Federal Contractors Deal With?

The main security frameworks federal contractors deal with are FedRAMP, NIST SP 800-53, NIST SP 800-171, CMMC, and FIPS 199, each covering a different piece of the same problem. They layer rather than compete:

  • FIPS 199 categorizes how sensitive a system's data is and sets the baseline everything else follows.
  • NIST SP 800-53 supplies the full control catalog for federal information systems, with 17 control families drawn on by every FedRAMP baseline.
  • FedRAMP selects controls from that catalog, requires third-party assessment, and authorizes cloud services at Class B, C, or D.
  • NIST SP 800-171 defines the 110 requirements protecting Controlled Unclassified Information on contractor-owned systems.
  • CMMC is the Department of Defense mechanism for verifying 800-171 implementation, currently operating through self-assessment while the Phase 2 transition stays suspended.

Industry adds a further layer on top. Healthcare organizations carry HIPAA alongside any federal cloud obligation, manufacturers in the defense supply chain carry 800-171 and often ISO 27001, finance firms carry FTC Safeguards and PCI requirements, and government contracting carries DFARS and the FedRAMP cloud clause. Most organizations we work with answer to more than one framework at once, which is why we designed our program to handle several in a single effort instead of running parallel projects that collect the same evidence twice.

Frequently Asked Questions

What Is an Authority to Operate (ATO)?

An Authority to Operate (ATO) is a formal decision by a federal agency official accepting the risk of running a specific information system and permitting it to operate with federal data. For cloud services, an ATO follows a completed security assessment and is granted for a defined boundary. One authorization can be reused by other agencies, which is why FedRAMP Marketplace data showed 350 reuse authorizations in fiscal year 2025 against 131 new ones.

How Long Does FedRAMP Authorization Take?

FedRAMP authorization has historically taken twelve to eighteen months from initial planning through the authorization decision, covering documentation, control implementation, third-party assessment, remediation, and final approval. That timeline has compressed sharply. GSA reported average agency review time falling to roughly five weeks and 114 authorizations completed in fiscal year 2025, more than double the prior year.

What Documents Does FedRAMP Require?

FedRAMP requires a System Security Plan, a Security Assessment Plan, a Security Assessment Report, and a Plan of Action and Milestones. The System Security Plan is the primary artifact, describing the architecture and how each control is implemented, and it commonly runs past 300 pages. The POA&M tracks identified weaknesses and remediation timelines, and it stays active after authorization rather than closing out.

How Often Does FedRAMP Require Vulnerability Scanning?

FedRAMP requires monthly vulnerability scanning of operating systems, databases, and web applications inside the authorization boundary, with results reported to the authorizing agency and findings tracked through remediation. Annual assessment sits on top of the monthly cycle, and significant system changes trigger their own review outside the normal schedule.

Why Is FedRAMP Required for CUI?

FedRAMP is required for Controlled Unclassified Information because the Moderate baseline, now Class C, is the control set the government considers adequate for data whose loss would cause serious harm. DFARS 252.204-7012 states the requirement in contract terms, obligating contractors to use external cloud providers meeting security requirements equivalent to the FedRAMP Moderate baseline for covered defense information.

Is FedRAMP Required for State and Local Government Work?

No, FedRAMP is not required for state and local government work, because the program governs federal data. State and local agencies often reference FedRAMP standards in their own procurement or use parallel programs modeled on it, and some require equivalent evidence contractually. The requirement in those cases comes from the contract rather than from FedRAMP itself.

The Bottom Line

FedRAMP requirements come down to a control baseline set by data sensitivity, an independent assessment, a documented security package, a government authorization, and monitoring that never finishes. Your company does not earn the authorization, but your contract makes proving it your job, and under DFARS 252.204-7012 that obligation applies whether or not any assessment program is currently gating awards. With FedRAMP Authorization now FedRAMP Certification, impact levels now Classes B, C, and D, and the legacy Rev5 path closing through 2028, the cloud platform decisions made this year carry further than usual.

The practical work is less about the program and more about discipline: knowing which cloud services hold federal data, confirming each one's standing and class against the contract, keeping the evidence current, and re-checking it on a schedule instead of at audit time. That has been the pattern across the government contractors, healthcare providers, manufacturers, and financial firms we work with throughout Huntsville and North Alabama.

If you are sorting out which of your cloud platforms fall inside a federal data boundary, or what your contract actually requires of them, the team at Interweave Technologies is glad to take a look with you. Give us a call at 256.837.2300 and we will walk through where things stand.

‍