Interweave Technologies
Aug 14

What Is FedRAMP Certification and What DoD Suppliers Should Know

FedRAMP certification is the federal government's verification that a cloud service meets the security standards required to handle government data. Defense contractors do not get FedRAMP certified. Cloud service providers do. What defense contractors have to do is make sure the cloud tools holding their Controlled Unclassified Information carry that certification, because DFARS 252.204-7012 requires it and a CMMC assessor will check.

That distinction costs contractors more money than almost any other mix-up in defense compliance. Companies spend months hardening their internal network, then fail an assessment because their email platform was never eligible to hold CUI in the first place.

FedRAMP also changed shape two months ago. The words on your contract no longer match the words on the FedRAMP Marketplace, which is creating real confusion right now. This article covers what FedRAMP certification is, what changed in 2026, how to check whether a vendor holds it, what happens when CUI lands in a service that does not, and what your cloud vendors actually go through to earn it.

What Is FedRAMP Certification and How Does It Work?

FedRAMP certification is a government-wide program that standardizes how cloud products and services are security tested, approved, and monitored for federal use. FedRAMP stands for the Federal Risk and Authorization Management Program. The General Services Administration launched it in 2011 at the direction of the Office of Management and Budget.

It solved a specific waste problem. Before FedRAMP, every federal agency ran its own independent security review of every cloud service it wanted to buy. Twenty agencies evaluating the same product meant twenty separate assessments of identical software. FedRAMP replaced that with a do once, use many model, where one certification can be reused across the entire federal government.

The mechanics run in four steps. A cloud provider implements security controls drawn from NIST Special Publication 800-53. An independent Third-Party Assessment Organization, called a 3PAO, tests those controls and produces a Security Assessment Report. The provider documents any open findings in a Plan of Action and Milestones. A federal agency reviews the whole package and, if it accepts the risk, issues an Authority to Operate.

The certification covers the cloud service offering itself, not the company that uses it. That single fact is the root of most confusion on this topic, and it applies whether the offering is SaaS, PaaS, or IaaS.

What Companies Require FedRAMP Certification?

The companies that require FedRAMP certification are cloud service providers selling cloud-based products to United States federal agencies. That covers software, platform, and infrastructure providers whose offerings create, collect, process, store, or maintain federal information on behalf of an agency. Where the company is headquartered does not matter; international providers serving federal customers face the same requirement.

Federal agencies do not get certified themselves. They are required to use certified services for covered use cases, and they act as sponsors in the certification process.

Scope has limits, and OMB Memorandum M-24-15 spells them out. Systems used only for a single agency's operations that are not offered as a shared service fall outside FedRAMP. So do social media platforms used under agency social media policies, search engines, widely available services that supply commercial information without collecting federal information, and ancillary services whose compromise would pose negligible risk. Only a federal agency can decide whether its specific use case falls inside the program.

As of mid-2026, the FedRAMP Marketplace lists 499 certified cloud services plus 23 certified under the newer FedRAMP 20x path, according to FedRAMP.gov. Against the size of the commercial software market, that is a small catalog, and the gap is exactly why cloud selection is harder for defense contractors than most people expect.

Do DoD Suppliers Need FedRAMP Certification?

No, DoD suppliers do not need FedRAMP certification for their own organizations. Defense contractors are buyers in this program, not providers. You need FedRAMP certification only if you sell a cloud service to federal agencies.

What you do need is proof that the cloud services inside your CUI environment hold it.

DFARS 252.204-7012 is the clause that creates the obligation. When a contractor uses an external cloud service to store, process, or transmit covered defense information, that service must meet security requirements equivalent to the FedRAMP Moderate baseline. The responsibility for verifying that sits with the contractor, not the cloud provider.

Most contractors underestimate how many services this touches. Email. File storage and sharing. Backup. Ticketing systems. Collaboration platforms. Remote monitoring tools. Anywhere a technical drawing, a specification, or an export-controlled document can travel, the hosting service is inside your assessment boundary. Contractors pursuing compliance for government contractors in the Redstone Arsenal supplier network routinely discover CUI sitting in three or four cloud services nobody had scoped.

What Are the FedRAMP Certification Classes?

The FedRAMP certification classes are Class A, Class B, Class C, and Class D, and they replaced the old Low, Moderate, and High impact levels in 2026. Class A is a new pilot tier. Class B covers what used to be Low. Class C covers Moderate. Class D covers High.

The figures below combine the NIST SP 800-53 baseline control counts with the class mapping published by FedRAMP under its Consolidated Rules for 2026.

Attribute

Class B (formerly Low)

Class C (formerly Moderate)

Class D (formerly High)

Controls, per NIST SP 800-53

About 156

About 323

About 410

Data sensitivity

Non-sensitive, minimal personal data

Sensitive but unclassified, includes CUI

Law enforcement, financial, health

Breach consequence

Limited adverse effect

Serious adverse effect

Severe or catastrophic effect

Relevance to defense contractors

Not sufficient for CUI

The minimum baseline DFARS requires for CUI

Exceeds the DFARS minimum

Typical timeline, industry estimate

6 to 12 months

12 to 18 months

18 to 36 months

Class C is the one that matters to you. It carries the same controls and the same boundary as the Moderate baseline it replaced, and it is the level DFARS points at for CUI. Because Class C sits on the NIST 800-53 catalog while your own obligations sit on NIST 800-171, the two standards are related but separate, and meeting NIST compliance in your own systems does nothing to certify your vendors.

One trap worth naming. The letters are not a security ranking you should shop up. Class D is not a safer choice than Class C for CUI work; it is a different scope built for different data. Buying above your requirement adds cost without adding compliance.

What Changed in FedRAMP in 2026?

FedRAMP replaced the word authorization with certification and replaced impact levels with classes, effective under the Consolidated Rules for 2026. FedRAMP finalized those rules on June 25, 2026. Optional early adoption opened July 4, 2026, mandatory effect lands January 1, 2027, and the ruleset runs through December 31, 2028.

The Marketplace states the change directly: FedRAMP Authorization is now FedRAMP Certification, and Impact Levels have been replaced with Classes A through D. FedRAMP will show the previous impact levels in parentheses after the classes until December 31, 2026, and beginning in January 2027 the Low, Moderate, and High labels come off entirely.

Three practical consequences for anyone buying cloud services:

  • Existing certifications carry over. A service authorized at Moderate today is Class C tomorrow, same controls, same boundary, no re-authorization. A vendor is not less compliant because the label moved.
  • FedRAMP Ready is retired. It became Legacy FedRAMP Ready on July 28, 2026, and no new Ready submissions are accepted. Class A is a separate new pilot tier, not a renamed Ready. Any vendor still selling you on Ready status is quoting a designation on its way out.
  • The word certification is a legal correction. FedRAMP certifies that an assessment was completed. The agency, not FedRAMP, issues the Authority to Operate under the NIST Risk Management Framework. The old wording overstated what FedRAMP itself grants.

The reason behind the rename should interest defense suppliers more than anyone. The Low, Moderate, and High labels collided with Department of War Impact Levels, which use similar words for a completely different framework. Two programs, two meanings, one vocabulary. FedRAMP switched to letters to end the overlap.

Why Does DFARS Still Say FedRAMP Moderate?

DFARS 252.204-7012 still says FedRAMP Moderate because the contract clause has not been rewritten to match FedRAMP's new terminology. The clause language and the program language are temporarily out of step.

Here is the situation a contractor walks into today. Your contract says Moderate. You open the Marketplace and find a program that is retiring the word. Until December 31, 2026 you will see the old label in parentheses next to the class, which bridges the gap. After that the parentheses disappear and the clause will still say Moderate while nothing on the Marketplace does.

The practical translation is simple: where DFARS says FedRAMP Moderate, look for Class C. Same controls, same baseline, different name. We expect the clause to catch up eventually, but contracts move slower than programs, and your obligation runs on the clause you signed.

Document the translation in your assessment records rather than leaving an assessor to infer it. A short note in your system security plan explaining that a Class C service satisfies the Moderate requirement costs you ten minutes and removes a question during your compliance audit.

What Happens if You Put CUI in a Cloud Service That Is Not Certified?

Putting CUI in a cloud service that is not FedRAMP certified or documented as equivalent makes you non-compliant with DFARS 252.204-7012 and will produce a finding during a CMMC Level 2 assessment. The cloud environment sits inside your assessment boundary. An assessor evaluates it the same way they evaluate your own network.

The most common version of this problem involves email, and it catches good companies.

Microsoft 365 Commercial, the standard business subscription most organizations run, does not hold FedRAMP Moderate or High authorization and has not been assessed by a 3PAO against the Moderate baseline. Storing, processing, or transmitting CUI in Microsoft 365 Commercial while subject to DFARS 252.204-7012 is non-compliant, and it will disqualify you during a CMMC Level 2 or Level 3 assessment.

Read that again if your company emails technical drawings. A very large number of small defense contractors are doing exactly this today, on the reasonable assumption that a Microsoft product is a Microsoft product. The commercial tenant and the government tenant are different services with different certifications.

The failure mode is expensive because it is architectural. You cannot patch it with a policy. Moving a CUI workload out of a non-certified platform means migrating mailboxes, re-pointing integrations, retraining staff, and rebuilding evidence, which is a project measured in months. Contractors who find this during assessment prep have options. Contractors who find it during the assessment do not. Strong file encryption in your own environment does not rescue a platform that was never eligible to hold the data.

How Do You Find Out if a Company Is FedRAMP Certified?

You find out whether a company is FedRAMP certified by searching the FedRAMP Marketplace, which is the authoritative government catalog of certified cloud service offerings. Vendor marketing pages are not authoritative. The Marketplace is.

Search carefully, because four details decide whether a listing actually covers you.

  1. Match the exact offering, not the company. Large vendors list multiple cloud service offerings, and certification attaches to a specific one. A provider can hold certification for a government edition while its commercial product holds none.
  2. Check the class. Class B, or Low under the old labels, does not satisfy the CUI requirement. You need Class C or above.
  3. Check the status. In Process means a provider is working toward certification, not that they hold it. Neither does Legacy FedRAMP Ready. Only a completed certification counts.
  4. Confirm the boundary. Certification covers a defined system boundary. If you use a module or integration that sits outside it, that piece is not covered.

Write down what you find. Screenshot the listing, record the package identifier, and date it. That record is evidence during an assessment, and vendor status changes over time. Building this into a recurring review is part of how a defense contractor compliance program stays current between assessments rather than scrambling before one.

What Is FedRAMP Equivalency?

FedRAMP equivalency is a documented demonstration that a cloud service meets security requirements equal to the FedRAMP Moderate baseline without holding FedRAMP certification itself. The Department of Defense created the pathway so providers that do not sell to federal agencies could still serve defense contractors.

Equivalency is a real option and a frequently abused one. Before the Department published its guidance, many providers claimed equivalency on their own definitions, often by pointing out that they run on Amazon Web Services or Azure. Sitting on certified infrastructure does not make the application on top of it equivalent.

The bar is documentation. A provider claiming equivalency should be able to produce a body of evidence assessed against the full Moderate baseline, not a marketing statement. If a vendor cannot hand you that package, you are carrying their compliance risk on your own contract. A structured gap analysis across your cloud stack is usually how these claims surface, because equivalency assertions rarely survive being asked for the paperwork.

What Do Cloud Providers Go Through To Get Certified?

Cloud providers get FedRAMP certified by preparing a security package, passing an independent 3PAO assessment, and obtaining an agency review, followed by permanent continuous monitoring obligations. Knowing this process is useful to a buyer for one reason: it explains why the certified version of a product costs more than the commercial version, and why so few products are certified at all.

  1. Readiness assessment. The provider compares its current security posture against the target class baseline and identifies missing controls and documentation gaps.
  2. Security package development. The provider builds a system security plan describing how every required control works in its environment, implements the controls, and stands up a continuous monitoring strategy. This phase commonly runs three to seven months.
  3. Independent assessment. A 3PAO accredited by the American Association for Laboratory Accreditation conducts documentation review, technical testing, staff interviews, and vulnerability scanning, then issues a Security Assessment Report. Industry practitioners put this phase at two to four months.
  4. Agency review and Authority to Operate. Under the traditional path a sponsoring agency reviews the package and issues the Authority to Operate. Under FedRAMP 20x, the Program Certification path lets a provider submit directly to FedRAMP without an agency partner, which removes the single hardest barrier in the old process.
  5. Continuous monitoring, permanently. Certification is not a finish line. Providers submit monthly security deliverables, run annual assessments, and remediate vulnerabilities on defined timelines for the life of the certification.

FedRAMP 20x is the modernization effort behind the newer path. It replaces control-by-control narrative review with Key Security Indicators and machine-readable evidence. The Class A pipeline opened August 3, 2026 and the Class B and Class C pipelines open August 31, 2026, with FedRAMP scheduled to stop accepting new legacy Rev5 applications on June 11, 2027.

How Much Does FedRAMP Certification Cost and Why Is It So Expensive?

FedRAMP certification is expensive because it requires hundreds of implemented controls, extensive documentation, independent third-party testing, and permanent continuous monitoring. Industry estimates, and these are vendor estimates rather than government figures, commonly put traditional certification at $250,000 to $500,000 for Low, $500,000 to $1,500,000 for Moderate, and $2,000,000 or more for High. The 3PAO assessment alone typically runs $50,000 to $350,000, and continuous monitoring adds $50,000 to $150,000 a year. Early estimates for the FedRAMP 20x path fall considerably lower, in the $100,000 to $300,000 range.

Four things drive those numbers. Control volume, since Class C requires roughly 323 individually implemented and evidenced controls. Documentation depth, since the system security plan alone can run into the hundreds of pages before policies, diagrams, and baselines. Assessment rigor, since 3PAO testing is hands-on rather than a paperwork review. And permanence, since monthly deliverables and annual reassessments never stop.

For a buyer, this is the answer to the question we hear most often. Contractors ask why they cannot simply keep using the commercial tools they already pay for. The reason is that a provider carrying a seven-figure certification cost and an ongoing monitoring burden cannot offer that product at commercial pricing. The premium is not margin. It is the cost of the assurance your contract requires you to buy, and budgeting for it early is a normal part of CMMC compliance support rather than a surprise line item discovered at renewal.

Is FedRAMP the Same as CMMC?

No, FedRAMP is not the same as CMMC. FedRAMP certifies cloud service offerings sold to federal agencies. CMMC certifies defense contractors handling FCI or CUI. Different populations, different frameworks, no reciprocity between them.

They meet at one point, and it is the point that decides assessments. Your CMMC Level 2 assessment examines your cloud services. If a service inside your boundary holds no certification and no documented equivalency, that is a finding against you, not against the vendor.

The two clauses stack rather than substitute. DFARS 252.204-7012 governs the cloud side and predates CMMC entirely. DFARS 252.204-7021 governs your organizational CMMC requirements. Meeting one has never satisfied the other.

There is a genuine upside to getting the cloud side right. A certified provider has already implemented and evidenced a large body of controls at the infrastructure layer. Building your CUI environment on top of one narrows your own assessment scope to the layer you actually operate, which reduces both the cost and the duration of your certification work.

What DoD Suppliers Should Do About FedRAMP

DoD suppliers should inventory every cloud service touching CUI, verify each one against the Marketplace, document the results, and migrate anything that cannot be verified. That sequence is the whole job.

Start with the inventory, because it is always longer than expected. Email, file sharing, backup, ticketing, CRM, engineering tools, remote monitoring, and any integration passing data between them. Then verify each against the Marketplace at Class C or above, capturing evidence as you go. Anything that fails verification needs either a documented equivalency package from the vendor or a migration plan with a date on it.

The part that gets missed is that this is not a one-time exercise. Vendor certifications lapse. Your team adopts a new tool. Someone enables an integration that moves data somewhere new. A cloud environment that was compliant in January can quietly stop being compliant by June with nobody making a decision about it. Keeping the inventory current is exactly the kind of continuous work a break-fix IT arrangement never covers, because nothing has broken and nobody has called.

Interweave manages this as part of the environment rather than as a separate compliance exercise. Our Managed IT Department owns the cloud stack the same way it owns the network, which means new tools get evaluated against your contract obligations before they are deployed rather than discovered during an assessment. Our managed compliance program keeps the documentation current between assessments. To be clear about scope: we do not perform FedRAMP certifications and we are not a 3PAO. What we do is make sure the cloud services in your environment hold the certification your contract requires, and that you can prove it.

Frequently Asked Questions

Is FedRAMP Certification Mandatory?

FedRAMP certification is mandatory for cloud service providers selling to federal agencies for use cases inside the program's scope, and it is not mandatory for defense contractors as organizations. Contractors face a related but separate obligation under DFARS 252.204-7012 to use cloud services meeting the Moderate baseline, now Class C, for CUI.

Is ChatGPT FedRAMP Approved?

Public AI chatbots are treated by FedRAMP scope guidance as search engines, which are outside the program's scope when used with public or non-sensitive information only. That exclusion depends entirely on what you put in. FedRAMP guidance draws the line at sensitivity: an AI assistant working against strictly controlled information falls inside the scope of FedRAMP, while one working against public information does not. For a defense contractor the practical rule is direct. Never paste CUI into a public AI tool. Doing so is a disclosure, and no scope exclusion protects you from it.

Are Azure and Google Cloud FedRAMP Certified?

Major providers including Microsoft, Google, Amazon Web Services, and Adobe hold FedRAMP certification for specific cloud service offerings. Certification attaches to the individual offering rather than the company, so a provider's government edition may be certified while its standard commercial edition is not. Verify the exact offering you plan to use in the Marketplace.

What Are the Three Main Goals of the FedRAMP Program?

The three main goals of the FedRAMP program are to protect federal information in cloud systems consistently, to standardize security assessment and continuous monitoring across the government, and to eliminate duplicate agency-by-agency reviews so one certification can be reused government-wide.

What Is a 3PAO in FedRAMP?

A 3PAO is a Third-Party Assessment Organization accredited by the American Association for Laboratory Accreditation to conduct independent security assessments of cloud service offerings. The 3PAO tests the provider's controls and produces the Security Assessment Report that agencies rely on. 3PAOs are listed in the FedRAMP Marketplace.

What Is the DoD Equivalent to FedRAMP?

The DoD equivalent to FedRAMP is the Cloud Computing Security Requirements Guide, which layers additional requirements on top of FedRAMP baselines through Impact Levels 2, 4, 5, and 6. Cloud services carrying DoD workloads must satisfy both FedRAMP and the applicable Impact Level. These Impact Levels are a separate construct from FedRAMP classes, which is precisely the overlap the 2026 rename was meant to resolve.

Is FedRAMP Worth It?

For a cloud provider, FedRAMP certification is the entry ticket to federal sales, and one certification is reusable across every agency. For a defense contractor, the question is different, because you are not buying certification, you are buying eligibility. Using certified services is what keeps your CUI environment defensible during a CMMC assessment.

Putting It All Together

FedRAMP certification is not something you obtain. It is something you verify. Your obligation under DFARS 252.204-7012 is to make sure every cloud service holding CUI meets the Moderate baseline, which is now Class C, and to hold the evidence proving it. Your CMMC assessor will look at that evidence, and a non-certified platform inside your boundary becomes a finding against your company, not your vendor.

Two things are worth acting on now. The terminology shift means the words on your contract and the words on the Marketplace will not match for the rest of this year, so document the translation before an assessor asks. And if CUI is moving through a standard commercial email or file-sharing tenant, that is an architectural problem with a months-long fix, which makes it far cheaper to find today than during assessment prep.

We have spent more than 20 years building compliant IT environments for defense suppliers across Huntsville and North Alabama, and cloud inventory is where we find the most surprises. A free scoping audit will map every service touching your CUI, check each one against the Marketplace, and show you the gap between where your environment is and what your contract requires. Reach out to Interweave Technologies or call (256) 837-2300.