What Is FedRAMP Compliance and What It Means for Defense Suppliers
FedRAMP compliance is the federal standard a cloud service has to meet before it can hold government data. For a defense supplier, FedRAMP compliance is not something you achieve. It is something your cloud vendors have to prove to you, and something you then have to prove to an assessor.
Most contractors work that out eventually. What catches them is the next part. There are two ways a cloud service can satisfy DFARS 252.204-7012, and the one that sounds easier is actually the harder of the two. FedRAMP Moderate equivalency demands 100% of the controls with zero open findings, which is a stricter bar than an actual FedRAMP certification, where open findings are permitted.
Contractors reach for equivalency thinking it is the back door. It is not a back door. It is a taller wall.
This article covers what FedRAMP compliance requires, what your obligation looks like under DFARS 7012, what equivalency actually demands, what documentation you have to hold, and what fails a CMMC assessment on the cloud side.
What Is FedRAMP Compliance?
FedRAMP compliance is the set of security requirements a cloud service provider satisfies before federal agencies or defense contractors can put government data in that provider's platform. The Federal Risk and Authorization Management Program is run by the General Services Administration and builds its baselines from NIST Special Publication 800-53.
Compliance runs on evidence rather than assertion. A provider implements the controls, an accredited Third-Party Assessment Organization tests them independently, and the results go into a package a federal agency reviews. The provider then carries permanent continuous monitoring duties: monthly vulnerability scans, annual reassessment, and ongoing management of open items.
For a defense supplier, the reason this matters is contractual rather than aspirational. DFARS clause 252.204-7012 requires that any external cloud service storing, processing, or transmitting covered defense information meet the FedRAMP Moderate baseline or an equivalent standard. That obligation predates CMMC entirely and has applied since the clause took effect.
The scale of who this touches is easy to underestimate. The Department of Defense regulatory analysis behind the final DFARS rule identifies 337,968 impacted entities, of which 229,818 are small businesses. Nearly all of them use cloud services. Very few have documented which ones hold FedRAMP standing.
What Does FedRAMP Stand For and How Does the Program Work?
FedRAMP stands for the Federal Risk and Authorization Management Program. It operates as a do once, use many framework, so a cloud service assessed once can be reused across agencies instead of every agency running its own duplicate review.
The program began in 2011 through an Office of Management and Budget memorandum. In December 2022 Congress codified it through the FedRAMP Authorization Act, passed as part of the FY2023 National Defense Authorization Act. That statute made FedRAMP the authoritative approach for federal cloud security assessment and introduced a presumption of adequacy, meaning an approved product is presumed suitable for reuse unless an agency documents a specific need for further review.
Four artifacts make up a security package, and a defense supplier should recognize all four by name because you may need to ask for them:
- System Security Plan. Describes how every required control is implemented and how the system is architected. For a Moderate-baseline service this routinely runs into the hundreds of pages. The same document type governs your own environment, which is why a well-built system security plan is the backbone of any compliance program.
- Security Assessment Report. Produced by the 3PAO after independently testing the controls. This is the document that separates a tested claim from a marketing claim.
- Plan of Action and Milestones. Tracks identified gaps and remediation dates. Whether a POA&M is permitted turns out to be the single most important difference between the two compliance pathways, which we come to below.
- Continuous monitoring deliverables. Monthly scan results, annual assessment output, and incident response records. Compliance is a state you maintain, not a certificate you frame.
What Are the FedRAMP Certification Classes?
FedRAMP replaced the Low, Moderate, and High impact levels with Certification Classes A through D under the Consolidated Rules for 2026. Class A is a new pilot tier available only on the FedRAMP 20x path. Class B covers what used to be Low along with Low-Impact SaaS. Class C covers Moderate. Class D covers High.
Get that mapping right, because it is commonly reported incorrectly. Low did not become Class A. Low folded into Class B, and Class A is a new entry tier that did not previously exist.
The control counts below come from the NIST SP 800-53 Revision 5 baselines, and the cost and timeline figures are industry estimates rather than government numbers.
Attribute
Class B (formerly Low)
Class C (formerly Moderate)
Class D (formerly High)
Controls, NIST SP 800-53 Rev 5
About 156
About 323
About 410
Data sensitivity
Limited adverse impact if breached
Serious adverse impact; covers most CUI
Severe or catastrophic impact
Satisfies DFARS 7012 for CUI
No
Yes, this is the minimum
Yes, exceeds the minimum
Typical timeline, industry estimate
6 to 12 months
12 to 18 months
18 to 36 months
Typical cost, industry estimate
$250,000 to $500,000
$500,000 to $1,500,000
$2,000,000 and up
Class C is the class defense suppliers care about, because it is the one DFARS points at. As of August 2026 the FedRAMP Marketplace lists 528 certified cloud services plus 28 certified through the FedRAMP 20x path, according to FedRAMP.gov, and the large majority of certifications sit at the Moderate, now Class C, baseline.
Worth noting the two frameworks stacked on top of each other here. FedRAMP classes are built on NIST 800-53, while your own obligations run on NIST 800-171. Achieving NIST compliance inside your network does nothing to establish your vendors' standing, and vice versa.
Does the DoD Require FedRAMP for Defense Contractors?
Yes, the DoD requires FedRAMP for defense contractors through DFARS clause 252.204-7012, but the requirement lands on your cloud services rather than on your company. The clause applies to DoD acquisitions other than commercial off-the-shelf items.
DFARS 7012 carries four obligations, and the cloud requirement is only one of them.
- Implement NIST SP 800-171. All 110 security requirements apply to any system touching covered defense information.
- Verify your cloud services. Any external cloud service handling that information must meet FedRAMP Moderate, now Class C, or documented equivalency.
- Report incidents within 72 hours. Cyber incidents go to DIBNet within 72 hours of discovery.
- Preserve forensic evidence. System images and relevant data are retained for at least 90 days after an incident report.
Prime contractors flow every one of these down to subcontractors handling the same information. That flow-down is a private contractual obligation between two companies, which means it does not move when federal implementation schedules move.
That distinction matters right now. On July 13, 2026 the Department of War suspended CMMC Phase 2, pausing the planned expansion of third-party assessment requirements. Phase 1 self-assessments remain in force and DFARS 252.204-7012 was untouched. Contractors who read the pause as relief on the cloud side read it wrong. The cloud obligation never depended on the CMMC certification rollout calendar in the first place.
What Is FedRAMP Moderate Equivalency?
FedRAMP Moderate equivalency is a documented demonstration that a cloud service meets the full Moderate baseline without holding FedRAMP certification itself. A DoD CIO memorandum issued December 21, 2023 defines what qualifies.
The criteria are narrow. The provider must demonstrate 100% compliance with the Moderate baseline, with no outstanding POA&Ms, through an assessment conducted by an independent FedRAMP-recognized 3PAO. No self-attestation is permitted. The provider then supplies a complete Body of Evidence, which may be reviewed by the Defense Industrial Base Cybersecurity Assessment Center.
The Body of Evidence is a defined document set rather than a summary letter. It includes the System Security Plan, the Security Assessment Plan, the Security Assessment Report, scan results, penetration testing documentation, and continuous monitoring materials validated by the 3PAO.
Why Equivalency Is Harder Than Certification
Equivalency is harder than certification because a FedRAMP certification permits open findings and equivalency does not. A certified service can carry POA&M items and remain in good standing. An equivalent service cannot carry a single control finding out of its assessment.
Read the two standards side by side and the asymmetry is obvious. Certification asks a provider to implement the baseline and document what remains outstanding. Equivalency asks for perfection, independently proven, with every finding corrected and validated as closed by the assessor before the claim holds. Operational POA&Ms arising later are allowed; findings from the equivalency assessment are not.
This inverts what most contractors assume. Equivalency is not the affordable alternative for a vendor who could not manage full certification. It is a higher technical bar reached by fewer providers, which is exactly why a casual equivalency claim deserves more scrutiny than a Marketplace listing, not less.
Two consequences fall on you rather than on the vendor.
First, you hold the evidence. The contractor provides the Body of Evidence to the C3PAO during a CMMC Level 2 assessment. Your vendor's paperwork becomes your exhibit, and a vendor who will not release it under NDA has effectively given you nothing to stand on.
Second, you carry the liability. The DoD memorandum identifies the contractor as the approver for use of the cloud service and makes the contractor responsible for reporting a compromise of that service. If your vendor's controls slip, the reporting obligation and the exposure are yours. Building that verification into a structured defense contractor compliance program is considerably cheaper than discovering the gap during an assessment.
What Is a Customer Responsibility Matrix and Who Operates Your Half?
A Customer Responsibility Matrix is the document a cloud provider publishes that splits every security control into what the provider operates and what you must operate yourself. Every certified service ships one, and it is the most commonly ignored document in cloud compliance.
The split is real work, not paperwork. A provider may hold Class C standing for its platform while the matrix assigns you configuration of access controls, review of user permissions, retention of audit logs, encryption key handling, and incident escalation on your side of the boundary. Those are your controls in your assessment. Certification on the provider's side does not implement them.
This is where a compliance program quietly fails. The contractor selects a certified platform, files the Marketplace listing as evidence, and never operates the customer column. An assessor opens the matrix, asks who reviews privileged access quarterly, and there is no answer because the question never belonged to anyone.
Ownership is the whole issue. Under a break-fix IT arrangement, nobody is paid to review a permissions report in a month when nothing has broken. The provider bills when something fails, and an unreviewed access log has not failed in any way a ticket would capture. That is the structural difference between managed services and a vendor on call.
We built our Managed IT Department to operate the customer column as part of running the environment, with unlimited remote and onsite support on one all-inclusive monthly fee, so the controls the matrix assigns you actually get performed on the months nothing goes wrong.
What Fails a CMMC Assessment on the Cloud Side?
The cloud findings that fail assessments come from services that were never eligible to hold CUI, equivalency claims with no evidence behind them, and customer-side controls nobody operated. The cloud environment sits inside your assessment boundary and gets evaluated exactly like your own network, which is why government contracting compliance has to cover the vendor stack rather than stopping at the firewall.
Five patterns account for most of it.
- Commercial tenants holding CUI. Standard commercial subscriptions of common productivity platforms are different services from their government editions and generally hold no Moderate-baseline standing. The government editions do. Contractors assume a brand is a brand and put export-controlled drawings in the wrong tenant.
- Equivalency asserted, not documented. A vendor states equivalency in a sales deck and cannot produce a 3PAO-assessed Body of Evidence. Running on certified infrastructure underneath does not make the application on top of it equivalent.
- Wrong class. Class B, formerly Low, does not satisfy the CUI requirement no matter how well regarded the vendor is.
- Out-of-boundary components. Certification covers a defined system boundary. Plugins, integrations, and add-on modules outside that boundary are not covered, and data routinely flows through them.
- Unowned customer responsibilities. The matrix assigns you controls and no evidence exists that anyone performed them.
Every one of these is cheaper to find early. Migrating a CUI workload out of an ineligible platform means moving mailboxes, re-pointing integrations, retraining staff, and rebuilding evidence, which is measured in months. A cloud-focused gap analysis surfaces all five patterns before an assessor does.
What Happens if You Misrepresent Cloud Compliance?
Misrepresenting cloud security compliance can produce civil False Claims Act liability for the company and criminal charges for the individuals who signed off. The Department of Justice has pursued both.
On December 10, 2025 a federal grand jury in the District of Columbia indicted a former senior manager at a Virginia-based federal contractor on charges of major government fraud, two counts of wire fraud, and two counts of obstructing a federal audit. Prosecutors allege a multi-year scheme between March 2020 and November 2021 to mislead federal agencies about the security of a cloud platform used by the Army and other agencies, on contracts valued at roughly $250 million.
The specific allegations are worth sitting with. Prosecutors say the platform was falsely represented as meeting FedRAMP High and DoD Impact Level 4 and 5 requirements despite repeated internal warnings that it lacked required access controls, logging, and monitoring, and that assessors were obstructed during audits by concealment of known deficiencies. The wire fraud counts carry a maximum penalty of 20 years. These are allegations and the case has not been decided.
Two things make this case different from the civil settlements that came before it. The charges are criminal rather than civil, and they target an individual rather than the company. Personal liability for cybersecurity representations is no longer theoretical.
For a defense supplier the lesson runs in a direction people miss. You will not be indicted for your vendor's controls. You are exposed for what you assert about them. Stating on a form that your cloud environment meets Moderate requirements, when nobody verified it, is the representation that carries the risk. Documenting the verification is what a compliance audit process exists to produce.
Can You Automate FedRAMP Compliance?
You can automate significant parts of compliance evidence collection, and FedRAMP itself is moving that direction, but automation does not remove the obligation to verify and operate. FedRAMP 20x replaces narrative control descriptions with machine-readable Key Security Indicators and continuous evidence collection rather than point-in-time documentation.
For a defense supplier, useful automation covers the recurring work: scheduled re-checks of vendor status, alerting when a certification lapses or a boundary changes, continuous log collection, and evidence capture that timestamps itself. That reduces the labor of staying current considerably.
What automation does not do is decide whether a service belongs in your CUI boundary, read a Body of Evidence and judge whether it holds, or perform the controls a responsibility matrix assigns to your staff. Those are judgment and operations. Tools support them; tools do not replace them.
How Do You Keep Cloud Compliance Current Between Assessments?
You keep cloud compliance current by maintaining a live inventory of services touching CUI, re-verifying vendor status on a schedule, and reviewing changes before they reach production. A compliant cloud environment does not stay compliant on its own.
Drift arrives through ordinary business activity. A vendor's certification lapses at renewal. A team adopts a new tool because it solves a real problem. Someone enables an integration that moves data into a service nobody assessed. A provider changes its boundary. None of these events announce themselves, and each one can move you out of compliance without a single decision being made about it.
Four practices hold the line: a maintained inventory of every service in the CUI boundary, quarterly re-verification against the Marketplace with dated evidence, a review gate so new tools are checked against contract obligations before deployment rather than after, and an owner for the customer-responsibility controls with a schedule and a record.
None of that is difficult. All of it is continuous, which is the reason it fails in practice. Our managed compliance program runs these cycles as part of operating the environment, so the documentation is current when a prime asks rather than reconstructed under deadline. Defense suppliers across the Redstone Arsenal supplier base tend to find the inventory step alone surfaces two or three services nobody had scoped.
Frequently Asked Questions
Who Needs To Be FedRAMP Compliant?
Cloud service providers selling to federal agencies need FedRAMP compliance for their offerings. Defense contractors do not become FedRAMP compliant as organizations; they are required under DFARS 252.204-7012 to use cloud services that hold Class C standing, formerly Moderate, or documented equivalency for anything touching covered defense information.
What Is the Difference Between FedRAMP Authorization and FedRAMP Certification?
The difference is terminology rather than substance. Under the Consolidated Rules for 2026, finalized June 25, 2026, FedRAMP replaced the term authorization with certification, because FedRAMP certifies that an assessment was completed while the agency issues the Authority to Operate. Existing authorizations carry over with the same controls and the same boundary.
Is Microsoft GCC High FedRAMP Compliant?
Microsoft 365 GCC High holds a FedRAMP High authorization, which exceeds the Moderate baseline DFARS requires, and it runs on Azure Government with United States person access restrictions. It is the environment most commonly used by contractors handling export-controlled CUI. Standard Microsoft 365 Commercial is a separate service and does not hold Moderate or High authorization.
Is FedRAMP for Cloud Only?
Yes, FedRAMP applies to cloud service offerings only, covering Software as a Service, Platform as a Service, and Infrastructure as a Service. On-premises systems fall under other federal frameworks, principally the Risk Management Framework described in NIST SP 800-37.
What Is the Difference Between FedRAMP and FISMA?
FISMA is the 2002 federal law requiring agencies to protect government information systems. FedRAMP is the program that applies that mandate specifically to cloud services, giving agencies a standardized way to assess cloud providers rather than each agency interpreting FISMA independently.
What Is the Difference Between FedRAMP and SOC 2?
FedRAMP is a government program built on NIST 800-53, requiring roughly 323 controls at Class C, independent 3PAO assessment, and continuous monitoring. SOC 2 is a voluntary industry attestation against the AICPA Trust Services Criteria with no government mandate. SOC 2 can shorten a provider's path to FedRAMP because controls overlap, but it does not substitute for FedRAMP in defense contexts.
What Is a 3PAO?
A 3PAO is a Third-Party Assessment Organization accredited by the American Association for Laboratory Accreditation to independently assess cloud service offerings. The 3PAO tests controls and produces the Security Assessment Report, and only a 3PAO assessment can support a FedRAMP Moderate equivalency claim, since self-attestation is not permitted.
What It All Comes Down To
FedRAMP compliance reaches defense suppliers through their vendors, not through their own certifications. Your obligation under DFARS 252.204-7012 is to confirm that every cloud service holding covered defense information carries Class C standing or documented equivalency, to hold the evidence, and to operate the controls the responsibility matrix assigns to you.
Equivalency deserves the most attention, because it is the pathway contractors accept most casually and the standard is the strictest one in the framework. One hundred percent of the controls, zero findings out of the assessment, no self-attestation, and a full Body of Evidence you can hand to an assessor. A vendor who cannot produce that package has given you a claim, not a compliance position, and the exposure for relying on it is yours rather than theirs.
None of this is one-time work. Vendor status lapses, boundaries change, and new tools arrive through the front door every quarter, which is why the contractors who stay ready are the ones treating cloud verification as a standing process instead of an assessment-season scramble. Budgeting for that continuity is a normal part of CMMC compliance support rather than an unexpected cost.
We have spent more than 20 years building compliant IT environments for defense suppliers across Huntsville and North Alabama, and the cloud inventory is consistently where we find the most exposure. A free scoping audit will map every service touching your CUI, verify each against the Marketplace, review any equivalency claims against what the DoD memorandum actually requires, and show you which customer-side controls currently have no owner. Reach out to Interweave Technologies or call (256) 837-2300.
.webp)
.webp)



.webp)





Share Post