Free Consultation
#fedramp
#compliance
#nist

FedRAMP Explained: Authorization, Impact Levels, and Selling to Government

September 29, 2026

Federal agencies generally cannot purchase cloud software from a vendor that has not cleared a specific government security bar. That bar has a name: the Federal Risk and Authorization Management Program, or FedRAMP. FedRAMP is the standardized approach agencies use for security assessment and authorization of cloud computing products and services that handle unclassified federal information. Cloud service providers that want to offer cloud services to federal agencies must hold a FedRAMP designation to be listed on the FedRAMP Marketplace.

The program has grown substantially in recent years, driven by rising federal cloud adoption and a 2026 modernization effort that reshaped how authorization works. This article lays out what FedRAMP is, how the authorization process runs, what the Low, Moderate, and High impact levels mean for a vendor's addressable market, and what the program's 2026 changes mean for cloud companies planning a federal sales strategy.

What Is FedRAMP?

FedRAMP is the federal government's standardized program for vetting the security of cloud products before agencies use them. Congress established the program in 2011 to provide a risk-based approach to adopting and using cloud services across the federal government. For over a decade it ran on agency policy alone, without a permanent legal foundation.

That changed in late 2022. Congress created a permanent legal foundation for FedRAMP through the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 (Public Law 117-263). The law also created a FedRAMP Board within the General Services Administration. The board advises the FedRAMP Administrator on requirements, guidelines, and priorities for cloud security assessments. Roughly two years after that, the Office of Management and Budget issued Memorandum M-24-15 to guide government-wide implementation of the modernized program.

For a cloud vendor, the practical takeaway sits underneath all that legal history: FedRAMP compliance is not optional paperwork. It is the entry ticket for selling directly to a federal agency, and increasingly a factor agencies weigh when purchasing indirectly through resellers or integrators as well.

How Does FedRAMP Authorization Work?

FedRAMP authorization is a multi-stage process that starts with categorizing a cloud system and ends with ongoing monitoring. Cloud service offerings get categorized into one of three impact levels, Low, Moderate, and High, across three security objectives: confidentiality, integrity, and availability. That categorization follows a federal standard for rating potential harm from a data breach, and it determines everything that follows.

From there, the traditional path runs through a sponsoring agency. The first step in pursuing FedRAMP authorization is for a cloud service provider to establish a partnership with a federal agency. This agency-led route remains the only formal path to FedRAMP authorization available to most cloud service providers today. The provider then builds out its security documentation and control implementation against the relevant baseline.

Independent verification comes next. A cloud provider implements controls under the relevant tier, and an accredited assessor known as a Third-Party Assessment Organization independently validates that work. Once the program reviews and approves the package, the provider achieves FedRAMP authorization. From that point, other agencies can reuse the work already done: an individual federal agency can review the existing package and issue its own Authority to Operate without repeating the full assessment. That reuse principle, sometimes summarized as "authorize once, use many times," is the core economic argument for pursuing FedRAMP in the first place.

FedRAMP High vs Moderate vs Low

FedRAMP impact levels sort cloud systems by how much damage a breach could cause, and each level carries a different set of required controls. Low systems process public or non-sensitive data. Moderate systems handle Controlled Unclassified Information or other sensitive but unclassified data. High systems support critical missions where a breach could cause severe or catastrophic effects.

Moderate is where most authorized products land. Moderate impact applies where loss of confidentiality, integrity, or availability would cause serious harm to an agency's operations, assets, or individuals. That harm can include significant operational damage or financial loss, short of loss of life, and it accounts for the majority of cloud offerings that receive FedRAMP authorization.

The control burden scales sharply between tiers. The FedRAMP Moderate baseline includes several hundred security controls covering a broad range of security domains. Moderate systems demand more thorough policies, processes, and monitoring than Low systems. The FedRAMP High baseline builds on the Moderate control set and adds a significantly higher number of controls, with added emphasis on strong identity and access management. That includes multi-factor authentication and privileged access monitoring.

A smaller, lighter-weight option exists below Low as well. FedRAMP also offers a Low Impact SaaS baseline designed for software providers hosting low-risk government data. It reduces documentation requirements and simplifies continuous monitoring, which supports a faster and lower-cost path to authorization.

One caution matters for vendors chasing defense contracts specifically. FedRAMP Moderate covers most civilian agency needs and much of the Controlled Unclassified Information handled outside the Defense Department. Cloud services authorized at FedRAMP Moderate do not automatically satisfy the Defense Department's own cloud security rules, which apply a separate classification framework for defense workloads.

What FedRAMP 20x Changes for Vendors

FedRAMP is in the middle of its biggest structural change in over a decade, and vendors evaluating the program today are working with a moving target. In 2026 the program finalized a consolidated set of rules for cloud service authorization. Those rules made a modernized certification path called FedRAMP 20x widely available and began shifting the framework from impact levels toward certification classes. As part of that shift, the program formally changed its terminology from "authorization" to "certification" and replaced impact-level labels with Classes A, B, C, and D.

Older and newer paths currently run side by side. FedRAMP Rev5, the legacy certification framework, is planned to remain available for a transition period, though officials have urged Rev5 providers not to wait to understand the new rules. The High tier is the last to transition. FedRAMP 20x is targeted to enter its next phase with a Class D pilot covering the equivalent of High impact, planned for fiscal year 2027.

For a vendor mapping a federal sales strategy in 2026, this transition means two things. First, the underlying impact-level logic still determines the scope of work even as the naming shifts toward classes: Low, Moderate, and High risk remain tied to data sensitivity. Second, the choice of which authorization path to pursue now depends partly on timing. A company further along on Rev5 may finish that route, while a company starting fresh has reason to look closely at the newer certification track.

What FedRAMP Compliance Means for a Federal Sales Strategy

FedRAMP compliance functions as a gate on total addressable market, not a one-time compliance checkbox. Deciding which baseline to pursue is fundamentally a business decision layered on top of a technical one. Vendors commonly treat it as a growth path rather than a single destination. Companies may start with Low or the Low Impact SaaS baseline and gradually upgrade to Moderate and High to expand government contracting opportunities.

That upgrade path takes real lead time. Higher tiers add control families that touch identity management, logging, and system architecture, not just documentation. Vendors weighing a jump to a higher impact tier benefit from starting security and evidence-gathering work well before a target agency needs a decision. Reauthorization work, sponsor negotiations, and control uplifts often stretch across many months. A vendor that waits until a contract is on the table to start the FedRAMP conversation is usually too late to compete for it.

Moving Forward with FedRAMP

FedRAMP determines which cloud vendors get considered for federal contracts. The impact level a vendor targets shapes how large and how lucrative that opportunity can become. The program's 2026 changes add real near-term complexity. The underlying logic has not changed: security investment should match the sensitivity of the data a system will handle. Vendors that treat FedRAMP planning as a long-term sales strategy, rather than a late-stage compliance scramble, tend to reach agency customers faster and with fewer costly missteps along the way.

Planet 9 is a Bay Area cybersecurity consulting firm specializing in FedRAMP readiness for SMBs in defense contracting and government suppliers. Our vCISOs and compliance managers help organizations choose the right approach, configure GRC tools if needed, and get audit-ready without wasted time.

Book a Free Consultation

Schedule a free consultation today to explore how Planet 9 can help you achieve your security and compliance goals.
Book Free Consultation

FAQs

How does a vCISO service differ from hiring a full-time CISO?
A part-time CISO offers the same strategic oversight and expertise as a full-time CISO but on a flexible, cost-effective basis. It’s ideal for small to mid-sized businesses that need executive-level guidance without the overhead.
Is a virtual CISO service suitable for regulated industries like healthcare or finance?
Yes, virtual CISOs (or fractional CISOs) are especially valuable for industries with strict compliance requirements such as HIPAA, PCI DSS, or GLBA. They help ensure your organization meets regulatory standards and is prepared for audits.
What can I expect during a vCISO engagement?
Our vCISO service typically includes cybersecurity assessments, program development, compliance planning, incident response strategy, vendor risk management, and ongoing executive reporting tailored to your business.
How do I know if my business needs a CISO-as-a-Service?
If you lack in-house security leadership, struggle with compliance, or face growing cyber risks, a vCISO can fill that gap, providing strategic direction, improving resilience, and helping you make smarter security investments.

FAQs

What is FedRAMP?
FedRAMP, the Federal Risk and Authorization Management Program, is the federal government's standardized process for assessing and authorizing the security of cloud products and services before agencies use them. Congress made it the legally required approach for authorizing cloud systems that handle unclassified federal information, replacing what had been agency-level policy guidance.
What is FedRAMP authorization?
FedRAMP authorization is the outcome of a formal security assessment process in which a cloud provider implements a required set of controls, undergoes independent testing by an accredited third-party assessor, and receives sign-off that a federal agency can rely on to grant its own Authority to Operate. Once granted, other agencies can reuse the same authorization package rather than each running a separate assessment.
What is the difference between FedRAMP High and Moderate?
FedRAMP Moderate applies to systems where a breach could cause serious harm to agency operations, assets, or individuals, and it covers the majority of authorized cloud products. FedRAMP High applies to systems supporting the government's most sensitive, high-consequence missions and requires a substantially larger set of security controls, particularly around identity verification and access monitoring.
Do all cloud vendors need FedRAMP to sell to government agencies?
Cloud vendors seeking to sell software or infrastructure directly to federal agencies generally need a FedRAMP designation to be listed as an option in the federal marketplace. Vendors selling only through certain resale arrangements or serving state and local governments may face different rules, so the need for FedRAMP depends heavily on the specific customer and contract structure.
What is FedRAMP 20x?
FedRAMP 20x is a modernization of the FedRAMP program that replaces much of the older manual, document-heavy authorization process with a faster, more automated certification path. As of 2026 it uses new certification classes in place of the traditional Low, Moderate, and High labels, while the legacy Rev5 process continues to run alongside it during a multi-year transition.

Related blog posts