Federal Risk and Authorization Management Program (FedRAMP) is a program that standardizes how the US federal government assesses, authorizes, and monitors cloud services.
FedRAMP compliance
FedRAMP is required for any organization providing a cloud-based service to the US federal government.
There are four FedRAMP baselines (complexity levels) - the determination of which level an org needs to do is by discussion with the US federal government:
Li-SaaS (does not store PII - personally identifiable information): 156 controls
Low: 156 controls
Moderate: 323 controls
High: 410 controls
FedRAMP requires a formal audit from a Third-Party Assessment Organization (3PAO). You can add your 3PAO as an auditor in Vanta so they can review your controls, tests, and evidence directly.
We recommend working with a FedRAMP third-party consultant for full readiness support and implementation.
FedRAMP core requirements
Sponsorship: US federal agency or FedRAMP Board agrees to “back” an organization through the process
Documentation: Many unique policies & procedures, a system security plan (SSP), and other FedRAMP-specific documentation
Controls: Selection and implementation of your FedRAMP baseline (Li-SaaS, Low, Moderate, High)
Assessments:
Readiness Assessment Report (RAR): Pre-assessment review of the organization’s security capabilities
Security Assessment Report (SAR): Full security assessment that evaluates the in-place controls of the organization and system/service
FedRAMP status
FedRAMP status refers to the level of compliance an organization or cloud service provider (CSP) has achieved within the FedRAMP.
Ready: The FedRAMP assessor attests to the organization’s security capability and accepts the RAR
In-Process: The organization is actively working towards authorization
Authorized: The organization has successfully completed the SAR and maintains a FedRAMP Authorization
How Vanta supports FedRAMP
Vanta offers features for supported government frameworks designed to support FedRAMP readiness and ongoing compliance workflows. For example:
OSCAL exports: Export your framework's controls, tests, and evidence as an OSCAL document in JSON format. Publish the OSCAL export as a synced knowledge base resource to keep the latest version available on your Trust Center.
📖 Learn more: See a full overview of Vanta's FedRAMP product.
