Federal Risk and Authorization Management Program (FedRAMP) is a program that standardizes how the US federal government assesses, authorizes, and monitors cloud services.
FedRAMP compliance
FedRAMP is required for any organization providing a cloud-based service to the US federal government.
There are four FedRAMP baselines (complexity levels) - the determination of which level an org needs to do is by discussion with the US federal government:
Li-SaaS (does not store PII - personally identifiable information): 156 controls
Low: 156 controls
Moderate: 323 controls
High: 410 controls
FedRAMP requires a formal audit from a Third-Party Assessment Organization (3PAO). You can add your 3PAO as an auditor in Vanta so they can review your controls, tests, and evidence directly.
We recommend working with a FedRAMP third-party consultant for full readiness support and implementation.
FedRAMP core requirements
Sponsorship: US federal agency or FedRAMP Board agrees to “back” an organization through the process
Documentation: Many unique policies & procedures, a system security plan (SSP), and other FedRAMP-specific documentation
Controls: Selection and implementation of your FedRAMP baseline (Li-SaaS, Low, Moderate, High)
Assessments:
Readiness Assessment Report (RAR): Pre-assessment review of the organization’s security capabilities
Security Assessment Report (SAR): Full security assessment that evaluates the in-place controls of the organization and system/service
FedRAMP status
FedRAMP status refers to the level of compliance an organization or cloud service provider (CSP) has achieved within the FedRAMP.
Ready: The FedRAMP assessor attests to the organization’s security capability and accepts the RAR
In-Process: The organization is actively working towards authorization
Authorized: The organization has successfully completed the SAR and maintains a FedRAMP Authorization
How Vanta supports FedRAMP
Vanta offers features for supported government frameworks designed to support FedRAMP readiness and ongoing compliance workflows. For example:
OSCAL exports: Export your framework's controls, tests, and evidence as an OSCAL document in JSON format. Publish the OSCAL export as a synced resource in your Knowledge Base to keep the latest version available on your Trust Center.
Account auto-approval: Wildcard domains let you share your Trust Center continuously with federal agency reviewers. For example, you can create a Customer Trust Account called Government Entities, assign it the
*.govdomain, turn on auto-approval for Trust Center access, and disable the NDA requirement for that account. From that point on, every requester whose email matches*.govis approved instantly and grouped under that account, without requiring you to review access requests manually.Control access: FedRAMP customers can share their full control set—including pass/fail status—with federal agency reviewers, while keeping commercial visitors limited to public controls only. In the Trust Center editor, set the relevant control category visibility to shareable, set its status visibility to show all controls with status, and add a tag to the controls. Then add that same tag to your federal agency's Customer Trust Account. Agency reviewers see the full control set with status, while everyone else sees only your public controls.
📖 Learn more: See a full overview of Vanta's FedRAMP product.
