Skip to main content

FedRAMP

Federal Risk and Authorization Management Program (FedRAMP) is a program that standardizes how the US federal government assesses, authorizes, and monitors cloud services.


FedRAMP compliance

FedRAMP is required for any organization providing a cloud-based service to the US federal government.

There are four FedRAMP baselines (complexity levels) - the determination of which level an org needs to do is by discussion with the US federal government:

  • Li-SaaS (does not store PII - personally identifiable information): 156 controls

  • Low: 156 controls

  • Moderate: 323 controls

  • High: 410 controls

FedRAMP requires a formal audit from a Third-Party Assessment Organization (3PAO). You can add your 3PAO as an auditor in Vanta so they can review your controls, tests, and evidence directly.

We recommend working with a FedRAMP third-party consultant for full readiness support and implementation.


FedRAMP core requirements

  • Sponsorship: US federal agency or FedRAMP Board agrees to “back” an organization through the process

  • Documentation: Many unique policies & procedures, a system security plan (SSP), and other FedRAMP-specific documentation

  • Controls: Selection and implementation of your FedRAMP baseline (Li-SaaS, Low, Moderate, High)

  • Assessments:

    • Readiness Assessment Report (RAR): Pre-assessment review of the organization’s security capabilities

    • Security Assessment Report (SAR): Full security assessment that evaluates the in-place controls of the organization and system/service


FedRAMP status

FedRAMP status refers to the level of compliance an organization or cloud service provider (CSP) has achieved within the FedRAMP.

  • Ready: The FedRAMP assessor attests to the organization’s security capability and accepts the RAR

  • In-Process: The organization is actively working towards authorization

  • Authorized: The organization has successfully completed the SAR and maintains a FedRAMP Authorization


How Vanta supports FedRAMP

Vanta offers features for supported government frameworks designed to support FedRAMP readiness and ongoing compliance workflows. For example:

  • OSCAL exports: Export your framework's controls, tests, and evidence as an OSCAL document in JSON format. Publish the OSCAL export as a synced resource in your Knowledge Base to keep the latest version available on your Trust Center.

  • Account auto-approval: Wildcard domains let you share your Trust Center continuously with federal agency reviewers. For example, you can create a Customer Trust Account called Government Entities, assign it the *.gov domain, turn on auto-approval for Trust Center access, and disable the NDA requirement for that account. From that point on, every requester whose email matches *.gov is approved instantly and grouped under that account, without requiring you to review access requests manually.

  • Control access: FedRAMP customers can share their full control set—including pass/fail status—with federal agency reviewers, while keeping commercial visitors limited to public controls only. In the Trust Center editor, set the relevant control category visibility to shareable, set its status visibility to show all controls with status, and add a tag to the controls. Then add that same tag to your federal agency's Customer Trust Account. Agency reviewers see the full control set with status, while everyone else sees only your public controls.

📖 Learn more: See a full overview of Vanta's FedRAMP product.