Accelerating FedRAMP High ATOs to Address Fast Growing Federal Demand
Federal and Defense agencies are increasingly encouraged to buy the best of breed commercial solutions. Commercial Software-as-a-Service (SaaS) Cloud Service Providers (CSPs) or Independent Software Vendors (ISVs) looking to meet this growing demand must meet the Federal Risk and Authorization Management Program (FedRAMP®) cybersecurity requirements. FedRAMP provides a standardized, reusable approach to security assessment and authorization for commercial cloud service offerings. The FedRAMP Marketplace lists cloud service offerings (CSOs) based on their Impact Levels (amongst other filters). The primary levels are Low, Moderate, and High. A quick analysis of the FedRAMP Marketplace data shows the growing demand for FedRAMP High cloud service offerings. As the graphic below demonstrates, FedRAMP High authorizations are growing faster than those for the Moderate baseline. Understanding FedRAMP High Requirements The FedRAMP cybersecurity requirements are rooted in Federal standards, such as the Federal Information Processing Standard (FIPS) 199, that outlines the security categorization of federal information