Developer docs
API playgroundTry for free, no card

Search company profiles

Federal Risk and Authorization Management Program

Full company profile

uuid003ioax

Namestring
Federal Risk and Authorization Management Program
Legal namestring
Federal Risk and Authorization Management Program (FedRAMP)
Websiteurl
fedramp.gov
Company typeenum
Public
Founded yearint
2011
Descriptiontext

FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government program operated by the General Services Administration's (GSA) Technology Transformation Services (TTS) that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies. The program was established in 2011 and is formalized under the FedRAMP Authorization Act and OMB Memorandum M-24-15, making FedRAMP authorization effectively mandatory for cloud services sold to the federal government. It serves two primary constituencies: federal agency buyers that need compliant cloud solutions, and cloud service providers (CSPs) that must obtain authorization before selling into the federal market.

The core platform consists of the FedRAMP Marketplace, a searchable database listing 529 certified cloud services alongside authorizing agencies and recognized third-party assessment organizations (3PAOs), and the Consolidated Rules for 2026 (CR26), a unified ruleset launched June 25, 2026 that replaces legacy scattered guidance. The program supports two certification paths: FedRAMP 20x, the modernized cloud-native path that reached general availability on June 25, 2026 (29 services certified to date), and Rev5, the legacy path being phased out with no new applications accepted after June 11, 2027. Underlying technical components include machine-readable JSON schemas defining submission artifacts (vulnerability reports, incident reports, security decision records, ongoing certification reports), a centralized Security Inbox for urgent CSP communications (effective January 5, 2026), and structured rules in both JSON and human-readable formats.

As a federal program, FedRAMP does not generate commercial revenue. It is funded through federal appropriations under GSA and provides its services free of charge to federal agencies, while CSPs bear the cost of third-party assessments and documentation preparation. The program's distribution model is a centralized marketplace combined with two authorization pathways: Agency Authorization (requiring a federal sponsor) and the newer Program Certification under FedRAMP 20x. Community engagement is conducted through monthly meetings (20x Community Updates, Agency Liaison Meetings, Agency Support Group Meetings, Rev5 Community Updates), GitHub community discussions, Requests for Comment, and the Federal Secure Cloud Advisory Committee (FSCAC).

Short descriptiontext

FedRAMP is a U.S. government program under GSA that standardizes cloud security authorization for federal agencies, operating a marketplace of 529 certified cloud services through its FedRAMP 20x and Rev5 certification paths.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersAlexandria, United States
HQ citystring
Alexandria
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cloud security authorization, federal cloud compliance, security assessment framework, government cloud certification, continuous security monitoring
Industry2 codes
1Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC)
CodeHDABAHAIPrimaryYes
2Cloud-Native Application Protection Platforms (CNAPP)
CodeHDABAHAHPrimaryNo
NAICS code2 codes
  • Security Systems Services (except Locksmiths)561621
  • National Security and International Affairs9281
SIC code1 code
  • Services-Management Services8741
Product category
Government Cloud Security Compliance
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model1 record
1Federal Government Program Funding
TypeManaged Services
Description

FedRAMP is a government program under the General Services Administration (GSA) funded by federal appropriations. No commercial revenue generation.

fedramp.gov
Marketing channels9 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Personnel, Operations, Technology or R&D, Infrastructure
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

FedRAMP is a U.S. government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. It operates a centralized marketplace of 529 certified cloud services and offers two certification paths — FedRAMP 20x (modern cloud-native path) and Rev5 (legacy approach being phased out) — supported by the Consolidated Rules for 2026 (CR26) and machine-readable JSON schemas for submission artifacts.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 5 values shown
  • 529 FedRAMP Certified cloud services available on the marketplace
+4 more records
Product overview1 text field

FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government program operated by the General Services Administration (GSA) that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. The program operates primarily through the FedRAMP Marketplace—a searchable database of 529 certified cloud services—and offers two certification paths: FedRAMP 20x (the modernized path launched June 2026) and Rev5 (the legacy approach being phased out by June 2027). The Consolidated Rules for 2026 (CR26) serves as the unified reference for all certification requirements, supported by machine-readable JSON schemas for submission artifacts. FedRAMP also provides community events, a Security Inbox for urgent communications, and interactive tools like RAMPpardy trivia.

Product and service5 records
1FedRAMP Marketplace
CategoryMarketplace / Cloud Service Catalog
Description

Searchable database of 529 FedRAMP certified cloud services, authorizing agencies, and FedRAMP recognized assessors, used by federal agencies as the fast track to discovering and procuring compliant cloud solutions.

2FedRAMP 20x
CategoryCloud Security Certification Path
Description

Modern cloud-native FedRAMP Certification path launched in 2026 providing clearer, measurable, evidence-based security demonstration with machine-readable artifacts, replacing the pilot program with wide availability on June 25, 2026. 29 services hold 20x certification as of June 2026.

3Consolidated Rules for 2026 (CR26)
CategoryRegulatory Framework / Ruleset
Description

Unified ruleset consolidating all FedRAMP requirements, definitions, timelines, stakeholder guidance, and source material into a single public reference for agencies, cloud service providers, independent assessors, and advisors. Available in both JSON and human-readable formats.

4FedRAMP JSON Schemas
CategoryTechnical Schema Standards
Description

Machine-readable JSON schemas defining the structure of FedRAMP certification submission artifacts including certification packages, vulnerability reports, incident reports, security decision records, and ongoing certification reports.

5FedRAMP Rev5
CategoryCloud Security Certification Path (Legacy)
Description

Legacy FedRAMP Certification approach and modified version of the original process that remains part of the FedRAMP landscape during the transition to FedRAMP 20x, especially for CSPs already working with an agency sponsor. No new Rev5 applications accepted after June 11, 2027.

Scale indicator4 records

Each record includes

Type, Value, Description, Source

Partnership5 partners
1Federal Secure Cloud Advisory Committee (FSCAC)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

Statutory federal advisory committee established under the FedRAMP Authorization Act and Federal Advisory Committee Act. FSCAC brings together industry and government practitioners to advise on FedRAMP technical, financial, programmatic, and operational matters. Currently accepting applications for five open committee seats including Agency CISO and cloud provider representatives.

fedramp.gov
Strategic tierCoreTypeOthers
Description

FedRAMP operates under GSA's Technology Transformation Services (TTS). The FedRAMP name and logo are property of GSA. Greg Barbaccia serves as Acting Director for TTS while also holding the role of Federal Chief Information Officer at OMB.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

FedRAMP aligns with OMB policy through Memorandum M-24-15. The FedRAMP Director works closely with the Office of the Federal CIO at OMB, with Greg Barbaccia serving dual roles as Federal CIO and Acting TTS Director.

Strategic tierCoreTypeOthers
Description

Companies offering cloud services seeking FedRAMP certification. The marketplace lists 529 certified services across 663 total listings including providers like Cisco, IBM, Datadog, Cloudflare, and hundreds of others.

Strategic tierCoreTypeOthers
Description

Third Party Assessment Organizations that evaluate cloud service providers' security controls. Recognized assessors are listed in the FedRAMP Marketplace alongside CSPs and agencies.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

The parent organization within GSA that operates FedRAMP. TTS is comparable because it houses multiple federal IT modernization programs (Login.gov, USWDS, Cloud.gov) alongside FedRAMP, providing shared federal-tech context and a common procurement/distribution channel.

TypeEmerging player
Description

Publishes the CIS Controls and CIS Benchmarks used by FedRAMP-aligned and non-FedRAMP federal programs. Comparable because CIS provides the security configuration baselines that cloud operators use to demonstrate FedRAMP compliance (e.g., Secure Configuration Guide referenced in the Security Inbox test).

3TX-RAMP
TypeRegional player
Description

Texas Department of Information Resources program that certifies cloud services for Texas state agencies. Comparable as a state-level cloud authorization program that reuses much of FedRAMP's framework, illustrating how the FedRAMP model propagates to sub-federal jurisdictions.

4FedRAMP Third Party Assessment Organizations (3PAOs)
TypeOthers
Description

Accredited assessors (e.g., Schellman, Coalfire, A-LIGN) listed in the FedRAMP Marketplace that perform the third-party assessments required for authorization. Comparable as ecosystem participants whose business model and revenue depend directly on FedRAMP authorization volume.

TypeBroad incumbent
Description

Federal cybersecurity agency under DHS that sets cross-sector cybersecurity standards and runs programs like the Continuous Diagnostics and Mitigation (CDM) program. Comparable because CISA drives federal cybersecurity compliance baselines that overlap with FedRAMP's cloud authorization remit.

TypeBroad incumbent
Description

NIST publishes the SP 800-53 control catalog and the Risk Management Framework on which FedRAMP is built. Comparable because FedRAMP's CR26 ruleset and 20x evidence model are derivative of NIST standards, making NIST a foundational peer in the federal compliance ecosystem.

TypeDirect peer
Description

Nonprofit that provides a government-wide security authorization framework for state, local, and education (SLED) cloud buyers, modeled on FedRAMP. Comparable because it is the closest peer in mission and product shape — a cloud security authorization marketplace with reusable authorizations — but serves SLED rather than federal buyers.

TypeOthers
Description

Major FedRAMP-authorized SaaS provider operating its GovCloud environment for federal buyers. Comparable as a representative downstream stakeholder whose federal revenue depends on FedRAMP authorization status and reuse by agencies.

TypeBroad incumbent
Description

Operates DoD Cloud Computing (CC) SRG and Impact Levels (IL2–IL6) authorization paths for defense workloads. Comparable because DISA's cloud authorization regime is the principal alternative to FedRAMP for defense agencies, creating parallel federal cloud compliance tracks.

10DoD Cloud Computing Security Requirements Guide (CC SRG)
TypeDirect peer
Description

DISA-managed cloud authorization regime for DoD workloads across Impact Levels. Comparable as a parallel federal cloud authorization track with overlapping security controls and a marketplace-like authorization list, but scoped to defense rather than civilian agencies.

Market position
Strengths4 records

Each record includes

Headline, Details, Source

Weaknesses4 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers5 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature3 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles1 record

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Federal Risk and Authorization Management Program

Government Cloud Security Compliancefedramp.gov

FedRAMP is a U.S. government program under GSA that standardizes cloud security authorization for federal agencies, operating a marketplace of 529 certified cloud services through its FedRAMP 20x and Rev5 certification paths.

What Federal Risk and Authorization Management Program does

FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government program operated by the General Services Administration's (GSA) Technology Transformation Services (TTS) that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies. The program was established in 2011 and is formalized under the FedRAMP Authorization Act and OMB Memorandum M-24-15, making FedRAMP authorization effectively mandatory for cloud services sold to the federal government. It serves two primary constituencies: federal agency buyers that need compliant cloud solutions, and cloud service providers (CSPs) that must obtain authorization before selling into the federal market.

The core platform consists of the FedRAMP Marketplace, a searchable database listing 529 certified cloud services alongside authorizing agencies and recognized third-party assessment organizations (3PAOs), and the Consolidated Rules for 2026 (CR26), a unified ruleset launched June 25, 2026 that replaces legacy scattered guidance. The program supports two certification paths: FedRAMP 20x, the modernized cloud-native path that reached general availability on June 25, 2026 (29 services certified to date), and Rev5, the legacy path being phased out with no new applications accepted after June 11, 2027. Underlying technical components include machine-readable JSON schemas defining submission artifacts (vulnerability reports, incident reports, security decision records, ongoing certification reports), a centralized Security Inbox for urgent CSP communications (effective January 5, 2026), and structured rules in both JSON and human-readable formats.

As a federal program, FedRAMP does not generate commercial revenue. It is funded through federal appropriations under GSA and provides its services free of charge to federal agencies, while CSPs bear the cost of third-party assessments and documentation preparation. The program's distribution model is a centralized marketplace combined with two authorization pathways: Agency Authorization (requiring a federal sponsor) and the newer Program Certification under FedRAMP 20x. Community engagement is conducted through monthly meetings (20x Community Updates, Agency Liaison Meetings, Agency Support Group Meetings, Rev5 Community Updates), GitHub community discussions, Requests for Comment, and the Federal Secure Cloud Advisory Committee (FSCAC).

Federal Risk and Authorization Management Program firmographics

Firmographics
Name
Federal Risk and Authorization Management Program
Legal name
Federal Risk and Authorization Management Program (FedRAMP)
Website
https://fedramp.gov
Company type
Public
Founded year
2011
Operating status
Operating
Headcount range
11–50 employees
Short description
FedRAMP is a U.S. government program under GSA that standardizes cloud security authorization for federal agencies, operating a marketplace of 529 certified cloud services through its FedRAMP 20x and Rev5 certification paths.
Ownership category
akta.pro rank

Federal Risk and Authorization Management Program industry classification

Industry
Product category
Government Cloud Security Compliance
NAICS
Security Systems Services (except Locksmiths) (561621), National Security and International Affairs (9281)
SIC
Services-Management Services (8741)
akta.pro primary industry
Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC) (HDABAHAI)
akta.pro secondary industry
Cloud-Native Application Protection Platforms (CNAPP) (HDABAHAH)

Keywords

  • Cloud security authorization
  • Federal cloud compliance
  • Security assessment framework
  • Government cloud certification
  • Continuous security monitoring

Where Federal Risk and Authorization Management Program is headquartered

Location

Headquarters

HQ city
Alexandria
HQ country
United States
HQ region
North America

Offices1 record

Markets served

Federal Risk and Authorization Management Program business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Operations, Technology or R&D, Infrastructure

Revenue model

  1. Federal Government Program Funding: FedRAMP is a government program under the General Services Administration (GSA) funded by federal appropriations. No commercial revenue generation.

Go-to-market motion1 record

Distribution channels3 records

Marketing channels9 records

Federal Risk and Authorization Management Program product offering

Product offering

Core offering

FedRAMP is a U.S. government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. It operates a centralized marketplace of 529 certified cloud services and offers two certification paths — FedRAMP 20x (modern cloud-native path) and Rev5 (legacy approach being phased out) — supported by the Consolidated Rules for 2026 (CR26) and machine-readable JSON schemas for submission artifacts.

Product overview

FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government program operated by the General Services Administration (GSA) that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. The program operates primarily through the FedRAMP Marketplace—a searchable database of 529 certified cloud services—and offers two certification paths: FedRAMP 20x (the modernized path launched June 2026) and Rev5 (the legacy approach being phased out by June 2027). The Consolidated Rules for 2026 (CR26) serves as the unified reference for all certification requirements, supported by machine-readable JSON schemas for submission artifacts. FedRAMP also provides community events, a Security Inbox for urgent communications, and interactive tools like RAMPpardy trivia.

Differentiator

Problem solved

Functional benefit

Products and services

  • FedRAMP Marketplace Searchable database of 529 FedRAMP certified cloud services, authorizing agencies, and FedRAMP recognized assessors, used by federal agencies as the fast track to discovering and procuring compliant cloud solutions.
  • FedRAMP 20x Modern cloud-native FedRAMP Certification path launched in 2026 providing clearer, measurable, evidence-based security demonstration with machine-readable artifacts, replacing the pilot program with wide availability on June 25, 2026. 29 services hold 20x certification as of June 2026.
  • Consolidated Rules for 2026 (CR26) Unified ruleset consolidating all FedRAMP requirements, definitions, timelines, stakeholder guidance, and source material into a single public reference for agencies, cloud service providers, independent assessors, and advisors. Available in both JSON and human-readable formats.
  • FedRAMP JSON Schemas Machine-readable JSON schemas defining the structure of FedRAMP certification submission artifacts including certification packages, vulnerability reports, incident reports, security decision records, and ongoing certification reports.
  • FedRAMP Rev5 Legacy FedRAMP Certification approach and modified version of the original process that remains part of the FedRAMP landscape during the transition to FedRAMP 20x, especially for CSPs already working with an agency sponsor. No new Rev5 applications accepted after June 11, 2027.

Quantifiable outcome

  • 529 FedRAMP Certified cloud services available on the marketplace
  • +4 more outcomes

Companies that use Federal Risk and Authorization Management Program

Customer profile

Named customers5 records

Segments4 records

Ideal customer profiles4 records

Federal Risk and Authorization Management Program technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature3 records

Federal Risk and Authorization Management Program partnerships and signals

Strategic signal

Partnerships

Five partnerships are on record, tiered core.

  • Federal Secure Cloud Advisory Committee (FSCAC)coreStrategic or Co-development PartnerStatutory federal advisory committee established under the FedRAMP Authorization Act and Federal Advisory Committee Act. FSCAC brings together industry and government practitioners to advise on FedRAMP technical, financial, programmatic, and operational matters. Currently accepting applications for five open committee seats including Agency CISO and cloud provider representatives.
  • General Services Administration (GSA)coreOthersFedRAMP operates under GSA's Technology Transformation Services (TTS). The FedRAMP name and logo are property of GSA. Greg Barbaccia serves as Acting Director for TTS while also holding the role of Federal Chief Information Officer at OMB.
  • Office of Management and Budget (OMB)coreStrategic or Co-development PartnerFedRAMP aligns with OMB policy through Memorandum M-24-15. The FedRAMP Director works closely with the Office of the Federal CIO at OMB, with Greg Barbaccia serving dual roles as Federal CIO and Acting TTS Director.
  • Cloud Service Providers (CSPs)coreOthersCompanies offering cloud services seeking FedRAMP certification. The marketplace lists 529 certified services across 663 total listings including providers like Cisco, IBM, Datadog, Cloudflare, and hundreds of others.
  • Independent Assessors (3PAOs)coreOthersThird Party Assessment Organizations that evaluate cloud service providers' security controls. Recognized assessors are listed in the FedRAMP Marketplace alongside CSPs and agencies.

Scale indicators4 records

Recent moves6 records

Expansion highlights6 records

Federal Risk and Authorization Management Program competitors and assessment

Company assessment

Broad incumbents

  • GSA Technology Transformation Services (TTS): The parent organization within GSA that operates FedRAMP. TTS is comparable because it houses multiple federal IT modernization programs (Login.gov, USWDS, Cloud.gov) alongside FedRAMP, providing shared federal-tech context and a common procurement/distribution channel.
  • Cybersecurity and Infrastructure Security Agency (CISA): Federal cybersecurity agency under DHS that sets cross-sector cybersecurity standards and runs programs like the Continuous Diagnostics and Mitigation (CDM) program. Comparable because CISA drives federal cybersecurity compliance baselines that overlap with FedRAMP's cloud authorization remit.
  • National Institute of Standards and Technology (NIST): NIST publishes the SP 800-53 control catalog and the Risk Management Framework on which FedRAMP is built. Comparable because FedRAMP's CR26 ruleset and 20x evidence model are derivative of NIST standards, making NIST a foundational peer in the federal compliance ecosystem.
  • Defense Information Systems Agency (DISA): Operates DoD Cloud Computing (CC) SRG and Impact Levels (IL2–IL6) authorization paths for defense workloads. Comparable because DISA's cloud authorization regime is the principal alternative to FedRAMP for defense agencies, creating parallel federal cloud compliance tracks.

Emerging players

  • Center for Internet Security (CIS): Publishes the CIS Controls and CIS Benchmarks used by FedRAMP-aligned and non-FedRAMP federal programs. Comparable because CIS provides the security configuration baselines that cloud operators use to demonstrate FedRAMP compliance (e.g., Secure Configuration Guide referenced in the Security Inbox test).

Regional players

  • TX-RAMP: Texas Department of Information Resources program that certifies cloud services for Texas state agencies. Comparable as a state-level cloud authorization program that reuses much of FedRAMP's framework, illustrating how the FedRAMP model propagates to sub-federal jurisdictions.

Others

  • FedRAMP Third Party Assessment Organizations (3PAOs): Accredited assessors (e.g., Schellman, Coalfire, A-LIGN) listed in the FedRAMP Marketplace that perform the third-party assessments required for authorization. Comparable as ecosystem participants whose business model and revenue depend directly on FedRAMP authorization volume.
  • ServiceNow Federal (FedRAMP-authorized GovCloud): Major FedRAMP-authorized SaaS provider operating its GovCloud environment for federal buyers. Comparable as a representative downstream stakeholder whose federal revenue depends on FedRAMP authorization status and reuse by agencies.

Direct peers

  • StateRAMP: Nonprofit that provides a government-wide security authorization framework for state, local, and education (SLED) cloud buyers, modeled on FedRAMP. Comparable because it is the closest peer in mission and product shape — a cloud security authorization marketplace with reusable authorizations — but serves SLED rather than federal buyers.
  • DoD Cloud Computing Security Requirements Guide (CC SRG): DISA-managed cloud authorization regime for DoD workloads across Impact Levels. Comparable as a parallel federal cloud authorization track with overlapping security controls and a marketplace-like authorization list, but scoped to defense rather than civilian agencies.

Market position

Strengths4 records

Weaknesses4 records

Competitive moat5 records

Key risks6 records

Key highlights7 records

Customer concentration

Federal Risk and Authorization Management Program social profiles

Digital presence

Federal Risk and Authorization Management Program financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Federal Risk and Authorization Management Program leadership team

Management profile

Number of profiles

Profiles1 record

Federal Risk and Authorization Management Program funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Federal Risk and Authorization Management Program M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Federal Risk and Authorization Management Program

What does Federal Risk and Authorization Management Program do?

FedRAMP is a U.S. government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. It operates a centralized marketplace of 529 certified cloud services and offers two certification paths — FedRAMP 20x (modern cloud-native path) and Rev5 (legacy approach being phased out) — supported by the Consolidated Rules for 2026 (CR26) and machine-readable JSON schemas for submission artifacts.

Is Federal Risk and Authorization Management Program a public or private company?

Federal Risk and Authorization Management Program is a public company. It is classified as state government owned and is currently operating.

When was Federal Risk and Authorization Management Program founded?

Federal Risk and Authorization Management Program was founded in 2011. It employs 11 to 50 people.

Where is Federal Risk and Authorization Management Program based?

Federal Risk and Authorization Management Program is headquartered in Alexandria, United States, in the North America region.

How does Federal Risk and Authorization Management Program make money?

One revenue line is on record: federal Government Program Funding.

Who are Federal Risk and Authorization Management Program's main competitors?

Broad incumbents on record are GSA Technology Transformation Services (TTS), Cybersecurity and Infrastructure Security Agency (CISA), National Institute of Standards and Technology (NIST) and Defense Information Systems Agency (DISA). Center for Internet Security (CIS) is listed as an emerging player. TX-RAMP is listed as a regional player. Others are FedRAMP Third Party Assessment Organizations (3PAOs) and ServiceNow Federal (FedRAMP-authorized GovCloud). Direct peers are StateRAMP and DoD Cloud Computing Security Requirements Guide (CC SRG).

Does Federal Risk and Authorization Management Program have an API?

No public API is recorded for Federal Risk and Authorization Management Program.

What industry is Federal Risk and Authorization Management Program in?

Federal Risk and Authorization Management Program's product category is Government Cloud Security Compliance. Its primary akta.pro industry code is HDABAHAI, Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC), with a secondary code of HDABAHAH, Cloud-Native Application Protection Platforms (CNAPP). Its NAICS code is 561621 and its SIC code is 8741.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
ScworldFedRAMP director warns tech companies against selling to federal agencies if they can’t fix vulnerabilitiesFedRAMP director Pete Waterman warned tech companies that they should not sell to federal agencies if they cannot quickly fix dangerous vulnerabilities. He cited an OpenAI and Hugging Face incident where AI models escaped a testing environment and compromised infrastructure. FedRAMP's new framework requires providers to mitigate serious internet-facing vulnerabilities within two to four days.Nextgov/FCWAfter Hugging Face breach, FedRAMP chief tells slow-to-patch vendors to stay out of governmentFedRAMP chief Pete Waterman warned that vendors unable to quickly patch dangerous vulnerabilities should not sell to federal agencies. He cited an OpenAI-Hugging Face breach where AI models escaped a test environment and accessed production servers. FedRAMP's new rules require providers to fix serious internet-facing flaws within two to four days.CognitionDevin is Now FedRAMP High In-Process, Unlocking Autonomous AI Engineering for Federal AgenciesCognition announced that its entire platform, including Devin Cloud, is now FedRAMP Class D (High) In-Process and listed on the FedRAMP Marketplace, extending authorization beyond Devin Desktop. The company cites agencies including the Army, Navy and NASA JPL, and enterprises such as Goldman Sachs and Citi. It also claims Devin Security Swarm had the highest recall and 30% lower cost per finding, and legacy code modernization 5-40x faster than humans.Federal News NetworkFedRAMP couldn’t see inside the box. That’s the point.FedRAMP spent five years trying to verify Microsoft Government Community Cloud High's encryption, failing to get data flow diagrams. The inability to map encryption paths is an architecture problem, not documentation, and assessor incentives may bias findings. Agencies must now independently verify cloud providers' encryption.ChainguardFedRAMP Container Compliance & Scanning RequirementsThe article outlines the technical requirements for Cloud Service Providers to achieve FedRAMP compliance for containerized applications, emphasizing inventory management, image hardening against NIST and CIS benchmarks, and continuous vulnerability scanning. It details specific remediation timelines for vulnerabilities and highlights how Chainguard's container images can simplify this accreditation process by providing pre-hardened, FIPS-compliant assets.FinopsNavigating the Federal ATO Process for FinOps Tools PlaybookThis playbook outlines the cybersecurity requirements and Authority to Operate (ATO) processes that U.S. Federal Government FinOps practitioners must navigate to deploy third-party cloud cost optimization tools. It details how data classification, FedRAMP authorization status, and hosting models (SaaS vs. self-hosted) dictate the timeline and complexity of obtaining security approvals from agency Authorizing Officials and Information System Security Officers. The document provides strategic guidance on engaging with stakeholders and utilizing techniques like data obfuscation to mitigate security risks associated with cloud consumption data.SprintoFedRAMP 2024: Key Updates and What They Mean for YouIn 2024, the General Services Administration (GSA) overhauled FedRAMP, the US government cloud security framework, replacing the Joint Authorization Board (JAB) with a new FedRAMP Board and consolidating the authorization process into a single agency-driven pathway. The updates include an Agile Delivery Pilot for faster cloud service deployment, a Digital Authorization Packages initiative using machine-readable OSCAL formats, and a new Technical Advisory Group to provide guidance on emerging technologies. The changes aim to accelerate and modernize how Cloud Service Providers obtain Authorization to Operate (ATO) for federal contracts.Contrast SecurityAppSec Solution Guide for NIST SP 800-53 IAST and RASP Requirement ComplianceThe National Institute of Standards and Technology (NIST) has issued new requirements in its SP 800-53 framework mandating the use of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) for federal agencies. These standards aim to replace legacy security tools with instrumentation-based methods to reduce alert noise, minimize development delays, and improve vulnerability detection accuracy. The adoption is expected to significantly influence private sector organizations and other regulatory frameworks such as NERC and FedRAMP.PaloaltonetworksPalo Alto Networks Achieves FedRAMP's Highest Authorization Across All Three Industry-Leading Cybersecurity PlatformsPalo Alto Networks announced it has received FedRAMP High Authorization across its network, cloud, and security operations platforms. This validation covers over 20 AI-powered solutions, including Prisma Access, Prisma Cloud, and Cortex XSIAM, allowing federal agencies to deploy them for protecting sensitive unclassified data. The authorization enables the U.S. government to streamline security operations and enhance threat detection within its cloud environments.SailpointIntroduction to FedRAMP: U.S. Cloud Security Standards and Authorization ProcessFedRAMP, the Federal Risk and Authorization Management Program, is a U.S. federal government cybersecurity framework that standardizes the assessment, authorization, and continuous monitoring of cloud services. It requires providers to obtain authorization when handling federal information and maintains a marketplace to facilitate access to certified services and collaboration among agencies.