New! AI Board Member: Walk into every meeting knowing nothing was missed. Request early accessarrow_forward
Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

FedRAMP compliance: What it is, what it requires and how to achieve it

August 9, 2026
15 min read

In this article

  • Intro
  • What is FedRAMP compliance?
  • What does FedRAMP compliance mean for cloud providers?
  • FedRAMP compliance levels: low, moderate and high
  • FedRAMP compliance checklist: key steps before you pursue authorization
  • How to achieve FedRAMP compliance step by step
  • FedRAMP continuous compliance: What happens after authorization?
  • Automating FedRAMP compliance: tools and approaches
  • FedRAMP container compliance
  • How Diligent helps you achieve and maintain FedRAMP compliance
  • Frequently asked questions about FedRAMP compliance
Writing on governance, risk, compliance and audit since 2020

Kezia Farnham

Writing on governance, risk, compliance and audit since 2020

FedRAMP compliance is the process cloud service providers and federal contractors follow to meet the US government's standardized security requirements for cloud products sold to federal agencies. Understanding what FedRAMP compliance is starts with the goal: an Authorization to Operate (ATO) from a federal agency or the Joint Authorization Board, granted only after a provider implements a defined set of NIST SP 800-53 controls and passes an independent assessment.

Achieving and maintaining that authorization is a multi-year undertaking, not a one-time project, but FedRAMP compliance software can automate much of the documentation, evidence collection and monitoring work involved.

This guide covers:

  • What FedRAMP compliance is and who must comply
  • The three FedRAMP impact levels and what separates them
  • The core requirements every authorized provider must meet
  • A checklist to run before you pursue authorization
  • The step-by-step path to an ATO, including timelines and cost
  • What continuous monitoring requires after authorization
  • Where automation delivers the most value
  • How Diligent supports every phase of a FedRAMP program

What is FedRAMP compliance?

The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that standardizes how cloud products and services are assessed, authorized and monitored for use by federal agencies. In this context, compliance means implementing and maintaining conformance with a defined FedRAMP security control baseline drawn from NIST SP 800-53, not simply passing a single audit.

Any cloud service provider (CSP) offering services to a US federal agency must comply, as must contractors whose systems process federal data on the CSP's behalf. The FedRAMP Marketplace publishes the current FedRAMP compliance list of authorized cloud products, along with each product's designated impact level and sponsoring agency, giving agencies a single source to confirm a vendor's status before procurement.

"FedRAMP compliant" is common shorthand, but the precise term is FedRAMP Authorized. A provider earns that designation only after a federal agency or the Joint Authorization Board issues an Authorization to Operate (ATO) or Authorization to Use (ATU), following an independent Third-Party Assessment Organization (3PAO) review of the provider's System Security Plan (SSP). Until that authorization is granted, a provider working toward compliance is "in process," not authorized.

What does FedRAMP compliance mean for cloud providers?

For a cloud provider, FedRAMP compliance means:

  • Implementing the full NIST SP 800-53 baseline that matches the provider's impact level
  • Undergoing an independent 3PAO assessment of those controls
  • Achieving an ATO from a sponsoring agency or the Joint Authorization Board
  • Committing to ongoing continuous monitoring (ConMon) reporting for as long as the authorization lasts

As federal agencies adopt AI-powered tools, the same standard extends to them. An AI tool or platform used inside a federal environment must sit within a FedRAMP Authorized boundary and meet the same controls for data residency, access management, encryption and audit logging as any other cloud service. Vendors building AI products for federal customers should treat FedRAMP authorization as a prerequisite for that market, not an optional add-on.

FedRAMP compliance levels: low, moderate and high

FedRAMP assigns every system one of three impact levels, based on the potential harm a security breach would cause to the confidentiality, integrity and availability of the data involved.

LevelRev 5 controlsTypical use caseExample agency type
Low156Public-facing tools with limited sensitive dataAgencies publishing open data or public services
Moderate323Most commercial SaaS and general business systemsCivilian agencies handling standard operational data
High410Systems handling highly sensitive dataLaw enforcement, financial and health agencies

Under FedRAMP's Consolidated Rules for 2026, these impact levels are being replaced by certification classes: Class B corresponds to Low, Class C to Moderate and Class D to High, with Class A as a new entry-level path. Both sets of terms are in circulation during the transition.

FedRAMP Moderate is the baseline most CSPs pursue first; it accounts for roughly three-quarters of authorized systems and is the minimum most civilian agencies require before procurement. FedRAMP High applies when a breach could cause severe or catastrophic harm, and it requires substantially greater control depth and assessment rigor.

Defense contractors should also account for DoD Impact Level 5 (IL-5), a Department of Defense designation that sits above FedRAMP Moderate and applies to Controlled Unclassified Information in defense environments. IL-5 is not a FedRAMP level itself, but DISA's reciprocity guidance lets providers build toward it once they hold a qualifying FedRAMP authorization, which shortens the path to defense contracts for providers that plan ahead.

FedRAMP compliance requirements: a complete overview

FedRAMP compliance requirements fall into six categories that every authorized provider must satisfy, regardless of impact level.

  • Security control implementation. Providers implement the full NIST SP 800-53 control baseline that matches their impact level, covering access control, encryption, incident response and a dozen other control families.
  • System Security Plan (SSP) documentation. The SSP describes the system's architecture, data flows and how each control is implemented — the single largest documentation burden in the process.
  • Plan of Action and Milestones (POAM). Every identified control gap gets logged in a POAM with a remediation owner and deadline, tracked until closure.
  • Third-Party Assessment Organization (3PAO) assessment. An accredited, independent assessor tests the SSP's claims before FedRAMP will consider authorization.
  • Continuous monitoring (ConMon). Authorization is not a one-time event; providers report monthly vulnerability scans and maintain an ongoing evidence trail for as long as the authorization remains in effect.
  • Penetration testing. FedRAMP requires an annual penetration test for all authorized systems.

Managing these requirements across separate teams and spreadsheets, including security running scans, compliance tracking the POAM and legal reviewing the SSP, creates the gaps and delays that slow most authorizations down. This is not solely a security team's concern: According to the GC Risk Index 2026 by Diligent Institute, 39% of general counsels cite cyber threats as one of the risks most influencing their organization's current risk rating, tied with AI-related risk.

It is worth stating plainly: Meeting FedRAMP's control baseline does not automatically mean an organization is secure. FedRAMP compliance measures conformance with a defined standard at a point in time and on a recurring cadence; it is not a substitute for an organization's broader security posture. Treat a green FedRAMP status as one input into that picture, not the whole picture.

FedRAMP compliance checklist: key steps before you pursue authorization

  1. Determine your impact level (low, moderate or high) based on the data your system will handle.
  2. Define your system boundary and map every component and data flow inside it.
  3. Select and implement the NIST SP 800-53 control baseline that matches your impact level.
  4. Document your System Security Plan, describing your architecture and control implementations in detail.
  5. Remediate control gaps and log any that remain open in your Plan of Action and Milestones.
  6. Engage an accredited 3PAO to conduct an independent assessment of your security package.
  7. Submit your security package to the FedRAMP PMO or your sponsoring agency for review.
  8. Achieve your Authorization to Operate, either through an agency ATO or a JAB Provisional ATO.
  9. Establish your continuous monitoring program before your first monthly reporting deadline arrives.

How to achieve FedRAMP compliance step by step

Achieving FedRAMP compliance follows five stages, each expanding on the checklist above with the process context behind it.

1. Prepare

Run a gap assessment against the control baseline for your target impact level, define your system boundary and confirm the impact level itself. Boundary decisions carry outsized risk: Providers that scope too broadly or carve a boundary from existing commercial infrastructure rather than a dedicated environment tend to face significant rework later in the process.

2. Document

Complete the System Security Plan. This is typically the most labor-intensive phase, since it requires a full accounting of architecture, data flows and how every control in the baseline is actually implemented, not just described in general terms.

3. Assess

An accredited 3PAO conducts independent testing and review of the SSP's claims. If your organization used a 3PAO as an advisor earlier in the process, a different 3PAO must perform this assessment.

4. Authorize

Your sponsoring agency issues an Agency ATO, or the Joint Authorization Board issues a Provisional ATO (P-ATO) that other agencies can then adopt.

5. Monitor

Continuous monitoring begins immediately and does not stop: monthly vulnerability scans, ongoing POAM updates and annual reassessment become permanent operating requirements.

Initial authorization typically takes 6 to 18 months, depending on system complexity and the extent of remediation the assessment identifies. Continuous monitoring, by contrast, is perpetual for as long as the authorization stands.

Cost varies with the same variables. A 2024 GAO cost review of selected cloud providers found authorization costs ranging from $300,000 to $3.7 million, though the underlying cost data were limited. Those figures cover 3PAO assessment fees, remediation work and internal program management. Automation tools that handle SSP generation, evidence collection and ConMon reporting can meaningfully reduce both the upfront and the ongoing figure.

Simplify your FedRAMP program

See how compliance teams reduce authorization overhead while staying continuously audit-ready. Check out our FedRAMP compliance software.

FedRAMP continuous compliance: What happens after authorization?

FedRAMP authorization is not a finish line. Once granted, providers enter a permanent continuous monitoring cycle: monthly vulnerability scanning across the entire in-boundary inventory, monthly POAM updates, annual independent 3PAO reassessment, annual penetration testing and incident reporting within one hour of discovery. Without automation, assembling that evidence trail every month is highly manual and resource-intensive.

"One important trend is continuous compliance. Not from the perspective of complying with a regulation. I mean security policy compliance and regulatory compliance, in one continuous loop. And that offers a tremendous amount of benefits for organizations. You're continuously gathering your risks and remediating them. That helps to reduce the amount of time that compliance teams take to do their work. For auditors, the data is already there. It accelerates the analysts' ability to do their job and do it more accurately," says Philip D. Harris, Research Director, Governance, Risk and Compliance Services and Software at IDC.

FedRAMP's Consolidated Rules for 2026 (CR26) are actively reshaping this obligation. Under RFC-0012's Collaborative Continuous Monitoring model, FedRAMP is shifting from static, point-in-time evidence toward continuous validation using Key Security Indicators (KSIs). Existing Rev5 authorizations face a compressed timeline to adapt: Machine-readable packages become mandatory on September 30, 2026; all Rev5 certifications must adopt the new rules by January 1, 2027; and FedRAMP stops accepting new Rev5 applications on June 11, 2027.

See FedRAMP 20x changes for the full rule set.

Automating FedRAMP compliance: tools and approaches

FedRAMP compliance lends itself to compliance automation because the underlying requirements are standardized, the deliverables are templated and the evidence requirements repeat on a fixed schedule. Six areas deliver the most value when automated:

  • Control mapping. Automatically map NIST SP 800-53 controls to your actual system environment instead of maintaining that mapping by hand.
  • SSP generation. Structured templates auto-populate system information and control narratives, cutting the most labor-intensive phase of the process.
  • Evidence collection. Automated workflows gather and organize evidence across security, compliance and engineering teams instead of leaving it scattered in individual inboxes.
  • POAM tracking. Real-time tracking surfaces open findings, owners and remediation deadlines so nothing ages past its window unnoticed.
  • OSCAL exports. Machine-readable OSCAL output is generated automatically for FedRAMP submissions, a requirement that is becoming more central under CR26.
  • ConMon reporting. Monthly monitoring reports are generated directly from integrated asset and vulnerability data rather than through manual compilation.

How do you automate FedRAMP compliance?

Start with the phase consuming the most manual hours, which is usually SSP drafting or monthly ConMon reporting, and automate that workflow first, then expand into control mapping and evidence collection as the program matures. Purpose-built FedRAMP compliance software exists specifically to handle this workload end-to-end, within an environment that is itself authorized.

See the platform in actionExplore how Diligent automates SSP generation, evidence collection and ConMon reporting in one FedRAMP-authorized environment.Request a demo

What is the best FedRAMP compliance software?

When evaluating FedRAMP compliance software, look for a platform that satisfies four criteria: Is the platform itself FedRAMP-authorized, so you are not running your compliance program through a tool that sits outside your own authorization boundary? Does it automate SSP drafting, POAM tracking and ConMon reporting rather than just storing documents? Does it generate OSCAL output natively? And does it map to the other cloud control frameworks your organization already carries, such as NIST, CMMC or ISO/IEC 27001, so you are not maintaining duplicate control sets?

Startups and newer CSPs should weigh two additional factors more heavily: pre-built FedRAMP project templates that shorten the ramp-up period, and vendor onboarding support experienced enough to catch boundary and scoping mistakes before they turn into SSP rework.

FedRAMP container compliance

Container environments introduce FedRAMP challenges that traditional infrastructure does not, because containers are ephemeral, frequently rebuilt and must maintain a compliant configuration state continuously rather than at a fixed point in time.

FedRAMP container compliance requires providers to address:

  • Container vulnerability scanning at build and runtime, not only at deployment
  • Image hardening to eliminate unnecessary packages and known vulnerabilities before an image ships
  • Runtime monitoring for configuration drift once containers are live
  • Network segmentation between containerized workloads and the rest of the authorization boundary
  • Full inclusion of the container environment inside the documented authorization boundary

NIST SP 800-190, the Application Container Security Guide, is the relevant federal guidance for these controls. Every container-specific control decision needs to appear in the SSP, and container evidence needs to feed the same continuous monitoring program as the rest of the environment. A separate, undocumented process for containers is itself a finding waiting to happen.

How Diligent helps you achieve and maintain FedRAMP compliance

Preparing, authorizing and monitoring a FedRAMP program each create their own operational burden, and most CSPs manage all three with a mix of spreadsheets, point tools and manual evidence collection.

Diligent One Platform is itself FedRAMP Moderate and DoD IL-5 Authorized, meaning CSPs run their compliance program inside an already-authorized environment rather than introducing an unauthorized third-party tool into their own boundary.

Within that platform, Diligent IT Compliance automates SSP generation and control narratives, maps controls to NIST SP 800-53 and surfaces gaps before they reach an assessor. Built-in OSCAL export support produces machine-readable submissions in minutes rather than through manual formatting, and automated ConMon workflows turn monthly vulnerability scans and POAM updates into a near-real-time program instead of a recurring scramble. The platform also maps to CMMC and ISO/IEC 27001, so organizations managing multiple compliance programs at once are not maintaining duplicate control sets across separate tools.

For organizations that need to escalate FedRAMP risk findings into enterprise-level reporting, Diligent Enterprise Risk Management tracks FedRAMP as a named enterprise risk with an assigned owner and current mitigation status, alongside an organization's other compliance obligations.

"We're seeing a lot of focus on consolidation. One organization I work with has 10 different GRC platforms deployed. A German automaker has seven GRC platforms. There can be a central platform that can be the hub of things, but there's room for best of breed software in places," says Michael Rasmussen, CEO of GRC Report.

Diligent's FedRAMP team has guided providers through the authorization process at every impact level, from initial boundary definition through ongoing ConMon reporting. Explore Diligent's FedRAMP compliance software to see the full platform in action.

Frequently asked questions about FedRAMP compliance

What does FedRAMP compliance mean?

FedRAMP compliance means a CSP has successfully implemented the required NIST 800-53 security controls, undergone independent third-party assessment by an accredited 3PAO and achieved an Authorization to Operate. It also implies an ongoing commitment to continuous monitoring, including monthly vulnerability scans, POAM updates and annual penetration testing. Being "FedRAMP compliant" is shorthand for being FedRAMP Authorized.

How much does FedRAMP compliance cost?

FedRAMP compliance costs vary widely. A 2024 GAO review of selected cloud service providers found estimates ranging from $300,000 to $3.7 million, depending on system complexity, the number of controls in scope, 3PAO assessment fees and the scale of remediation required. Ongoing continuous monitoring adds annual operational costs. Automation tools that simplify SSP creation, evidence collection and ConMon reporting can substantially reduce both upfront and recurring costs.

What is FedRAMP continuous compliance?

FedRAMP continuous compliance (ConMon) is the ongoing obligation all FedRAMP Authorized CSPs must fulfill after receiving their ATO. It includes monthly vulnerability scanning, monthly POAM updates, annual penetration testing, annual security assessments and incident reporting within one hour of discovery. ConMon is designed to ensure CSPs maintain their security posture, not just demonstrate it at the point of authorization.

What is FedRAMP container compliance?

FedRAMP container compliance refers to meeting FedRAMP security requirements for containerized cloud environments such as Docker or Kubernetes. Containers must sit within the system's authorization boundary, undergo vulnerability scanning, follow image hardening standards and be continuously monitored. Relevant guidance includes NIST SP 800-190. Container configurations must be documented in the SSP and monitored as part of the ConMon program.

What is FedRAMP and how does AI compliance work?

FedRAMP compliance applies to all cloud services provided to US federal agencies, including AI-powered services. An AI tool or platform used within a federal environment must reside within a FedRAMP Authorized boundary. All the same control requirements apply: data residency, access controls, encryption, audit logging and continuous monitoring. Vendors offering AI tools to federal agencies must seek FedRAMP authorization before deployment.

Ready to accelerate your path to FedRAMP authorization? Schedule a demo to see Diligent in action.