Back to FedRAMP

FedRAMP Authorization Checklist: Every Step, Deliverable and Baseline

Photo: Unsplash

FedRAMP authorization checklist

FedRAMP is the hardest compliance programme most SaaS companies will attempt. It is not a certification you pass, it is an authorization a federal agency grants to a specific cloud service at a specific impact level, and it comes with monthly obligations that continue for as long as the authorization stands.

This checklist covers the decisions, phases and deliverables in order, so you can see the whole shape of the programme before committing to it.

Key takeaways

  • FedRAMP is built on NIST SP 800-53 controls. Under Rev 5, the baselines are roughly 156 controls at Low, 323 at Moderate and 410 at High. Moderate is what most agencies require.
  • You need a federal agency sponsor. There is no way to self-initiate a full authorization and sit on the Marketplace waiting for customers.
  • An accredited 3PAO must perform the security assessment. You cannot assess yourself.
  • Authorization is the beginning of the work, not the end. Monthly continuous monitoring deliverables and an annual assessment are mandatory.
  • Budget 12 to 24 months and a seven-figure total cost for a Moderate authorization from a standing start.

Before you start: three prerequisites

Confirm all three before spending money. Each one has ended FedRAMP projects.

  1. An agency sponsor who will grant the ATO. A federal customer who wants your product and will commit staff time to reviewing your package. Verbal interest is not a sponsor.
  2. A US-based, appropriately isolated environment. FedRAMP data must reside in the United States, and personnel with access are subject to screening requirements. For most companies this means building a separate government cloud environment (AWS GovCloud, Azure Government or equivalent), not adding controls to the commercial one.
  3. Executive commitment to the ongoing cost. Continuous monitoring is a permanent staffing line, not a project cost.

If you cannot check all three, the honest answer is that you are not ready to start.

Step 1: determine your impact level

Impact level follows FIPS 199 categorisation of the data your service handles, assessed across confidentiality, integrity and availability. The highest of the three sets your level.

Level Approximate control count (Rev 5) Use when Reality
Low ~156 Loss would have limited adverse effect Rare as a target; most agencies ask for more
Li-SaaS (Tailored) Reduced subset Low-impact SaaS with no PII beyond login credentials A genuine shortcut, but the eligibility criteria are narrow
Moderate ~323 Loss would have serious adverse effect. Covers most federal data that is not classified or safety-critical The default target. Around four in five authorizations
High ~410 Loss would have severe or catastrophic effect. Law enforcement, emergency services, financial systems, health data Significantly harder; plan for a longer runway

Do this step with your sponsoring agency, not alone. Agencies determine the categorisation of their own data, and being told in month eight that Moderate is insufficient is an expensive correction.

Step 2: choose your authorization path

FedRAMP's governance changed materially following OMB Memorandum M-24-15 in 2024, which replaced the Joint Authorization Board with the FedRAMP Board and pushed agency authorization as the primary route.

  • Agency authorization. Your sponsoring agency reviews your package and issues an Authority to Operate. This is the standard path today. Once authorized, other agencies can reuse your package.
  • FedRAMP Board authorization. Reserved for services with broad government-wide demand, prioritised centrally.
  • FedRAMP 20x. A newer programme aimed at faster, more automated authorization for cloud-native services. It has been running as a phased pilot, and eligibility and requirements have been evolving, so check the current FedRAMP guidance rather than relying on any secondhand summary including this one.

Whichever path applies, you also register in the FedRAMP Marketplace, which lists your status: "In Process" once a sponsor is confirmed and the programme is underway, then "Authorized".

Step 3: work the authorization phases

Phase 1: Preparation and readiness

  • FIPS 199 categorisation agreed with your sponsor
  • System boundary defined and diagrammed. This is the highest-leverage decision in the whole programme. Everything inside the boundary is in scope, including external services you call.
  • Gap assessment against the applicable baseline
  • Optional but recommended: a Readiness Assessment Report (RAR) produced by a 3PAO, which surfaces boundary and architecture problems before you have built on top of them
  • 3PAO selected from the accredited list

Phase 2: Documentation

  • System Security Plan (SSP) written, with every control in the baseline addressed. This is the core deliverable and typically runs to hundreds of pages.
  • All required attachments and policies drafted and approved
  • Control implementation statements written per control, describing what you actually do

Phase 3: Implementation

  • Controls implemented in the government environment
  • Inheritance documented where you rely on your underlying cloud provider's authorization, with a clear customer responsibility matrix
  • Evidence generation started, since the assessment will sample it

Phase 4: Assessment

  • 3PAO writes the Security Assessment Plan (SAP) and your sponsor approves it
  • Testing performed: control testing, vulnerability scanning, penetration testing
  • 3PAO issues the Security Assessment Report (SAR) with findings
  • You produce the Plan of Action and Milestones (POA&M) for every open finding, with severity, owner and remediation date

Phase 5: Authorization

  • Full package submitted to the sponsoring agency
  • Agency risk review, usually with rounds of questions
  • Agency issues the ATO letter
  • Marketplace status updated to Authorized

Phase 6: Continuous monitoring

Begins the day authorization is granted and never stops.

The deliverable checklist

Deliverable Produced by Notes
FIPS 199 categorisation You, with your agency Sets the baseline
System boundary diagram and data flows You Scrutinised heavily; get it right early
System Security Plan (SSP) You Every baseline control addressed
Policies and procedures You One set per control family
Configuration and hardening baselines You Usually mapped to CIS or DISA STIG
Incident response plan You Must include US-CERT reporting timelines
Contingency plan and test results You Including a completed test, not just a plan
Readiness Assessment Report (RAR) 3PAO Optional, strongly recommended
Security Assessment Plan (SAP) 3PAO Agency approves before testing
Penetration test report 3PAO Scope defined by FedRAMP guidance
Security Assessment Report (SAR) 3PAO The findings
Plan of Action and Milestones (POA&M) You Living document, maintained forever
ATO letter Sponsoring agency The authorization itself

Continuous monitoring: the obligation that never ends

This is the part companies underestimate, and it is where authorizations get suspended.

Monthly:

  • Vulnerability scans of operating systems, web applications and databases, submitted to your agency
  • Updated POA&M reflecting remediation progress
  • Remediation within FedRAMP timelines, generally 30 days for high-severity findings, 90 for moderate and 180 for low
  • Inventory updates

Annually:

  • A 3PAO assessment covering a defined subset of controls
  • Contingency plan test
  • Policy and procedure review
  • Penetration test

On change:

  • Significant Change Requests submitted and approved before major architecture changes. Deploying a significant change without approval is a compliance failure in its own right.

Plan for at least one full-time person on continuous monitoring for a Moderate system, more if your scanning surface is large.

Timeline and cost

For a Moderate authorization starting without existing federal work:

Phase Typical duration
Readiness and gap assessment 2 to 4 months
Government environment build 3 to 6 months, often in parallel
SSP and documentation 3 to 6 months
3PAO assessment 2 to 3 months
Agency review and ATO 3 to 6 months
Total 12 to 24 months

Costs vary widely, but for Moderate expect 3PAO fees in the low-to-mid six figures, a comparable or larger internal engineering cost for the isolated environment, advisory support, and then an ongoing annual cost for continuous monitoring and the annual assessment. Treating FedRAMP as under a million dollars all-in for a first Moderate authorization is optimistic for most companies.

Where FedRAMP projects stall

  1. No real sponsor. The single most common cause of abandoned projects.
  2. A boundary drawn too wide. Every service inside it needs to be authorized or properly inherited. Pulling your commercial analytics stack inside the boundary can add a year.
  3. Starting the SSP before the architecture is settled. The document then chases the system.
  4. Assuming cloud provider inheritance covers more than it does. Their authorization covers their layer. The customer responsibility matrix is yours to satisfy.
  5. Treating the POA&M as a closing document. It is permanent, and agencies watch whether remediation dates slip.
  6. Underfunding continuous monitoring. Missed monthly submissions put the authorization at risk.
  7. Choosing a 3PAO on price alone. An assessor who has not worked your architecture pattern costs more in rework than they save.

How SecureSlate helps

SecureSlate maintains your control inventory, evidence and POA&M in one place, and maps a single control set across FedRAMP, SOC 2 and ISO 27001 so the work you do for one framework counts toward the others. Continuous monitoring tasks, scan results and remediation deadlines are tracked against FedRAMP timelines rather than managed in spreadsheets.

Get started for free

Related guides:

FAQ

How many controls are in FedRAMP?
It depends on your impact level. Under NIST SP 800-53 Rev 5, the FedRAMP baselines are approximately 156 controls at Low, 323 at Moderate and 410 at High. Always work from the current baseline published by the FedRAMP PMO, since baselines are revised.

Can we get FedRAMP authorized without an agency sponsor?
Not for a full agency authorization, which is the primary path. A sponsor is required to grant the ATO. You can complete readiness work and engage a 3PAO for a Readiness Assessment Report beforehand, which is how many companies position themselves to win a sponsor.

What is the difference between FedRAMP Ready, In Process and Authorized?
Ready means a 3PAO has produced a Readiness Assessment Report and the PMO has accepted it. In Process means an authorization effort is formally underway with a sponsor. Authorized means an agency has issued an ATO. Only Authorized permits federal agencies to use the service under FedRAMP.

Does a SOC 2 report help with FedRAMP?
It helps your posture but does not substitute for anything. There is meaningful control overlap, so mature SOC 2 controls reduce the gap, but FedRAMP requires NIST 800-53 controls assessed by a 3PAO against a FedRAMP baseline.

How long does FedRAMP authorization last?
The ATO does not expire on a fixed schedule the way a certificate does, but it is contingent on meeting continuous monitoring obligations and passing the annual assessment. Failing those can lead to suspension or revocation.

Is FedRAMP required to sell to state and local government?
Not directly. FedRAMP is a federal programme, though some state programmes such as StateRAMP are modelled on it and may accept FedRAMP artefacts.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory, or professional advice. FedRAMP requirements, baselines, and programme structure change over time; verify current requirements against official FedRAMP PMO guidance. Consult your sponsoring agency, an accredited 3PAO, and qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.7(96 reviews)

Keep reading

Jun 17, 2026 · FedRAMP

FISMA vs FedRAMP

Jun 15, 2026 · FedRAMP

FedRAMP Requirements

Jun 14, 2026 · FedRAMP

FedRAMP Overview

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?