Photo: Unsplash
FedRAMP authorization checklist
FedRAMP is the hardest compliance programme most SaaS companies will attempt. It is not a certification you pass, it is an authorization a federal agency grants to a specific cloud service at a specific impact level, and it comes with monthly obligations that continue for as long as the authorization stands.
This checklist covers the decisions, phases and deliverables in order, so you can see the whole shape of the programme before committing to it.
Key takeaways
- FedRAMP is built on NIST SP 800-53 controls. Under Rev 5, the baselines are roughly 156 controls at Low, 323 at Moderate and 410 at High. Moderate is what most agencies require.
- You need a federal agency sponsor. There is no way to self-initiate a full authorization and sit on the Marketplace waiting for customers.
- An accredited 3PAO must perform the security assessment. You cannot assess yourself.
- Authorization is the beginning of the work, not the end. Monthly continuous monitoring deliverables and an annual assessment are mandatory.
- Budget 12 to 24 months and a seven-figure total cost for a Moderate authorization from a standing start.
Before you start: three prerequisites
Confirm all three before spending money. Each one has ended FedRAMP projects.
- An agency sponsor who will grant the ATO. A federal customer who wants your product and will commit staff time to reviewing your package. Verbal interest is not a sponsor.
- A US-based, appropriately isolated environment. FedRAMP data must reside in the United States, and personnel with access are subject to screening requirements. For most companies this means building a separate government cloud environment (AWS GovCloud, Azure Government or equivalent), not adding controls to the commercial one.
- Executive commitment to the ongoing cost. Continuous monitoring is a permanent staffing line, not a project cost.
If you cannot check all three, the honest answer is that you are not ready to start.
Step 1: determine your impact level
Impact level follows FIPS 199 categorisation of the data your service handles, assessed across confidentiality, integrity and availability. The highest of the three sets your level.
| Level | Approximate control count (Rev 5) | Use when | Reality |
|---|---|---|---|
| Low | ~156 | Loss would have limited adverse effect | Rare as a target; most agencies ask for more |
| Li-SaaS (Tailored) | Reduced subset | Low-impact SaaS with no PII beyond login credentials | A genuine shortcut, but the eligibility criteria are narrow |
| Moderate | ~323 | Loss would have serious adverse effect. Covers most federal data that is not classified or safety-critical | The default target. Around four in five authorizations |
| High | ~410 | Loss would have severe or catastrophic effect. Law enforcement, emergency services, financial systems, health data | Significantly harder; plan for a longer runway |
Do this step with your sponsoring agency, not alone. Agencies determine the categorisation of their own data, and being told in month eight that Moderate is insufficient is an expensive correction.
Step 2: choose your authorization path
FedRAMP's governance changed materially following OMB Memorandum M-24-15 in 2024, which replaced the Joint Authorization Board with the FedRAMP Board and pushed agency authorization as the primary route.
- Agency authorization. Your sponsoring agency reviews your package and issues an Authority to Operate. This is the standard path today. Once authorized, other agencies can reuse your package.
- FedRAMP Board authorization. Reserved for services with broad government-wide demand, prioritised centrally.
- FedRAMP 20x. A newer programme aimed at faster, more automated authorization for cloud-native services. It has been running as a phased pilot, and eligibility and requirements have been evolving, so check the current FedRAMP guidance rather than relying on any secondhand summary including this one.
Whichever path applies, you also register in the FedRAMP Marketplace, which lists your status: "In Process" once a sponsor is confirmed and the programme is underway, then "Authorized".
Step 3: work the authorization phases
Phase 1: Preparation and readiness
- FIPS 199 categorisation agreed with your sponsor
- System boundary defined and diagrammed. This is the highest-leverage decision in the whole programme. Everything inside the boundary is in scope, including external services you call.
- Gap assessment against the applicable baseline
- Optional but recommended: a Readiness Assessment Report (RAR) produced by a 3PAO, which surfaces boundary and architecture problems before you have built on top of them
- 3PAO selected from the accredited list
Phase 2: Documentation
- System Security Plan (SSP) written, with every control in the baseline addressed. This is the core deliverable and typically runs to hundreds of pages.
- All required attachments and policies drafted and approved
- Control implementation statements written per control, describing what you actually do
Phase 3: Implementation
- Controls implemented in the government environment
- Inheritance documented where you rely on your underlying cloud provider's authorization, with a clear customer responsibility matrix
- Evidence generation started, since the assessment will sample it
Phase 4: Assessment
- 3PAO writes the Security Assessment Plan (SAP) and your sponsor approves it
- Testing performed: control testing, vulnerability scanning, penetration testing
- 3PAO issues the Security Assessment Report (SAR) with findings
- You produce the Plan of Action and Milestones (POA&M) for every open finding, with severity, owner and remediation date
Phase 5: Authorization
- Full package submitted to the sponsoring agency
- Agency risk review, usually with rounds of questions
- Agency issues the ATO letter
- Marketplace status updated to Authorized
Phase 6: Continuous monitoring
Begins the day authorization is granted and never stops.
The deliverable checklist
| Deliverable | Produced by | Notes |
|---|---|---|
| FIPS 199 categorisation | You, with your agency | Sets the baseline |
| System boundary diagram and data flows | You | Scrutinised heavily; get it right early |
| System Security Plan (SSP) | You | Every baseline control addressed |
| Policies and procedures | You | One set per control family |
| Configuration and hardening baselines | You | Usually mapped to CIS or DISA STIG |
| Incident response plan | You | Must include US-CERT reporting timelines |
| Contingency plan and test results | You | Including a completed test, not just a plan |
| Readiness Assessment Report (RAR) | 3PAO | Optional, strongly recommended |
| Security Assessment Plan (SAP) | 3PAO | Agency approves before testing |
| Penetration test report | 3PAO | Scope defined by FedRAMP guidance |
| Security Assessment Report (SAR) | 3PAO | The findings |
| Plan of Action and Milestones (POA&M) | You | Living document, maintained forever |
| ATO letter | Sponsoring agency | The authorization itself |
Continuous monitoring: the obligation that never ends
This is the part companies underestimate, and it is where authorizations get suspended.
Monthly:
- Vulnerability scans of operating systems, web applications and databases, submitted to your agency
- Updated POA&M reflecting remediation progress
- Remediation within FedRAMP timelines, generally 30 days for high-severity findings, 90 for moderate and 180 for low
- Inventory updates
Annually:
- A 3PAO assessment covering a defined subset of controls
- Contingency plan test
- Policy and procedure review
- Penetration test
On change:
- Significant Change Requests submitted and approved before major architecture changes. Deploying a significant change without approval is a compliance failure in its own right.
Plan for at least one full-time person on continuous monitoring for a Moderate system, more if your scanning surface is large.
Timeline and cost
For a Moderate authorization starting without existing federal work:
| Phase | Typical duration |
|---|---|
| Readiness and gap assessment | 2 to 4 months |
| Government environment build | 3 to 6 months, often in parallel |
| SSP and documentation | 3 to 6 months |
| 3PAO assessment | 2 to 3 months |
| Agency review and ATO | 3 to 6 months |
| Total | 12 to 24 months |
Costs vary widely, but for Moderate expect 3PAO fees in the low-to-mid six figures, a comparable or larger internal engineering cost for the isolated environment, advisory support, and then an ongoing annual cost for continuous monitoring and the annual assessment. Treating FedRAMP as under a million dollars all-in for a first Moderate authorization is optimistic for most companies.
Where FedRAMP projects stall
- No real sponsor. The single most common cause of abandoned projects.
- A boundary drawn too wide. Every service inside it needs to be authorized or properly inherited. Pulling your commercial analytics stack inside the boundary can add a year.
- Starting the SSP before the architecture is settled. The document then chases the system.
- Assuming cloud provider inheritance covers more than it does. Their authorization covers their layer. The customer responsibility matrix is yours to satisfy.
- Treating the POA&M as a closing document. It is permanent, and agencies watch whether remediation dates slip.
- Underfunding continuous monitoring. Missed monthly submissions put the authorization at risk.
- Choosing a 3PAO on price alone. An assessor who has not worked your architecture pattern costs more in rework than they save.
How SecureSlate helps
SecureSlate maintains your control inventory, evidence and POA&M in one place, and maps a single control set across FedRAMP, SOC 2 and ISO 27001 so the work you do for one framework counts toward the others. Continuous monitoring tasks, scan results and remediation deadlines are tracked against FedRAMP timelines rather than managed in spreadsheets.
Related guides:
- Best FedRAMP compliance software
- FedRAMP collection
- Incident response plan template
- BCP and disaster recovery plan template
- SOC 2 compliance checklist
FAQ
How many controls are in FedRAMP?
It depends on your impact level. Under NIST SP 800-53 Rev 5, the FedRAMP baselines are approximately 156 controls at Low, 323 at Moderate and 410 at High. Always work from the current baseline published by the FedRAMP PMO, since baselines are revised.
Can we get FedRAMP authorized without an agency sponsor?
Not for a full agency authorization, which is the primary path. A sponsor is required to grant the ATO. You can complete readiness work and engage a 3PAO for a Readiness Assessment Report beforehand, which is how many companies position themselves to win a sponsor.
What is the difference between FedRAMP Ready, In Process and Authorized?
Ready means a 3PAO has produced a Readiness Assessment Report and the PMO has accepted it. In Process means an authorization effort is formally underway with a sponsor. Authorized means an agency has issued an ATO. Only Authorized permits federal agencies to use the service under FedRAMP.
Does a SOC 2 report help with FedRAMP?
It helps your posture but does not substitute for anything. There is meaningful control overlap, so mature SOC 2 controls reduce the gap, but FedRAMP requires NIST 800-53 controls assessed by a 3PAO against a FedRAMP baseline.
How long does FedRAMP authorization last?
The ATO does not expire on a fixed schedule the way a certificate does, but it is contingent on meeting continuous monitoring obligations and passing the annual assessment. Failing those can lead to suspension or revocation.
Is FedRAMP required to sell to state and local government?
Not directly. FedRAMP is a federal programme, though some state programmes such as StateRAMP are modelled on it and may accept FedRAMP artefacts.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory, or professional advice. FedRAMP requirements, baselines, and programme structure change over time; verify current requirements against official FedRAMP PMO guidance. Consult your sponsoring agency, an accredited 3PAO, and qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
