Article

What Is FedRAMP? Federal Cloud Authorization in the 20x Era

FedRAMP authorizes cloud services for U.S. federal agencies. Learn how it works, the three impact levels, and what FedRAMP 20x is changing.

U.S. federal agencies acquiring cloud services for production use are required to procure from FedRAMP®-authorized providers. The requirement is driven by FISMA, reinforced by OMB policy, and enforced through federal procurement. In practice, it also extends to federal contractors, state and local entities handling federal data, and commercial vendors selling cloud services into the federal market.

Without a FedRAMP® authorization, a cloud service provider cannot sell its product to U.S. federal agencies for production workloads. For companies targeting the federal market, FedRAMP® is a prerequisite. For companies targeting regulated commercial industries — healthcare, financial services, defense supply chain — FedRAMP® authorization also signals a level of security rigor that often accelerates enterprise sales.

FedRAMP® is the U.S. government's standardized way of verifying that a cloud service is secure enough for federal agencies to use. Instead of every agency doing its own security review, a cloud provider goes through one rigorous assessment — and once it passes, any agency can adopt the service without repeating the work.

FedRAMP® Ready means an independent 3PAO has assessed a cloud service and confirmed it meets the requirements necessary to pursue full authorization — a verified readiness milestone. FedRAMP® Authorized means a federal agency has issued an Authority to Operate (ATO), the service is listed on the FedRAMP® Marketplace as Authorized, and federal agencies can use it in production.

FISMA is the U.S. law requiring federal agencies to secure their information systems. NIST SP 800-53 is the control catalog agencies use to meet that requirement. FedRAMP® takes the relevant NIST 800-53 controls, tailors them to the cloud context, and defines the assessment and continuous monitoring process cloud service providers follow. In short: FISMA is the law, NIST 800-53 is the controls, and FedRAMP® is how both are applied to the cloud.

A 3PAO — Third Party Assessment Organization — is an independent auditor accredited by FedRAMP® to evaluate a cloud service provider's security controls. 3PAOs perform Readiness Assessments, full Security Assessments, and annual assessments, and they are the source of the independent verification that underpins every FedRAMP® authorization.

Learn more about how Teradata delivers secure, compliant analytics for federal agencies at the Trust and Security Center, or read the announcement on VantageCloud Lake's FedRAMP® Ready milestone.

Stay in the know

Subscribe to get weekly insights delivered to your inbox.



I consent that Teradata Corporation, as provider of this website, may occasionally send me Teradata Marketing Communications emails with information regarding products, data analytics, and event and webinar invitations. I understand that I may unsubscribe at any time by following the unsubscribe link at the bottom of any email I receive.

Your privacy is important. Your personal information will be collected, stored, and processed in accordance with the Teradata Global Privacy Statement.