# What is the Federal Risk and Authorization Management Program (FedRAMP)?

> The Federal Risk and Authorization Management Program (FedRAMP) is a United States government-wide program that standardizes reusable security information about in-scope cloud services processing unclassified federal information.

- Canonical URL: https://yellowcube.eu/glossary/federal-risk-and-authorization-management-program/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Under the Consolidated Rules for 2026, a service obtains and maintains FedRAMP Certification through a defined type, class, and path; agencies use its package in risk and authorization decisions.

FedRAMP is transitioning under the Consolidated Rules for 2026: optional adoption began July 4, 2026, and mandatory adoption is scheduled for January 1, 2027. The rules support Rev5 and FedRAMP 20x certification types. A provider defines the service boundary, identifies the Certification Profile — its type, class, and path — and supplies validation evidence plus ongoing reporting. An agency authorization to operate remains a separate agency decision.

### Key points

- **Choose the profile:** Determine whether the service is eligible, select the certification type, class, and program or agency path, and identify its requirements and evidence.
- **Establish the package:** Describe the offering and boundary, supply machine-readable information, document inherited and customer responsibilities, validate implementation, and address findings.
- **Maintain certification:** Monitor security conditions, report ongoing information and incidents, manage significant changes, and keep certification data available to FedRAMP and agency customers.
- **Important limitation:** FedRAMP Certification does not determine that a service is universally secure or approve every deployment. Each agency must still authorize and govern its own use, data, configurations, integrations, inherited controls, and accepted risk.

### Related terms

[Cloud security](<https://yellowcube.eu/glossary/cloud-security/>) · [National Institute of Standards and Technology Special Publication (NIST SP) 800-53](<https://yellowcube.eu/glossary/national-institute-of-standards-and-technology-special-publication-800-53/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Security telemetry](<https://yellowcube.eu/glossary/security-telemetry/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Federal Information Security Modernization Act (FISMA)](<https://yellowcube.eu/glossary/federal-information-security-modernization-act/>)

### Sources

[FedRAMP, Choosing a Certification Path](https://www.fedramp.gov/2026/providers/start/path/) · [FedRAMP, Using Rev5 Certification Packages](https://www.fedramp.gov/2026/agencies/use/packages/rev5/) · [FedRAMP, Important Dates for the Consolidated Rules for 2026](https://www.fedramp.gov/2026/timeline/) · [44 U.S.C. § 3608, Federal Risk and Authorization Management Program](https://uscode.house.gov/view.xhtml?edition=prelim&num=0&req=granuleid%3AUSC-prelim-title44-section3608)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

