SECOMPSSECOMPS
Home/Services/FedRAMP
CMP 04

FedRAMP readiness.

The authorisation US federal agencies require before they can use your cloud service. It is the most demanding programme we support, and we will tell you honestly whether the market opportunity justifies it.

At a glance

Applies to
Cloud service providers selling to US federal agencies
Baselines
Low, Moderate and High
Timeline
12 to 18 months typical, sometimes longer
Assessment
By an accredited third-party assessment organisation
Our role
Readiness, documentation and remediation support
01Overview

What this actually is.

FedRAMP is not a heavier SOC 2. It is a different category of commitment: hundreds of NIST SP 800-53 controls, continuous monitoring obligations, and a sponsorship or marketplace path that takes a year or more. Companies that start it without understanding the ongoing cost tend to abandon it halfway.

02Scope

What we cover.

Readiness assessmentAn honest evaluation of how far you are from the baseline and what the realistic timeline and cost look like.
Baseline selectionLow, Moderate or High, driven by the data your federal customers will actually put in the system.
Boundary definitionWhat is inside the authorisation boundary, which drives the entire scope and is expensive to get wrong.
System Security PlanThe core document describing how every applicable NIST SP 800-53 control is implemented.
Control implementationTechnical and procedural gaps closed against the selected baseline, prioritised by assessment risk.
Policies and proceduresThe full documentation set FedRAMP requires, at the specificity assessors expect.
Pre-assessmentA dry run against the baseline before your assessment organisation begins, so findings surface while they are cheap.
Continuous monitoringThe ongoing scanning, reporting and POA&M management that begins the day you are authorised and never stops.
03Fit

Who needs this.

  • Cloud service providers with a federal agency sponsor
  • SaaS companies where federal revenue justifies a multi-year programme
  • Vendors whose competitors are already listed on the marketplace
  • Organisations already holding SOC 2 or ISO 27001 and extending to federal
04Questions

Frequently asked.

Do we need an agency sponsor?

The agency authorisation path requires a sponsoring agency. There are other routes to the marketplace, and the programme has evolved, so we assess which path is realistic for you before you commit budget.

Is FedRAMP worth it for us?

Often not, and we will say so. If federal revenue is speculative, the twelve to eighteen month timeline and the permanent continuous monitoring cost usually outweigh the opportunity. Ask us before you start, not after.

How does it relate to SOC 2 and ISO 27001?

There is real overlap in control intent, and existing certifications reduce effort. They do not shortcut it. FedRAMP demands a depth of documentation and evidence neither of the others approaches.

What is continuous monitoring in practice?

Monthly vulnerability scanning, ongoing POA&M management, annual assessment and significant change requests. It is a permanent operating cost, not a project that finishes.

Find out what stands between you and certification.

Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.