FedRAMP readiness.
The authorisation US federal agencies require before they can use your cloud service. It is the most demanding programme we support, and we will tell you honestly whether the market opportunity justifies it.
At a glance
- Applies to
- Cloud service providers selling to US federal agencies
- Baselines
- Low, Moderate and High
- Timeline
- 12 to 18 months typical, sometimes longer
- Assessment
- By an accredited third-party assessment organisation
- Our role
- Readiness, documentation and remediation support
What this actually is.
FedRAMP is not a heavier SOC 2. It is a different category of commitment: hundreds of NIST SP 800-53 controls, continuous monitoring obligations, and a sponsorship or marketplace path that takes a year or more. Companies that start it without understanding the ongoing cost tend to abandon it halfway.
What we cover.
Who needs this.
- Cloud service providers with a federal agency sponsor
- SaaS companies where federal revenue justifies a multi-year programme
- Vendors whose competitors are already listed on the marketplace
- Organisations already holding SOC 2 or ISO 27001 and extending to federal
Frequently asked.
Do we need an agency sponsor?
The agency authorisation path requires a sponsoring agency. There are other routes to the marketplace, and the programme has evolved, so we assess which path is realistic for you before you commit budget.
Is FedRAMP worth it for us?
Often not, and we will say so. If federal revenue is speculative, the twelve to eighteen month timeline and the permanent continuous monitoring cost usually outweigh the opportunity. Ask us before you start, not after.
How does it relate to SOC 2 and ISO 27001?
There is real overlap in control intent, and existing certifications reduce effort. They do not shortcut it. FedRAMP demands a depth of documentation and evidence neither of the others approaches.
What is continuous monitoring in practice?
Monthly vulnerability scanning, ongoing POA&M management, annual assessment and significant change requests. It is a permanent operating cost, not a project that finishes.
Related services.
The certification your enterprise customers ask for by name, and the one most likely to be blocking a deal right now. We take you from gap assessment to a clean Type I or Type II report.
SVC 05CloudYour provider secures the cloud. You are responsible for what is in it. We test identity, exposure and blast radius across AWS, Azure and GCP, and we do it against your actual configuration rather than a checklist.
SectorGovernmentPublic sector work brings procurement requirements that commercial buyers do not impose, and a threat profile that includes actors with time and budget.
Find out what stands between you and certification.
Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.