Skip to content

Compliance matrix

Federal Risk and Authorization Management Program

United States (federal government) · Updated 2026-07-19

Applies to: Cloud service providers selling to US federal agencies; built on NIST SP 800-53 controls.

Vendor certification snapshot

FedRAMP status across the 48 vendors we track, read live from each profile.

9

Certified

1

Partial

38

Not stated

Status is one signal, not a guarantee. Always confirm current certification scope directly with the vendor.

Requirements mapped to CIAM

Identification and authentication (IA family)

Users must authenticate with phishing-resistant MFA, and cryptography must be FIPS 140 validated.

CIAM controls

  • Phishing-resistant MFA (PIV / CAC or FIDO2)
  • FIPS 140-validated cryptographic modules
  • Unique identification of every user

Evidence

  • FedRAMP authorization package (SSP)
  • FIPS validation certificates

Ask the vendor

  • At what impact level are you FedRAMP authorized, and in which environment?
  • Do you support PIV/CAC and FIDO2 phishing-resistant authentication?

Access control (AC family)

Access must follow least privilege with session controls and separation of duties.

CIAM controls

  • Least-privilege RBAC
  • Session lock and termination
  • Separation of duties for privileged roles

Evidence

  • Access control policy in the SSP
  • Role definitions

Ask the vendor

  • Are least-privilege roles, session lock, and SoD supported in the authorized boundary?

Audit and accountability (AU family)

Authentication and access events must be logged, protected, and retained per federal requirements.

CIAM controls

  • Comprehensive audit logging
  • Log protection and defined retention

Evidence

  • Audit records
  • Retention configuration

Ask the vendor

  • What is the audit log retention in your FedRAMP environment?

Take this into procurement

Turn these requirements into vendor questions.

The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.

Go deeper

Where it bites hardest

FAQ

Is a vendor's commercial cloud FedRAMP authorized?
Usually not. FedRAMP authorization applies to a specific environment and impact level, typically a separate government cloud, not the vendor's standard commercial offering. Always confirm the authorized boundary and impact level (Low, Moderate, or High) for the exact product you would deploy.
Does FedRAMP require phishing-resistant MFA?
Federal direction (OMB M-22-09 zero-trust strategy) pushes agencies toward phishing-resistant MFA such as PIV/CAC and FIDO2, and IA controls at Moderate and High baselines expect strong, FIPS-validated authentication. Plan for phishing-resistant methods, not SMS OTP.

Source

FedRAMP (official program site)

This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.