Compliance matrix
Federal Risk and Authorization Management Program
United States (federal government) · Updated 2026-07-19
Applies to: Cloud service providers selling to US federal agencies; built on NIST SP 800-53 controls.
Vendor certification snapshot
FedRAMP status across the 48 vendors we track, read live from each profile.
9
Certified
1
Partial
38
Not stated
Certified / supported
Partial
Status is one signal, not a guarantee. Always confirm current certification scope directly with the vendor.
Requirements mapped to CIAM
Identification and authentication (IA family)
Users must authenticate with phishing-resistant MFA, and cryptography must be FIPS 140 validated.
CIAM controls
- Phishing-resistant MFA (PIV / CAC or FIDO2)
- FIPS 140-validated cryptographic modules
- Unique identification of every user
Evidence
- FedRAMP authorization package (SSP)
- FIPS validation certificates
Ask the vendor
- At what impact level are you FedRAMP authorized, and in which environment?
- Do you support PIV/CAC and FIDO2 phishing-resistant authentication?
Access control (AC family)
Access must follow least privilege with session controls and separation of duties.
CIAM controls
- Least-privilege RBAC
- Session lock and termination
- Separation of duties for privileged roles
Evidence
- Access control policy in the SSP
- Role definitions
Ask the vendor
- Are least-privilege roles, session lock, and SoD supported in the authorized boundary?
Audit and accountability (AU family)
Authentication and access events must be logged, protected, and retained per federal requirements.
CIAM controls
- Comprehensive audit logging
- Log protection and defined retention
Evidence
- Audit records
- Retention configuration
Ask the vendor
- What is the audit log retention in your FedRAMP environment?
Take this into procurement
Turn these requirements into vendor questions.
The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.
Go deeper
Where it bites hardest
FAQ
- Is a vendor's commercial cloud FedRAMP authorized?
- Usually not. FedRAMP authorization applies to a specific environment and impact level, typically a separate government cloud, not the vendor's standard commercial offering. Always confirm the authorized boundary and impact level (Low, Moderate, or High) for the exact product you would deploy.
- Does FedRAMP require phishing-resistant MFA?
- Federal direction (OMB M-22-09 zero-trust strategy) pushes agencies toward phishing-resistant MFA such as PIV/CAC and FIDO2, and IA controls at Moderate and High baselines expect strong, FIPS-validated authentication. Plan for phishing-resistant methods, not SMS OTP.
Source
FedRAMP (official program site)
This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.