01Introduction
To sell cloud services to US federal agencies, you need FedRAMP authorization. It's one of the most demanding security programs a cloud provider can take on, and one of the most valuable.
02What is FedRAMP?
The Federal Risk and Authorization Management Program (FedRAMP) is a US government program that standardizes security assessment, authorization and continuous monitoring for cloud products used by federal agencies. It is based on NIST SP 800-53 controls at Low, Moderate or High impact baselines.
Authorization requires an assessment by an accredited Third Party Assessment Organization (3PAO), including penetration testing to FedRAMP's guidance, followed by monthly continuous monitoring. SBOMs are increasingly expected under federal software requirements.
03How FedRAMP works
FedRAMP is a long process with an ongoing tail.
- 1.
Prepare
Choose a baseline, find an agency sponsor and write the System Security Plan.
- 2.
Assess
A 3PAO tests the controls, including a penetration test covering defined attack vectors.
- 3.
Authorize
The agency or FedRAMP board reviews the package and issues an authorization.
- 4.
Continuous monitoring
Monthly vulnerability scanning, plan-of-action tracking and annual assessments.
04Threats and risks
FedRAMP punishes gaps in continuous monitoring.
POA&M backlog
Open vulnerabilities past remediation deadlines put the authorization at risk.
Boundary drift
New services or data flows outside the authorized boundary.
Supply chain scrutiny
Federal requirements for software provenance and component inventory. See software supply chain security.
Testing depth
Pentests have to cover the attack vectors FedRAMP specifies, not just a scan.
05How Parameter helps
Parameter helps keep the continuous part of FedRAMP continuous. See FedRAMP penetration testing.
Ongoing testing
The pentesting agents test between annual assessments, so issues are found before the 3PAO does.
Proven remediation
Retests on fix give evidence for closing plan-of-action items.
Signed SBOMs
Supply Chain regenerates a signed inventory on every build.

