The encyclopedia · Engineering & Operations · Operational decision · 2011-2021
FedRAMP lets one cloud security review be reused by every US agency.
In 2011 OMB created FedRAMP so a cloud provider is authorized once; every agency reuses that authorization instead of repeating the work.
U.S. General Services Administration
the move
Before 2011, any US agency wanting a cloud service ran its own security assessment. That meant the same product, and sometimes the same risk, was reviewed dozens of times, slowing cloud adoption and burning scarce security staff.
On 8 December 2011 OMB signed a memo establishing FedRAMP to provide a cost-effective, risk-based approach. It created one standardized control baseline and a single provisional authorization from the Joint Authorization Board, which agencies could then accept.
Once approved, a provider's offering becomes reusable: 240 authorized cloud offerings were reused more than 3,000 times across the federal government in the program's first decade. FedRAMP made the security hurdle a fixed, one-time cost instead of a per-agency one.
why it works
- Repeating the same review across agencies was wasteful and slow
- A single authorization lets a small agency ride on a big agency's work
- Standard controls make cloud security comparable and auditable
- It turned security from a blocker into a reusable procurement asset
what transfers
Standardize the hard part once and let everyone reuse it: duplicated due diligence, not the technology, is often the real bottleneck in procurement.
what came after
By its tenth anniversary FedRAMP had over 180 participating agencies, 280-plus cloud service providers and 40 recognized 3PAOs, with 240 offerings and 3,000-plus reuses. It became the default gateway for federal cloud adoption and a template for shared authorization programs.
references
spotted an error? The archive wants to know.