{"id":15966,"date":"2021-08-13T09:06:00","date_gmt":"2021-08-13T03:36:00","guid":{"rendered":"https:\/\/www.varutra.com\/?p=15966"},"modified":"2022-12-02T12:25:43","modified_gmt":"2022-12-02T06:55:43","slug":"roadmap-to-fedramp-compliance","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/","title":{"rendered":"Roadmap to FedRAMP Compliance"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2021\/08\/Roadmap-to-FedRAMP-Compliance-1024x535.png\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"Roadmap to FedRAMP Compliance - Varutra Consulting\"><br \/>\nThe basic layman\u2019s concept behind cloud computing technology is that the user does not need to physically manage any server or hardware to process his data, Cloud computing is more like using someone\u2019s computer resources remotely to perform and execute your task. Over the period the cloud computing has seen a steep rise in migration of users from On-Premise\u2019s hosting platform to <a href=\"https:\/\/www.plesk.com\/blog\/various\/cloud-hosting-platforms-choose-the-right-one\/\">Cloud Hosting Platforms<\/a>. The Cloud solutions are comparatively cheaper, and the users need not worry about the investment required for the use of NICHE technology.<\/p>\n<p>According to Gartner, INC the worldwide end-user expenditure on public cloud platform services is predicted to forecast to rise by 18.4% in the year 2021 to a total sum of $304.9 billion, rising from a huge $257.5 billion even during the Covid Pandemic in 2020.<\/p>\n<p>Just as the cloud computing platform has transformed the way many organizations and companies manage their infrastructure and IT assets and do business; the federal government has further recognized the impact that clouds computing platforms and services will have in re-structuring how they do business and perform operations as well as how they can save the commercial expenditure on federal IT infrastructure. The federal government has further identified the associated Threats \u2013 Risks that are a part of worry for processing the federal data on a cloud computing platform.<\/p>\n<p>Thus, the federal government has established the process coined as FedRAMP &#8211; Federal Risk and Authorization Management Program, to address the federal information and data security concerns with respect to Confidentiality, Integrity, Availability, and reliability of cloud services that are used by the federal government, offices, and agencies.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What is FedRAMP Compliance?<\/strong><\/h3>\n<p>FedRAMP was established in the year 2011 with a vision to provide a cost-effective and risk-based assessment approach for the incorporation and ease of use of cloud services by the federal government agencies. FedRAMP has empowered the agencies to use the modern state-of-the-art niche cloud technologies, with a mission and vision to safeguard the confidentiality \u2013 integrity, and availability of federal data.<\/p>\n<p>For a commercial cloud service offering (CSO) to be used as a service by any federal agency, the CSO must be FedRAMP compliant to further adhere to the government security requirements that are outlined in NIST 800-53 Standard and supplemented by the FedRAMP Program Management Office (PMO).<\/p>\n<p>In layman\u2019s language, the cloud service providers (CSP) need to obtain a FedRAMP authorization, or FedRAMP Authority to Operate (ATO) to demonstrate his compliance with FedRAMP.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What is FedRAMP Security Assessment Framework (SAF)?<\/strong><\/h3>\n<p>The CSP is assessed by the Federal Agencies based on the FISMA requirements. The FedRAMP SAF is based on and is compliant with FISMA which is further based on NIST Special Publication Standard 800-37.<\/p>\n<p>FedRAMP has defined a set of control for Low and Moderate and High-security impact level systems based on NIST baseline controls (NIST SP 800-53, as revised) with a set of controls that pertain specifically to the security requirements of cloud computing technology.<\/p>\n<p>FedRAMP uses the same documents and deliverables that NIST requires Agencies to use, as described in NIST SP 800-37. FedRAMP has simplified the NIST <a href=\"https:\/\/www.varutra.com\/risk-management\/\">Risk Management<\/a> Framework by creating four process areas around it that encompass the steps detailed within NIST SP 800-37: Document, Assess, Authorize, and Monitor as shown the below figure.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-15969 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/08\/FedRAMP-Risk-Management-Framework.png\" alt=\"FedRAMP Compliance Risk Management Framework\" width=\"392\" height=\"399\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/08\/FedRAMP-Risk-Management-Framework.png 392w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/08\/FedRAMP-Risk-Management-Framework-295x300.png 295w\" sizes=\"(max-width: 392px) 100vw, 392px\" \/><\/p>\n<p style=\"text-align: center\">FedRAMP Risk Management Framework<\/p>\n<ol>\n<li><strong> Document<\/strong><\/li>\n<\/ol>\n<p>CSPs have to categorize CSO as per and according to the FIPS-199. The resulting categorization of the evaluation based on FIPS &#8211; 199(Low, Moderate, or High) will determine the associated NIST 800-53 controls (and FedRAMP supplemental controls) that will apply to the CSO and need to comply with.<\/p>\n<ol>\n<li><strong> Assess<\/strong><\/li>\n<\/ol>\n<p>For the Assessment, phase to begin the SSP and other required documentation need to be in place, reviewed, and approved. Post which a Third-Party Assessment Organization \u2013 3PAO will come up with a security assessment plan (SAP) which outlines the testing approach for the CSO.<\/p>\n<p>Once the SAP is approved by the CSO (and the counterpart federal agency for the ATO), the 3PAO will further test the implementation of controls and derive a Security Assessment Report (SAR).<\/p>\n<ol>\n<li><strong> Authorize<\/strong><\/li>\n<\/ol>\n<p>During this phase, the SAR prepared by the 3PAO is reviewed by the federal agency (for an agency authorization) and approved. Once the SAR is approved by the Agency an agency ATO letter (for the agency path) is issued and uploaded to a secure controlled central repository with all other required mandatory documentation that is needed for FedRAMP Compliance. The FedRAMP PMO then further reviews these documentation sets and decides regarding the FedRAMP authorization.<\/p>\n<ol>\n<li><strong> Continuous Monitoring<\/strong><\/li>\n<\/ol>\n<p>Once an initial agency ATO or JAB P-ATO is achieved by the CSP, the CSP enters the continuous monitoring phase. During this phase, the CSP ensures that the controls that were assessed by the Authorizing body will continue to operate effectively. A part of the implemented controls are monitored and evaluated at specified predefined time intervals and data regarding compliance status is provided to the authorizing agency duly.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What are the FedRAMP compliance requirements?<\/strong><\/h3>\n<p>The high-level requirements to achieve FedRAMP compliance are as follows:<\/p>\n<ul>\n<li>The CSP should ensure and complete the FedRAMP Compliance required mandatory documentation including the FedRAMP System Security Plan (SSP).<\/li>\n<li>The controls as per the FIPS 199 categorization of the CSO are to be implemented.<\/li>\n<li>The CSP must be assessed by a FedRAMP Third Party Assessment Organization (3PAO).<\/li>\n<li>The findings are to be remediated if any are highlighted by the 3PAO during this engagement.<\/li>\n<li>A Plan of Action and Milestones (POA&amp;M)must be developed.<\/li>\n<li>The Agency ATO or Joint Authorization Board (JAB) Provisional ATO (P-ATO) approval must be obtained.<\/li>\n<li>Process of continuous monitoring must be incorporated including the monthly scans for vulnerability.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong>Two Ways to Achieve FedRAMP Compliance<\/strong><\/h3>\n<p>There are two ways that a CSP can take to obtain a FedRAMP authorization or an ATO(Authority to Operate). The first path is to obtain a FedRAMP ATO directly from a federal agency that you intend to provide service to. The second path is to receive a FedRAMP P-ATO from the JAB.<\/p>\n<p><strong>Agency ATO Vs JAB P-ATO<\/strong><\/p>\n<p>The major difference between an Agency FedRAMP ATO and a JAB P-ATO is the authorization scope or an ATO.<\/p>\n<p>The Agency FedRAMP ATO is applicable and limited to that federal agency itself. And this does not further mean that the other federal agencies are authorized to use the services of that CSO. The different federal agencies have their different buckets of risk appetite and evaluation standards. So a CSO getting an Agency FedRAMP ATO from one agency will not be authorized to operate with the other agency unless and until he obtains that agency-specific FedRAMP ATO.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-15968 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/08\/Agency-Authorization-Process-RoadMap.png\" alt=\"Agency Authorization Process RoadMap\" width=\"622\" height=\"253\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/08\/Agency-Authorization-Process-RoadMap.png 622w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/08\/Agency-Authorization-Process-RoadMap-300x122.png 300w\" sizes=\"(max-width: 622px) 100vw, 622px\" \/><\/p>\n<p style=\"text-align: center\"><strong>Agency Authorization Process RoadMap<\/strong><\/p>\n<p>Once a Cloud Service Operator has Agency FedRAMP ATO with a Federal Agency, and some other agency now wants to use the services of this CSO then the other Agency will evaluate the authorization packages with respect to the risk profile and appetite of the Agency and will determine if the, if the resulting assessment is and determined security posture of the CSO, is sufficient to meet the risk standards and the security requirements.<\/p>\n<p>It this is found true, and the Authorization Packages are enough to handle and sustain the requirements of the new Federal Agency then the agency will issue the FedRAMP Authorization \u2013 ATO to the CSP for his CSO to the federal agency. And if it is not meeting the Authorization Standard Requirements then additional requirements and testing are needed to address the need of the new federal agency.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-15970 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/08\/JAB-Authorization-Process-Road-Map-2.png\" alt=\"JAB Authorization Process Road Map \" width=\"627\" height=\"310\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/08\/JAB-Authorization-Process-Road-Map-2.png 627w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/08\/JAB-Authorization-Process-Road-Map-2-300x148.png 300w\" sizes=\"(max-width: 627px) 100vw, 627px\" \/><\/p>\n<p style=\"text-align: center\"><strong>JAB Authorization Process Road Map<\/strong><\/p>\n<p>The JAB \u2013 Joint Authorization Board is the primary governing body for FedRAMP compliance regulations and includes the representative and stakeholders from the Department of Defense (DoD), Department of Homeland Security (DHS), and General Services Administration (GSA).<\/p>\n<p>The JAB governing body selects approximately 12 cloud products or CSO a year to work with for a JAB Provisional Authority to Operate (P-ATO). The JAB is further responsible for performing the continuous monitoring for all JAB Authorized cloud products or CSO. The Authorization is a Provisional \u2013 ATO and this does not determine the risk acceptance and mitigation part of the Federal Agencies. Thus, to further operate or get associated with an Agency for a CSO, the CSO needs to obtain an ATO from the Agency.<\/p>\n<p>&nbsp;<\/p>\n<p>Author,<\/p>\n<p><strong>Omkar Gaikwad\u00a0<\/strong><\/p>\n<p>Audit and Compliance<\/p>\n<p>Varutra Consulting Pvt. Ltd.<\/p>","protected":false},"excerpt":{"rendered":"<p>The basic layman\u2019s concept behind cloud computing technology is that the user does not need to physically manage any server or hardware to process his&#8230;<\/p>\n","protected":false},"author":4,"featured_media":16006,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[290,446],"tags":[484,325,488,483,486,438,485,487],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Are you FedRamp authorised cloud provider? Here is our new article for better understanding of FedRAMP compliance requirements, and ways to achieve it.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"kalpblogger\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Roadmap to FedRAMP Compliance For Cloud Computing Services\" \/>\n\t\t<meta property=\"og:description\" content=\"Are you FedRamp authorised cloud provider? Here is our new article for better understanding of FedRAMP compliance requirements, and ways to achieve it.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/08\/Roadmap-to-FedRAMP-Compliance.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/08\/Roadmap-to-FedRAMP-Compliance.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t\t<meta property=\"article:section\" content=\"Governance Risk &amp; Compliance\" \/>\n\t\t<meta property=\"article:tag\" content=\"cloud computing\" \/>\n\t\t<meta property=\"article:tag\" content=\"compliance\" \/>\n\t\t<meta property=\"article:tag\" content=\"csp\" \/>\n\t\t<meta property=\"article:tag\" content=\"fedramp\" \/>\n\t\t<meta property=\"article:tag\" content=\"fisma\" \/>\n\t\t<meta property=\"article:tag\" content=\"nist\" \/>\n\t\t<meta property=\"article:tag\" content=\"sar\" \/>\n\t\t<meta property=\"article:tag\" content=\"ssp\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-08-13T03:36:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-02T06:55:43+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Roadmap to FedRAMP Compliance For Cloud Computing Services\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Are you FedRamp authorised cloud provider? Here is our new article for better understanding of FedRAMP compliance requirements, and ways to achieve it.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/08\/Roadmap-to-FedRAMP-Compliance.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpblogger\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#article\",\"name\":\"Roadmap to FedRAMP Compliance For Cloud Computing Services\",\"headline\":\"Roadmap to FedRAMP Compliance\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Roadmap-to-FedRAMP-Compliance.png\",\"width\":1200,\"height\":627,\"caption\":\"Roadmap to FedRAMP Compliance\"},\"datePublished\":\"2021-08-13T09:06:00+05:30\",\"dateModified\":\"2022-12-02T12:25:43+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#webpage\"},\"articleSection\":\"Cloud Security, Governance Risk &amp; Compliance, Cloud Computing, compliance, CSP, FedRAMP, FISMA, NIST, SAR, SSP\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/cloud-security\\\/#listItem\",\"name\":\"Cloud Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/cloud-security\\\/#listItem\",\"position\":2,\"name\":\"Cloud Security\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/cloud-security\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#listItem\",\"name\":\"Roadmap to FedRAMP Compliance\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#listItem\",\"position\":3,\"name\":\"Roadmap to FedRAMP Compliance\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/cloud-security\\\/#listItem\",\"name\":\"Cloud Security\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/\",\"name\":\"kalpblogger\",\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/\",\"name\":\"Roadmap to FedRAMP Compliance For Cloud Computing Services\",\"description\":\"Are you FedRamp authorised cloud provider? Here is our new article for better understanding of FedRAMP compliance requirements, and ways to achieve it.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Roadmap-to-FedRAMP-Compliance.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#mainImage\",\"width\":1200,\"height\":627,\"caption\":\"Roadmap to FedRAMP Compliance\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/roadmap-to-fedramp-compliance\\\/#mainImage\"},\"datePublished\":\"2021-08-13T09:06:00+05:30\",\"dateModified\":\"2022-12-02T12:25:43+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Roadmap to FedRAMP Compliance For Cloud Computing Services<\/title>\n\n","aioseo_head_json":{"title":"Roadmap to FedRAMP Compliance For Cloud Computing Services","description":"Are you FedRamp authorised cloud provider? Here is our new article for better understanding of FedRAMP compliance requirements, and ways to achieve it.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#article","name":"Roadmap to FedRAMP Compliance For Cloud Computing Services","headline":"Roadmap to FedRAMP Compliance","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/08\/Roadmap-to-FedRAMP-Compliance.png","width":1200,"height":627,"caption":"Roadmap to FedRAMP Compliance"},"datePublished":"2021-08-13T09:06:00+05:30","dateModified":"2022-12-02T12:25:43+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#webpage"},"articleSection":"Cloud Security, Governance Risk &amp; Compliance, Cloud Computing, compliance, CSP, FedRAMP, FISMA, NIST, SAR, SSP"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/cloud-security\/#listItem","name":"Cloud Security"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/cloud-security\/#listItem","position":2,"name":"Cloud Security","item":"https:\/\/www.varutra.com\/varutravrt3\/category\/cloud-security\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#listItem","name":"Roadmap to FedRAMP Compliance"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#listItem","position":3,"name":"Roadmap to FedRAMP Compliance","previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/cloud-security\/#listItem","name":"Cloud Security"}}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","description":"Secure your digital world with our Cybersecurity services.","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/","name":"kalpblogger","image":{"@type":"ImageObject","url":"https:\/\/secure.gravatar.com\/avatar\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/","name":"Roadmap to FedRAMP Compliance For Cloud Computing Services","description":"Are you FedRamp authorised cloud provider? Here is our new article for better understanding of FedRAMP compliance requirements, and ways to achieve it.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/08\/Roadmap-to-FedRAMP-Compliance.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#mainImage","width":1200,"height":627,"caption":"Roadmap to FedRAMP Compliance"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/#mainImage"},"datePublished":"2021-08-13T09:06:00+05:30","dateModified":"2022-12-02T12:25:43+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"Roadmap to FedRAMP Compliance For Cloud Computing Services","og:description":"Are you FedRamp authorised cloud provider? Here is our new article for better understanding of FedRAMP compliance requirements, and ways to achieve it.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/08\/Roadmap-to-FedRAMP-Compliance.png","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/08\/Roadmap-to-FedRAMP-Compliance.png","og:image:width":"1200","og:image:height":"627","article:section":"Governance Risk &amp; Compliance","article:tag":["cloud computing","compliance","csp","fedramp","fisma","nist","sar","ssp"],"article:published_time":"2021-08-13T03:36:00+00:00","article:modified_time":"2022-12-02T06:55:43+00:00","twitter:card":"summary_large_image","twitter:title":"Roadmap to FedRAMP Compliance For Cloud Computing Services","twitter:description":"Are you FedRamp authorised cloud provider? Here is our new article for better understanding of FedRAMP compliance requirements, and ways to achieve it.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/08\/Roadmap-to-FedRAMP-Compliance.png","twitter:label1":"Written by","twitter:data1":"kalpblogger","twitter:label2":"Est. reading time","twitter:data2":"7 minutes"},"aioseo_meta_data":{"post_id":"15966","title":"Roadmap to FedRAMP Compliance For Cloud Computing Services","description":"Are you FedRamp authorised cloud provider? Here is our new article for better understanding of FedRAMP compliance requirements, and ways to achieve it.","keywords":[],"keyphrases":{"focus":{"keyphrase":"FedRAMP Compliance","analysis":{"keyphraseInTitle":{"title":"Focus keyphrase in SEO title","description":"Focus keyphrase found in SEO title.","score":9,"maxScore":9,"error":0},"keyphraseInDescription":{"title":"Focus keyphrase in meta description","description":"Focus keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Focus keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":2},"keyphraseInURL":{"title":"Focus keyphrase in URL","description":"Focus keyphrase used in the URL.","score":5,"maxScore":5,"error":0},"keyphraseInIntroduction":{"title":"Focus keyphrase in introduction","description":"Your Focus keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInSubHeadings":{"title":"Focus keyphrase in Subheadings","description":"Your H2 and H3 subheadings reflects the topic of your copy. Good job!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Focus keyphrase in image alt attributes","description":"Focus keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}},"score":90},"additional":[{"keyphrase":"Compliance","score":83,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},{"keyphrase":"FedRAMP","score":100,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase appears in the first paragraph. Well done!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}}]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/08\/Roadmap-to-FedRAMP-Compliance.png","og_image_width":"1200","og_image_height":"627","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Governance Risk &amp; Compliance","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"created":"2021-10-27 15:11:07","updated":"2026-05-24 09:56:49","ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-05-22 13:05:16"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/cloud-security\/\" title=\"Cloud Security\">Cloud Security<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tRoadmap to FedRAMP Compliance\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Cloud Security","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/cloud-security\/"},{"label":"Roadmap to FedRAMP Compliance","link":"https:\/\/www.varutra.com\/varutravrt3\/roadmap-to-fedramp-compliance\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/15966"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=15966"}],"version-history":[{"count":5,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/15966\/revisions"}],"predecessor-version":[{"id":20273,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/15966\/revisions\/20273"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/16006"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=15966"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=15966"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=15966"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}