HomeGlossaryFedRAMP Moderate
Cybersecurity & Compliance

FedRAMP Moderate

The FedRAMP authorization baseline for cloud services handling government data where a breach would cause serious adverse effects.

Quick answer

The FedRAMP authorization baseline for cloud services handling government data where a breach would cause serious adverse effects.


FedRAMP Moderate is one of three impact baselines under the Federal Risk and Authorization Management Program (FedRAMP), calibrated to NIST FIPS 199 Moderate impact levels. It applies to cloud services where the unauthorized disclosure, modification, or destruction of government information would cause serious adverse effects on agency operations, agency assets, or individuals. The majority of unclassified federal data falls into this category, making FedRAMP Moderate the most common authorization baseline across federal civilian agencies.

What is FedRAMP Moderate?

FedRAMP was established by the Office of Management and Budget through OMB Memorandum M-11-30 and is codified in federal policy as the standard security framework for cloud services used by the federal government. The Moderate baseline draws from NIST SP 800-53 and requires approximately 325 security controls spanning 17 control families, including access control, audit and accountability, contingency planning, identification and authentication, and system and communications protection.

Cloud Service Providers (CSPs) seeking FedRAMP Moderate authorization must engage an accredited Third Party Assessment Organization (3PAO) to conduct an independent security assessment. The resulting package, which includes a System Security Plan, security assessment report, and plan of action and milestones, is reviewed either by the Joint Authorization Board (JAB) or by a sponsoring federal agency before an Authority to Operate (ATO) is issued. Once a CSP achieves FedRAMP Moderate authorization, the ATO can be reused by other agencies through the FedRAMP Marketplace, eliminating the need for each agency to conduct a separate assessment.

Why it matters for contractors

Cloud service providers cannot typically sell cloud-hosted solutions to federal civilian agencies without a FedRAMP Moderate authorization. Agencies are required by OMB policy to use only FedRAMP-authorized cloud services. For contractors building platforms that will host agency data, process federal records, or integrate with agency systems, FedRAMP Moderate is the standard minimum threshold. The authorization process is time-consuming and can take 12 to 18 months or longer, so contractors should plan for it early in their business development cycle.

Achieving FedRAMP Moderate also provides a significant competitive advantage in federal procurement. Solicitations frequently list FedRAMP authorization status as an evaluation factor or a pass/fail eligibility requirement. Contractors who enter the marketplace with an existing authorization can win contracts more quickly than competitors who must begin the process at proposal time.

Example

A software company develops a SaaS case management platform and identifies the Department of Health and Human Services (HHS) as a target customer. HHS handles sensitive program data that falls under the FedRAMP Moderate impact level. Before HHS can award a contract, the company must demonstrate FedRAMP Moderate authorization. The company engages a 3PAO to conduct the security assessment, submits its authorization package to a sponsoring HHS component for agency review, and receives an ATO. The authorized offering is then listed on the FedRAMP Marketplace, which allows other agencies to reuse the authorization without requiring a separate assessment, expanding the company's federal customer base.

How Bidovate helps

Bidovate puts FedRAMP Moderate to work inside your capture and proposal workflow.

Find cloud opportunities

See Bidovate in action

Book a demo and we will show you the platform using your actual contract data.