xmodoxmodo

Frameworks · Americas

FedRAMP

The Federal Risk and Authorization Management Program (FedRAMP) authorises cloud services for US federal use. Its baselines come from NIST SP 800-53 Rev. 5: Low, Moderate and High, each with the same 17 control families at increasing depth. FedRAMP 20x is the programme's automation-first track. Its Phase One pilot in 2025 granted Low authorisations against Key Security Indicators, with Moderate to follow.

Who it applies to

It applies to cloud service providers that sell to US federal agencies, and to the agencies that authorise and reuse those services.

Main requirements

Baseline selection

The impact level depends on the confidentiality, integrity and availability of the data the service handles.

Control implementation

The provider implements the Rev. 5 baseline and describes it in the system security plan.

Assessment

A third-party assessment organisation carries out an independent assessment, and open items go into a plan of action.

Continuous monitoring

Monthly vulnerability scanning, incident reporting and an annual assessment continue for as long as the authorisation stands.

How xmodo supports it

  • 1

    The Moderate baseline is the default pack. Low and High are scopes over the same NIST SP 800-53 Rev. 5 control library.

  • 2

    Continuous monitoring evidence, including scans, incidents and changes, is collected through integrations and filed against the controls it supports.

  • 3

    FedRAMP 20x Key Security Indicators run as a separate edition for providers on the automation-first track.

Related frameworks

FedRAMP shares requirements with the frameworks below. Controls you already run for any of them count towards FedRAMP as well.

Frequently asked questions

Which baseline should we start with?

Moderate covers most federal SaaS use and is the default pack. Low applies to public or low-impact data. High applies to law enforcement, emergency and financial systems. The baseline is a scope, so you can change it without restarting the programme.

What is FedRAMP 20x?

FedRAMP 20x is the programme's automation-first track. Its 2025 Phase One pilot granted Low authorisations against Key Security Indicators, which are measurable outcomes used in place of the full control narrative. Moderate follows. xmodo sets up the indicators as their own edition.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo