Frameworks · Americas
FedRAMP
The Federal Risk and Authorization Management Program (FedRAMP) authorises cloud services for US federal use. Its baselines come from NIST SP 800-53 Rev. 5: Low, Moderate and High, each with the same 17 control families at increasing depth. FedRAMP 20x is the programme's automation-first track. Its Phase One pilot in 2025 granted Low authorisations against Key Security Indicators, with Moderate to follow.
Who it applies to
It applies to cloud service providers that sell to US federal agencies, and to the agencies that authorise and reuse those services.
Main requirements
Baseline selection
The impact level depends on the confidentiality, integrity and availability of the data the service handles.
Control implementation
The provider implements the Rev. 5 baseline and describes it in the system security plan.
Assessment
A third-party assessment organisation carries out an independent assessment, and open items go into a plan of action.
Continuous monitoring
Monthly vulnerability scanning, incident reporting and an annual assessment continue for as long as the authorisation stands.
How xmodo supports it
- 1
The Moderate baseline is the default pack. Low and High are scopes over the same NIST SP 800-53 Rev. 5 control library.
- 2
Continuous monitoring evidence, including scans, incidents and changes, is collected through integrations and filed against the controls it supports.
- 3
FedRAMP 20x Key Security Indicators run as a separate edition for providers on the automation-first track.
Related frameworks
FedRAMP shares requirements with the frameworks below. Controls you already run for any of them count towards FedRAMP as well.
Frequently asked questions
Which baseline should we start with?
Moderate covers most federal SaaS use and is the default pack. Low applies to public or low-impact data. High applies to law enforcement, emergency and financial systems. The baseline is a scope, so you can change it without restarting the programme.
What is FedRAMP 20x?
FedRAMP 20x is the programme's automation-first track. Its 2025 Phase One pilot granted Low authorisations against Key Security Indicators, which are measurable outcomes used in place of the full control narrative. Moderate follows. xmodo sets up the indicators as their own edition.