The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program, codified into law by the FedRAMP Authorization Act of 2022, that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies. FedRAMP is administered by the General Services Administration (GSA) and is mandatory — any cloud service (SaaS, PaaS, IaaS) that stores, processes, or transmits federal data or metadata must achieve FedRAMP authorization before it can be used by US government agencies or their contractors. The program defines three impact levels: Low (limited adverse effect), Moderate (serious adverse effect), and High (severe or catastrophic effect — applies to law enforcement, emergency, financial, and health systems). Each level maps to NIST SP 800-53 Rev 5 control baselines: FedRAMP High requires implementation of approximately 421 controls. Authorization is achieved through either an Agency ATO (a specific agency sponsors the assessment) or the newer FedRAMP 20-X experimental accelerated path. Once authorized, cloud service providers (CSPs) must maintain continuous monitoring — monthly vulnerability scans, annual penetration testing, and Plan of Action & Milestones (POA&M) reporting — or risk revocation. Authorized services are listed on the FedRAMP Marketplace.
Red Hat holds FedRAMP High Authorization for Red Hat OpenShift Service on AWS (ROSA) — both the classic architecture and the hosted control planes variant — operating in AWS GovCloud (US-Gov-East/US-Gov-West). Red Hat Insights and Red Hat Lightspeed are also FedRAMP High authorized. This means US federal agencies can deploy their most sensitive unclassified workloads on a fully managed, Kubernetes-based application platform that has successfully undergone rigorous audits against the NIST 800-53 Rev 5 High baseline. The practical impact for customers is significant: by inheriting ROSA’s authorization boundary, software vendors and agencies building on ROSA can see their own FedRAMP assessment scope reduced by up to 70 % of the High baseline controls — because Red Hat manages and is responsible for the underlying infrastructure controls (physical security, network architecture, OS hardening, encryption, logging, incident response). For organizations running on-premises RHEL in federal environments, Red Hat provides DISA STIG and NIST 800-53 profiles, FIPS 140-3 validated cryptography, and OpenSCAP tooling to support their own Agency ATO process — even though on-premises software is not “FedRAMP authorized” (FedRAMP only applies to cloud services). Red Hat’s presence on the FedRAMP Marketplace has become a key enabler for government ISVs who can accelerate their own authorization timeline by building atop an already-authorized platform.
