> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# US FedRAMP

> Achieve Federal Risk and Authorization Management Program authorization for US government cloud services.

> Achieve Federal Risk and Authorization Management Program authorization for US government cloud services.

The Federal Risk and Authorization Management Program (FedRAMP) is a US government program that standardizes security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies. It is based on NIST SP 800-53 controls and offers Low, Moderate, and High baselines.

<Note>
  FedRAMP authorization is required for cloud service providers that want to sell cloud services to US federal agencies.
</Note>

## Who needs US FedRAMP?

<CardGroup cols={2}>
  <Card title="Cloud service providers" icon="cloud">
    Vendors offering cloud products or services to US federal agencies.
  </Card>

  <Card title="GovTech and SaaS firms" icon="landmark">
    Organizations expanding into the federal market.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="Low baseline" icon="1">
    For systems where the impact of a breach would be limited.
  </Card>

  <Card title="Moderate baseline" icon="2">
    The most common baseline, covering the majority of federal SaaS.
  </Card>

  <Card title="High baseline" icon="3">
    For systems handling the most sensitive unclassified federal data.
  </Card>

  <Card title="Continuous monitoring" icon="gauge">
    Ongoing security monitoring and monthly reporting after authorization.
  </Card>
</CardGroup>

## How DSALTA helps with US FedRAMP

<Steps>
  <Step title="Activate FedRAMP">
    Select FedRAMP and your impact level. DSALTA maps the NIST 800-53 baseline to controls.
  </Step>

  <Step title="Review mapped controls">
    Review the NIST 800-53 controls for your baseline and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations to gather technical evidence continuously.
  </Step>

  <Step title="Document the SSP">
    Build your System Security Plan and supporting documents.
  </Step>

  <Step title="Prepare for assessment">
    Organize evidence for a 3PAO assessment and agency authorization.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="What are the FedRAMP paths to authorization?" icon="route">
    You can pursue a Joint Authorization Board (JAB) Provisional ATO or an Agency ATO sponsored by a specific federal agency.
  </Accordion>

  <Accordion title="How does FedRAMP relate to NIST 800-53?" icon="arrows-left-right">
    FedRAMP baselines are tailored sets of NIST SP 800-53 controls, plus FedRAMP-specific requirements and continuous monitoring.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
