Skip to main content
Skip to main content
FedRAMP Intelligence

FedRAMP Authorized Vendor List

March 1, 2026 · Updated September 11, 2026

Check the current FedRAMP status of common SaaS and cloud vendors, including the specific certified offering where applicable. A vendor appearing on the FedRAMP Marketplace does not mean every product it sells is FedRAMP authorized: authorization attaches to a specific cloud service offering (CSO), usually a government edition of the product. This guide also explains what Authorized, In Process and Ready mean, and covers the questions FedRAMP does not answer before you approve a vendor.

Skip to the vendor status table ↓

Evaluating a vendor for federal or regulated use?

Check its FedRAMP evidence alongside security, privacy, regulatory, and external-risk signals.

Assess the Vendor Free →

One vendor. No account. No credit card.

What FedRAMP authorization means

FedRAMP authorization means a specific cloud service offering (CSO) has been independently assessed by a Third Party Assessment Organization (3PAO) and granted an Authority to Operate (ATO) by a federal agency. The authorization confirms that offering meets a defined set of NIST 800-53 security controls appropriate to the data sensitivity level. It is granted to the offering, not to the company: a vendor whose government edition is authorized usually still sells a commercial edition that is not. Authorized offerings appear on the FedRAMP Marketplace with their status, impact level or certification class, and authorizing agency. Older listings show a JAB (Joint Authorization Board) path; those authorizations remain valid and listed even though the board itself has since been replaced by the FedRAMP Board. FedRAMP Ready is a preliminary designation, not an authorization.

A note on terminology. FedRAMP's Consolidated Rules for 2026 (CR26) renamed "Authorization" to "Certification" and replaced impact levels with certification classes: Class B for Low, Class C for Moderate, Class D for High. Enforcement begins 1 January 2027 and existing authorizations remain valid through the transition, so this page shows both terms, as the Marketplace itself now does.

FedRAMP Moderate vs. FedRAMP High impact levels

FedRAMP authorization is granted at one of three impact levels defined by FIPS 199: Low (including the tailored LI-SaaS baseline), Moderate, and High. Under CR26 these are Class B, Class C, and Class D. The level determines how many security controls the offering must implement.

FedRAMP Moderate (Class C) requires approximately 325 security controls and covers systems where the loss of confidentiality, integrity, or availability would have a serious adverse effect on organizational operations, assets, or individuals. Most SaaS products serving federal civilian agencies target Moderate. Examples of Moderate-authorized offerings: Zoom for Government, Datadog for Government, Docusign IAM eSignature, and Snowflake Government regions.

FedRAMP High (Class D) requires approximately 421 security controls and covers systems processing data where loss would have a severe or catastrophic effect — including law enforcement data, emergency services, financial systems, and health data. Examples: AWS GovCloud, Microsoft Azure Government, Salesforce Government Cloud Plus, and Okta IDaaS Government High Cloud.

In every example above the authorization belongs to the named government offering, not to the vendor's commercial product. GitHub Enterprise Cloud is a reminder that the level matters as much as the listing: it is authorized at Low (Class B), which does not satisfy a Moderate requirement.

An offering authorized at High can process Moderate and Low data. An offering authorized at Moderate cannot process High-impact data.

Why FedRAMP Ready does not mean authorized

FedRAMP Ready is a preliminary designation that means a 3PAO has confirmed the vendor's system meets FedRAMP security requirements in a readiness assessment — but no federal agency has granted an Authority to Operate (ATO). FedRAMP Ready vendors appear on the FedRAMP Marketplace but cannot process federal data until they complete the full authorization process with a sponsoring agency. The gap between Ready and Authorized can take 6-18 months. Organizations evaluating vendors for federal workloads should not treat FedRAMP Ready as equivalent to FedRAMP Authorized. If your compliance framework requires FedRAMP authorization, only vendors with an active ATO at the appropriate impact level satisfy the requirement.

Common SaaS vendors and their FedRAMP status

The table below shows FedRAMP status for common enterprise SaaS vendors, reconciled against the FedRAMP Marketplace. Each Certified row names the specific cloud service offering that holds the authorization, usually a government edition such as Zoom for Government or Salesforce Government Cloud Plus. The vendor's commercial product is a separate offering and is not covered unless the Marketplace lists it. Where ThirdProof has published an assessment of the vendor, the row links to it; otherwise you can start a free assessment of that vendor from the row.

For search and status filters across the same vendors, use the FedRAMP vendor tracker. For category-specific lists, see our FedRAMP authorized storage vendors guide covering AWS S3, Azure Blob, Box, and Google Cloud Storage, or our FedRAMP authorized collaboration tools guide covering Microsoft Teams, Webex, Zoom, and GovSlack.

Evaluating one of these vendors?

Run a free ThirdProof vendor assessment using available compliance, security, privacy, regulatory, and vendor-risk evidence.

Assess a Vendor Free

No account needed to start. The first assessment is free.

Statuses reconciled by hand against the FedRAMP Marketplace. Table last reviewed August 28, 2026. A linked vendor report shows the dated registry reading and the certified package.

1Password
No Marketplace listing
Not Listed on FedRAMP Marketplace
ADP
No Marketplace listing
Not Listed on FedRAMP Marketplace
Adyen
No Marketplace listing
Not Listed on FedRAMP Marketplace
Airtable
No Marketplace listing
Not Listed on FedRAMP Marketplace
Amazon Web Services
Certified offering: AWS GovCloud
FedRAMP Certified — Class D (High)
Amplitude
No Marketplace listing
Not Listed on FedRAMP Marketplace
Apollo.io
No Marketplace listing
Not Listed on FedRAMP Marketplace
Asana
No Marketplace listing
Not Listed on FedRAMP Marketplace
Auth0
No Marketplace listing
Not Listed on FedRAMP Marketplace
BambooHR
No Marketplace listing
Not Listed on FedRAMP Marketplace
Bill.com
No Marketplace listing
Not Listed on FedRAMP Marketplace
Bitbucket
No Marketplace listing
Not Listed on FedRAMP Marketplace
Box
Certified offering: Box Enterprise Cloud Content Collaboration Platform
FedRAMP Certified — Class D (High)
Braintree
No Marketplace listing
Not Listed on FedRAMP Marketplace
Canva
No Marketplace listing
Not Listed on FedRAMP Marketplace
CircleCI
No Marketplace listing
Not Listed on FedRAMP Marketplace
ClickUp
No Marketplace listing
Not Listed on FedRAMP Marketplace
Cloudflare
No Marketplace listing
Not Listed on FedRAMP Marketplace
Confluence
No Marketplace listing
Not Listed on FedRAMP Marketplace
CrowdStrike
Certified offering: CrowdStrike Falcon
FedRAMP Certified — Class C (Moderate)
CyberArk
Certified offering: CyberArk Privilege Cloud
FedRAMP Certified — Class C (Moderate)
Databricks
No Marketplace listing
Not Listed on FedRAMP Marketplace
Datadog
Certified offering: Datadog for Government
FedRAMP Certified — Class C (Moderate)
dbt Labs
No Marketplace listing
Not Listed on FedRAMP Marketplace
Deel
No Marketplace listing
Not Listed on FedRAMP Marketplace
DigitalOcean
No Marketplace listing
Not Listed on FedRAMP Marketplace
Docker
No Marketplace listing
Not Listed on FedRAMP Marketplace
DocuSign
Certified offering: Docusign IAM eSignature
FedRAMP Certified — Class C (Moderate)
Drata
No Marketplace listing
Not Listed on FedRAMP Marketplace
Drift
No Marketplace listing
Not Listed on FedRAMP Marketplace
Dropbox
No Marketplace listing
Not Listed on FedRAMP Marketplace
FedRAMP Certified — Class C (Moderate)
Elastic
No Marketplace listing
Not Listed on FedRAMP Marketplace
Epic Systems
No Marketplace listing
Not Listed on FedRAMP Marketplace
Fastly
No Marketplace listing
Not Listed on FedRAMP Marketplace
Figma
No Marketplace listing
Not Listed on FedRAMP Marketplace
Fivetran
No Marketplace listing
Not Listed on FedRAMP Marketplace
Fortinet
No Marketplace listing
Not Listed on FedRAMP Marketplace
Freshdesk
No Marketplace listing
Not Listed on FedRAMP Marketplace
Freshworks
No Marketplace listing
Not Listed on FedRAMP Marketplace
GitHub
Certified offering: GitHub Enterprise Cloud
FedRAMP Certified — Class B (Low)
GitLab
No Marketplace listing
Not Listed on FedRAMP Marketplace
Gong
No Marketplace listing
Not Listed on FedRAMP Marketplace
Google Cloud
Certified offering: Google Services (Google Cloud Platform)
FedRAMP Certified — Class D (High)
Google Drive
No Marketplace listing
Not Listed on FedRAMP Marketplace
Google Workspace
No Marketplace listing
Not Listed on FedRAMP Marketplace
Grafana
No Marketplace listing
Not Listed on FedRAMP Marketplace
Gusto
No Marketplace listing
Not Listed on FedRAMP Marketplace
HashiCorp
No Marketplace listing
Not Listed on FedRAMP Marketplace
Heroku
No Marketplace listing
Not Listed on FedRAMP Marketplace
Huawei
No Marketplace listing
Not Listed on FedRAMP Marketplace
HubSpot
No Marketplace listing
Not Listed on FedRAMP Marketplace
Intercom
No Marketplace listing
Not Listed on FedRAMP Marketplace
Jira
No Marketplace listing
Not Listed on FedRAMP Marketplace
Kaspersky
No Marketplace listing
Not Listed on FedRAMP Marketplace
LastPass
No Marketplace listing
Not Listed on FedRAMP Marketplace
LaunchDarkly
No Marketplace listing
Not Listed on FedRAMP Marketplace
Linear
No Marketplace listing
Not Listed on FedRAMP Marketplace
Looker
No Marketplace listing
Not Listed on FedRAMP Marketplace
Loom
No Marketplace listing
Not Listed on FedRAMP Marketplace
Mailchimp
No Marketplace listing
Not Listed on FedRAMP Marketplace
Microsoft 365
Certified offering: Microsoft 365 Government
FedRAMP Certified — Class C (Moderate)
Microsoft Azure
Certified offering: Azure Government
FedRAMP Certified — Class D (High)
Microsoft Teams
Certified offering: Microsoft 365 Government (Teams)
FedRAMP Certified — Class C (Moderate)
Miro
No Marketplace listing
Not Listed on FedRAMP Marketplace
Mixpanel
No Marketplace listing
Not Listed on FedRAMP Marketplace
Monday.com
No Marketplace listing
Not Listed on FedRAMP Marketplace
MongoDB
No Marketplace listing
Not Listed on FedRAMP Marketplace
NetSuite
No Marketplace listing
Not Listed on FedRAMP Marketplace
New Relic
No Marketplace listing
Not Listed on FedRAMP Marketplace
Norton
No Marketplace listing
Not Listed on FedRAMP Marketplace
Notion
No Marketplace listing
Not Listed on FedRAMP Marketplace
Okta
Certified offering: Okta IDaaS Government High Cloud
FedRAMP Certified — Class D (High)
OneTrust
No Marketplace listing
Not Listed on FedRAMP Marketplace
Oracle
No Marketplace listing
Not Listed on FedRAMP Marketplace
FedRAMP Certified — Class C (Moderate)
Palo Alto Networks
Certified offering: Prisma Cloud
FedRAMP Certified — Class C (Moderate)
PandaDoc
No Marketplace listing
Not Listed on FedRAMP Marketplace
Paycom
No Marketplace listing
Not Listed on FedRAMP Marketplace
Ping Identity
No Marketplace listing
Not Listed on FedRAMP Marketplace
Pipedrive
No Marketplace listing
Not Listed on FedRAMP Marketplace
Plaid
No Marketplace listing
Not Listed on FedRAMP Marketplace
Postmark
No Marketplace listing
Not Listed on FedRAMP Marketplace
QuickBooks
No Marketplace listing
Not Listed on FedRAMP Marketplace
Redis
No Marketplace listing
Not Listed on FedRAMP Marketplace
Render
No Marketplace listing
Not Listed on FedRAMP Marketplace
RingCentral
No Marketplace listing
Not Listed on FedRAMP Marketplace
Rippling
No Marketplace listing
Not Listed on FedRAMP Marketplace
Salesforce
Certified offering: Salesforce Government Cloud Plus
FedRAMP Certified — Class D (High)
SAP
No Marketplace listing
Not Listed on FedRAMP Marketplace
Secureframe
No Marketplace listing
Not Listed on FedRAMP Marketplace
Segment
No Marketplace listing
Not Listed on FedRAMP Marketplace
SendGrid
No Marketplace listing
Not Listed on FedRAMP Marketplace
SentinelOne
No Marketplace listing
Not Listed on FedRAMP Marketplace
Sentry
No Marketplace listing
Not Listed on FedRAMP Marketplace
ServiceNow
Certified offering: ServiceNow Government Community Cloud
FedRAMP Certified — Class C (Moderate)
Shopify
No Marketplace listing
Not Listed on FedRAMP Marketplace
Slack
Certified offering: Slack government cloud (GovSlack)
FedRAMP Certified — Class C (Moderate)
Snowflake
Certified offering: Snowflake Government regions
FedRAMP Certified — Class C (Moderate)
SolarWinds
No Marketplace listing
Not Listed on FedRAMP Marketplace
Splunk
Certified offering: Splunk Cloud
FedRAMP Certified — Class C (Moderate)
Square
No Marketplace listing
Not Listed on FedRAMP Marketplace
Stripe
No Marketplace listing
Not Listed on FedRAMP Marketplace
Supabase
No Marketplace listing
Not Listed on FedRAMP Marketplace
Tableau
No Marketplace listing
Not Listed on FedRAMP Marketplace
Terraform
No Marketplace listing
Not Listed on FedRAMP Marketplace
TikTok
No Marketplace listing
Not Listed on FedRAMP Marketplace
FedRAMP Certified — Class C (Moderate)
Vanta
No Marketplace listing
Not Listed on FedRAMP Marketplace
Veeva Systems
No Marketplace listing
Not Listed on FedRAMP Marketplace
Vercel
No Marketplace listing
Not Listed on FedRAMP Marketplace
Webex
Certified offering: Webex for Government
FedRAMP Certified — Class C (Moderate)
Wise
No Marketplace listing
Not Listed on FedRAMP Marketplace
WooCommerce
No Marketplace listing
Not Listed on FedRAMP Marketplace
Workday
No Marketplace listing
Not Listed on FedRAMP Marketplace
Xero
No Marketplace listing
Not Listed on FedRAMP Marketplace
Zendesk
No Marketplace listing
Not Listed on FedRAMP Marketplace
Zoom
Certified offering: Zoom for Government
FedRAMP Certified — Class C (Moderate)
FedRAMP Certified — Class C (Moderate)

Check the current FedRAMP vendor tracker →

FedRAMP is one signal, not the entire vendor assessment

FedRAMP authorization tells you something important about a specific cloud offering: an independent assessor tested it against a defined control baseline and a federal agency accepted the result. It does not automatically tell you whether every product sold by that vendor is covered, or whether the vendor fits your organization's risk requirements.

The table below separates the questions FedRAMP answers from the ones it does not. None of this diminishes the authorization. It is strong evidence about the offering's security controls, and for federal workloads it is mandatory. Vendor approval is a broader decision, and the remaining questions still need an answer from somewhere.

QuestionFedRAMP answers it?

Is this specific cloud offering authorized, and at what level?

Yes

Is every product sold by this vendor covered?

No

Is the product we are buying the covered offering?

Match your order form to the offering named on the Marketplace.

Must verify

What other security evidence exists (SOC 2, ISO 27001, pen tests)?

FedRAMP covers its own control baseline, not the vendor's other attestations.

Not completely

Has the vendor's broader risk posture changed since authorization?

No

Are there relevant breach, incident, or regulatory signals?

No

Does the vendor's privacy or data-handling posture create risk for us?

No

What should our team investigate before approval?

No

ThirdProof treats FedRAMP and other certification evidence as one input to a broader vendor assessment. Each assessment records the FedRAMP Marketplace reading with the date it was taken and sets it alongside evidence from 27 public sources covering security, privacy, regulatory, and external-risk signals, so the registry status informs the decision rather than standing in for it.

How to verify FedRAMP status independently

The authoritative source for FedRAMP authorization status is the FedRAMP Marketplace at marketplace.fedramp.gov. Do not rely on vendor marketing pages — vendors sometimes claim FedRAMP authorization for their commercial product when only their government-specific offering is authorized. To verify: search for the vendor name on the Marketplace, confirm the specific Cloud Service Offering (CSO) matches what you plan to use, check the authorization status (Authorized vs. In Process vs. Ready), verify the impact level meets your data classification, and note the sponsoring agency and authorization date.

ThirdProof automates this verification as part of its certification registry checks during vendor assessments. The assessment queries the FedRAMP Marketplace API directly and includes the result in the vendor's compliance evidence section.

Before approving a FedRAMP vendor, verify these 5 things

1. The exact cloud service offering. Match the product named in your contract or order form to the CSO named on the Marketplace. "Zoom" and "Zoom for Government" are different offerings with different authorization boundaries; only one of them is authorized.

2. Current status. Confirm the listing still reads Authorized (Certified under CR26) rather than In Process or Ready, and record the date you checked. Authorizations can be suspended or revoked, and a reading from last year's review is not evidence today.

3. The impact level or certification class. Confirm the level meets your requirement. A Low (Class B) authorization does not satisfy a Moderate (Class C) requirement, and Moderate does not satisfy High (Class D). Your data classification, contract clause, or agency sponsor sets the bar, not the vendor.

4. Scope mismatch between what was authorized and what you are buying. The common failure is a vendor's sales material citing its government offering while the order form provisions the commercial environment. Ask which environment your tenant will live in and where the authorization boundary ends. Integrations, add-ons, and regions can sit outside it.

5. Residual vendor risk. FedRAMP status does not answer questions about the company itself: ownership and sanctions exposure, breach and incident history, regulatory actions, privacy practices, or whether the product suits your specific use. Those checks are still yours to make, and they are the same checks you would run on a vendor with no FedRAMP listing at all.

Already have a vendor in mind?

Run a ThirdProof assessment from public evidence before the vendor responds. Results in under 10 minutes.

Assess a Vendor Free →

One vendor, no account, no credit card

What to do when a required vendor is not FedRAMP authorized

When a vendor you need is not FedRAMP authorized, you have several options depending on your compliance requirements:

1. Identify the authorized offering, or an authorized alternative. Often the vendor you already use has a separate government edition. Commercial Slack workspaces are not covered, but GovSlack, Slack's government offering, is authorized at Moderate; commercial Zoom is not covered, but Zoom for Government is. Moving to the government edition is a migration with its own contract, not a license change. If no government edition exists, look for an authorized alternative in the same category, such as Microsoft Teams (Microsoft 365 Government) or Webex for Government for collaboration.

2. Request the vendor pursue authorization. Large vendors sometimes prioritize FedRAMP authorization when customers demonstrate demand. Ask your vendor contact about their FedRAMP roadmap.

3. Document compensating controls. If no authorized alternative exists and the vendor handles non-CUI data, document the gap with compensating controls: encryption requirements, access restrictions, data residency controls, and monitoring.

4. Obtain risk acceptance. For CMMC, FedRAMP, and agency-specific requirements, formal risk acceptance from your authorizing official may be required when using non-authorized vendors.

5. Isolate the workload. Deploy the non-authorized vendor in a separate environment that does not process federal data or CUI.

Frequently asked questions

How many vendors are FedRAMP authorized?+
As of March 2026, the FedRAMP Marketplace lists over 300 authorized cloud service offerings from hundreds of providers. ThirdProof tracks FedRAMP status for 100+ common enterprise SaaS vendors. The exact number changes as new vendors achieve authorization and existing authorizations are renewed or revoked.
Is FedRAMP authorization required for all government contracts?+
FedRAMP authorization is required for cloud service providers selling to US federal agencies under the Federal Acquisition Regulation (FAR). State and local governments may reference FedRAMP but are not legally required to mandate it. Department of Defense contracts may require additional authorization under the DoD Cloud Computing SRG in addition to FedRAMP.
How long does FedRAMP authorization take?+
The FedRAMP authorization process typically takes 6-18 months from initial engagement to ATO, depending on the authorization path (Agency vs. JAB), the vendor's existing security posture, and the target impact level. FedRAMP Ready assessment can be completed in 2-4 months as a preliminary step.
If a vendor is on the FedRAMP Marketplace, is every product it sells authorized?+
No. FedRAMP authorization attaches to a specific cloud service offering, usually a government edition such as Zoom for Government or Salesforce Government Cloud Plus. The vendor's commercial product is a separate offering and is not covered unless it has its own Marketplace listing. Before approving a vendor for federal or regulated use, match the product named in your contract to the offering named on the Marketplace.
Is FedRAMP authorization enough to approve a vendor?+
For federal workloads it is required, but it is not the whole assessment. FedRAMP tells you that the named offering met a control baseline when it was authorized. It does not tell you about the vendor's breach history, sanctions or regulatory exposure, privacy practices, or whether the product you are buying is the authorized one. Most organizations treat FedRAMP as one certification input inside a broader vendor risk assessment.

Put this into practice

Investigate any vendor across 27 intelligence sources in under 10 minutes. The first one is free and needs no account.

Assess a Vendor Free →

No account, no credit card