FedRAMP Authorized Vendor List
March 1, 2026 · Updated September 11, 2026
Check the current FedRAMP status of common SaaS and cloud vendors, including the specific certified offering where applicable. A vendor appearing on the FedRAMP Marketplace does not mean every product it sells is FedRAMP authorized: authorization attaches to a specific cloud service offering (CSO), usually a government edition of the product. This guide also explains what Authorized, In Process and Ready mean, and covers the questions FedRAMP does not answer before you approve a vendor.
Evaluating a vendor for federal or regulated use?
Check its FedRAMP evidence alongside security, privacy, regulatory, and external-risk signals.
One vendor. No account. No credit card.
What FedRAMP authorization means
FedRAMP authorization means a specific cloud service offering (CSO) has been independently assessed by a Third Party Assessment Organization (3PAO) and granted an Authority to Operate (ATO) by a federal agency. The authorization confirms that offering meets a defined set of NIST 800-53 security controls appropriate to the data sensitivity level. It is granted to the offering, not to the company: a vendor whose government edition is authorized usually still sells a commercial edition that is not. Authorized offerings appear on the FedRAMP Marketplace with their status, impact level or certification class, and authorizing agency. Older listings show a JAB (Joint Authorization Board) path; those authorizations remain valid and listed even though the board itself has since been replaced by the FedRAMP Board. FedRAMP Ready is a preliminary designation, not an authorization.
A note on terminology. FedRAMP's Consolidated Rules for 2026 (CR26) renamed "Authorization" to "Certification" and replaced impact levels with certification classes: Class B for Low, Class C for Moderate, Class D for High. Enforcement begins 1 January 2027 and existing authorizations remain valid through the transition, so this page shows both terms, as the Marketplace itself now does.
FedRAMP Moderate vs. FedRAMP High impact levels
FedRAMP authorization is granted at one of three impact levels defined by FIPS 199: Low (including the tailored LI-SaaS baseline), Moderate, and High. Under CR26 these are Class B, Class C, and Class D. The level determines how many security controls the offering must implement.
FedRAMP Moderate (Class C) requires approximately 325 security controls and covers systems where the loss of confidentiality, integrity, or availability would have a serious adverse effect on organizational operations, assets, or individuals. Most SaaS products serving federal civilian agencies target Moderate. Examples of Moderate-authorized offerings: Zoom for Government, Datadog for Government, Docusign IAM eSignature, and Snowflake Government regions.
FedRAMP High (Class D) requires approximately 421 security controls and covers systems processing data where loss would have a severe or catastrophic effect — including law enforcement data, emergency services, financial systems, and health data. Examples: AWS GovCloud, Microsoft Azure Government, Salesforce Government Cloud Plus, and Okta IDaaS Government High Cloud.
In every example above the authorization belongs to the named government offering, not to the vendor's commercial product. GitHub Enterprise Cloud is a reminder that the level matters as much as the listing: it is authorized at Low (Class B), which does not satisfy a Moderate requirement.
An offering authorized at High can process Moderate and Low data. An offering authorized at Moderate cannot process High-impact data.
Why FedRAMP Ready does not mean authorized
FedRAMP Ready is a preliminary designation that means a 3PAO has confirmed the vendor's system meets FedRAMP security requirements in a readiness assessment — but no federal agency has granted an Authority to Operate (ATO). FedRAMP Ready vendors appear on the FedRAMP Marketplace but cannot process federal data until they complete the full authorization process with a sponsoring agency. The gap between Ready and Authorized can take 6-18 months. Organizations evaluating vendors for federal workloads should not treat FedRAMP Ready as equivalent to FedRAMP Authorized. If your compliance framework requires FedRAMP authorization, only vendors with an active ATO at the appropriate impact level satisfy the requirement.
Common SaaS vendors and their FedRAMP status
The table below shows FedRAMP status for common enterprise SaaS vendors, reconciled against the FedRAMP Marketplace. Each Certified row names the specific cloud service offering that holds the authorization, usually a government edition such as Zoom for Government or Salesforce Government Cloud Plus. The vendor's commercial product is a separate offering and is not covered unless the Marketplace lists it. Where ThirdProof has published an assessment of the vendor, the row links to it; otherwise you can start a free assessment of that vendor from the row.
For search and status filters across the same vendors, use the FedRAMP vendor tracker. For category-specific lists, see our FedRAMP authorized storage vendors guide covering AWS S3, Azure Blob, Box, and Google Cloud Storage, or our FedRAMP authorized collaboration tools guide covering Microsoft Teams, Webex, Zoom, and GovSlack.
Evaluating one of these vendors?
Run a free ThirdProof vendor assessment using available compliance, security, privacy, regulatory, and vendor-risk evidence.
Assess a Vendor Free →No account needed to start. The first assessment is free.
Statuses reconciled by hand against the FedRAMP Marketplace. Table last reviewed August 28, 2026. A linked vendor report shows the dated registry reading and the certified package.
FedRAMP is one signal, not the entire vendor assessment
FedRAMP authorization tells you something important about a specific cloud offering: an independent assessor tested it against a defined control baseline and a federal agency accepted the result. It does not automatically tell you whether every product sold by that vendor is covered, or whether the vendor fits your organization's risk requirements.
The table below separates the questions FedRAMP answers from the ones it does not. None of this diminishes the authorization. It is strong evidence about the offering's security controls, and for federal workloads it is mandatory. Vendor approval is a broader decision, and the remaining questions still need an answer from somewhere.
Is this specific cloud offering authorized, and at what level?
Is every product sold by this vendor covered?
Is the product we are buying the covered offering?
Match your order form to the offering named on the Marketplace.
What other security evidence exists (SOC 2, ISO 27001, pen tests)?
FedRAMP covers its own control baseline, not the vendor's other attestations.
Has the vendor's broader risk posture changed since authorization?
Are there relevant breach, incident, or regulatory signals?
Does the vendor's privacy or data-handling posture create risk for us?
What should our team investigate before approval?
ThirdProof treats FedRAMP and other certification evidence as one input to a broader vendor assessment. Each assessment records the FedRAMP Marketplace reading with the date it was taken and sets it alongside evidence from 27 public sources covering security, privacy, regulatory, and external-risk signals, so the registry status informs the decision rather than standing in for it.
How to verify FedRAMP status independently
The authoritative source for FedRAMP authorization status is the FedRAMP Marketplace at marketplace.fedramp.gov. Do not rely on vendor marketing pages — vendors sometimes claim FedRAMP authorization for their commercial product when only their government-specific offering is authorized. To verify: search for the vendor name on the Marketplace, confirm the specific Cloud Service Offering (CSO) matches what you plan to use, check the authorization status (Authorized vs. In Process vs. Ready), verify the impact level meets your data classification, and note the sponsoring agency and authorization date.
ThirdProof automates this verification as part of its certification registry checks during vendor assessments. The assessment queries the FedRAMP Marketplace API directly and includes the result in the vendor's compliance evidence section.
Before approving a FedRAMP vendor, verify these 5 things
1. The exact cloud service offering. Match the product named in your contract or order form to the CSO named on the Marketplace. "Zoom" and "Zoom for Government" are different offerings with different authorization boundaries; only one of them is authorized.
2. Current status. Confirm the listing still reads Authorized (Certified under CR26) rather than In Process or Ready, and record the date you checked. Authorizations can be suspended or revoked, and a reading from last year's review is not evidence today.
3. The impact level or certification class. Confirm the level meets your requirement. A Low (Class B) authorization does not satisfy a Moderate (Class C) requirement, and Moderate does not satisfy High (Class D). Your data classification, contract clause, or agency sponsor sets the bar, not the vendor.
4. Scope mismatch between what was authorized and what you are buying. The common failure is a vendor's sales material citing its government offering while the order form provisions the commercial environment. Ask which environment your tenant will live in and where the authorization boundary ends. Integrations, add-ons, and regions can sit outside it.
5. Residual vendor risk. FedRAMP status does not answer questions about the company itself: ownership and sanctions exposure, breach and incident history, regulatory actions, privacy practices, or whether the product suits your specific use. Those checks are still yours to make, and they are the same checks you would run on a vendor with no FedRAMP listing at all.
Already have a vendor in mind?
Run a ThirdProof assessment from public evidence before the vendor responds. Results in under 10 minutes.
Assess a Vendor Free →One vendor, no account, no credit card
What to do when a required vendor is not FedRAMP authorized
When a vendor you need is not FedRAMP authorized, you have several options depending on your compliance requirements:
1. Identify the authorized offering, or an authorized alternative. Often the vendor you already use has a separate government edition. Commercial Slack workspaces are not covered, but GovSlack, Slack's government offering, is authorized at Moderate; commercial Zoom is not covered, but Zoom for Government is. Moving to the government edition is a migration with its own contract, not a license change. If no government edition exists, look for an authorized alternative in the same category, such as Microsoft Teams (Microsoft 365 Government) or Webex for Government for collaboration.
2. Request the vendor pursue authorization. Large vendors sometimes prioritize FedRAMP authorization when customers demonstrate demand. Ask your vendor contact about their FedRAMP roadmap.
3. Document compensating controls. If no authorized alternative exists and the vendor handles non-CUI data, document the gap with compensating controls: encryption requirements, access restrictions, data residency controls, and monitoring.
4. Obtain risk acceptance. For CMMC, FedRAMP, and agency-specific requirements, formal risk acceptance from your authorizing official may be required when using non-authorized vendors.
5. Isolate the workload. Deploy the non-authorized vendor in a separate environment that does not process federal data or CUI.
Frequently asked questions
How many vendors are FedRAMP authorized?+
Is FedRAMP authorization required for all government contracts?+
How long does FedRAMP authorization take?+
If a vendor is on the FedRAMP Marketplace, is every product it sells authorized?+
Is FedRAMP authorization enough to approve a vendor?+
Vendors assessed by ThirdProof
Put this into practice
Investigate any vendor across 27 intelligence sources in under 10 minutes. The first one is free and needs no account.
Assess a Vendor Free →No account, no credit card