Data Rooms Providers Find a data room
VDR glossary · Compliance and privacy

What is FedRAMP?

Definition

FedRAMP: The US Federal Risk and Authorization Management Program, a standardized security assessment and authorization process for cloud services used by federal agencies.

How it works in a data room

A provider seeking FedRAMP authorization is assessed by an accredited third party against a baseline of controls derived from NIST guidance, at a low, moderate or high impact level. Once authorized, the service is listed in the program’s marketplace and must be continuously monitored. Authorized environments often run separately from a provider’s commercial platform, with their own hosting, staff screening and encryption based on validated modules described under FIPS 140-3.

Why it matters in a deal

Few deals require it, but those that do have no flexibility. Federal agencies selling assets, government contractors sharing controlled information, and some public-private partnerships may need an authorized service. For most corporate transactions, SOC 2 and ISO certification provide the assurance buyers look for. Knowing which category your process falls into early saves a late provider switch. US hosting and data residency are usually part of the same conversation. The United States guide covers federal and state context.

Example

A federal agency runs a competitive process to sell spectrum-related assets and needs bidders to review technical files. Its procurement rules limit the choice to authorized services, so the shortlist is short. Corporate bidders log in through the agency’s chosen room, while their own internal deal rooms, which hold no government data, use ordinary commercial providers.

Related terms