← Back to glossary

What FedRAMP authorises

FedRAMP authorisations are tied to impact levels: Low, Moderate, and High under FIPS 199. Higher impact levels require stricter security controls (from NIST SP 800-53), more rigorous continuous monitoring, and stricter operational practices. Most enterprise cloud services target Moderate; defence-grade workloads typically require High.

The authorisation paths

Joint Authorization Board (JAB) provisional authorisation — issued by DoD, DHS, and GSA — is the most prestigious path; only a small number of providers achieve it each year. Agency authorisation, where a single federal agency sponsors a provider, is more common.

What FedRAMP requires technically

Detailed control implementations from NIST SP 800-53. Continuous monitoring of system state. Incident-reporting timelines and escalation procedures. Cryptography that's FIPS 140 validated. Data residency within authorised geographies. Personnel with appropriate clearances handling system administration.

IL2 through IL5

The Defense Department's Impact Levels (IL2-IL6) layer additional requirements on top of FedRAMP for DoD workloads. IL2 (publicly releasable but mission-critical) is the lowest; IL5 (controlled unclassified information) is increasingly the procurement bar for DoD cloud services. SkyeConnex's architecture fits IL2 through IL5 with appropriate deployment configuration.

SkyeConnex's posture

FedRAMP authorisation is a process, not a product feature. The architecture is FedRAMP-amenable: US-only geo-policy supports the residency requirement. Continuous monitoring is delivered through the provider heartbeat infrastructure. FIPS-published cryptography end-to-end. Cryptographic boundary candidates are identified for the FIPS 140-3 module certification that FedRAMP references.

Customers pursuing their own ATO

Customers pursuing their own Authority to Operate inherit a strong cryptographic and architectural foundation by adopting SkyeConnex. The architecture documentation aligned with NIST SP 800-53 controls is available under NDA.

Related terms

See also

Want to see this in production?