Certification · US

FedRAMP, without the spreadsheets.

Prepare your cloud service for US government authorisation.

What is FedRAMP?

FedRAMP standardises how US federal agencies assess and authorise cloud services. Its baselines are built on NIST SP 800-53 Rev. 5 and assessed by an accredited third-party assessment organisation (3PAO), followed by continuous monitoring once authorised.

Who needs it

  • Cloud service providers selling to US federal agencies
  • SaaS companies pursuing public-sector revenue

What FedRAMP looks at

Authorisation boundary

A clear definition of the system and everything inside it.

System security plan

How each baseline control is implemented.

Continuous monitoring

Monthly vulnerability scanning and plan of action and milestones (POA&M) reporting.

How Beviso gets you there

  • FedRAMP controls pre-loaded with evidence shared with NIST 800-53
  • Continuous evidence collection that suits ongoing monitoring
  • Vulnerability evidence from cloud and scanning integrations

10 FedRAMP controls, ready on day one

These controls are loaded when you enable FedRAMP, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

AC-2

Account Management

Manage information system accounts in accordance with Federal requirements, including establishing, reviewing, modifying, and removing accounts.

Evidence from

  • Okta
  • Google Workspace
  • Microsoft Azure
  • AWS
  • GitHub

AC-6

Least Privilege

Employ the concept of least privilege, allowing only authorized accesses for users which are necessary to accomplish assigned tasks.

Evidence from

  • AWS
  • Okta
  • HashiCorp Vault
  • Microsoft Azure

IA-2(1)

MFA — Privileged Accounts

Implement MFA for access to privileged accounts as required by FedRAMP.

Evidence from

  • Okta
  • Duo
  • Microsoft Azure
  • JumpCloud

AU-2

Audit Events

Identify the types of events that the system is capable of logging, including all FedRAMP-required events.

Evidence from

  • Datadog
  • AWS
  • Okta
  • Splunk
  • HashiCorp Vault

CA-7

Continuous Monitoring

Develop a continuous monitoring strategy and implement a continuous monitoring program.

Evidence from

  • Datadog
  • AWS
  • Splunk
  • Grafana
  • Lacework

CM-6

Configuration Settings

Establish and document configuration settings for IT products employed within the information system following FedRAMP baseline.

Evidence from

  • Terraform Cloud
  • AWS
  • Doppler
  • Jamf
  • Kandji

IR-4

Incident Handling

Implement an incident handling capability including US-CERT reporting as required by FedRAMP.

Evidence from

  • PagerDuty
  • ServiceNow
  • Jira

RA-5

Vulnerability Scanning

Scan for vulnerabilities in the information system and hosted applications at the FedRAMP-required frequency.

Evidence from

  • Snyk
  • Wiz
  • Qualys
  • Rapid7
  • AWS

SC-7

Boundary Protection

Monitor and control communications at the external boundary and key internal boundaries within FedRAMP authorization boundary.

Evidence from

  • Cloudflare
  • AWS

SI-2

Flaw Remediation

Identify, report, and correct information system flaws within FedRAMP-defined timeframes (critical: 30 days).

Evidence from

  • Snyk
  • GitHub
  • Qualys
  • Wiz
  • SonarCloud

FedRAMP questions

Is Beviso itself FedRAMP authorised?
No. Beviso is EU-hosted and helps you prepare and organise evidence for your own FedRAMP effort.

Start your FedRAMP programme today.

Free while Beviso is in beta. No credit card required.

Get started free