Updated guidance on the Scope of FedRAMP as required by M-24-15 (following RFC-0010)
FedRAMP has published updated guidance on the scope of FedRAMP authorization requirements, issued in response to OMB Memorandum M-24-15 and following the completion of RFC-0010 (Request for Comments process). This guidance clarifies which cloud services and systems fall under FedRAMP authorization requirements.
What changed
- Clarification of FedRAMP scope requirements
- Updated interpretation of which systems require FedRAMP authorization
Who is affected
Cloud service providers (CSPs) and federal agencies evaluating FedRAMP authorization requirements
- Language
- EN