Photo of Kate GrowleyPhoto of Michael G. Gruden, CIPP/GPhoto of Jacob Harrison

What is FedRAMP?

The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide initiative established to standardize the security assessment, authorization, and continuous monitoring of cloud products and services used by federal agencies. FedRAMP’s primary objective is to ensure that cloud service providers (CSPs) implement robust security controls to protect federal information in cloud environments. By leveraging a consistent framework for security assessment and authorization, FedRAMP is intended to reduce duplication of effort, cost, and time for both agencies and vendors.

The program’s statutory authority has been reinforced through the 2022 FedRAMP Authorization Act, which clarifies requirements for CSPs and strengthens FedRAMP’s role in federal cloud security. These updates are designed to enhance transparency, improve stakeholder engagement, and ensure that FedRAMP remains responsive to evolving cybersecurity threats and federal needs.

FedRAMP provides two authorization pathways: the traditional FedRAMP Rev5 agency authorization path and the modernized FedRAMP 20x authorization path. FedRAMP Rev5 relies on NIST SP 800-53, Revision 5 security controls, requires agency sponsorship, and requires manual review of expansive documentation to validate FedRAMP compliance. FedRAMP 20x, by contrast, uses Key Security Indicators, does not require agency sponsorship, and relies heavily on automated validation of security controls. FedRAMP 20x is currently in Phase 2.

Overview of Released RFCs

On January 13, 2026, FedRAMP announced the release of six new RFCs (numbered 0019 through 0024) as part of its effort to implement the FedRAMP Authorization Act and modernize its processes. The proposed changes focus on clarity, transparency, and quicker authorizations.

The RFCs propose several changes to the FedRAMP program, summarized below:

FedRAMP is seeking stakeholder input on these proposed updates and has staggered comment closing dates to ease the burden on reviewers.

Conclusion

FedRAMP’s release of six new RFCs represents a significant milestone in the ongoing modernization of federal cloud security standards and the implementation of the FedRAMP Authorization Act. CSPs, federal agencies, and third-party assessment organizations should take this opportunity to engage in the public comment process to ensure their perspectives are considered in future program requirements. Crowell & Moring continues to monitor these developments and provide guidance on how the proposed updates may affect your FedRAMP authorization strategy, compliance obligations, and risk management practices.  For questions about the RFCs or how these changes may impact your organization, please contact our team.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Kate Growley Kate Growley

Kate M. Growley (CIPP/US, CIPP/G) is a director with Crowell & Moring International and based in Hong Kong. Drawing from over a decade of experience as a practicing attorney in the United States, Kate helps her clients understand, navigate, and shape the policy…

Kate M. Growley (CIPP/US, CIPP/G) is a director with Crowell & Moring International and based in Hong Kong. Drawing from over a decade of experience as a practicing attorney in the United States, Kate helps her clients understand, navigate, and shape the policy and regulatory environment for some of the most complex data issues facing multinational companies, including cybersecurity, privacy, and digital transformation. Kate has worked with clients across every major sector, with particular experience in technology, health care, manufacturing, and aerospace and defense. Kate is a Certified Information Privacy Professional (CIPP) in both the U.S. private and government sectors by the International Association of Privacy Professionals (IAPP). She is also a Registered Practitioner with the U.S. Cybersecurity Maturity Model Certification (CMMC) Cyber Accreditation Body (AB).

Photo of Michael G. Gruden, CIPP/G Michael G. Gruden, CIPP/G

Michael G. Gruden is a counsel in Crowell & Moring’s Washington, D.C. office, where he is a member of the firm’s Government Contracts and Privacy and Cybersecurity groups. He possesses real-world experience in the areas of federal procurement and data security, having worked…

Michael G. Gruden is a counsel in Crowell & Moring’s Washington, D.C. office, where he is a member of the firm’s Government Contracts and Privacy and Cybersecurity groups. He possesses real-world experience in the areas of federal procurement and data security, having worked as a Contracting Officer at both the U.S. Department of Defense (DoD) and the U.S. Department of Homeland Security (DHS) in the Information Technology, Research & Development, and Security sectors for nearly 15 years. Michael is a Certified Information Privacy Professional with a U.S. government concentration (CIPP/G). He is also a Registered Practitioner under the Cybersecurity Maturity Model Certification (CMMC) framework. Michael serves as vice-chair for the ABA Science & Technology Section’s Homeland Security Committee.

Michael’s legal practice covers a wide range of counseling and litigation engagements at the intersection of government contracts and cybersecurity. His government contracts endeavors include supply chain security counseling, contract disputes with federal entities, suspension and debarment proceedings, mandatory disclosures to the government, prime-subcontractor disputes, and False Claims Act investigations. His privacy and cybersecurity practice includes cybersecurity compliance reviews, risk assessments, data breaches, incident response, and regulatory investigations.

Photo of Jacob Harrison Jacob Harrison

Jacob Harrison helps his clients navigate both domestic and international legal challenges.

Jake advises U.S. government contractors on internal investigations and state and federal regulatory compliance. His compliance practice focuses on counseling clients operating at the intersection of government contracts and cybersecurity, including

Jacob Harrison helps his clients navigate both domestic and international legal challenges.

Jake advises U.S. government contractors on internal investigations and state and federal regulatory compliance. His compliance practice focuses on counseling clients operating at the intersection of government contracts and cybersecurity, including for cybersecurity compliance reviews, risk assessments, and data breaches.

In his international practice, Jake represents foreign and domestic clients in Foreign Sovereign Immunities Act and Anti-Terrorism Act litigation. He also has experience advising clients involved in cross-border commercial arbitration proceedings.

During law school, Jake served as an associate editor of the Emory Law Journal and interned at the Supreme Court of Georgia and the Georgia House Democratic Caucus. Before attending law school, Jake worked in politics and state government.