Skip to content
    Back to Regulatory Radar
    CriticalNew RegulationDecember 23, 2022

    FedRAMP Authorization Act Signed Into Law

    The FedRAMP Authorization Act was signed into law as part of the FY2023 National Defense Authorization Act, codifying the Federal Risk and Authorization Management Program for the first time. The legislation established FedRAMP as the authoritative framework for federal cloud security assessments, mandated agency presumption of adequacy for existing FedRAMP authorizations, and required automated continuous monitoring. It formalized the program that had operated since 2011 under OMB memoranda alone.

    FedRAMPSaaSDefense

    Key Analytics

    December 23, 2022
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Cloud service providers seeking federal contracts now operate under a statutory mandate rather than policy guidance, making FedRAMP compliance non-negotiable for government market entry. The presumption of adequacy provision reduces redundant security assessments across agencies, accelerating the authorization reuse process. Implementation has since reshaped the program: GSA dissolved the Joint Authorization Board in 2024 under OMB Memorandum M-24-15, consolidating all authorizations under a single FedRAMP Authorized designation, and launched the automation-focused FedRAMP 20x authorization path in 2025.

    Recommended Actions

    • Assess current FedRAMP readiness and choose between the agency-sponsored path and the FedRAMP 20x program; the former JAB path was dissolved in 2024
    • Implement automated continuous monitoring tooling that meets the Act's requirements for real-time security posture reporting
    • Review and update System Security Plans (SSPs) to align with statutory language and current program guidance under OMB Memorandum M-24-15

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant120-280 hours
    Key Workstreams
    • Path analysis: agency sponsorship versus FedRAMP 20x
    • Continuous monitoring automation gaps against the Act
    • SSP updates to statutory and M-24-15 language

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 120-280 hours
    Start cold under pressureMajor · 280-680 hours

    Roughly 160 to 400 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events