Skip to main content
Category: FedRAMP Program

FedRAMP In Process

Also known as: FedRAMP In Process Designation, In Process (FedRAMP)
Simply put

FedRAMP In Process is a status that indicates a cloud service provider is actively working toward, but has not yet achieved, a FedRAMP authorization. It generally means the provider's cloud offering is undergoing the auditing, testing, and review steps of the Federal Risk and Authorization Management Program. This status shows progress toward authorization but does not by itself mean the service is authorized or approved for federal use.

Formal definition

Within the Federal Risk and Authorization Management Program (FedRAMP), a government-wide program administered under GSA that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services, the 'In Process' designation identifies a Cloud Service Offering that has entered but not completed the FedRAMP authorization workflow. Practitioners should treat this status as distinct from an achieved authorization: an 'In Process' listing reflects active pursuit of authorization (typically including auditing, scrutiny, and testing of the offering) rather than a completed authorization decision, and it does not confer an Authority to Operate or satisfy an agency's independent authorization responsibilities. The specific criteria, milestones, and listing requirements for the 'In Process' designation are defined and maintained by the FedRAMP program and are subject to change; readers should verify the current definition, eligibility conditions, and process steps against the authoritative FedRAMP source. Note also that FedRAMP status governs civilian federal cloud use and does not automatically satisfy DoD-specific requirements.

Why it matters

The FedRAMP In Process designation is frequently misread as a green light for federal adoption, when in fact it signals only that a Cloud Service Offering has entered, but not completed, the FedRAMP authorization workflow. For acquisition officials and program managers, this distinction is consequential: a service listed as In Process has not received a completed authorization decision and does not carry an Authority to Operate. Treating an In Process listing as equivalent to an achieved authorization can expose an agency to using a cloud service before its security posture has been fully assessed and authorized under the program's standardized approach.

The designation matters because it provides transparency into the marketplace while preserving a clear boundary between active pursuit of authorization and a finished authorization. A provider undergoing auditing, scrutiny, and testing is demonstrating progress and commitment, which can be useful market intelligence for agencies planning future procurements. However, that progress is not a substitute for the completed review, and an In Process status can stall or fail to result in authorization. Practitioners should confirm current status against the authoritative FedRAMP source rather than relying on a provider's marketing representation of where it stands.

It is also important to remember that compliance status is not the same as security, and that FedRAMP status governs civilian federal cloud use. A FedRAMP authorization, once achieved, does not automatically satisfy DoD-specific requirements, and an In Process designation confers even less. Agencies retain their own independent authorization responsibilities regardless of a provider's FedRAMP standing, so an In Process listing does not relieve an agency of its obligation to make its own risk-based authorization decision.

Who it's relevant to

Cloud Service Providers
Providers pursuing federal business use the In Process designation to signal active progress through the FedRAMP authorization workflow, including auditing, scrutiny, and testing of their offering. They should be careful to represent this status accurately, since it reflects pursuit of authorization rather than a completed authorization, and should verify current listing requirements against the authoritative FedRAMP source.
Federal Agency Acquisition and Program Officials
Officials evaluating cloud services for civilian federal use should treat an In Process listing as market intelligence, not as approval for adoption. Because the designation does not confer an Authority to Operate, agencies remain responsible for their own independent authorization decisions before placing federal information in the service.
Information System Security Managers and Authorizing Officials
These practitioners must distinguish an In Process status from an achieved authorization when weighing risk. An In Process offering has not completed the FedRAMP review, so it should not be assumed to satisfy authorization requirements, and any authorization decision remains the agency's own responsibility and must be verified against current FedRAMP status.
DoD Stakeholders
Personnel working with defense systems should note that FedRAMP status governs civilian federal cloud use and does not automatically satisfy DoD-specific requirements. An In Process designation confers even less assurance, so DoD requirements must be confirmed separately against the applicable defense authorities.

Inside FedRAMP In Process

In Process Designation
A status indicating that a cloud service offering (CSO) is actively pursuing FedRAMP authorization but has not yet achieved it. This designation is generally tracked by the FedRAMP Program Management Office (PMO) and reflects an ongoing effort rather than a completed authorization.
Sponsoring Relationship
In most implementations, an In Process listing requires a federal agency partner pursuing an Agency Authorization, or engagement with the Joint Authorization Board (JAB) where that path applies. The nature and requirements of these paths may change across FedRAMP program updates, so readers should verify against current FedRAMP PMO guidance.
FedRAMP Marketplace Listing
The In Process status is typically reflected on the FedRAMP Marketplace, which distinguishes between designations such as In Process and Authorized. The specific milestone categories and their definitions are maintained by the FedRAMP PMO and are subject to revision.
Authorization Path
The In Process phase generally involves working toward one of the FedRAMP authorization paths at a defined impact level (such as Low, Moderate, or High). The applicable baseline draws on NIST SP 800-53 controls as tailored by the FedRAMP PMO for the relevant revision.
Assessment Activities
During the In Process phase, activities commonly include independent assessment by a Third Party Assessment Organization (3PAO) and development of the security authorization package. Assessment is a distinct step from authorization and does not by itself confer an Authority to Operate (ATO).

Common questions

Answers to the questions practitioners most commonly ask about FedRAMP In Process.

Does a FedRAMP 'In Process' designation mean a cloud service is authorized and ready for federal use?
No. 'In Process' indicates that a cloud service offering is actively pursuing a FedRAMP authorization but has not yet received one. It generally signals that the provider has an agency partner or is working toward authorization, not that any authorization has been granted. Federal customers should not treat 'In Process' as equivalent to an Authority to Operate (ATO) or a FedRAMP authorization, and should confirm the current status in the FedRAMP Marketplace before relying on the service.
Does a FedRAMP 'In Process' status satisfy DoD cloud requirements?
Not on its own. FedRAMP authorization is a federal civilian program managed by the FedRAMP PMO, and even a completed FedRAMP authorization does not automatically satisfy DoD-specific requirements, which may involve additional controls and impact-level considerations under DoD Cloud Computing guidance. An 'In Process' designation, which precedes any FedRAMP authorization, would generally not meet DoD requirements. Readers should verify DoD-specific obligations against current DoD authoritative sources.
How can I verify whether a cloud service is genuinely 'In Process' rather than simply claiming it?
The FedRAMP Marketplace is generally the authoritative place to confirm a cloud service offering's current status, including 'In Process' designations. Because a provider's marketing may not reflect its official standing, reviewers should confirm the listed status directly and note that statuses change over time as offerings progress toward or away from authorization.
What typically distinguishes an 'In Process' offering from one that is 'FedRAMP Ready'?
These are generally distinct designations tracked in the FedRAMP Marketplace. 'FedRAMP Ready' typically reflects that an independent assessor has attested to a provider's readiness to pursue authorization, while 'In Process' generally indicates the provider is actively undergoing the authorization effort. Neither designation is equivalent to an achieved authorization. Confirm the precise meaning and current criteria of each designation against current FedRAMP PMO guidance, as program terminology and processes evolve.
Can an agency use a service while it is still 'In Process'?
An 'In Process' designation does not by itself provide an authorization basis for use. An agency generally must obtain and accept the applicable authorization and issue or leverage an ATO before operational use, subject to its own risk determination and continuous monitoring obligations. Whether any interim arrangement is permissible depends on agency-specific policy and risk acceptance, which the reader should confirm with the relevant authorizing official and current official sources.
What should I monitor about an offering's 'In Process' status over time?
Because status is time-sensitive and subject to change, reviewers should periodically re-check the FedRAMP Marketplace to see whether an offering has progressed to an authorization, remains in process, or has changed status. An 'In Process' designation is not a permanent or guaranteed path to authorization, and reliance on it should be revisited as circumstances change. Verify the current status against the authoritative FedRAMP source rather than assuming continuity.

Common misconceptions

A FedRAMP In Process designation means the cloud service is FedRAMP authorized and can be used for federal workloads.
In Process indicates that authorization is being pursued, not achieved. Only an Authorized status reflects a granted ATO or provisional authorization. Treating In Process as equivalent to Authorized confuses the assessment and authorization steps and can lead to non-compliant use of the service.
FedRAMP In Process status satisfies Department of Defense requirements for handling CUI or DoD workloads.
FedRAMP authorization is oriented toward federal civilian agency use under FISMA, and even a completed FedRAMP authorization does not automatically satisfy DoD-specific requirements such as those in the DoD Cloud Computing Security Requirements Guide or obligations under DFARS clause 252.204-7012. An In Process designation, which is not yet an authorization, satisfies neither. Readers should confirm DoD applicability against current DoD CIO guidance.
Once a service reaches In Process, achieving full authorization is essentially guaranteed and permanent.
In Process reflects ongoing effort that may or may not result in authorization. Even after an ATO is granted, it is time-bound and subject to continuous monitoring, and can be revoked. Achieving authorization is not assured by the In Process designation alone.

Best practices

Verify a cloud service's current status directly on the FedRAMP Marketplace and distinguish In Process from Authorized before making procurement or use decisions.
Confirm which authorization path (Agency Authorization or the JAB path, as applicable under current FedRAMP program structure) and which impact level a service is pursuing, since these determine the applicable control baseline and use cases.
Do not rely on an In Process designation as authorization for production federal workloads; wait for a granted ATO or provisional authorization and document that basis.
For DoD or CUI-related use cases, separately confirm requirements against DoD CIO guidance and applicable DFARS obligations rather than assuming FedRAMP status is sufficient.
Engage early with a FedRAMP-recognized 3PAO and the sponsoring or authorizing party to keep the assessment and authorization package aligned with the current NIST SP 800-53 tailoring maintained by the FedRAMP PMO.
Plan for continuous monitoring obligations that follow authorization, and verify all program specifics against current official FedRAMP PMO sources, as designations and requirements are subject to revision.