FedRAMP In Process
FedRAMP In Process is a status that indicates a cloud service provider is actively working toward, but has not yet achieved, a FedRAMP authorization. It generally means the provider's cloud offering is undergoing the auditing, testing, and review steps of the Federal Risk and Authorization Management Program. This status shows progress toward authorization but does not by itself mean the service is authorized or approved for federal use.
Within the Federal Risk and Authorization Management Program (FedRAMP), a government-wide program administered under GSA that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services, the 'In Process' designation identifies a Cloud Service Offering that has entered but not completed the FedRAMP authorization workflow. Practitioners should treat this status as distinct from an achieved authorization: an 'In Process' listing reflects active pursuit of authorization (typically including auditing, scrutiny, and testing of the offering) rather than a completed authorization decision, and it does not confer an Authority to Operate or satisfy an agency's independent authorization responsibilities. The specific criteria, milestones, and listing requirements for the 'In Process' designation are defined and maintained by the FedRAMP program and are subject to change; readers should verify the current definition, eligibility conditions, and process steps against the authoritative FedRAMP source. Note also that FedRAMP status governs civilian federal cloud use and does not automatically satisfy DoD-specific requirements.
Why it matters
The FedRAMP In Process designation is frequently misread as a green light for federal adoption, when in fact it signals only that a Cloud Service Offering has entered, but not completed, the FedRAMP authorization workflow. For acquisition officials and program managers, this distinction is consequential: a service listed as In Process has not received a completed authorization decision and does not carry an Authority to Operate. Treating an In Process listing as equivalent to an achieved authorization can expose an agency to using a cloud service before its security posture has been fully assessed and authorized under the program's standardized approach.
The designation matters because it provides transparency into the marketplace while preserving a clear boundary between active pursuit of authorization and a finished authorization. A provider undergoing auditing, scrutiny, and testing is demonstrating progress and commitment, which can be useful market intelligence for agencies planning future procurements. However, that progress is not a substitute for the completed review, and an In Process status can stall or fail to result in authorization. Practitioners should confirm current status against the authoritative FedRAMP source rather than relying on a provider's marketing representation of where it stands.
It is also important to remember that compliance status is not the same as security, and that FedRAMP status governs civilian federal cloud use. A FedRAMP authorization, once achieved, does not automatically satisfy DoD-specific requirements, and an In Process designation confers even less. Agencies retain their own independent authorization responsibilities regardless of a provider's FedRAMP standing, so an In Process listing does not relieve an agency of its obligation to make its own risk-based authorization decision.
Who it's relevant to
Inside FedRAMP In Process
Common questions
Answers to the questions practitioners most commonly ask about FedRAMP In Process.