Joint Authorization Board
The Joint Authorization Board was the senior governing body for the Federal Risk and Authorization Management Program (FedRAMP), the program that reviews cloud services for use across the U.S. government. It provided one of the paths for cloud service providers to get authorized to operate. Based on the available evidence, the JAB has since been replaced as part of an effort to streamline how cloud services are authorized.
The Joint Authorization Board (JAB) was historically the top governing body within FedRAMP, described in the evidence as comprised of officials from the Department of Homeland Security (DHS) among other agencies. Under the JAB model, cloud service providers could pursue a Provisional Authority to Operate (P-ATO) through the JAB as an alternative to the agency authorization path. According to the evidence, a new FedRAMP board was launched (announced May 14, 2024) to replace the JAB, and the JAB and its P-ATO process have since been removed in favor of a consolidated FedRAMP authorization path. Readers should note that FedRAMP governance is evolving and should verify the current authorization structure, applicable roles, and terminology against official FedRAMP sources, as the specifics of the successor board and transition timeline are not fully detailed in this evidence.
Why it matters
The Joint Authorization Board historically represented one of the two principal routes to FedRAMP authorization, and understanding it remains important for anyone reading older cloud service provider (CSP) documentation, prior authorization packages, or legacy contractual references. Under the JAB model, a CSP could pursue a Provisional Authority to Operate (P-ATO) through the board rather than obtaining an authorization from a single sponsoring agency. Because the JAB was described as the senior governing body for FedRAMP and was comprised of officials from the Department of Homeland Security (DHS) among other agencies, its endorsement carried government-wide weight and was often treated as a rigorous, high-bar path to authorization.
Who it's relevant to
Inside JAB
Common questions
Answers to the questions practitioners most commonly ask about JAB.