Skip to main content
Category: FedRAMP Program

Joint Authorization Board

Also known as: JAB, FedRAMP Joint Authorization Board
Simply put

The Joint Authorization Board was the senior governing body for the Federal Risk and Authorization Management Program (FedRAMP), the program that reviews cloud services for use across the U.S. government. It provided one of the paths for cloud service providers to get authorized to operate. Based on the available evidence, the JAB has since been replaced as part of an effort to streamline how cloud services are authorized.

Formal definition

The Joint Authorization Board (JAB) was historically the top governing body within FedRAMP, described in the evidence as comprised of officials from the Department of Homeland Security (DHS) among other agencies. Under the JAB model, cloud service providers could pursue a Provisional Authority to Operate (P-ATO) through the JAB as an alternative to the agency authorization path. According to the evidence, a new FedRAMP board was launched (announced May 14, 2024) to replace the JAB, and the JAB and its P-ATO process have since been removed in favor of a consolidated FedRAMP authorization path. Readers should note that FedRAMP governance is evolving and should verify the current authorization structure, applicable roles, and terminology against official FedRAMP sources, as the specifics of the successor board and transition timeline are not fully detailed in this evidence.

Why it matters

The Joint Authorization Board historically represented one of the two principal routes to FedRAMP authorization, and understanding it remains important for anyone reading older cloud service provider (CSP) documentation, prior authorization packages, or legacy contractual references. Under the JAB model, a CSP could pursue a Provisional Authority to Operate (P-ATO) through the board rather than obtaining an authorization from a single sponsoring agency. Because the JAB was described as the senior governing body for FedRAMP and was comprised of officials from the Department of Homeland Security (DHS) among other agencies, its endorsement carried government-wide weight and was often treated as a rigorous, high-bar path to authorization.

Who it's relevant to

Cloud Service Providers (CSPs)
CSPs that previously pursued or held a JAB P-ATO, or that are evaluating current authorization routes, need to understand that the JAB path has reportedly been removed in favor of a consolidated FedRAMP authorization path. Because the transition details are not fully specified in the available evidence, providers should verify the current authorization requirements and any implications for existing authorizations directly with the FedRAMP PMO and official sources rather than relying on legacy JAB guidance.
Federal Agency Authorizing Officials and Procurement Staff
Agency personnel reviewing older FedRAMP packages or contract references may encounter JAB P-ATO terminology. They should distinguish the historical JAB path from the current consolidated authorization structure and confirm how the successor board and single authorization path affect reliance on prior authorizations. Note that FedRAMP authorization does not automatically satisfy DoD-specific requirements, which must be confirmed separately.
Compliance Officers and Auditors
Those auditing cloud authorization status or maintaining compliance records should be aware that FedRAMP governance is evolving and that references to the JAB and its P-ATO process reflect a superseded model. Given that the specifics of the successor board and transition timeline are not fully detailed in this evidence, practitioners should anchor findings to current official FedRAMP publications and treat JAB-era terminology as historical context.

Inside JAB

Governing FedRAMP Authority
The Joint Authorization Board historically served as one of the two primary authorization paths within the FedRAMP program, which is administered by the FedRAMP Program Management Office (PMO). Practitioners should verify the current authorizing structure against official FedRAMP sources, as the program's governance and pathways have evolved over time.
Provisional Authorization (P-ATO)
The JAB was associated with issuing a Provisional Authority to Operate (P-ATO) for cloud service offerings. A P-ATO reflects a JAB-level risk determination that individual agencies could then leverage when granting their own agency ATO. The provisional nature generally means it is not a substitute for an agency's own authorization decision.
Member Agencies
The JAB has traditionally comprised senior representatives from a defined set of federal departments. Practitioners should confirm the precise current composition against authoritative FedRAMP materials rather than assuming a fixed membership, as governance arrangements are subject to change.
Scope, Federal Civilian Cloud Services
JAB authorizations relate to cloud service offerings assessed under the FedRAMP program, which governs federal executive agency use of cloud services. This is distinct from DoD-specific authorization processes under the Risk Management Framework and from requirements for classified national security systems.
Relationship to Continuous Monitoring
A P-ATO issued through the JAB is time-bound and subject to ongoing continuous monitoring obligations rather than being a permanent state. Maintaining the authorization generally depends on the cloud service provider meeting continuous monitoring expectations.

Common questions

Answers to the questions practitioners most commonly ask about JAB.

Does a JAB Provisional Authorization (P-ATO) mean an agency can use a cloud service without doing anything further?
No. A JAB P-ATO is a provisional authorization that reflects the Joint Authorization Board's risk review, but it is not an agency Authority to Operate (ATO). Each federal agency that wants to use the service generally must review the security package and issue its own ATO, accepting the residual risk for its specific use. Treating the P-ATO as a substitute for an agency authorization is a common mistake. Confirm current FedRAMP process requirements against official sources, as roles and procedures have evolved over time.
Does a JAB authorization satisfy DoD requirements for handling defense information?
Not automatically. FedRAMP authorization, including a JAB P-ATO, addresses federal cloud security at defined impact levels, but DoD systems are subject to additional requirements under the DoD RMF and DoD cloud guidance, and protection of Controlled Unclassified Information may implicate DFARS clause obligations. Assuming that a civilian-oriented FedRAMP authorization fully covers DoD needs is a frequent error. Verify applicable DoD-specific requirements, such as those tied to DoD impact levels, against current official DoD and FedRAMP guidance.
How does a JAB P-ATO differ from an Agency ATO within the FedRAMP program?
A JAB P-ATO is a provisional authorization issued centrally through the Joint Authorization Board's review, intended to support reuse by multiple agencies, whereas an Agency ATO is issued by an individual agency's authorizing official for that agency's use. In most implementations, agencies still perform their own review and issue an ATO even when a P-ATO exists. Because FedRAMP governance and authorization pathways have changed over time, confirm the current structure and available authorization paths against official FedRAMP sources.
How do cloud service providers typically pursue a JAB-related authorization?
Historically, cloud service providers engaged with the JAB after a prioritization process, worked with a third-party assessment organization to produce a security assessment package, and underwent JAB review before a provisional authorization could be granted. The specific prioritization criteria, documentation expectations, and process steps are set by the FedRAMP program and have been subject to revision. Providers should verify the current intake and authorization procedures, including whether the JAB pathway remains available, against official FedRAMP guidance.
What continuous monitoring obligations follow a JAB provisional authorization?
A JAB P-ATO is time-bound and conditioned on ongoing continuous monitoring rather than being a one-time approval. In most implementations this includes periodic reporting, vulnerability scanning, and review of changes to the authorized system, with the authorization subject to revision or withdrawal if risk posture degrades. Treating any authorization as permanent is a common error. Confirm the specific monitoring deliverables and cadence against current FedRAMP requirements and any conditions stated in the authorization.
How should an agency use a JAB security package when deciding whether to adopt a cloud service?
An agency generally reviews the authorization package, including the security assessment results and residual risk information, and its authorizing official determines whether the risk is acceptable for the agency's intended use and data before issuing an agency ATO. Reuse of the package is a core benefit, but authorization and risk acceptance remain agency responsibilities. Note that assessment is distinct from authorization, and that agency-specific tailoring may apply. Verify current reuse procedures and package access processes against official FedRAMP sources.

Common misconceptions

A JAB Provisional Authorization (P-ATO) automatically satisfies any agency's authorization requirement.
A P-ATO reflects a JAB-level provisional risk determination that agencies may leverage, but individual agencies generally must still issue their own ATO and accept the associated risk for their specific use case. The 'provisional' designation signals that it is not a final agency authorization.
A JAB authorization is permanent once granted.
Like any ATO, a P-ATO is time-bound and contingent on continuous monitoring. Authorizations can be affected if the cloud service provider fails to meet ongoing monitoring and reporting obligations, so a P-ATO should not be treated as a one-time, indefinite approval.
A JAB or FedRAMP authorization satisfies DoD authorization requirements automatically.
FedRAMP authorization does not by itself satisfy DoD-specific requirements. DoD systems follow their own Risk Management Framework processes and may impose additional impact-level and security requirements beyond baseline FedRAMP authorization.

Best practices

Verify the current FedRAMP authorization pathways and JAB governance against official FedRAMP PMO sources, since program structure and membership have evolved over time.
Do not treat a JAB P-ATO as a completed agency authorization; confirm whether your agency must issue its own ATO and accept the associated residual risk for your specific use.
Track continuous monitoring status for any cloud service relied upon under a P-ATO, treating the authorization as time-bound rather than permanent.
When operating in the defense space, separately confirm DoD-specific requirements and impact-level determinations rather than assuming FedRAMP authorization is sufficient.
Distinguish assessment activities from authorization decisions when reviewing a cloud provider's documentation, and confirm which authority made the risk determination.
Consult current authoritative publications for precise membership, control baselines, and process details rather than relying on potentially outdated summaries.