FedRAMP Intelligence

FedRAMP Authorized Vendor List (2026)

FedRAMP (Federal Risk and Authorization Management Program) is the US government's standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. Any cloud service provider selling to federal agencies must achieve FedRAMP authorization — a process that requires independent assessment against NIST 800-53 security controls. This article covers what FedRAMP authorization means, the differences between authorization levels, and which common SaaS vendors hold (or lack) FedRAMP authorization as of March 2026.

What FedRAMP authorization means

FedRAMP authorization means a cloud service offering (CSO) has been independently assessed by a Third Party Assessment Organization (3PAO) and granted an Authority to Operate (ATO) by a federal agency or the Joint Authorization Board (JAB). The authorization confirms the vendor meets a defined set of NIST 800-53 security controls appropriate to the data sensitivity level. There are three authorization paths: Agency Authorization (sponsored by a single agency), JAB Authorization (reviewed by DoD, DHS, and GSA), and FedRAMP Ready (a preliminary designation indicating the vendor has been assessed but not yet authorized). An authorized vendor appears on the FedRAMP Marketplace with their authorization status, impact level, and sponsoring agency.

FedRAMP Moderate vs. FedRAMP High impact levels

FedRAMP authorization is granted at one of three impact levels defined by FIPS 199: Low (LI-SaaS), Moderate, and High. The impact level determines how many security controls the vendor must implement.

FedRAMP Moderate requires approximately 325 security controls and covers systems where the loss of confidentiality, integrity, or availability would have a serious adverse effect on organizational operations, assets, or individuals. Most SaaS products serving federal civilian agencies target Moderate authorization. Examples: Salesforce Government Cloud, Okta, GitHub Enterprise Cloud, Snowflake Government.

FedRAMP High requires approximately 421 security controls and covers systems processing data where loss would have a severe or catastrophic effect — including law enforcement data, emergency services, financial systems, and health data. Examples: AWS GovCloud, Microsoft Azure Government.

A vendor authorized at High can process Moderate and Low data. A vendor authorized at Moderate cannot process High-impact data.

Why FedRAMP Ready does not mean authorized

FedRAMP Ready is a preliminary designation that means a 3PAO has confirmed the vendor's system meets FedRAMP security requirements in a readiness assessment — but no federal agency has granted an Authority to Operate (ATO). FedRAMP Ready vendors appear on the FedRAMP Marketplace but cannot process federal data until they complete the full authorization process with a sponsoring agency. The gap between Ready and Authorized can take 6-18 months. Organizations evaluating vendors for federal workloads should not treat FedRAMP Ready as equivalent to FedRAMP Authorized. If your compliance framework requires FedRAMP authorization, only vendors with an active ATO at the appropriate impact level satisfy the requirement.

Common SaaS vendors and their FedRAMP status

The table below shows FedRAMP authorization status for common enterprise SaaS vendors as verified against the FedRAMP Marketplace API. For the full interactive list with search and filtering, see the FedRAMP Authorization Status Tracker.

VendorFedRAMP Status
1PasswordNot Listed on FedRAMP Marketplace
ADPNot Listed on FedRAMP Marketplace
AdyenNot Listed on FedRAMP Marketplace
AirtableNot Listed on FedRAMP Marketplace
Amazon Web ServicesFedRAMP Authorized (High)
AmplitudeNot Listed on FedRAMP Marketplace
Apollo.ioNot Listed on FedRAMP Marketplace
AsanaNot Listed on FedRAMP Marketplace
Auth0Not Listed on FedRAMP Marketplace
BambooHRNot Listed on FedRAMP Marketplace
Bill.comNot Listed on FedRAMP Marketplace
BitbucketNot Listed on FedRAMP Marketplace
BoxFedRAMP Authorized (Moderate)
BraintreeNot Listed on FedRAMP Marketplace
CanvaNot Listed on FedRAMP Marketplace
CircleCINot Listed on FedRAMP Marketplace
ClickUpNot Listed on FedRAMP Marketplace
CloudflareNot Listed on FedRAMP Marketplace
ConfluenceNot Listed on FedRAMP Marketplace
CrowdStrikeFedRAMP Authorized (Moderate)
CyberArkFedRAMP Authorized (Moderate)
DatabricksNot Listed on FedRAMP Marketplace
DatadogFedRAMP Authorized (Moderate)
dbt LabsNot Listed on FedRAMP Marketplace
DeelNot Listed on FedRAMP Marketplace
DigitalOceanNot Listed on FedRAMP Marketplace
DockerNot Listed on FedRAMP Marketplace
DocuSignFedRAMP Authorized (Moderate)
DrataNot Listed on FedRAMP Marketplace
DriftNot Listed on FedRAMP Marketplace
DropboxNot Listed on FedRAMP Marketplace
DynatraceFedRAMP Authorized (Moderate)
ElasticNot Listed on FedRAMP Marketplace
Epic SystemsNot Listed on FedRAMP Marketplace
FastlyNot Listed on FedRAMP Marketplace
FigmaNot Listed on FedRAMP Marketplace
FivetranNot Listed on FedRAMP Marketplace
FortinetNot Listed on FedRAMP Marketplace
FreshdeskNot Listed on FedRAMP Marketplace
FreshworksNot Listed on FedRAMP Marketplace
GitHubFedRAMP Authorized (Moderate)
GitLabNot Listed on FedRAMP Marketplace
GongNot Listed on FedRAMP Marketplace
Google CloudFedRAMP Authorized (Moderate)
Google DriveNot Listed on FedRAMP Marketplace
Google WorkspaceNot Listed on FedRAMP Marketplace
GrafanaNot Listed on FedRAMP Marketplace
GustoNot Listed on FedRAMP Marketplace
HashiCorpNot Listed on FedRAMP Marketplace
HerokuNot Listed on FedRAMP Marketplace
HuaweiNot Listed on FedRAMP Marketplace
HubSpotNot Listed on FedRAMP Marketplace
IntercomNot Listed on FedRAMP Marketplace
JiraNot Listed on FedRAMP Marketplace
KasperskyNot Listed on FedRAMP Marketplace
LastPassNot Listed on FedRAMP Marketplace
LaunchDarklyNot Listed on FedRAMP Marketplace
LinearNot Listed on FedRAMP Marketplace
LookerNot Listed on FedRAMP Marketplace
LoomNot Listed on FedRAMP Marketplace
MailchimpNot Listed on FedRAMP Marketplace
Microsoft 365FedRAMP Authorized (Moderate)
Microsoft AzureFedRAMP Authorized (High)
Microsoft TeamsFedRAMP Authorized (Moderate)
MiroNot Listed on FedRAMP Marketplace
MixpanelNot Listed on FedRAMP Marketplace
Monday.comNot Listed on FedRAMP Marketplace
MongoDBNot Listed on FedRAMP Marketplace
NetSuiteNot Listed on FedRAMP Marketplace
New RelicNot Listed on FedRAMP Marketplace
NortonNot Listed on FedRAMP Marketplace
NotionNot Listed on FedRAMP Marketplace
OktaFedRAMP Authorized (Moderate)
OneTrustNot Listed on FedRAMP Marketplace
OracleNot Listed on FedRAMP Marketplace
PagerDutyFedRAMP Authorized (Moderate)
Palo Alto NetworksFedRAMP Authorized (Moderate)
PandaDocNot Listed on FedRAMP Marketplace
Ping IdentityNot Listed on FedRAMP Marketplace
PipedriveNot Listed on FedRAMP Marketplace
PlaidNot Listed on FedRAMP Marketplace
PostmarkNot Listed on FedRAMP Marketplace
QuickBooksNot Listed on FedRAMP Marketplace
RedisNot Listed on FedRAMP Marketplace
RenderNot Listed on FedRAMP Marketplace
RingCentralNot Listed on FedRAMP Marketplace
RipplingNot Listed on FedRAMP Marketplace
SalesforceFedRAMP Authorized (Moderate)
SAPNot Listed on FedRAMP Marketplace
SecureframeNot Listed on FedRAMP Marketplace
SegmentNot Listed on FedRAMP Marketplace
SendGridNot Listed on FedRAMP Marketplace
SentinelOneNot Listed on FedRAMP Marketplace
SentryNot Listed on FedRAMP Marketplace
ServiceNowFedRAMP Authorized (Moderate)
ShopifyNot Listed on FedRAMP Marketplace
SlackNot Listed on FedRAMP Marketplace
SnowflakeFedRAMP Authorized (Moderate)
SolarWindsNot Listed on FedRAMP Marketplace
SplunkFedRAMP Authorized (Moderate)
SquareNot Listed on FedRAMP Marketplace
StripeNot Listed on FedRAMP Marketplace
SupabaseNot Listed on FedRAMP Marketplace
TableauNot Listed on FedRAMP Marketplace
TerraformNot Listed on FedRAMP Marketplace
TikTokNot Listed on FedRAMP Marketplace
TwilioFedRAMP Authorized (Moderate)
VantaNot Listed on FedRAMP Marketplace
Veeva SystemsNot Listed on FedRAMP Marketplace
VercelNot Listed on FedRAMP Marketplace
WebexNot Listed on FedRAMP Marketplace
WiseNot Listed on FedRAMP Marketplace
WooCommerceNot Listed on FedRAMP Marketplace
WorkdayNot Listed on FedRAMP Marketplace
XeroNot Listed on FedRAMP Marketplace
ZendeskNot Listed on FedRAMP Marketplace
ZoomFedRAMP Authorized (Moderate)
ZscalerFedRAMP Authorized (Moderate)

View the full interactive FedRAMP tracker with search and filtering →

How to verify FedRAMP status independently

The authoritative source for FedRAMP authorization status is the FedRAMP Marketplace at marketplace.fedramp.gov. Do not rely on vendor marketing pages — vendors sometimes claim FedRAMP authorization for their commercial product when only their government-specific offering is authorized. To verify: search for the vendor name on the Marketplace, confirm the specific Cloud Service Offering (CSO) matches what you plan to use, check the authorization status (Authorized vs. In Process vs. Ready), verify the impact level meets your data classification, and note the sponsoring agency and authorization date.

ThirdProof automates this verification as part of its certification registry checks during vendor investigations. The investigation queries the FedRAMP Marketplace API directly and includes the result in the vendor's compliance evidence section.

What to do when a required vendor is not FedRAMP authorized

When a vendor you need is not FedRAMP authorized, you have several options depending on your compliance requirements:

1. Identify FedRAMP-authorized alternatives. For many software categories, authorized alternatives exist. For example, if Slack (not authorized) is required for messaging, GovSlack or Microsoft Teams (authorized at Moderate) are alternatives.

2. Request the vendor pursue authorization. Large vendors sometimes prioritize FedRAMP authorization when customers demonstrate demand. Ask your vendor contact about their FedRAMP roadmap.

3. Document compensating controls. If no authorized alternative exists and the vendor handles non-CUI data, document the gap with compensating controls: encryption requirements, access restrictions, data residency controls, and monitoring.

4. Obtain risk acceptance. For CMMC, FedRAMP, and agency-specific requirements, formal risk acceptance from your authorizing official may be required when using non-authorized vendors.

5. Isolate the workload. Deploy the non-authorized vendor in a separate environment that does not process federal data or CUI.

See this in action

ThirdProof automates vendor risk assessment across 24 intelligence sources. Investigate any vendor in under 2 minutes — no questionnaires, no vendor cooperation required.

Try ThirdProof Free →

No credit card required

Frequently asked questions

How many vendors are FedRAMP authorized?+
As of March 2026, the FedRAMP Marketplace lists over 300 authorized cloud service offerings from hundreds of providers. ThirdProof tracks FedRAMP status for 100+ common enterprise SaaS vendors. The exact number changes as new vendors achieve authorization and existing authorizations are renewed or revoked.
Is FedRAMP authorization required for all government contracts?+
FedRAMP authorization is required for cloud service providers selling to US federal agencies under the Federal Acquisition Regulation (FAR). State and local governments may reference FedRAMP but are not legally required to mandate it. Department of Defense contracts may require additional authorization under the DoD Cloud Computing SRG in addition to FedRAMP.
How long does FedRAMP authorization take?+
The FedRAMP authorization process typically takes 6-18 months from initial engagement to ATO, depending on the authorization path (Agency vs. JAB), the vendor's existing security posture, and the target impact level. FedRAMP Ready assessment can be completed in 2-4 months as a preliminary step.

Put this into practice

Investigate any vendor across 24 intelligence sources in under 2 minutes. Your first investigation is free.

Start Free Investigation →

No credit card required