FedRAMP updates scope guidance per M-24-15 memo

Original title: Updated guidance on the Scope of FedRAMP as required by M-24-15 (following RFC-0010)

FedRAMP has updated its guidance on the scope of the FedRAMP program in response to the M-24-15 presidential memo and following the closure of RFC-0010. This update clarifies what systems and services fall under FedRAMP's authorization requirements. Organizations evaluating cloud services for federal use must review the updated scope definitions to determine which systems require FedRAMP authorization.

What changed

  • FedRAMP publishes updated guidance on program scope in response to M-24-15 memo requirements
  • Scope guidance incorporates resolution from RFC-0010 public comment process

Who is affected

Federal agencies and cloud service providers offering services to the U.S. federal government

Summary generated by a language model; the official text prevails. Not legal advice.