FedRAMP is the US government's standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. Any cloud service provider (CSP) wanting to serve federal agencies must achieve FedRAMP authorization at one of three impact levels: LOW, MODERATE, or HIGH.
FedRAMP is built on NIST SP 800-53 control selections. LOW baseline uses 125 controls, MODERATE uses 325, and HIGH uses 410. The authorization process costs $250,000 to $1,000,000+ and takes 6-18 months. This is the gate that determines which AI cloud services the federal government can use — and by extension, which AI services the entire federal supply chain can use.
LOW (125 controls): For cloud services where a breach would have limited adverse effect. Covers publicly available information. Minimal security requirements.
MODERATE (325 controls): For services where a breach would have serious adverse effect. Most cloud services fall here. Requires 3PAO (Third-Party Assessment Organization) audit.
HIGH (410 controls): For services where a breach would have severe or catastrophic effect. Handles sensitive but unclassified data. Most rigorous assessment.
FedRAMP is the infrastructure gate for federal AI. Any AI service deployed in the federal cloud environment must be FedRAMP authorized. This means only AI services from companies that can afford the $250K-$1M+ authorization process and 6-18 month timeline can serve federal agencies.
The cost is the filter. Small AI companies, open-source AI deployments, and self-hosted AI cannot achieve FedRAMP authorization individually. Only large cloud providers (AWS, Azure, GCP) have the resources to pursue and maintain authorizations. This concentrates federal AI spending on a handful of platforms.
Self-hosted AI is structurally excluded. FedRAMP authorizes cloud service offerings, not on-premises deployments. An agency running local AI models on its own hardware doesn't need FedRAMP — but it also doesn't get the procurement vehicles, shared services, and inter-agency agreements that come with FedRAMP-authorized cloud. The system nudges agencies toward cloud AI.
Step 1 — Preparation: CSP implements required NIST 800-53 controls, develops System Security Plan (SSP).
Step 2 — Initial Assessment: 3PAO conducts initial security assessment, produces Security Assessment Report (SAR).
Step 3 — Authorization: Authorizing Official (AO) reviews SSP and SAR, grants Authority to Operate (ATO) or Authority to Use (ATO).
Step 4 — Continuous Monitoring: Ongoing security assessment, monthly attestations, annual assessments.
The 6-18 month timeline is the moat. AI moves faster than FedRAMP. By the time an AI service is authorized, it may be two generations behind. But the authorization is required anyway — agencies can't use unauthorized services regardless of capability gap.
3PAOs are a bottleneck. There are a limited number of accredited Third-Party Assessment Organizations. They charge $100K-$500K for assessments. This creates a queue and a cost barrier that only large companies can navigate.
Continuous monitoring creates permanent dependency. Once a CSP is authorized, they must maintain continuous monitoring, submit monthly reports, and undergo annual assessments. Leaving the FedRAMP ecosystem means losing federal customers — creating lock-in that's hard to escape.
FedRAMP was designed for traditional cloud services (IaaS, PaaS, SaaS). AI introduces new challenges: model training data handling, inference API security, model update frequency, adversarial AI defenses, and AI-specific supply chain risks.
The FedRAMP Technical Advisory Group (TAG) has been working on AI-specific guidance, but the core authorization process remains built for static cloud services. AI models that update weekly or daily don't fit neatly into a framework designed for quarterly assessments.
The mismatch is the point. FedRAMP's slow, expensive, static framework applied to fast-moving AI creates a natural selection pressure: only AI services that can slow down enough to comply survive. That means large, established cloud providers with dedicated compliance teams. Fast-moving AI startups, open-source models, and self-hosted deployments are filtered out.
FedRAMP becomes an AI market filter. Not by design, but by effect. The framework was built for cloud infrastructure. Applied to AI, it gates which AI capabilities the government can access — and which AI companies can survive in the federal market. The result: fewer, larger, more compliant AI providers. Exactly what the infrastructure play predicts.
Related frameworks: NIST SP 800-53 (FedRAMP's control basis) · NIST SP 800-171 (contractor equivalent) · EO 14409 (directs federal AI deployment through FedRAMP)
Investigation tracks: The Infrastructure Play (cloud AI as "safe") · The Asymmetry (capability gap)