How to answer
Are you FedRAMP authorized?
The answer is almost always no, and the mistake is a yes borrowed from a cloud provider. It is a status on a public list, so it is the easiest claim in the file to check.
No. FillTrust is not FedRAMP authorized and is not currently in the FedRAMP process. Our infrastructure runs on a FedRAMP-authorized cloud provider, which covers their platform and not our service.
FillTrust grades an answer like this answered “no” from your documents when your documents support it.
- Answered from
- Nothing in your document set, unless you have been through the process. This is a status held in a public marketplace, not a claim made in a policy.
- Evidence to attach
- The listing itself. It is public, so a reviewer can check it without asking you.
- Where it is asked
- SIG LiteBespoke vendor questionnaires
FedRAMP is a US government programme that authorizes cloud services for federal use. Authorization is a status recorded on a public marketplace, which makes this an unusual questionnaire row: the reviewer can verify your answer without your help, in about thirty seconds, before they read anything else you wrote.
Do not borrow your provider's authorization. This is the mistake that gets made, and it is the same shape as claiming PCI compliance because your payment provider holds it. A FedRAMP-authorized cloud platform gives you an authorized place to run. It says nothing about your application, your access controls, your personnel or your incident process, which is what an authorization of your service would cover. Saying "we run on FedRAMP-authorized infrastructure" is true, useful and materially different from "we are FedRAMP authorized", and the difference is a multi-year programme with a real budget.
"In process" is also a checkable status. There is a published list of services genuinely working through it with a sponsoring agency. Claiming to be in process without being on it is a claim that fails in the same thirty seconds.
A no is often fine. Not every federal or federally-funded purchase requires authorization, and many of the questionnaires asking this are from universities and contractors rather than agencies, where it is one row among two hundred and a no costs nothing. What helps is answering the question behind it: which of the underlying controls can you actually evidence. A SOC 2, an ISO 27001 certificate or a completed CAIQ gives the reviewer something to work with.
If it genuinely blocks the deal, treat it as a strategic decision rather than a questionnaire answer. Authorization needs an agency sponsor, a documented control implementation against a federal baseline, an assessment by an accredited third party and continuous monitoring afterwards. It is a company-shaping commitment, and "not currently, and here is what we do hold" is the honest answer until that decision has actually been made.
How this one goes wrong
Specific to this question, not general advice.
- Answering yes because your cloud provider is authorized. Their authorization covers their platform. Yours would cover your service running on it, and the gap between the two is the entire programme.
- Saying "in process" without being in it. There is a public list of what is genuinely in process, and a reviewer buying for a federal agency knows where it is.
- Treating a no as the end of the conversation. Plenty of agency purchases do not require authorization, and the follow-up question is usually which controls you can evidence anyway.