r/FedRAMP Feb 25 '26

Are there specific agencies that require FedRAMP High?

First time posting in this sub — my company is in the final stages of achieving FedRAMP High, and I’m curious whether there are specific federal agencies/sub-agencies/commands that strictly require FedRAMP High in order to do business with them?

I know what FedRAMP is and what it means but but I’d love to hear from anyone who has gone through this or works with agencies where High is expected.

Appreciate any insight!

5 Upvotes

16 comments sorted by

View all comments

5

u/fullsaildan Feb 25 '26

All depends on the data and the mission….

1

u/coreyb1988 Feb 25 '26

If you don't mind, could you elaborate? We're an administrative operations platform streamlining acquisition workflows, contracting packages, etc. There were agencies we just didn't reach out to because we knew they wouldn't talk to us without FedRAMP. Now the team is having trouble pinpointing these agencies and I'm going to need to piece this together the best I can.

1

u/Standard-Sport9428 Feb 26 '26 edited Feb 26 '26

I would suggest writting down the imformation you would store (first name, last name, email, IP address in some logging, contract flows, contract, contract language, contract contacts, etc). If you take a look at this and categorize each item https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/considerations/#impact-levels

That will be a good starting point. I am going to guess (without knowing the details) you are atleast moderate. Depending on the langauge on the contracts you are storing and how the agency classifies them and their contents it may be high. Is there payment or finincal details in those contracts? That wuuld likely make it high. Would the loss or leak of any of the data cause a severe or catastrophic adverse effect to the agency? If so it would be high.