Skip to main content
fedramp-help Help Center home page fedramp-help
  • Submit a request
  • Sign in
  • Sign in
  • Submit a request
  1. fedramp-help
  2. Frequently Asked Questions (FAQs)
  3. Authorizations

Authorizations

  • What is the process for handling false positives found during an initial or annual assessment when the security assessment report (SAR) is closed but has not yet been approved by the partnering agency?
  • Is a penetration test required for FedRAMP authorization?
  • If a Software-as-a-Service (SaaS) or Platform-as-a-Service (PaaS) resides on a FedRAMP Authorized Infrastructure-as-a-Service (IaaS), does that mean it is also FedRAMP Authorized?

The Federal Risk and Authorization Management Program (FedRAMP®) is managed by the FedRAMP Program Management Office.

The FedRAMP name and the FedRAMP logo are the property of the General Services Administration (GSA) and may not be used without GSA’s express, written permission. For more information, please see the FedRAMP Brand Guide.

Connect With Us

Please reach out to FedRAMP with any questions.

mail to fedrampinfo@FedRAMP.gov

Follow Us

x icon X

youtube icon YouTube

Keep Up To Date

To receive news and updates, join the GSA’s subscriber list.

Subscribe
GSA logo

FedRAMP.gov

An official website of the GSA’s Technology Transformation Services

  • About GSA
  • Accessibility statement
  • GSA FOIA
  • No FEAR Act data
  • Office of the Inspector General
  • Performance reports
  • GSA privacy policy
  • Vulnerability disclosure policy
Looking for U.S. government information and services?
Visit USA.gov