Skip to main content

How-to

How to Verify a FedRAMP Marketplace Listing

A field by field guide to the FedRAMP Marketplace: certification class, agency, assessor, package status, and what the 2026 Consolidated Rules changed.

Solomon AmosPublished 19 Sep 202610 min read

A FedRAMP listing on the Marketplace looks authoritative at a glance, but the page you land on is a compressed summary of a much larger evidence trail. Before you rely on a vendor's claim in front of a federal customer, a security questionnaire, or a procurement checklist, read the underlying data the way FedRAMP itself structures it: certification class, sponsoring agency, assessor of record, and package status. This guide walks through that data file field by field, using the public FedRAMP Marketplace and CertReports' registry snapshots as reference points. It also covers what changed on 4 July 2026, when the FedRAMP Consolidated Rules replaced the informal labels of 'Ready', 'In Process' and 'Authorized' that most buyers still repeat from memory. CertReports keeps a live copy of the registry at /registries/fedramp, and the framework page at /frameworks/fedramp explains how the programme fits alongside other frameworks in the index.

What the Marketplace data file actually contains

Every listing on the FedRAMP Marketplace is generated from a structured record, not free text written by the vendor. The fields that matter for verification are the certification class, which is Low, Moderate, High or LI-SaaS, the authorizing path, meaning a single agency or the Joint Authorization Board, the assessor of record, known as the Third Party Assessment Organisation or 3PAO, and the current package status. Marketing pages routinely drop or blur these fields, which is why a screenshot of a vendor's trust page is not evidence on its own. The Marketplace entry, and the underlying package documentation it links to, is the primary source. CertReports pulls the same fields into its own registry snapshot so that a listing's history, not just its current state, stays visible.

FieldWhat to look forWhy it matters
Certification classLow, Moderate, High or LI-SaaS baselineSets the control set the assessor tested against
Authorizing pathSingle agency ATO or JAB provisional authorizationDetermines which agency owns the risk decision
Assessor of recordNamed 3PAO accredited by the FedRAMP PMOConfirms an independent party ran the assessment
Package statusCurrent lifecycle state, for example In Process or FedRAMP CertifiedTells you whether the authorization is active, lapsed or never finished

Core fields on a FedRAMP Marketplace listing

Step 1: find the listing and confirm the certification class

Search the Marketplace using the vendor's legal entity name rather than its product brand, since large vendors often list several cloud service offerings under one parent name. Once you find the package, open it and read the certification class before anything else. A vendor may hold a High authorization for one product line and only a Moderate authorization, or no authorization at all, for a related product it also sells. The class shown on the package page is the only one that counts for that specific offering.

  1. 1

    Search by legal entity name

    Use the Marketplace search field with the vendor's registered corporate name, then filter results to the specific product you intend to buy.

  2. 2

    Match the product to the package

    Confirm the package name matches the product, deployment environment and region the vendor is actually proposing to sell you.

  3. 3

    Read the certification class

    Note whether the package is Low, Moderate, High or LI-SaaS, and do not assume a higher class applies elsewhere in the vendor's portfolio.

  4. 4

    Compare against the vendor's claim

    Check any claim in a proposal or trust page against the class and product name shown on the package itself, not a generic company-wide statement.

Step 2: check the authorizing agency and sponsor

Every package lists either a sponsoring agency, for an Agency Authorization, or the Joint Authorization Board, for a JAB Provisional Authorization. This field tells you who reviewed the assessment package and accepted the risk on behalf of the federal government. An Agency Authorization means one agency's authorizing official signed off, and other agencies may still ask for their own review before reuse. A JAB Provisional Authorization has already passed a board-level review, which is one reason it is often treated as a stronger starting point for reuse across agencies. Neither path is a guarantee that a different agency, with a different risk tolerance, will accept the package without its own additional questions.

Desk covered in printed reports and binders
A FedRAMP package includes hundreds of pages of assessment evidence behind the one-line Marketplace status.

Step 3: verify the assessor of record

The 3PAO named on the package is meant to be an independent check on the vendor's own claims, so it is worth confirming that organisation actually holds current FedRAMP accreditation rather than taking the name at face value. The Marketplace package page names the assessor directly, and the FedRAMP programme maintains its own list of accredited 3PAOs separately from any individual vendor's package. If a package names an assessor you cannot find on that accredited list, or the assessor field is blank, treat the listing as unverified until you can confirm it through the primary source rather than the vendor's own summary.

Step 4: read the package status correctly

Status is the field most often misread, because buyers tend to treat any listing on the Marketplace as equivalent to an active authorization. It is not. A package can appear on the Marketplace while still in the pipeline, after it has lapsed, or after it has been formally removed. Read the status field on its own terms rather than inferring meaning from the fact that a listing exists at all.

Marketplace statusWhat it meansCan you rely on it today
In ProcessAssessment under way with an agency sponsor or the JAB and a named 3PAONo, this is a pipeline status, not a result
FedRAMP CertifiedActive authorization issued under the 2026 Consolidated RulesYes, subject to checking the date and scope
FedRAMP Ready (legacy)A pre-2026 readiness assessment, no longer being newly issuedNo, check the current status field instead
Retired or removedAuthorization withdrawn, expired without renewal, or package discontinuedNo, treat as unauthorized for current use

How to read the FedRAMP Marketplace status field

Check the primary source

A vendor's trust page or sales deck is not the assessment record. Always confirm class, agency, assessor and status against the Marketplace entry itself, or against a registry snapshot such as /registries/fedramp that captures the same fields with a timestamp.

FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization and continuous monitoring for cloud products and services.

Docebo is a worked example of a listing that passes these checks. Its FedRAMP line is read from the Marketplace data file, so it shows as verified with its date, while the ISO and SOC lines beside it are statements on the vendor's own trust centre.

Docebo logo

Docebo · Trust report

Education · Public evidence as of 22 Sep 2026

5Documents and agreements

Legal and review documents Docebo publishes or offers, as of 21 Sep 2026.

2Security practices

Public statements from Docebo, shown as statements, not attestations, as of 21 Sep 2026.

  • Penetration testing · annual
  • Data residency · Australia, Canada, EU, India, US

1Subprocessors

Named on Docebo's public subprocessor list, last seen 21 Sep 2026.

A FedRAMP row verified against the Marketplace data file. Every line is a dated public record from the FedRAMP Marketplace, the Data Privacy Framework list and Docebo's trust centre. A framework not shown means no public evidence was found, not that Docebo lacks it.CertReports

What changed under the 2026 Consolidated Rules

Since 4 July 2026, the official label for an active authorization on the Marketplace is FedRAMP Certified, replacing the older FedRAMP Authorized terminology that many vendors and buyers still use in conversation. The change came with the Consolidated Rules, which folded several prior process tracks into a single set of requirements. FedRAMP Ready, the earlier pre-authorization readiness assessment, became a legacy designation on 28 July 2026. New Ready determinations are no longer being issued, so any Ready badge you see on a vendor's site now refers to a status the programme itself has stopped granting. This matters when you are reading older documents, sales materials or cached vendor pages that predate the change, since the language in them no longer matches the current Marketplace field values. When a document uses 'Authorized' or 'Ready' language, check the live package status rather than assuming the terminology is current.

4 Jul 2026
Consolidated Rules take effect
FedRAMP Certified becomes the standard Marketplace status label
28 Jul 2026
FedRAMP Ready reclassified
Ready becomes a legacy designation; no new Ready listings are issued
1,180+
Active FedRAMP Certified listings tracked
in the CertReports index on 2026-09-19
Rows of servers in a data centre
The systems behind a FedRAMP package, not the marketing page, are what the assessor actually tests.

FedRAMP Moderate vs High: reading the baseline correctly

Moderate and High are not a ranking of vendor quality, they describe the data and impact level a system is authorized to handle. Moderate is the baseline most civilian agency workloads use, covering controlled unclassified information where a breach would cause serious but not catastrophic harm. High applies where a breach could cause severe or catastrophic harm, which is why it turns up most often for law enforcement, emergency response, and certain financial or health systems. A vendor authorized at Moderate has not been assessed against the High control set, regardless of how confident its marketing language sounds, and buyers with High-impact data should not accept a Moderate package as a substitute.

BaselineTypical data sensitivityWho tends to require it
LowLow-impact administrative or public-facing dataAgencies with minimal risk tolerance for that specific system
ModerateControlled unclassified information used across most agency workloadsThe majority of civilian agency contracts
HighLaw enforcement, emergency services, and financial or health data where a breach would be severeAgencies running mission-critical or high-impact systems

How FedRAMP baselines map to typical use, not a ranking of vendor quality

Common mistakes when verifying a listing

Most verification errors come from reading a summary instead of the underlying record. Watch for these specific patterns when a vendor's own materials do not match what the Marketplace shows.

  • Treating a parent company's authorization as covering every product it sells, when only one package is actually in scope
  • Quoting an old 'FedRAMP Authorized' or 'FedRAMP Ready' badge without checking the current package status field
  • Assuming JAB and Agency Authorizations carry identical weight for reuse across every federal customer
  • Accepting a vendor's self-reported assessor name without checking it against the accredited 3PAO list
  • Reading In Process as equivalent to an active authorization because the package already appears on the Marketplace
  • Comparing a Moderate package against a High requirement and assuming the gap is a formality rather than a real control set difference

Bringing it together

Verifying a FedRAMP listing is a short exercise once you know which four fields carry the weight: certification class, authorizing agency, assessor of record, and package status. None of them can be inferred from a badge or a sentence on a vendor's website. Go to the Marketplace package directly, or to a registry snapshot that mirrors the same fields with a timestamp, and read the status field on its own terms rather than assuming presence on the Marketplace equals an active authorization. CertReports' FedRAMP registry at /registries/fedramp and the framework overview at /frameworks/fedramp are built around exactly these fields, so the same check you would run manually on the Marketplace is available as a dated snapshot.

People also ask

How do I check if a vendor is FedRAMP certified?

Search the FedRAMP Marketplace by the vendor's legal entity name, not its marketing brand, and open the specific package for the product you are buying. Read the package status field: since 4 July 2026 an active authorization shows as FedRAMP Certified, with the authorizing agency and assessor listed alongside it. Cross check the same fields against a registry snapshot, such as CertReports' FedRAMP registry, to confirm the listing is current rather than lapsed or withdrawn.

What is the difference between FedRAMP Moderate and High?

Moderate and High are baselines, not quality tiers. Moderate covers controlled unclassified information and is the baseline most civilian agency workloads use. High applies to systems where a breach would cause severe or catastrophic harm, such as law enforcement, emergency response or certain financial and health systems, and it carries a wider and stricter set of controls. A vendor authorized at Moderate has not been assessed against the High baseline, whatever its marketing claims.

What does In Process mean on the Marketplace?

In Process means a vendor has engaged an agency sponsor or the JAB and a 3PAO, and the assessment is under way, but no authorization has been granted yet. It is a pipeline status, not a result. A package can sit In Process for months or stall entirely. Treat it as evidence that work has started, never as proof that a system meets the baseline.

Is FedRAMP Ready still a thing?

FedRAMP Ready still appears on older listings, but it became a legacy designation on 28 July 2026 under the Consolidated Rules, and new Ready determinations are no longer being issued. Existing Ready badges are kept for historical reference only and should not be read as an active authorization. Check the package status field directly rather than relying on a Ready badge found on a vendor's website.

fedrampmarketplacegovernment-cloudauthorizationhow-to
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

Read next on CertReports

You might also like