A FedRAMP listing on the Marketplace looks authoritative at a glance, but the page you land on is a compressed summary of a much larger evidence trail. Before you rely on a vendor's claim in front of a federal customer, a security questionnaire, or a procurement checklist, read the underlying data the way FedRAMP itself structures it: certification class, sponsoring agency, assessor of record, and package status. This guide walks through that data file field by field, using the public FedRAMP Marketplace and CertReports' registry snapshots as reference points. It also covers what changed on 4 July 2026, when the FedRAMP Consolidated Rules replaced the informal labels of 'Ready', 'In Process' and 'Authorized' that most buyers still repeat from memory. CertReports keeps a live copy of the registry at /registries/fedramp, and the framework page at /frameworks/fedramp explains how the programme fits alongside other frameworks in the index.
What the Marketplace data file actually contains
Every listing on the FedRAMP Marketplace is generated from a structured record, not free text written by the vendor. The fields that matter for verification are the certification class, which is Low, Moderate, High or LI-SaaS, the authorizing path, meaning a single agency or the Joint Authorization Board, the assessor of record, known as the Third Party Assessment Organisation or 3PAO, and the current package status. Marketing pages routinely drop or blur these fields, which is why a screenshot of a vendor's trust page is not evidence on its own. The Marketplace entry, and the underlying package documentation it links to, is the primary source. CertReports pulls the same fields into its own registry snapshot so that a listing's history, not just its current state, stays visible.
| Field | What to look for | Why it matters |
|---|---|---|
| Certification class | Low, Moderate, High or LI-SaaS baseline | Sets the control set the assessor tested against |
| Authorizing path | Single agency ATO or JAB provisional authorization | Determines which agency owns the risk decision |
| Assessor of record | Named 3PAO accredited by the FedRAMP PMO | Confirms an independent party ran the assessment |
| Package status | Current lifecycle state, for example In Process or FedRAMP Certified | Tells you whether the authorization is active, lapsed or never finished |
Core fields on a FedRAMP Marketplace listing
Step 1: find the listing and confirm the certification class
Search the Marketplace using the vendor's legal entity name rather than its product brand, since large vendors often list several cloud service offerings under one parent name. Once you find the package, open it and read the certification class before anything else. A vendor may hold a High authorization for one product line and only a Moderate authorization, or no authorization at all, for a related product it also sells. The class shown on the package page is the only one that counts for that specific offering.
- 1
Search by legal entity name
Use the Marketplace search field with the vendor's registered corporate name, then filter results to the specific product you intend to buy.
- 2
Match the product to the package
Confirm the package name matches the product, deployment environment and region the vendor is actually proposing to sell you.
- 3
Read the certification class
Note whether the package is Low, Moderate, High or LI-SaaS, and do not assume a higher class applies elsewhere in the vendor's portfolio.
- 4
Compare against the vendor's claim
Check any claim in a proposal or trust page against the class and product name shown on the package itself, not a generic company-wide statement.
Step 2: check the authorizing agency and sponsor
Every package lists either a sponsoring agency, for an Agency Authorization, or the Joint Authorization Board, for a JAB Provisional Authorization. This field tells you who reviewed the assessment package and accepted the risk on behalf of the federal government. An Agency Authorization means one agency's authorizing official signed off, and other agencies may still ask for their own review before reuse. A JAB Provisional Authorization has already passed a board-level review, which is one reason it is often treated as a stronger starting point for reuse across agencies. Neither path is a guarantee that a different agency, with a different risk tolerance, will accept the package without its own additional questions.
Step 3: verify the assessor of record
The 3PAO named on the package is meant to be an independent check on the vendor's own claims, so it is worth confirming that organisation actually holds current FedRAMP accreditation rather than taking the name at face value. The Marketplace package page names the assessor directly, and the FedRAMP programme maintains its own list of accredited 3PAOs separately from any individual vendor's package. If a package names an assessor you cannot find on that accredited list, or the assessor field is blank, treat the listing as unverified until you can confirm it through the primary source rather than the vendor's own summary.
Step 4: read the package status correctly
Status is the field most often misread, because buyers tend to treat any listing on the Marketplace as equivalent to an active authorization. It is not. A package can appear on the Marketplace while still in the pipeline, after it has lapsed, or after it has been formally removed. Read the status field on its own terms rather than inferring meaning from the fact that a listing exists at all.
| Marketplace status | What it means | Can you rely on it today |
|---|---|---|
| In Process | Assessment under way with an agency sponsor or the JAB and a named 3PAO | No, this is a pipeline status, not a result |
| FedRAMP Certified | Active authorization issued under the 2026 Consolidated Rules | Yes, subject to checking the date and scope |
| FedRAMP Ready (legacy) | A pre-2026 readiness assessment, no longer being newly issued | No, check the current status field instead |
| Retired or removed | Authorization withdrawn, expired without renewal, or package discontinued | No, treat as unauthorized for current use |
How to read the FedRAMP Marketplace status field
Check the primary source
A vendor's trust page or sales deck is not the assessment record. Always confirm class, agency, assessor and status against the Marketplace entry itself, or against a registry snapshot such as /registries/fedramp that captures the same fields with a timestamp.
FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization and continuous monitoring for cloud products and services.
Docebo is a worked example of a listing that passes these checks. Its FedRAMP line is read from the Marketplace data file, so it shows as verified with its date, while the ISO and SOC lines beside it are statements on the vendor's own trust centre.

Docebo · Trust report
Education · Public evidence as of 22 Sep 2026
Framework overview
CertReports state for each framework with public evidence: 2 verified, 9 vendor-stated.
FedRAMPVerifiedModerate impact
DPFVerifiedValid to 30 Dec 2026
SOC 2Vendor-statedTrust centre · 21 Sep 2026GDPRVendor-statedTrust centre · 21 Sep 2026
PCI DSSVendor-statedTrust centre · 21 Sep 2026
ISO 27001Vendor-statedTrust centre · 21 Sep 2026
ISO 27701Vendor-statedTrust centre · 21 Sep 2026
ISO 27017Vendor-statedTrust centre · 21 Sep 2026
ISO 27018Vendor-statedTrust centre · 21 Sep 2026
5Documents and agreements
Legal and review documents Docebo publishes or offers, as of 21 Sep 2026.
- Standard contractual clauses · On request
- Subprocessor list · Public
- Privacy policy · Public
- AI and data use policy · Public
- Public trust centre documents · Docebo SOC2 Report Renewal Statement (Bridge letter); Docebo ISO 27001, 27701, 27017, and 27018 latest certificate; Docebo ISO 9001 Certificate
2Security practices
Public statements from Docebo, shown as statements, not attestations, as of 21 Sep 2026.
- Penetration testing · annual
- Data residency · Australia, Canada, EU, India, US
1Subprocessors
Named on Docebo's public subprocessor list, last seen 21 Sep 2026.
What changed under the 2026 Consolidated Rules
Since 4 July 2026, the official label for an active authorization on the Marketplace is FedRAMP Certified, replacing the older FedRAMP Authorized terminology that many vendors and buyers still use in conversation. The change came with the Consolidated Rules, which folded several prior process tracks into a single set of requirements. FedRAMP Ready, the earlier pre-authorization readiness assessment, became a legacy designation on 28 July 2026. New Ready determinations are no longer being issued, so any Ready badge you see on a vendor's site now refers to a status the programme itself has stopped granting. This matters when you are reading older documents, sales materials or cached vendor pages that predate the change, since the language in them no longer matches the current Marketplace field values. When a document uses 'Authorized' or 'Ready' language, check the live package status rather than assuming the terminology is current.
- 4 Jul 2026
- Consolidated Rules take effect
- FedRAMP Certified becomes the standard Marketplace status label
- 28 Jul 2026
- FedRAMP Ready reclassified
- Ready becomes a legacy designation; no new Ready listings are issued
- 1,180+
- Active FedRAMP Certified listings tracked
- in the CertReports index on 2026-09-19
FedRAMP Moderate vs High: reading the baseline correctly
Moderate and High are not a ranking of vendor quality, they describe the data and impact level a system is authorized to handle. Moderate is the baseline most civilian agency workloads use, covering controlled unclassified information where a breach would cause serious but not catastrophic harm. High applies where a breach could cause severe or catastrophic harm, which is why it turns up most often for law enforcement, emergency response, and certain financial or health systems. A vendor authorized at Moderate has not been assessed against the High control set, regardless of how confident its marketing language sounds, and buyers with High-impact data should not accept a Moderate package as a substitute.
| Baseline | Typical data sensitivity | Who tends to require it |
|---|---|---|
| Low | Low-impact administrative or public-facing data | Agencies with minimal risk tolerance for that specific system |
| Moderate | Controlled unclassified information used across most agency workloads | The majority of civilian agency contracts |
| High | Law enforcement, emergency services, and financial or health data where a breach would be severe | Agencies running mission-critical or high-impact systems |
How FedRAMP baselines map to typical use, not a ranking of vendor quality
Common mistakes when verifying a listing
Most verification errors come from reading a summary instead of the underlying record. Watch for these specific patterns when a vendor's own materials do not match what the Marketplace shows.
- Treating a parent company's authorization as covering every product it sells, when only one package is actually in scope
- Quoting an old 'FedRAMP Authorized' or 'FedRAMP Ready' badge without checking the current package status field
- Assuming JAB and Agency Authorizations carry identical weight for reuse across every federal customer
- Accepting a vendor's self-reported assessor name without checking it against the accredited 3PAO list
- Reading In Process as equivalent to an active authorization because the package already appears on the Marketplace
- Comparing a Moderate package against a High requirement and assuming the gap is a formality rather than a real control set difference
Bringing it together
Verifying a FedRAMP listing is a short exercise once you know which four fields carry the weight: certification class, authorizing agency, assessor of record, and package status. None of them can be inferred from a badge or a sentence on a vendor's website. Go to the Marketplace package directly, or to a registry snapshot that mirrors the same fields with a timestamp, and read the status field on its own terms rather than assuming presence on the Marketplace equals an active authorization. CertReports' FedRAMP registry at /registries/fedramp and the framework overview at /frameworks/fedramp are built around exactly these fields, so the same check you would run manually on the Marketplace is available as a dated snapshot.
People also ask
How do I check if a vendor is FedRAMP certified?
Search the FedRAMP Marketplace by the vendor's legal entity name, not its marketing brand, and open the specific package for the product you are buying. Read the package status field: since 4 July 2026 an active authorization shows as FedRAMP Certified, with the authorizing agency and assessor listed alongside it. Cross check the same fields against a registry snapshot, such as CertReports' FedRAMP registry, to confirm the listing is current rather than lapsed or withdrawn.
What is the difference between FedRAMP Moderate and High?
Moderate and High are baselines, not quality tiers. Moderate covers controlled unclassified information and is the baseline most civilian agency workloads use. High applies to systems where a breach would cause severe or catastrophic harm, such as law enforcement, emergency response or certain financial and health systems, and it carries a wider and stricter set of controls. A vendor authorized at Moderate has not been assessed against the High baseline, whatever its marketing claims.
What does In Process mean on the Marketplace?
In Process means a vendor has engaged an agency sponsor or the JAB and a 3PAO, and the assessment is under way, but no authorization has been granted yet. It is a pipeline status, not a result. A package can sit In Process for months or stall entirely. Treat it as evidence that work has started, never as proof that a system meets the baseline.
Is FedRAMP Ready still a thing?
FedRAMP Ready still appears on older listings, but it became a legacy designation on 28 July 2026 under the Consolidated Rules, and new Ready determinations are no longer being issued. Existing Ready badges are kept for historical reference only and should not be read as an active authorization. Check the package status field directly rather than relying on a Ready badge found on a vendor's website.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
FedRAMP in 2026: Certified replaces Authorized, Ready is retired, 20x goes live
CertReports Research · 5 Sep 2026 · 10 min read
The state of public compliance evidence in 2026: what 3,000 vendors actually publish
CertReports Research · 18 Sep 2026 · 12 min read