Can 18F's pass FedRAMP review?

The team details its ongoing efforts to secure a provisional authority to operate.

Shutterstock image (by Lightspring): businessman hanging from a cloud concept image.

When the Federal Risk and Authorization Management Program unveiled its new "FedRAMP Accelerated" process in March, 18F's project was one of three test drivers for the new approach.

More than three months later, is still not through all the hoops.  But the General Services Administration-run cloud service provider was declared FedRAMP Ready in June, and on July 18 four members of 18F posted a lengthy update on the progress to date. Final approval from the FedRAMP Joint Authorization Board, they wrote, is expected in November. is a platform-as-a-service offering that aims to handle "shared technical and policy requirements common to all federal government systems," according to the 18F post. It runs on commercial infrastructure, and one of the team's next steps is migrating to Amazon Web Services' GovCloud. Also on the list is expanding the security incident response plan.

And while one of the goals of the new FedRAMP processes was to reduce the emphasis on up-front paperwork, is deep into documentation efforts now that it's before the Joint Authorization Board.

18F built its own "Compliance Masonry tool," and is using that for  "so that we can collaborate on required documentation in a structured way rather than wrangling a multi-hundred-page Word document."  The goal, the blog authors wrote, is to make the materials "easily reusable as part of compliance documentation" for agencies that choose to run services on

A November FedRAMP authorization for would put mean a roughly eight-month process -- far better than the nine to 18 months most CSPs have averaged, but not quite the three-to-six-month turnaround that FedRAMP Director Matt Goodrich has said is the goal. 

The pilot projects for FedRAMP Accelerated -- in addition to the team, Microsoft and Unisys have also been helping to test the new process -- were expected to take a bit longer, of course.  But there might soon be legislative pressure to accelerate further:  The MOVE IT Act, introduced on June 14 in both the House and Senate, calls for "maximum time limits for the completion of authorizations ... not to exceed six months."