FedRAMP Moderate baseline: what the authorization roadmap does not tell you

Key takeaways
FedRAMP Moderate baseline covers 325+ controls with parameter values and enhancements that have no direct equivalent in SOC 2, ISO 27001, or CMMC -- mapping from those frameworks produces false coverage confidence.
JAB authorization and agency authorization impose identical control requirements. The strategic difference is market reach, not compliance rigor.
ConMon failures -- missed scan submissions, aging POA&M items, incomplete audit log retention -- account for more program suspensions than failed initial 3PAO assessments.
FIPS 140-2 validated encryption is mandatory and inherited from cloud provider infrastructure only when the specific service configuration is confirmed, not assumed.
Agency ISSOs increasingly request raw audit logs during incident investigations. CSPs whose logging pipelines exclude containerized workloads or have gaps in retention cannot produce the evidence on demand.
The average gap between initial authorization and first ConMon deficiency finding is under 14 months, based on Vulnox assessment data from 2023 to 2024.
TL;DR
FedRAMP Moderate authorization is not a milestone. It is an operational state that requires sustained evidence production, monthly scan submissions, and POA&M discipline indefinitely. Most mid-size SaaS providers who achieve authorization discover the compliance gaps after the ATO letter arrives, not before. The authorization package gets you in. The ConMon program keeps you there. These are not the same problem and they require different organizational capabilities.
The authorization letter arrived. Then the real problems started.
A 60-person SaaS company spent 22 months and roughly $1.2 million in consulting fees, internal engineering time, and 3PAO assessment costs to achieve FedRAMP Moderate authorization. The ATO letter arrived from their agency sponsor in Q2. By Q4 of the same year, their ConMon submission was overdue, three POA&M items had passed their scheduled remediation dates without documented justification, and the agency ISSO had flagged a gap in audit log coverage for their containerized microservices layer. The PMO opened a significant change request. The federal contract they had spent two years qualifying for was paused pending remediation.
The problem was not that the compliance program failed. The problem was that the organization built a program to achieve authorization and had not built one to sustain it. These are structurally different programs. One produces a document package. The other produces operational evidence on a recurring schedule, indefinitely, against a federal oversight structure that does not grade on a curve.
What FedRAMP Moderate baseline actually requires and where the evidence standard diverges from commercial frameworks
FedRAMP Moderate baseline derives from NIST SP 800-53 Rev 5 with FedRAMP-specific parameter values and control enhancements layered on top. The 325+ controls span 17 families. The word 'moderate' refers to FIPS 199 impact categorization -- systems where a breach would produce serious adverse effects on federal operations, assets, or individuals. That definition has teeth. It shapes what evidence standards apply, what monitoring cadence is mandatory, and what an agency ISSO is entitled to request when something goes wrong.
The divergence from SOC 2 or ISO 27001 is not just coverage. It is the nature of the evidence obligation. SOC 2 produces an auditor opinion at a point in time. FedRAMP produces a continuous evidence stream: monthly vulnerability scan results submitted to the PMO, ongoing POA&M updates, incident reports within defined windows, and annual independent reassessments. The federal oversight relationship does not end at authorization. It continues for the life of the contract.
This matters for how compliance programs are built. A SOC 2 program can be run in bursts -- intensify effort before the audit window, then decompress. FedRAMP Moderate cannot. The PMO and agency ISSO have visibility into scan submission cadence. A missed month is a compliance event. A POA&M item that ages past its scheduled remediation date without a documented extension request is a compliance event. The program has to run continuously at operational tempo, not audit tempo.
Example
FIPS 140-2 validated encryption is a concrete example of where assumed inheritance fails. Many cloud environments inherit encryption from underlying IaaS providers. The provider's infrastructure may use FIPS 140-2 validated modules. But the specific service configuration -- the key management settings, the cipher suites enabled, the transport layer parameters -- determines whether the validation applies to the data in scope. CSPs that document FIPS 140-2 compliance by pointing to their cloud provider's FIPS certificate without confirming service-level configuration produce an SSP that will not survive 3PAO technical validation.
Control enhancements at the Moderate level that have no Low-baseline equivalent include requirements around session termination, boundary protection between tenant environments, protection of audit information, and supply chain risk management. Each enhancement requires explicit implementation documentation and testable evidence, not policy statements.
What gap assessments actually find in organizations pursuing FedRAMP Moderate
Assessment base: Vulnox assessment data, 2023 to 2024, drawn from gap assessments and post-authorization compliance reviews of cloud service providers at varying stages of the FedRAMP Moderate authorization lifecycle.
Logging coverage excludes containerized workloads
In assessments of cloud-native SaaS providers targeting FedRAMP Moderate, a consistent pattern emerged: logging pipelines were built around persistent infrastructure and did not capture events from containerized services with short lifespans. The SSP documented logging as comprehensive. The deployed architecture produced gaps. When Vulnox reviewed log coverage against the AU control family requirements, the gaps were structural -- not a configuration error that could be patched in a day, but an architectural decision that required a redesigned logging pipeline.
Agencies increasingly request raw audit logs during incident investigations, not summaries. A CSP whose logging architecture has structural gaps cannot produce the evidence on demand. This is not a finding that surfaces in the authorization package review -- it surfaces during the first real incident after authorization. By that point, the contractual and reputational exposure is already active.
POA&M processes exist on paper without operational ownership
Across multiple assessments of organizations 12 to 18 months post-authorization, Vulnox found POA&M items that had been documented at the time of initial assessment and then not touched. Scheduled remediation dates had passed. No extension requests had been filed. No ownership assignments were active. The POA&M existed as a document artifact from the authorization process, not as a live risk management tool.
The FedRAMP PMO monitors POA&M aging. Items that pass scheduled dates without documented justification are compliance findings. More importantly, a POA&M that is not operationally maintained is evidence that the risk management program is nominal -- which is exactly what an agency ISSO is looking for when they decide whether to renew an ATO.
Boundary protection documentation describes intended architecture, not deployed configuration
This pattern appeared consistently in assessments of organizations that went through rapid infrastructure changes after initial authorization. The SSP described boundary controls based on the architecture at time of authorization. The deployed environment had drifted -- new services, modified network segments, cloud configuration changes -- and the SSP had not been updated. The 3PAO at initial assessment validated what was documented. The ongoing drift was invisible to the PMO until an agency ISSO requested an architecture review.
FedRAMP treats significant changes to the system boundary as events that require notification and potentially reassessment. But most organizations do not have a change management workflow that flags infrastructure modifications as potential FedRAMP significant changes. The documentation drifts silently.
Supply chain risk management controls are described but not evidenced
Supply chain risk management (SR control family) is an area where SSPs consistently overstate implementation maturity. Organizations document SCRM policies and vendor assessment processes. When Vulnox requested the underlying evidence -- vendor assessment records, software bill of materials, third-party risk questionnaire results -- it was frequently absent or outdated by more than 24 months. The controls were implemented on paper. The evidence that would satisfy an agency inquiry or PMO audit did not exist.
SCRM is an increasing focus of federal oversight following supply chain incidents affecting federal systems. Agency ISSOs are more likely to probe this control family now than they were three years ago. A CSP whose SCRM documentation is a policy statement without supporting evidence records is exposed in a way that will not show in routine ConMon submissions but will surface under investigation.
Passing the 3PAO assessment is not the hardest part
Common belief
Most organizations pursuing FedRAMP Moderate treat the 3PAO assessment as the primary compliance challenge. The preparation, the document production, the technical testing -- this is where resources concentrate. Authorization is the goal. Once the ATO letter arrives, the hard part is over.
What we found
In post-authorization reviews of organizations 12 to 24 months past their ATO date, Vulnox found that the most common compliance deficiencies were not technical control failures -- they were evidence production failures. Controls were implemented. The operational infrastructure to demonstrate implementation on demand was not.
The authorization package is a point-in-time snapshot. The 3PAO validates that controls were implemented as documented at the time of assessment. What the assessment does not test is whether the organization can sustain evidence production at operational tempo for the following 36 months while also running a product, responding to incidents, and managing infrastructure changes.
ConMon is where the program either holds or doesn't. Monthly scan submissions have to happen on schedule. POA&M items have to be managed with documented remediation milestones. Significant changes have to be identified and reported. Annual reassessments have to be scoped and coordinated. None of this is technically harder than the initial authorization work. But it requires a different organizational capability: a team that owns compliance as an ongoing operational function, not a project that ends at ATO.
The evidence standard during an agency incident investigation is also qualitatively different from the evidence standard during 3PAO assessment. A 3PAO validates control implementation against the SSP. An agency ISSO investigating an incident wants raw logs, timeline reconstruction, and evidence of how boundary controls performed in real conditions. These are different evidence requests and they require different evidence infrastructure.
JAB authorization versus agency authorization: the decision that shapes program design
JAB authorization
JAB prioritizes a limited number of CSPs per cycle. Prioritization is based on agency demand signals -- the JAB wants evidence that multiple agencies have expressed interest in the service before investing assessment resources. The timeline from prioritization request to ATO typically runs 15 to 18 months. A JAB Provisional ATO is recognized government-wide, which means the authorization package can support contracts with any federal agency without re-authorization.
JAB authorization makes sense for CSPs with a genuine multi-agency market. It requires upfront investment in demonstrating agency demand before the authorization process begins. For a CSP that has one or two federal agency targets, the prioritization process adds time without proportional benefit.
Agency authorization
Agency authorization is initiated by a specific federal agency that agrees to act as the authorizing official. The timeline is more variable -- it depends on the agency's internal review capacity and prioritization -- but it can move faster than JAB when the agency sponsor is engaged. The resulting ATO applies to that agency. Other agencies can reuse the authorization package through the FedRAMP marketplace, but they are not obligated to accept it without their own review.
Agency authorization is the practical path for CSPs with a specific federal contract in view. It concentrates the authorization effort around one relationship. The risk is agency-side capacity constraints. Agencies vary significantly in their ability to resource authorization reviews, and delays on the agency side extend timelines in ways the CSP cannot control.
Where FedRAMP Moderate programs develop blind spots
Ephemeral infrastructure and logging
Container orchestration environments, serverless functions, and auto-scaling groups create and destroy compute resources at frequencies that traditional logging architectures were not designed for. FedRAMP AU controls require audit log generation for defined event types across all system components. When those components have lifespans measured in minutes or seconds, the logging pipeline has to be purpose-built for ephemeral capture. Most organizations discover this gap when they try to produce logs for a specific timeframe during an incident review and find gaps.
Significant change identification
FedRAMP defines significant changes as modifications that could affect the security posture of the system and require notification to the authorizing official. The definition is intentionally broad. Most organizations do not have a change management workflow that systematically evaluates infrastructure changes against FedRAMP's significant change criteria. Changes that qualify -- new external services, modifications to boundary architecture, changes to authentication systems -- get deployed without triggering the notification process. The SSP drifts from the deployed environment silently.
Inheritance boundaries between CSP and tenant
FedRAMP's inheritance model allows CSPs to inherit controls from the underlying cloud infrastructure they operate on -- assuming that platform has its own FedRAMP authorization. But inheritance boundaries require explicit documentation. Controls that are partially inherited require documentation of which portions the CSP implements versus which the underlying platform provides. Vague inheritance claims in the SSP fail 3PAO technical validation and, more importantly, fail to give the agency ISSO a clear picture of the CSP's actual control responsibility.
What organizations say before the assessment and what is actually driving the problem
'We already passed SOC 2 Type II six months ago. We figured FedRAMP Moderate would be roughly the same level of effort with some additional controls.'
Root cause:SOC 2 and FedRAMP Moderate share some control domain overlap but are structurally different compliance regimes. SOC 2 is an auditor opinion based on the organization's own defined trust service criteria. FedRAMP Moderate specifies the controls, the parameter values, the enhancement requirements, and the evidence format. The continuous monitoring obligation has no SOC 2 equivalent. FIPS 140-2 encryption requirements have no SOC 2 equivalent. Organizations that use SOC 2 readiness as a proxy for FedRAMP Moderate readiness typically find a gap analysis revealing 60 to 80 additional control requirements that need documented implementation and testable evidence.
'Our cloud provider is FedRAMP authorized. We assumed that covered most of our controls through inheritance.'
Root cause:Cloud provider FedRAMP authorization covers the infrastructure layer. The CSP building on that infrastructure inherits specific controls -- the list is documented in the provider's customer responsibility matrix. Controls that are listed as 'customer responsibility' or 'shared' require the CSP to implement and evidence their portion. A common pattern in gap assessments is CSPs who have not reviewed their provider's customer responsibility matrix and have assumed broader inheritance than actually applies. The FIPS 140-2 example is typical: the provider's platform uses validated modules, but the specific service configuration -- key management settings, cipher suite parameters -- is the CSP's responsibility to configure and document.
'We have a dedicated compliance team. We were not expecting the ConMon obligations to require this much ongoing engineering capacity.'
Root cause:ConMon is an operational program, not a compliance documentation function. Monthly vulnerability scans have to be run across all system components, results have to be analyzed and fed into the POA&M, and submissions have to be formatted and delivered to the PMO on schedule. When vulnerabilities in containerized environments or ephemeral infrastructure are involved, the scanning methodology requires engineering involvement to ensure coverage. Organizations that staff ConMon as a compliance documentation activity without engineering support discover the gap when scan coverage is challenged during a PMO review.
Where FedRAMP Moderate compliance programs are heading in the next three years
The PMO will introduce automated ConMon submission validation that flags coverage gaps in scan results before human review, increasing the detection rate of logging and scanning blind spots within 60 days of introduction rather than at the next annual assessment.
The FedRAMP PMO has been expanding its automated review capabilities. Manual review of monthly scan submissions from hundreds of authorized CSPs is not scalable. Automated flagging of gap patterns -- missing component classes, submission timing anomalies, POA&M items with no activity -- is a natural extension of the existing digital authorization repository infrastructure. When this capability is deployed, CSPs with structural logging gaps will encounter compliance findings on a monthly cycle rather than discovering them during annual reassessments.
Confidence: highIf the FedRAMP PMO publishes updated ConMon guidance or automated review tooling documentation by end of 2026 that includes coverage validation criteria, this prediction holds. If ConMon review remains manual-only through 2027, it does not.Supply chain risk management will become the most commonly cited deficiency in FedRAMP Moderate authorization packages within 18 months, displacing audit logging as the top finding category.
Federal oversight attention on software supply chain security has increased measurably since the executive order on improving the nation's cybersecurity. Agency ISSOs are asking harder questions about software bill of materials, vendor assessment cadence, and third-party component risk. The SR control family requirements in NIST SP 800-53 Rev 5 are more extensive than what most organizations were addressing under Rev 4. CSPs that have not updated their SCRM documentation and evidence practices since Rev 5 adoption are carrying an exposure that will materialize as federal scrutiny continues to intensify.
Confidence: mediumIf annual 3PAO assessment finding trend data published through the FedRAMP marketplace or PMO reporting shows SR control family deficiencies as the top category by end of 2025, this prediction holds ahead of schedule. If finding distributions remain stable through 2026, the prediction needs revision.
The authorization package review is the wrong place to focus compliance investment
Most of the consulting and legal spend in FedRAMP Moderate programs concentrates on the authorization package: the SSP, the policies, the evidence artifacts assembled for 3PAO review. This is understandable. The authorization package is the visible gate. But it is also the part of FedRAMP compliance that is most amenable to document production without corresponding operational capability. You can produce a technically compliant SSP that accurately describes a control environment and still have a ConMon program that cannot sustain itself past 14 months. The authorization package gets reviewed once. The ConMon program runs indefinitely.
If I were advising a 60-person SaaS company starting a FedRAMP Moderate program today, I would tell them to design the ConMon program first and build the authorization package around what the ConMon program can actually sustain. Not the other way around. The question is not 'what can we document for the 3PAO?' It is 'what evidence can we produce on a monthly basis, indefinitely, with the team and infrastructure we have?' Those two questions produce different program designs.
Counterargument
The counterargument is that building ConMon infrastructure before achieving authorization wastes resources -- if the 3PAO assessment reveals control gaps that require architectural changes, ConMon infrastructure built around the pre-remediation architecture may need to be rebuilt anyway. This is a legitimate sequencing concern and it is why the practical answer is not to ignore the authorization package but to treat ConMon operational design as a first-class requirement from the start, not a second-phase activity after ATO.
One thing to do before next week
Pull your current POA&M and identify every item with a scheduled remediation date in the past 90 days. For each one, verify that either the remediation was completed and documented, or a formal extension request was filed with documented justification. If neither is true for any item, that is an active ConMon deficiency. It is also a signal about whether your POA&M is a live risk management tool or a document artifact from your authorization process. That distinction will determine whether your ATO is intact 18 months from now.
Further Reading
Gap Analysis
framework gap analysisnetwork security
network security controlsFedRAMP baselines explained: R4, R5, Low, Moderate, High, and LI-SaaS
FedRAMP Moderate authorisation roadmapNational Vulnerability Database Home
National Vulnerability DatabaseNIST SP 800-30 Risk Assessment Guide
NIST risk assessment guideOWASP Testing Methodologies
OWASP penetration testing methods
Frequently Asked Questions
How long does FedRAMP Moderate authorization actually take end to end?
Most mid-size SaaS providers underestimate the timeline by six to twelve months. JAB prioritization alone can take three to six months before assessment work begins. Full authorization from gap assessment to ATO typically runs 18 to 24 months. Organizations that start with a mature SSP and clean POA&M process shave time at the 3PAO assessment stage, but the ConMon program must be operational before authorization is granted, not after.
What is the difference between JAB authorization and agency authorization for FedRAMP Moderate?
JAB authorization produces a Provisional ATO recognized across all federal agencies, but JAB prioritizes a small number of CSPs per cycle based on demand signals from agencies. Agency authorization is faster to initiate but scoped to one agency sponsor. The control requirements and evidence standards are identical. The strategic difference is market reach: JAB authorization enables multi-agency sales; agency authorization gets one contract moving.
What does FedRAMP Moderate ConMon actually require on a monthly basis?
Monthly obligations include vulnerability scans of all system components, submission of scan results to the FedRAMP PMO, updated POA&M tracking all open findings with remediation milestones, and incident reporting within defined timelines. Annual obligations include an independent security assessment by a 3PAO. Most programs that lose authorization fail on scan submission cadence or let POA&M items age past scheduled remediation dates without documented justification.
What evidence gaps most commonly cause FedRAMP Moderate programs to fail agency re-review?
The two most common gaps are audit log completeness and supply chain documentation. Agencies increasingly request raw audit logs during incident investigations, not just summaries. CSPs whose logging pipelines have gaps in coverage or retention periods below 12 months cannot produce the evidence. Supply chain risk management documentation is the second gap: many SSPs describe SCRM controls but have no documented vendor assessments or software bill of materials to back the claims.
Does passing SOC 2 Type II help with FedRAMP Moderate authorization?
SOC 2 Type II demonstrates audit discipline and some control overlap, particularly in availability and confidentiality domains. It does not map cleanly to FedRAMP Moderate requirements. FedRAMP adds control enhancements, parameter values, and overlays that have no SOC 2 equivalent. FIPS 140-2 validated encryption is mandatory under FedRAMP and not required under SOC 2. Organizations that treat SOC 2 as a stepping stone avoid rework, but the evidence formats, control descriptions, and continuous monitoring obligations are fundamentally different.
What are the most common findings in FedRAMP Moderate gap assessments?
Across assessments, the most consistent gaps are: logging coverage that excludes ephemeral workloads or containerized services; boundary protection documentation that describes intended architecture but does not reflect deployed configuration; and POA&M processes that exist on paper but have no assigned ownership or remediation tracking workflow. Encryption compliance is frequently overstated because FIPS 140-2 module validation is assumed from cloud provider inheritance without confirming the specific service configuration.
Related Articles

GovRAMP Moderate authorization: why the Significant Change Request process catches providers off guard
GovRAMP Moderate is the first tier where you need a government sponsor, annual 3PAO reassessment, and a Significant Change Request process that can pause normal product releases for months. Most providers who stall post-authorization were not prepared for what maintaining Moderate status actually costs operationally.

GovRAMP Low+ authorization: the impact level that punishes providers who get the CUI boundary wrong
GovRAMP Low+ is where providers handling limited Controlled Unclassified Information land — or discover they should not be there. The defining failure is not a missing control. It is a CUI boundary that was drawn before anyone asked what data the government actually sends through the system.

GovRAMP High authorization: why FIPS-validated crypto and personnel security controls catch providers off guard
GovRAMP High is where cloud providers discover that having strong encryption is not the same as having FIPS 140-2 validated encryption — and that distinction alone has derailed authorizations from vendors who passed every other control family. The architectural constraints at High are qualitatively different from every lower tier.
Ready to Secure Your Digital Assets?
Get a comprehensive vulnerability assessment for your website today.