FedRAMP CMMC position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

FedRAMP and CMMC Position

What they do well

  • US federal procurement signals — clear, recognized.
  • NIST 800-53 / 800-171 alignment — strong technical basis.
  • Continuous monitoring (FedRAMP) — ongoing security signal.
  • CMMC tiered approach — proportional.

What they do poorly

  • High cost — both programs expensive.
  • Long timelines for FedRAMP authorization (1-3 years).
  • 3PAO / C3PAO capacity — bottleneck.
  • CMMC implementation lag vs original 2020 schedule.
  • US-centric — non-US recognition limited.

Evidence

  • FedRAMP Marketplace lists authorized services.
  • CMMC 2.0 rollout through 2024-2026.
  • Cloud / SaaS investment in FedRAMP substantial.

Personal calibration

  • For US federal / DoD contract work: vocabulary essential.
  • For non-US-federal: limited applicability.

See also