Updated September 18, 2026

Sthenos Technologies (Sthenos LLC) builds software to run inside a FedRAMP boundary, for cloud service providers and the agencies that buy from them. Sthenos holds no FedRAMP certification, which attaches to an assessed cloud service offering and is held by the provider that operates it. This page sets out what the program requires in 2026 and how Sthenos builds to it.

Read the first section before the rest. The most common and most expensive mistake in this area is a team budgeting for FedRAMP on a system that was never in scope.

First question: is your system even in scope?

Only a federal agency can decide whether its use of a cloud service falls within the scope of FedRAMP. FedRAMP states this directly and declines to publish a list of services that are always out of scope, because the same service can be in scope for one agency use case and out of scope for another.

The scope itself comes from OMB Memorandum M-24-15, published July 25, 2024, which FedRAMP quotes: the scope of FedRAMP is cloud computing products and services, such as IaaS, PaaS and SaaS, that create, collect, process, store, or maintain Federal information on behalf of a Federal agency, and that are not otherwise specified as out of scope.

M-24-15 then names six categories that sit outside that scope, subject to exceptions made by the FedRAMP Director with OMB approval. The first one is the reason this section exists:

  • Information systems used only for a single agency’s operations, hosted on cloud infrastructure or a platform, that are not offered as a shared service and do not operate with a shared responsibility model.
  • Social media and communications platforms used in accordance with agency social media policies.
  • Search engines.
  • Widely available services that provide commercially available information to agencies but do not collect Federal information.
  • Ancillary services whose compromise would pose a negligible risk to Federal information or information systems, such as systems that make external measurements or only ingest information from other publicly available services.
  • Any other categories identified for exclusion by the FedRAMP Board, with the concurrence of the Federal CIO.

A great deal of custom agency software falls in that first bullet. A mission application built for one agency, running on that agency’s cloud account, not offered to anyone else, is the archetype of a single agency system. It still has to be secured, it still has to satisfy FISMA and the agency’s own authorization process, and it will still be assessed against NIST SP 800-53. What it does not need is a FedRAMP certification, because FedRAMP certifies reusable cloud service offerings rather than one agency’s application.

FedRAMP publishes four scope indicators an agency should review. If the answer is yes to all four, the system is in scope. If the answer is no to all four, it is out of scope. Mixed answers mean the agency has to work it through.

Scope indicator What it is asking
Agency responsibilities under 44 U.S.C. 3506 Does the planned use fall within those responsibilities, meaning is oversight required because the service will handle sensitive federal information?
Agency specific tenant Does agency use require configuration and maintenance of an agency specific tenant, or other centralized administration on the agency’s behalf?
Enterprise security integration Will the service be integrated into agency enterprise security services such as identity and access management, security information and event management, single sign on, or secure access service edge?
Reusability Is the service available to multiple agencies or third parties, and could other agencies reasonably be expected to use it?

We raise this in the first conversation rather than at proposal. If your requirement is a single agency system, we will say so, and the money you were going to spend on a certification path is better spent on the evidence package your own authorizing official actually needs.

What FedRAMP is, in law

FedRAMP was established on December 23, 2022, in Section 5921 of Public Law 117-263, the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023. That section, titled the FedRAMP Authorization Act, amended Chapter 36 of Title 44 of the United States Code by adding sections 3607 through 3616. Those sections cover definitions, the program itself, the roles of the General Services Administration, the FedRAMP Board, independent assessment, declaration of foreign interests, the roles of agencies and of OMB, reports to Congress, and the Federal Secure Cloud Advisory Committee.

Two consequences of that statute are worth knowing before you plan around FedRAMP.

The program was rebuilt, not amended. Section 3614 required OMB to issue implementing guidance, and M-24-15 followed on July 25, 2024. FedRAMP’s own description of that memorandum is that it rescinded and replaced FedRAMP in its entirety, creating a new program with the same name but an entirely different set of authority and responsibilities. Guidance written before mid 2024 describes a program that no longer exists in that form.

The statute carries a sunset. Effective five years after enactment, Chapter 36 of Title 44 is amended by striking sections 3607 through 3616. That is a date worth having in view on a multi year program plan.

What changed in 2026

FedRAMP launched the Consolidated Rules for 2026 on June 24, 2026, after a public preview earlier that year. The Consolidated Rules bring the rules, definitions, timelines, stakeholder guidance and source material into one public reference for agencies, cloud service providers, independent assessors, advisors and FedRAMP itself.

The vocabulary moved with it. The program now speaks of FedRAMP Certification, of Certification Types, Classes and Paths. If your internal documents still say “provisional ATO” and “JAB”, they are describing the pre 2024 program and will not map cleanly onto what a provider or an agency is doing today.

Types, classes and paths

There are two Certification Types. FedRAMP 20x is the current one. Rev5 is the legacy one, built on the NIST SP 800-53 Rev 5 baselines.

There are two Certification Paths, and FedRAMP is blunt that the choice is mostly made for you by decisions already taken:

  • Program Certification is provided directly by FedRAMP and does not require a federal agency to sponsor the service. It is mostly only available for the 20x Certification Type.
  • Agency Certification requires a federal agency to authorize the service in advance, following the legacy FedRAMP process, and then sponsor it. It is only available for the Rev5 Certification Type.

Classes run A through D and are designed to be taken progressively, so investment can scale with agency interest. Each class provides more assurance, commitment and alignment with agency needs, and costs more to reach. FedRAMP’s guidance on where to start is unusually direct: most providers entering the federal market should start at Class A, which is designed for existing commercial products that already hold a SOC 2 Type II and run a mature security program; and providers generally should not go straight to Class C or Class D unless an existing government contract requires that level of commitment.

Certification Class What FedRAMP says it supports in agency use
Class A Adequate information for most non sensitive use cases and some Low, Moderate or High security objectives.
Class B Adequate information for most Low security objectives and some Moderate or High security objectives.
Class C Adequate information for most Low and Moderate security objectives, and some High security objectives.
Class D Adequate information for most use cases regardless of security objective. This does not include systems that process classified information.

Low, Moderate and High have not gone away, but they are not the same axis

Agencies still categorize their own systems under FIPS 199, which defines low, moderate and high impact based on the potential effect on the agency of a loss of confidentiality, integrity or availability. FIPS 200 then requires an agency to set the overall impact level at the highest of those three security objectives and employ appropriately tailored controls.

FedRAMP Certification Classes loosely align with the baseline expectations for those impact levels in NIST SP 800-53B, but FedRAMP states there is no direct correlation between Class and Impact Level, partly because providers may tailor controls within a baseline and not every baseline is implemented the same way. Treating a Class as a synonym for an impact level will produce a plan that does not survive contact with an assessor.

One further distinction is worth carrying into any architecture conversation. FedRAMP notes that commercial cloud services are usually a component within a federal information system rather than a federal information system themselves, and that a cloud service is not subject to the laws, regulations and policies governing federal information systems unless it is built by the government or operated on the government’s behalf under explicit contract. Which side of that line your system sits on changes what you owe.

What the controls actually are

Underneath the program vocabulary, the Rev5 control set is NIST SP 800-53 Revision 5, “Security and Privacy Controls for Information Systems and Organizations”. NIST published Revision 5 in September 2020 with updates as of December 10, 2020, and issued release 5.2.0 as a minor patch release on August 27, 2025, adding SA-15(13), SA-24 and SI-02(07) among other changes.

FedRAMP’s published control reference vendors that catalog at version 5.2.0 and reports 1,014 active controls and control enhancements across 20 families, excluding withdrawn controls. The families are the shape of the work:

Family ID Controls and enhancements
Access Control AC 131
Awareness and Training AT 15
Audit and Accountability AU 56
Assessment, Authorization, and Monitoring CA 25
Configuration Management CM 56
Contingency Planning CP 49
Identification and Authentication IA 59
Incident Response IR 40
Maintenance MA 28
Media Protection MP 20
Physical and Environmental Protection PE 51
Planning PL 11
Program Management PM 37
Personnel Security PS 17
Personally Identifiable Information Processing and Transparency PT 21
Risk Assessment RA 22
System and Services Acquisition SA 108
System and Communications Protection SC 139
System and Information Integrity SI 102
Supply Chain Risk Management SR 27

Read that table as a budget rather than a checklist. Very few of those families are satisfied by writing code. Personnel Security, Physical and Environmental Protection, Program Management and most of Contingency Planning are organizational commitments held by whoever operates the service. A development partner moves the engineering families, chiefly AC, AU, CM, IA, SC, SI, SA and SR, and produces evidence that the rest can be assessed against.

FedRAMP 20x and Key Security Indicators

The 20x Certification Type expresses its expectations as Key Security Indicators rather than as a control list. FedRAMP’s published reference sets out 46 indicators grouped into 10 areas, each mapped back to the SP 800-53 controls it relates to:

  • Cybersecurity Education
  • Change Management
  • Cloud Native Architecture
  • Identity and Access Management
  • Incident Response
  • Monitoring, Logging, and Auditing
  • Policy and Inventory
  • Recovery Planning
  • Supply Chain Risk
  • Service Configuration

The indicators are written in engineering terms, which makes them useful to a build team in a way a control catalog is not. Two examples, quoted from FedRAMP’s own text: changes to machine based information resources are executed through the redeployment of version controlled resources rather than direct modification wherever reasonable; and persistent testing and validation of changes throughout deployment is automated. Those are statements about how your pipeline works. A team that already deploys immutable infrastructure from version control has done much of that work before anyone mentions FedRAMP.

What we do in a build to meet these controls

Each row below is a decision that is inexpensive while the architecture is still being set and painful once the system is in production. We take these as defaults on federal work rather than as options.

Control area What it means in the code and the pipeline Cheap now, expensive later
Authorization boundary What is inside the system, what is an external service, and where every interconnection crosses the line, settled and drawn before the first sprint Boundary drawn after the fact is the single most common cause of a schedule slipping, because every diagram, inventory and control statement keys off it
Access control (AC) Role and purpose checks enforced centrally on every route, not endpoint by endpoint Retrofitting authorization across an existing API is close to a rewrite
Identification and authentication (IA) Federated identity, phishing resistant multi factor for privileged access, and no shared accounts anywhere in the boundary Unpicking shared service accounts once operations depend on them takes longer than building the alternative
Audit and accountability (AU) Who did what, to which record, when, in an append only store, with retention set by policy rather than by disk cost You cannot reconstruct history you never recorded, and an assessor will ask for exactly the period you did not keep
Configuration management (CM) Infrastructure as code, version controlled, redeployed rather than modified in place, with drift detected automatically Hand configured environments cannot be evidenced, so every assessment becomes a manual screenshot exercise
System and communications protection (SC) Validated cryptographic modules, encryption in transit and at rest, keys managed outside the application, segmentation that matches the boundary diagram Swapping a cryptographic library late means re encrypting live data and a downtime window
System and information integrity (SI) Vulnerability scanning in the pipeline and in production, with remediation timeframes agreed in advance and tracked A backlog of findings discovered at assessment time is a schedule problem, not a security problem
Supply chain risk management (SR) A real inventory of dependencies and their provenance, generated by the build rather than maintained by hand A hand maintained inventory is wrong within a sprint, and wrong inventories fail assessments
Assessment and monitoring (CA) Control evidence produced by the system as a by product of running, in machine readable form where the program accepts it Evidence assembled by humans once a year is the most expensive line in a continuous monitoring budget

What Sthenos is, and what Sthenos is not

Stated plainly, because it is cheaper for both of us to know now.

As of September 2026, Sthenos holds no FedRAMP certification of any type or class, is not listed on the FedRAMP Marketplace, is not a FedRAMP recognized independent assessor, and is not a FedRAMP recognized advisor. We are also not SOC 2 attested, and we hold no HITRUST certification or ISO 27001 certificate. We hold no GSA Multiple Award Schedule contract and appear on no GSA vehicle.

None of that is an obstacle to the work described on this page, because none of those things is what a development contractor supplies. A FedRAMP certification attaches to an assessed cloud service offering and is held by the provider who operates it. An independent assessment has to be independent of the people who built the system, which means the firm that writes your code is disqualified from assessing it. What we supply is the engineering and the evidence trail. Your assessor and your authorizing official supply the judgment.

If your requirement asks for a vendor that already holds an attestation rather than a vendor who builds to a framework and hands over evidence, we are the wrong answer, and we will say so in the first conversation rather than consume your acquisition timeline finding out.

Who holds what

Role Who holds it Can Sthenos hold it?
FedRAMP Certification The cloud service provider whose service offering was assessed No. It attaches to an assessed service offering, not to a development contractor
Authority to operate The agency’s authorizing official No. It is an agency decision about an agency system
Independent assessment A FedRAMP recognized independent assessor, under 44 U.S.C. 3611 No, and not on a system we built, because the assessment has to be independent of the builder
Scope determination The federal agency, and only the agency No. We can walk the indicators with you; the determination is yours
The engineering, and the evidence it produces The build team Yes. This is the work

What moves the cost and the schedule

We publish our rates. They are $150 to $250 per hour depending on the seniority and mix of the team, and a typical project runs $50,000 to $200,000. On work with a federal compliance requirement, the variables below move the number more than the feature list does.

What moves it What it changes
Whether the system is in scope at all The largest single variable on this page. A single agency system outside FedRAMP scope has a materially different plan and budget
Certification Type and Class 20x and Rev5 produce different packages, and Classes A through D are progressive in preparation, automation, verification and cost
Where the authorization boundary falls It decides the inventory, the diagrams, the interconnections and how much of the control set you own rather than inherit
What you inherit from the platform Controls satisfied by an already certified underlying platform are controls you do not implement, but you still have to document the inheritance
Whether evidence is automated Continuous monitoring is an ongoing cost. Evidence generated by the system is cheap. Evidence assembled by people is not
Existing security maturity FedRAMP’s own guidance is that Class A suits products that already hold a SOC 2 Type II and run a mature program. Starting further back means the gap work comes first

What to ask any vendor who says they do FedRAMP work

  • Do you hold a FedRAMP certification yourself, and for which service offering? A development firm should say no. If it says yes, ask for the Marketplace listing and check it.
  • Is my system in scope? A vendor who answers yes without walking the M-24-15 exclusions and the four scope indicators is selling you something you may not need.
  • Which controls will you implement, and which will I still own? Personnel, physical and program management controls do not move to a build team. A vendor implying otherwise has not read the catalog.
  • Who assesses the result? It cannot be the team that built it.
  • What would make you decline this requirement? A vendor with no answer has not thought about where they are the wrong fit.

Frequently asked questions

Is Sthenos FedRAMP authorized or FedRAMP certified?

No. As of September 2026 Sthenos holds no FedRAMP certification and is not listed on the FedRAMP Marketplace. A FedRAMP certification attaches to a cloud service offering that has been assessed and is held by the provider who operates that service. A development partner builds software to meet FedRAMP requirements; the certification is pursued and held by the service owner.

Can a software development company be FedRAMP certified?

Only if it also operates a cloud service offering and takes that offering through the program. The certification covers the service, not the company’s ability to write software. A firm advertising itself as a FedRAMP certified developer is describing something the program does not issue.

Does my agency application need FedRAMP?

Often not. OMB Memorandum M-24-15 places outside the scope of FedRAMP any information system used only for a single agency’s operations that is hosted on cloud infrastructure or a platform, is not offered as a shared service, and does not operate with a shared responsibility model. Most bespoke agency applications fit that description. Only the agency can make the determination, and FedRAMP publishes four scope indicators to work through. The system will still be secured, assessed against NIST SP 800-53 and authorized by the agency; it just is not a FedRAMP matter.

What replaced the JAB and the provisional ATO?

The FedRAMP Authorization Act of December 2022 established the FedRAMP Board at 44 U.S.C. 3610, and OMB Memorandum M-24-15 of July 25, 2024 rescinded and replaced the previous program in its entirety. Under the Consolidated Rules for 2026 the two routes are Program Certification, provided directly by FedRAMP without an agency sponsor and mostly available for the 20x type, and Agency Certification, which requires an agency to authorize the service first and then sponsor it, and is only available for the Rev5 type.

What is the difference between FedRAMP 20x and Rev5?

They are the two Certification Types. Rev5 is the legacy type built on the NIST SP 800-53 Revision 5 baselines and assessed against the control catalog. FedRAMP 20x is the current type and expresses its expectations as 46 Key Security Indicators across 10 areas, each mapped back to related SP 800-53 controls. 20x runs on the Program Certification path; Rev5 generally runs on the Agency Certification path.

Which NIST controls does FedRAMP use?

NIST SP 800-53 Revision 5, currently at release 5.2.0. FedRAMP’s published reference covers 1,014 active controls and control enhancements across 20 families. NIST SP 800-53B supplies the control baselines that the Certification Classes loosely align to, and FIPS 199 and FIPS 200 are what an agency uses to categorize its own system.

Can Sthenos assess or audit our FedRAMP package?

No, and you should not want us to. Independent assessment under the FedRAMP Authorization Act has to be independent of the people who built the system. We are not a FedRAMP recognized independent assessor, and even if we were, we could not assess a system we wrote. We build it and we hand over the evidence; a recognized assessor examines it.

Who owns the code and the cloud accounts?

You do, entirely, from the first commit. The repository and the cloud accounts are in your name, with no license back to us and no dependency on our continuing to exist. On work that will be assessed, this matters more than usual: an authorization package describes a system you must be able to operate and evidence without us.

Do you work as a subcontractor to a prime?

Yes. Sthenos is an SBA certified Woman-Owned Small Business and Economically Disadvantaged Woman-Owned Small Business, both entered March 5, 2026. A prime’s subcontracting plan under FAR 19.704 must carry separate percentage goals for small business concerns and for women-owned small business concerns, and we sit in both of those goal lines. Our UEI is ULUZGKWYCJB7 and our CAGE code is 9RX92.

More about compliance driven builds

Talk to our engineers

If you have a requirement and want to know quickly whether we are a viable path, send it over. On this subject the first thing we will do is work the scope question with you, because the answer decides everything downstream and it is free to establish. If you already have a solicitation, send the solicitation number, the RFP or RFQ documents, any NDA you need in place, and the date responses are due, and we will check the NAICS code against our registration before we write anything.

We aim to reply within one business day. We schedule a call at your convenience, run a short bounded discovery scoped to the engagement, and give you a costed roadmap before committing to a build. Where the scope is clear we quote a fixed price for a defined outcome.

Contact Sthenos Technologies. 1775 Tysons Blvd 5th Floor, Suite, #04187, McLean, VA 22102, United States. Telephone +1 (301) 793-3980. Email info@sthenostechnologies.com.

Sources

Every standard named on this page, with the issuer and a link you can open. All were read on September 18, 2026.

Contact us
Talk to an engineer

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Rates and delivery
What happens next?
1

We schedule a call at your convenience

2

We run a short, bounded discovery, scoped per engagement

3

We give you a costed roadmap before committing to a build

Request a Free Consultation
Book a 30-minute call →Prefer to talk first? Skip the form and grab a time directly.

By submitting this form you agree to our privacy policy.

We aim to reply within one business day