r/FedRAMP

With moderator permission: r/FederalCyber for broader federal cybersecurity practice

Hi everyone. With the moderator team's permission, I wanted to introduce r/FederalCyber, an independent and unofficial community for public-source discussion spanning FedRAMP implementation, RMF and NIST controls, government cloud, ATO evidence, continuous monitoring, zero trust, incident response, and workforce questions.

r/FedRAMP remains the place for FedRAMP-specific discussion. The new community is intended for cross-cutting questions that sit between authorization, engineering, operations, and mission risk. The opening threads focus on evidence that controls actually work, inherited-responsibility gaps, vulnerability prioritization under VDR and VER, and how to share lessons without exposing protected operational details.

The boundaries are strict: no CUI, credentials, customer or agency identifiers, internal architecture, active incident data, nonpublic vulnerabilities, or implied government endorsement. Vendor link drops and low-effort promotion are not welcome.

If that broader scope fits your work, I would value your experience and criticism: https://www.reddit.com/r/FederalCyber/

reddit.com

What FedRAMP vulnerability management tools are actually working for teams?

One thing that seems to get messy fast is vulnerability prioritization. Finding vulnerabilities is easy enough. The problem is figuring out which ones actually need attention first.

Scanners can throw thousands of CVEs at you across containers and dependencies. Then you add FedRAMP requirements and the whole prioritization process gets a lot harder.

How are teams handling vulnerability management for FedRAMP systems today? Are traditional vulnerability management tools enough or are you using runtime context and attack surface reduction too?

Would be interested in hearing what is actually working instead of just generating bigger vulnerability reports.

reddit.com
u/JakeNorthwood1 — 8 days ago

Do my reservation system need FedRAMP ATO if it wasn't in RFP

Hi, my company is pursuing an solicitation that requires a end user facing accommodation reservation system. The RFP did not state any FedRAMP requirement but the Q&A mentions that the system must be in a "FedRAMP authorized environment". I'm trying to better understand if that means it just needs to run on FedRAMP certified infrastructure (AWS) or if it means we need an agency ATO?

reddit.com
u/Logical-Leek-882 — 9 days ago

When a seller says they’re listed on a government marketplace, what do you think it means? Does it mean their product is officially authorized, or can sellers be listed there for other reasons?

I’m looking to see how people interpret this now with the changes that will be in place in 2026.

I've noticed that ‘listed on the FedRAMP Marketplace’ seems to be used almost like a credential itself. Though a listing on the marketplace can actually mean so many things. Like initial implementation, ready, in Process, certified etc. And for 20x specifically, initial implementation ,arketplace listing is before the vendor provides certification.

So if a vendor says ‘We’re listed on the FedRamp marketplace’ without explaining it any further, do you think of that as something more indicative other than just having a listing? In my case I d need to know what kind of service and what status it is in before taking that as a guarantee. Maybe people that deal with this on a daily basis would understand how this could be misleading to a customer or someone involved in procurement - they could take “FedRAMP Marketplace” for “FedRAMP Certified”.

reddit.com
u/omytolawschool — 13 days ago