A SOC 2 report can be a launching pad for FedRAMP certification
- Organizations with a qualifying SOC 2 Type II report can now use it as a foundation for FedRAMP Class A certification.
- Class A lets companies test federal demand before making larger FedRAMP investments.
- Healthtech and SaaS providers can unlock significant federal opportunities, such as the VA, HHS, CMS and the Defense Health Agency.
Healthtech companies, SaaS organizations and other technology businesses that hold a current SOC 2 Type II report have a potential new market to tap into. Revisions to FedRAMP have created an easier path for selling cloud service offerings (CSOs) to federal agencies.
Continue reading to learn more about the FedRAMP program and the new, lower-resistance road to certification available to companies with a SOC 2 report.
What is FedRAMP?
The Federal Risk and Authorization Management Program is the federal government’s standardized approach for assessing, authorizing and monitoring cloud service offerings used by federal agencies. Cloud service providers (CSPs), including SaaS companies with cloud-based software, that want to sell their products and services to federal agencies via the FedRAMP marketplace need some level of FedRAMP certification (formerly known as authorization) before their CSO can be listed.
FedRAMP uses the NIST SP 800-53 security controls and includes parameters and guidance that go above the NIST baseline to address the unique elements of cloud computing.
How is FedRAMP changing?
To streamline certification, increase automation and reduce compliance friction, FedRAMP is transitioning from the legacy Rev. 5 model to FedRAMP 20x. As part of the transition, FedRAMP is also shifting away from the low, moderate and high impact-level terminology and moving to a class-based certification structure.
The certification classes are:
- Class A is a new entry-level certification designed to help eligible providers enter the FedRAMP marketplace.
- Class B generally aligns with lower-risk use cases and limited or departmental adoption.
- Class C is intended for broader agency use cases, including more sensitive or mission-critical workloads.
- Class D is expected to support the highest-risk or most sensitive use cases.
A SOC 2 report can serve as a foundation for FedRAMP Class A
FedRAMP 20x allows companies to use a qualifying SOC 2 Type II report as proof of the security maturity needed for Class A certification. Class A does not have the agency sponsorship requirement. In the past, many SaaS providers and healthtech organizations struggled to find an agency willing to sponsor them, creating a major roadblock to getting their products listed on the marketplace. The SOC 2 option creates an easier path to certification.
Businesses need to understand that Class A certification is not a permanent solution. It gives your business a two-year window to begin assessing your security framework against Class B, C or D standards. Class A is only authorized for low-risk deployments.
The value of FedRAMP Class A certification
Think of FedRAMP Class A as a way to test the federal market before making the full investment required for higher FedRAMP certification levels. If you are unsure whether there is federal demand for your products, Class A offers a chance to assess interest levels. It will also give your business time to determine which product or security improvements may be needed to support federal agency needs.
Easing into FedRAMP via Class A certification will allow your business to:
- Test demand for your cloud offering within the federal market.
- Increase visibility by appearing in the FedRAMP marketplace.
- Validate how well your CSOs fit the federal market before making larger compliance investments.
- Build a roadmap toward higher certification levels based on actual customer interest.
What federal opportunities exist for healthtech companies?
For healthtech companies, being able to sell their CSOs to federal agencies opens the potential to land significant contracts.
A notable example is the Department of Veterans Affairs (VA). Selling patient monitoring tools, telehealth platforms, medical imaging archiving systems or other cloud-based products to the largest integrated healthcare system in the U.S. could be very lucrative. But handling VA data requires FedRAMP certification. Instead of delaying market entry to pursue a more rigorous FedRAMP certification, your organization can use Class A to begin engaging the federal marketplace faster. Use your two-year window to prepare for a Class B, C or D certification.
Other federal agencies that are potential customers for FedRAMP-certified healthtech companies include HHS and CMS
What are the SOC 2 requirements to secure FedRAMP Class A?
A SOC 2 Type II report can support the Class A path, but you will still need to meet other FedRAMP-specific requirements. A provider cannot simply submit any SOC 2 report and assume it will be accepted.
To use SOC 2 for Class A, companies should be prepared to provide:
- A complete SOC 2 Type II report that was completed in the last 12 months
- Any bridge or gap letters
- Verified audit engagement documentation
- An estimated schedule for the next SOC 2 report
- Supplemental compliance evidence (if applicable)
Your SOC 2 scope does need to include cloud security.
There are other FedRAMP Class A requirements, including relevant Key Security Indicators, which address areas such as vulnerability detection, incident communication, network traffic restrictions, service configuration and more.
What are the steps to getting FedRAMP Class A certification?
The path to Class A is relatively short compared to higher FedRAMP certification classes. However, it still requires planning, evidence collection and implementation of FedRAMP-specific requirements.
Companies should consider the following steps:
- Confirm eligibility: Verify that your organization holds a current SOC 2 Type II report.
- Validate the scope of your SOC 2 report: Make sure the SOC 2 report covers the cloud service offering you want to submit for FedRAMP Class A. If the scope is too narrow, outdated or misaligned with the product being submitted, you may need to remediate gaps or complete additional assessment work.
- Assemble your evidence package: Gather the complete SOC 2 Type II report, any bridge or gap letters, verified audit engagement documentation, the estimated schedule for your next SOC 2 report and any supplemental evidence that helps show how your controls align with FedRAMP expectations.
- Implement the required FedRAMP controls: Implement the necessary policies, procedures and controls to meet the mandatory FedRAMP 20x rules and key security indicators required for Class A.
- Prepare machine-readable certification materials: FedRAMP 20x emphasizes more structured, machine-readable evidence. Companies should expect to modernize how they manage compliance documentation and move away from manual, screenshot-heavy evidence models.
- Submit through program certification: Apply through the FedRAMP program certification path.
How can businesses move to a higher FedRAMP certification?
If your business decides FedRAMP certification is a long-term strategy, it will need to advance to one of the more rigorous certification levels.
Here are some steps your business can take to prepare for Class B, C or D certification:
- Adopt a broader control baseline: Higher classes require more rigorous security controls and more extensive evidence. The organization will need to mature its control environment beyond what was necessary for Class A.
- Prepare for more detailed assessment expectations: Companies moving to Class B, C or D should be ready for a more comprehensive review of their cloud security controls.
- Strengthen automation and evidence collection: FedRAMP 20x places more emphasis on machine-readable evidence and automation. Providers may need to modernize their governance, risk and compliance processes so evidence is continuously available and easier to validate.
- Build ongoing certification processes: FedRAMP required companies to demonstrate that controls continue to operate effectively over time, not just at a single point in time during an assessment.
- Align the certification level to the target market: Class B may be appropriate for more limited or departmental use cases, while Class C and D may be needed for broader, more sensitive or mission-critical federal deployments. Companies should align their target class to the agencies and use cases they want to pursue.
- Plan early: The two-year Class A window can move quickly. Providers should use the time to validate federal demand, prioritize gaps and develop a realistic roadmap for reaching the next certification class.
CSPs that pursue Class B or C have a choice between the agency sponsorship route or the new program certification route without a sponsor. All Class D certifications require a sponsor.
How Wipfli can help
At Wipfli, we have a team of knowledgeable SOC 2 and FedRAMP professionals. We can help you assess how well your SOC 2 scope aligns with FedRAMP requirements and guide you through the process of securing Class A certification. As you move through your FedRAMP journey, we can also help with compliance with the higher-level certifications. Start a conversation.
Get started with FedRAMP certification