Infrastructure
Do you have FedRAMP or StateRAMP authorization?
How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.Expert answer
State your FedRAMP or StateRAMP status if applicable, including the impact level and authorization stage, or note that you align to the underlying NIST 800-53 controls. Be accurate, since these authorizations are independently verified.What the security reviewer is checking
This is a factual gate, and the reviewer can verify your claim in minutes on the FedRAMP Marketplace, so accuracy is non-negotiable. If you are not authorized, the reviewer is usually determining two things: whether the deal is viable at all (some public-sector buyers have flexibility, many do not), and whether your posture is close enough that sponsorship or a roadmap conversation makes sense. A useful answer distinguishes your own authorization status from your infrastructure provider’s (running on AWS GovCloud or another FedRAMP-authorized platform is inherited infrastructure, not your authorization), and points to compensating attestations like SOC 2 Type II mapped against NIST SP 800-53.Example response you can adapt
This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.We do not currently hold FedRAMP or StateRAMP authorization, and we state that plainly to avoid any ambiguity. Our platform runs entirely on cloud infrastructure that is itself FedRAMP High authorized, so physical, environmental, and foundational infrastructure controls are inherited from the provider, but this does not constitute authorization of our service. Our security program is independently audited under SOC 2 Type II, and our control set is aligned with NIST Cybersecurity Framework practices, with a mapping against NIST SP 800-53 moderate-baseline control families available for review. For public-sector prospects we can share this mapping, our shared-responsibility matrix, and our full audit reports under NDA. We evaluate FedRAMP authorization on our roadmap based on demand; if your procurement path requires authorization or an agency sponsor conversation, we are glad to discuss timeline and options directly.
Evidence reviewers expect you to attach
- SOC 2 Type II report (shareable under NDA)
- Cloud provider FedRAMP authorization reference for inherited infrastructure controls
- NIST SP 800-53 or NIST CSF control mapping, if maintained
- Shared responsibility matrix distinguishing provider, platform, and customer controls
Follow-up questions reviewers ask next
- Is FedRAMP authorization on your roadmap, and what is the expected timeline?
- Would you pursue authorization with an agency sponsor if we provided one?
- Can you deploy into a government cloud region (e.g., GovCloud) today?
- Which 800-53 control families would fail a gap assessment today?
- Do you support US-only data residency and US-persons support access?
Answer every security questionnaire in minutes
Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demoRelated infrastructure questions
Where is your infrastructure hosted (AWS, GCP, Azure)?Do you use a web application firewall (WAF)?How do you protect against DDoS attacks?Do you have logging and monitoring in place?How do you secure your CI/CD pipeline?What vulnerability scanning do you perform?
Browse the full security questionnaire question library