PoliticalRepoPoliticalRepo

United States · Bill · HR

H.R. 21 (117th)

FedRAMP Authorization Act

referredUnited States· United States Congress· EN

Introduced

4 January 2021

Last action

Status

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

Sponsors

Subjects

Discovery layer

Source updated

28 May 2025

Summary

Federal Risk and Authorization Management Program Authorization Act of 2021 or the FedRAMP Authorization Act This bill provides statutory authority for the Federal Risk and Authorization Management Program (FedRAMP) within the General Services Administration (GSA). The GSA must establish a government-wide program that provides the authoritative standardized approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies. Agencies must ensure that their cloud computing services meet GSA requirements. The bill establishes the Joint Authorization Board to conduct security assessments of cloud computing services and issue provisional authorizations to operate to cloud service providers that meet FedRAMP security guidelines. The GSA shall (1) publish a report that includes an assessment of the cost incurred by agencies and cloud service providers related to the issuance of FedRAMP authorizations and provisional authorizations, (2) determine the requirements for certification of independent assessment organizations, and (3) establish the Federal Secure Cloud Advisory Committee.

This text is taken from the official record. PoliticalRepo does not editorialize.

Timeline

No timeline events have been ingested for this record yet.

Votes

No vote records are attached yet.

Versions

No version snapshots stored. Document URLs remain at the source.

Documents

8 official files

Referred in Senate (text)

View fileDownload file

Sponsors

No sponsors or actors listed by the source.

Related records

No cross-record relationships stored yet.

Sources

PoliticalRepo is an index and interpretation layer, not the authoritative legal source.