Serving the most critical missions: Cloudflare for Government achieves FedRAMP Class D (High) Certified status

Wesley Evans, Tom Lianza, and Jake Schaeufele

5 minute read

BLOG-2966 hero image

We believe the Internet must be a force for good, and that it requires a foundation of trust. Nowhere is that trust more critical than in public service. Government agencies are the stewards of a nation’s most sensitive data. They protect national security, critical infrastructure, and the personal information of every citizen. 

Cloudflare’s mission is to help build a better Internet. A key part of that mission is giving public sector agencies the best technology to stay secure, fast, and reliable. That means meeting the highest possible standards.

Today, we are proud to announce a major milestone: Cloudflare for Government has achieved FedRAMP Class D (High) certification status. We are honored to take this step with our sponsoring agency, the National Institute of Standards and Technology, whose global mission demands the highest level of security.

We are also very excited to announce that we are using the new systems we developed for FedRAMP High as the foundation of our commitment to pursuing U.S. Department of Defense Impact Level 4 (DoD IL4) authorization. IL4 is the department’s cybersecurity standard for systems handling controlled, unclassified data. We are confident that bringing our global network to this space will change the pace of innovation in the defense community.

What is FedRAMP, and why does being “certified” matter?

The Federal Risk and Authorization Management Program (FedRAMP) is a U.S. government-wide program that provides a rigorous, standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

Think of FedRAMP as the gold standard for security in the U.S. government. Achieving "certified" status is a formal milestone. It means a federal agency has vetted our capabilities, sponsored our full authorization, and had that authorization verified by the FedRAMP Program Management Office. 

We achieved FedRAMP Moderate authorization in 2022, but moving from Moderate to High is not an incremental step. It is a substantial increase in both complexity of the requirements we have to meet and the impact of what would happen if we were to have a breach of those controls. For instance:

  • FedRAMP Class C (Moderate) is for systems where a compromise could have a serious adverse effect. Think of offerings like the National Park Service’s admission system.
  • FedRAMP Class D (High) is for the nation's most sensitive unclassified data. This is data related to law enforcement, emergency services, financial systems, and national security. A compromise here could be catastrophic, potentially leading to a loss of life or threatening the economic or national security of the country.

One unified platform running on one global network

For years, the standard approach for technology companies serving the public sector and the defense community was to build a separate, isolated, and often pared-down version of their commercial platform. The intention was good, but the result was often technology islands: isolated environments that frequently lagged years behind the pace of innovation. Federal agencies and contractors have been forced to choose between modern features and stringent compliance.

We made a fundamentally different architectural decision on day one. Cloudflare operates a single, global network, with the same software stack running in every one of our data centers worldwide. We have built our FedRAMP High offering on those same machines, running the same services, using software-defined regionality. Instead of an isolated environment, Cloudflare for Government - FedRAMP High is built with the same network that powers Cloudflare today. Achieving FedRAMP High certification is a powerful validation of that core principle.

So how do we meet the stringent data residency and handling requirements for FedRAMP High on a global network? The key is our Data Localization Suite. It allows us to apply precise, software-defined controls to how and where data is processed and stored. For our FedRAMP High services, we can ensure that all traffic inspection and processing occurs exclusively within our U.S. data centers.

Federal agencies don't have to settle for a watered-down version of our platform. Within the United States, they get the exact same cutting-edge technologies as our most innovative enterprise customers. Federal agencies will get our latest Zero Trust security tools, our industry-leading application performance, and our newest developer product features when they are released. 

When we began the FedRAMP process, we designed our systems with FedRAMP High and DoD IL4 controls in mind. We are excited that the same systems that power our global network and FedRAMP High will be the backbone of our DoD IL4 offering. For the defense community, this means that the pace of innovation in response to modern threats is no longer constrained by the pace of release-isolated government clouds.

The future of public sector modernization

Our investment in FedRAMP High isn't just about achieving a compliance certification. It’s about helping to build a better Internet that includes the most critical applications on the planet. Now that we have achieved FedRAMP High authorization, we hope to help federal agencies move to a modern Zero Trust security architecture, protect their infrastructure from the most sophisticated DDoS attacks, and deliver faster, more resilient digital services.

Cloudflare is proud to work with agencies across the U.S. government, including the Department of State and the Department of Commerce, among many others. This milestone deepens that commitment.

To learn more about what this means for the public sector, please visit our Cloudflare for Government page.