Azure FedRAMP compliance

Steven Netsch 1 Reputation point
2021-10-01T18:02:48.893+00:00

My company recently became a federal government contractor and all of our systems are deployed on Azure. Government agencies are asking about our FedRAMP compliance. I've seen that Azure commercial has FedRAMP high compliance available and Azure Government does as well.

For our Azure deployed apps, are we automatically FedRAMP compliant? If not, do we need to be on Azure Government? Is the pricing the same on Azure Government? Any help would be appreciated. -Steven

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,192 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,231 Reputation points Microsoft Employee
    2021-10-05T04:57:02.363+00:00

    @Steven Netsch Thanks for reaching out.

    Azure commercial and Azure Govt, both are FedRAMP compliant and you do not have to on Azure Govt Cloud for this.
    Check more about each service status within Azure Commercial/Public which is FedRAMP compliant :

    https://learn.microsoft.com/en-us/azure/azure-government/compliance/azure-services-in-fedramp-auditscope#azure-public-services-by-audit-scope

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.