FedRAMP
Readiness
FedRAMP is the highest-effort authorisation in commercial software, and the one that opens US federal agencies as customers. We run FedRAMP readiness - boundary, System Security Plan, control implementation and continuous monitoring - so that when a 3PAO assesses you, the programme is real.
Who this is for
Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.
Cloud service providers with a federal agency willing to sponsor an authorisation
SaaS companies whose federal pipeline is blocked without an ATO
Teams who have read the Moderate baseline and need help turning 300-plus controls into a plan
Providers preparing for a Readiness Assessment Report before committing to the full process
What the engagement does
Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.
- Define the authorisation boundary, including every external service and interconnection, which is where FedRAMP scope is won or lost
- Build the System Security Plan against the NIST SP 800-53 baseline that applies
- Assess control implementation and record the real position, control by control
- Establish the continuous monitoring machinery - monthly scanning, POA&M management, inventory - before it is an obligation
- Prepare the evidence a 3PAO will sample
- Support the assessment and the agency or programme review that follows
What you walk away with
A defensible boundary, an SSP that describes the system as built, a POA&M that reflects genuine remediation, and continuous monitoring that runs monthly rather than being invented at assessment time. FedRAMP punishes optimism harder than any other framework, and readiness is where that gets corrected cheaply.
How it runs
Four phases. You always know which one you are in and what is outstanding.
Scoping call
We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.
Assessment
We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.
Remediate and evidence
We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.
Hand off to your assessor
You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.
What the assessment covers
The control areas we walk for FedRAMP. Each breaks down into individual controls carrying status, owner and evidence in Talon.
FedRAMP assessments are performed by an accredited 3PAO, and authorisation is granted by a sponsoring agency or the programme itself. We prepare you and work alongside your 3PAO; we do not assess or authorise.
It runs in Talon, not in a spreadsheet
Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.
- Control-by-control status, kept current by the people doing the work
- Evidence filed against the control it satisfies, with expiry dates tracked
- The auditor request list, so nothing is chased over email
- A readiness view that shows what an assessor would see
Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.
Our partnersAsked on almost every FedRAMP call
For an agency ATO, yes - and it is the practical gating item for most providers. Readiness work is still worth starting before sponsorship, because the boundary and SSP take longer than anything else and are prerequisites either way.
Determined by the impact level of the data the system handles. Moderate covers the large majority of SaaS. The jump from Moderate to High is substantial in both control count and operational burden.
A 3PAO-produced attestation that you are likely to achieve authorisation, used to demonstrate seriousness before the full assessment. Getting to RAR-ready is a sensible first milestone.
Yes, for cryptography protecting federal information, and it is a common late discovery. Modules must be validated and used in an approved mode - "we use AES" is not the same claim.
Rarely run alone
Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.
FedRAMP readiness, on your timeline
A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.