* [Blog](https://www2.paloaltonetworks.com/blog) * [Cloud Security](https://www2.paloaltonetworks.com/blog/cloud-security/) * [Announcement](https://www2.paloaltonetworks.com/blog/category/announcement/) * Prisma Cloud Achieves Fed... # Prisma Cloud Achieves FedRAMP High Impact Level -- Ready Status [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fcloud-security%2Ffedramp-high-impact-ready%2F) [](https://twitter.com/share?text=Prisma+Cloud+Achieves+FedRAMP+High+Impact+Level+%E2%80%93+Ready+Status&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fcloud-security%2Ffedramp-high-impact-ready%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fcloud-security%2Ffedramp-high-impact-ready%2F&title=Prisma+Cloud+Achieves+FedRAMP+High+Impact+Level+%E2%80%93+Ready+Status&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www2.paloaltonetworks.com/blog/cloud-security/fedramp-high-impact-ready/&ts=markdown) \[\](mailto:?subject=Prisma Cloud Achieves FedRAMP High Impact Level – Ready Status) Link copied By [Cameron Hyde](https://www.paloaltonetworks.com/blog/author/cameron-hyde/?ts=markdown "Posts by Cameron Hyde") Mar 29, 2023 6 minutes [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown) [Cloud Native Application Platform](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-native-application-platform/?ts=markdown) [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [FedRAMP](https://www.paloaltonetworks.com/blog/tag/fedramp/?ts=markdown) *The FedRAMP Joint Advisory Board (JAB) has announced that Prisma Cloud has achieved FedRAMP High Impact Level Ready status.* Over the last few years, we've observed tremendous progress in cloud-native transformations across U.S. government agencies. As the demand for cloud computing accelerates, the cyber threat landscape becomes increasingly complex. In [2021](https://www.prnewswire.com/news-releases/palo-alto-networks-achieves-new-fedramp-authorization-including-prisma-cloud-cortex-xdr-and-cortex-data-lake-301214273.html), Prisma Cloud became the industry's first cloud-native application protection platform (CNAPP) to achieve Federal Risk and Authorization Management Program (FedRAMP) Moderate Authority to Operate (ATO). This achievement required Prisma Cloud to undergo rigorous auditing to prove it was fit to protect federal agencies. Today, we are proud to announce that Prisma Cloud has been accepted by the Joint Advisory Board (JAB) and reached Ready status for FedRAMP High. The JAB selects a limited number of cloud services offerings (CSOs) to sponsor each year, with each sponsorship acknowledging the CSO's ability to deliver best-of-breed, consolidated security for the most critical cloud deployments. ## The Need for Security Consolidation Cloud has become the dominant compute model for organizations, including U.S. Federal Government agencies. According to [The State of Cloud-Native Security 2023 Report](https://www.paloaltonetworks.com/state-of-cloud-native-security), respondents reported that 53% of their workloads are hosted in the cloud. In a second survey, Palo Alto Networks found that organizations rely on [30+ tools for overall security](https://start.paloaltonetworks.com/whats-next-in-cyber-report). Trying to secure rapidly changing cloud environments with myriad point tools creates complexity, elevated costs, and technical debt for security teams. Typical challenges faced by organizations working with siloed security tools include: * \*\*Blind spots:\*\*Understanding risk in the cloud requires an automated correlation of broad data points --- misconfigurations, excessive permissions, data risk, network exposure, vulnerabilities, and more. Point tools provide visibility into fragments of application risk and do not integrate for effective risk correlation. * \*\*Alert fatigue:\*\*While security teams may receive thousands of alerts daily, only a handful require urgent action. Without context, though, security teams aren't equipped to prioritize risks and must manually comb through each alert. * \*\*Overburdened staff:\*\*Because disparate tools don't talk to each other, security teams spend many cycles manually integrating products, which cuts into time needed to monitor threats. Given that these challenges oppose security outcomes, organizations are moving towards consolidation. According to Gartner, "By 2026, [80% of enterprises will have consolidated security tooling](https://start.paloaltonetworks.com/gartner-market-guide-cnapp) for the life cycle protection of cloud-native applications. ## U.S. Federal Government Agencies Are Taking Mission Critical Systems to the Cloud The ubiquity of cloud-based IT systems across the federal government puts a spotlight on how critical government data with the highest national impact is stored, accessed, and analyzed. In view of the outsized impact of a breach, law enforcement and emergency services systems, financial systems, and health systems require stringent controls. But government agencies face inefficiencies from independent capacity planning, as well as unused compute resources. Protecting cloud applications and elastic environments that aren't under their physical control presents agencies with new challenges --- and new challenges demand new security processes and tools to learn, integrate, and operate. In response to evolving threats and the imperative of national and economic security, the White House issued the Executive Order on Improving the Nation's Cybersecurity ([Executive Order 14028](https://www.cisa.gov/sites/default/files/publications/CISA%2520Cloud%2520Security%2520Technical%2520Reference%2520Architecture_Version%25201.pdf)) in May of 2021 to establish standardized policies for the prevention, detection, assessment, and remediation of cyber incidents. ## The Importance of FedRAMP By establishing a common security framework, FedRAMP has enabled the government to accelerate the adoption of cloud computing, as agencies no longer need to conduct individual technology audits and can rely on transparent standards and processes for security authorizations. ### Authorization Process Achieving FedRAMP authorization involves three milestones: Ready, In Process, and Authorized. Organizations can pursue a FedRAMP authorization through one of two approaches --- via the [JAB](https://www.fedramp.gov/jab-authorization/) or agency sponsorship. The JAB is the primary governing body for FedRAMP and includes representations from the Department of Defense (DoD), Department of Homeland Security (DHS), and General Services Administration (GSA). ![Figure 1: FedRAMP JAB authorization process (Source: FedRAMP)](https://www.paloaltonetworks.com/blog/wp-content/uploads/2023/03/word-image-182208-1.png) Figure 1: FedRAMP JAB authorization process (Source: FedRAMP) ### Levels of FedRAMP Authorizations FedRAMP security categories are determined by the potential impact that adverse events could have on an organization's ability to protect individuals, protect its assets, fulfill its legal obligations, and maintain its day-to-day functions. Based on this impact potential, FedRAMP authorizations are graded [low, moderate, and high](https://www.fedramp.gov/understanding-baselines-and-impact-levels/), These levels align with [NIST FIPS-199 Standards for Security Categorization of Federal Information and Information Systems](https://www.govinfo.gov/app/details/GOVPUB-C13-e0b9083be1f8208db0cfee04416ff16a), which provides the standards for categorizing information and information systems to ensure cloud service offerings (CSOs), or services, meet security requirements for the data processed, stored, and transmitted on public clouds. ## Actualizing the Shared Responsibility Model The [shared responsibility model](https://www.paloaltonetworks.com/blog/prisma-cloud/pitfalls-shared-responsibility-cloud-security/) specifies that cloud service providers share responsibility with their customers when it comes to securing workloads hosted on their clouds. CSPs, for example, don't have full control over everything users do on their clouds and can't force customers to configure IAM policies in a secure way or make sure that they patch their applications against the latest vulnerabilities. ![Figure 2: Shared responsibility model](https://www.paloaltonetworks.com/blog/wp-content/uploads/2023/03/word-image-182208-2.png) Figure 2: Shared responsibility model Likewise, organizations that use public clouds have limited control over their cloud infrastructure. They can't monitor for vulnerabilities in a CSP's servers or detect intrusions inside its network. Therefore, CSPs and their customers must share responsibility for security, with each party taking the lead in securing the resources it controls. With recent U.S. executive orders and the impetus compelling agencies to enhance cybersecurity and software supply chain integrity, it has become paramount that government agencies adopt cloud-native security tools to protect their environments. ## Prisma Cloud and FedRAMP Prisma Cloud secures applications from code to cloud across multicloud environments, delivering comprehensive security with continuous visibility and proactive threat prevention, enabling security and DevOps teams to effectively collaborate to accelerate secure cloud-native application development and deployment. ![Image 2: Prisma Cloud secures applications throughout the application lifecycle](https://www.paloaltonetworks.com/blog/wp-content/uploads/2023/03/word-image-182208-3.png) Image 2: Prisma Cloud secures applications throughout the application lifecycle As illustrated below, Palo Alto Networks is actively working on raising the FedRAMP impact level for Prisma Cloud services from Moderate to High. | **Prisma Cloud Capability** | | **Prisma Cloud Capability** | Moderate Impact Level: Authorized | High Impact Level: Ready | | [Cloud Security Posture Management](https://www.paloaltonetworks.com/prisma/cloud/cloud-security-posture-management) | ✔ | ✔ | | [Cloud Infrastructure Entitlement Management](https://www.paloaltonetworks.com/prisma/cloud/cloud-infrastructure-entitlement-mgmt) | ✔ | ✔ | | [Cloud Workload Protection](https://www.paloaltonetworks.com/prisma/cloud/cloud-workload-protection-platform) | | ✔ | | [Web Application \& API Security](https://www.paloaltonetworks.com/prisma/cloud/web-application-API-security) | | ✔ | | [Code Security](https://www.paloaltonetworks.com/prisma/cloud/cloud-code-security) | | ✔ | | [Cloud Network Security](https://www.paloaltonetworks.com/prisma/cloud/cloud-network-security) | | ✔ | |------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------|--------------------------| *Table 1: Current FedRAMP status by capability* These CNAPP capabilities provide the public sector with the security foundations and workforce enablement, as outlined in the [Federal CIOs Council's Federal Cloud Computing Cloud Smart strategy](https://cloud.cio.gov/strategy/). The Cloud Smart strategy encourages agencies to take a risk-based approach to securing cloud environments. Agencies should ensure protections at the data layer --- in addition to the network and physical infrastructure layers --- transitioning to a multilayer defense strategy, otherwise known as defense-in-depth. Prisma Cloud's ability to secure applications from code to cloud, coupled with the assurance of FedRAMP, helps agencies apply security practices through the entire application lifecycle. By providing multicloud visibility and control through a common platform for your many stakeholders, Prisma Cloud fosters the enablement of your workforce's capabilities. ## Learn More Palo Alto Networks looks forward to helping U.S. Government agencies secure their application from code to cloud. If you'd like to learn more, read the [Prisma Cloud for Federal Datasheet](https://www.paloaltonetworks.com/resources/datasheets/prisma-cloud-for-federal). *** ** * ** *** ## Related Blogs ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cloud Native Application Platform](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-native-application-platform/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security/?ts=markdown), [Company \& Culture](https://www.paloaltonetworks.com/blog/category/company-culture/?ts=markdown), [Points of View](https://www.paloaltonetworks.com/blog/category/points-of-view/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Prisma Cloud Is a CNAPP Leader According to Frost \& Sullivan](https://www2.paloaltonetworks.com/blog/2022/11/prisma-cloud-is-a-cnapp-leader/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### The Power of Glean and Prisma AIRS Integration](https://www2.paloaltonetworks.com/blog/2026/02/power-of-glean-and-prisma-airs-integration/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### New Year, New Program, New Opportunities](https://www2.paloaltonetworks.com/blog/2026/02/new-year-new-program-new-opportunities/) ### [AI Application Security](https://www.paloaltonetworks.com/blog/network-security/category/ai-application-security/?ts=markdown), [AI Governance](https://www.paloaltonetworks.com/blog/category/ai-governance/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Firewall](https://www.paloaltonetworks.com/blog/category/firewall/?ts=markdown), [Next-Generation Firewalls](https://www.paloaltonetworks.com/blog/network-security/category/next-generation-firewalls/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Palo Alto Networks Announces Support for NVIDIA Enterprise AI Factory](https://www2.paloaltonetworks.com/blog/2026/01/support-nvidia-enterprise-ai-factory/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cloud Network Security](https://www.paloaltonetworks.com/blog/category/cloud-network-security/?ts=markdown), [Cloud NGFW](https://www.paloaltonetworks.com/blog/network-security/category/cloud-ngfw/?ts=markdown), [Guest Post](https://www.paloaltonetworks.com/blog/category/guest-post/?ts=markdown), [Hybrid Cloud Data Center](https://www.paloaltonetworks.com/blog/network-security/category/hybrid-cloud-data-center/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Untangling Hybrid Cloud Security](https://www2.paloaltonetworks.com/blog/2025/12/untangling-hybrid-cloud-security/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Achieve True Zero Trust and Peak Performance with Prisma Access 6.1](https://www2.paloaltonetworks.com/blog/sase/achieve-true-zero-trust-and-peak-performance-with-prisma-access-6-1/) ### Subscribe to Cloud Security Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www2.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language