FedRAMP (the Federal Risk and Authorization Management Program, fedramp.gov) works on a boundary. Under the long-standing Rev5 process, a provider draws an authorization boundary around its service, implements the control baseline from NIST SP 800-53 for its impact level (Low, Moderate or High), and is assessed by a FedRAMP-recognized third-party assessor before it is authorized. The newer FedRAMP 20x path validates Key Security Indicators, largely with automated, machine-readable evidence, instead of a control-by-control audit. It now offers Class B (Low) and Class C (Moderate) certifications, with a High class still to be piloted, and FedRAMP plans to stop accepting new Rev5 certifications. FedRAMP now calls both outcomes certification. The FedRAMP Marketplace lists each offering’s status.

LangChain’s Deployed Engineer (Federal) posting, as of September 2026, asks for architectures that meet federal security and compliance requirements, naming FedRAMP, DoD IL2–IL6 and NIST. Source 1Deployed Engineer (Federal) @ LangChainPublisherLangChain (Ashby job board)Source typecompany job posting In a design round with a government customer, the boundary constrains every choice: a hosted model API, a SaaS vector store or a telemetry vendor you add must itself be authorized at a matching impact level, or the customer’s data cannot reach it. Check the Marketplace listing for the exact offering and region: a vendor’s commercial API and its government-region deployment are authorized separately, so the model endpoint you prototyped against may not be the one you can ship. The DoD impact levels come from the DoD Cloud Computing Security Requirements Guide: IL2 accepts a FedRAMP Moderate authorization, IL4 and IL5 add DoD controls on top of a FedRAMP baseline, and IL6 covers classified data. The customer may also require that only US persons hold privileged access, which decides who on your team can debug production or be on call.

Ask which services already sit inside the customer’s authorization, design around those, and say which controls your design supports. Never say the system “is FedRAMP compliant”; only the certification process can establish that. A planned design prompt, the authorized government boundary, will be the practice.