Cloudflare for Government earns FedRAMP Moderate Authorization

Cloudflare has announced that its public sector offering, Cloudflare for Government, has achieved FedRAMP Moderate Authorization from the US Federal Risk and Authorization Management Program. The designation confirms that the suite of services meets the standardized security assessment, authorization, and continuous monitoring requirements for cloud products used by federal agencies.

Built on the same global network

Rather than standing up a separate, isolated platform for government customers, Cloudflare for Government runs on the company's existing global network. That means agencies get the same performance and security capabilities as commercial customers, without hardware deployments, software installations, or code changes.

A notable differentiator is the footprint of the FedRAMP-authorized environment. Cloudflare for Government includes more than 30 US-based data centers, each capable of running the full stack of authorized services locally and managed through a single control plane on Cloudflare's private backbone. By comparison, other FedRAMP providers often operate with only a handful of data centers in scope. Because security and networking functions are most effective when executed close to the end user, this distributed architecture aims to avoid the performance penalties that can come with routing traffic to a small number of regional hubs.

Services in scope

Cloudflare for Government is a suite of application, zero trust, network, and developer services delivered from Cloudflare's network infrastructure. Key services include:

Application services

  • Web Application Firewall with API protection for securing web applications and APIs.
  • Rate Limiting to mitigate denial of service attacks, brute force logins, and application-layer abuse.
  • Load Balancing to route traffic away from unhealthy origins and toward available server pools.
  • Bot Management for real-time identification of legitimate and malicious bots, helping prevent credential stuffing, content scraping, spam, and application DDoS.
  • CDN for static and dynamic content delivery with configurable caching, reduced bandwidth costs, and built-in unmetered DDoS protection.
  • Enterprise DNS with low latency, redundancy, DDoS mitigation, and DNSSEC support.

Zero trust

  • Zero Trust Network Access to enforce access policies per request based on identity, context, and policy adherence.
  • Remote Browser Isolation to execute browser code in the cloud rather than on the endpoint.
  • Secure Web Gateway to inspect user traffic, filter malicious content, and detect compromised devices.

Network services

  • WAN-as-a-Service to replace legacy WAN architectures with cloud-based connectivity, security, and control.
  • L3/4 DDoS protection for websites, applications, and networks.
  • Network Interconnect for direct connections between on-premise or cloud environments and Cloudflare for Government.

Developer platform

  • Workers, a serverless execution environment for building or extending applications without managing infrastructure.
  • Workers KV, a global, low-latency key-value store designed for high read volumes.
  • Durable Objects, providing globally unique coordination and transactional storage for the Workers platform.

Next steps and broader public sector efforts

The FedRAMP Moderate authorization is positioned as an initial milestone rather than an endpoint. Cloudflare has also been applying its Zero Trust products outside the US through Project Safekeeping, which protects critical infrastructure in Japan, Australia, Germany, Portugal, and the UK, and through free Zero Trust support for organizations covered under Project Galileo and Project Athenian. The company intends to expand the Cloudflare for Government suite to support government entities worldwide.

For agencies, the goal is to strengthen cybersecurity without degrading the experience of digital government services. Details on the authorization are available through the FedRAMP Marketplace.