Cloudflare expands government compliance footprint

Cloudflare has announced plans to pursue FedRAMP High authorization in the US, IRAP PROTECTED assessment in Australia, and Spain’s Esquema Nacional de Seguridad (ENS) certification. These efforts extend the company’s existing Cloudflare for Government offering, which has operated under FedRAMP Moderate since 2022.

The company’s stated goal is to bring its full product portfolio into scope for government and regulated-industry customers. Rather than maintaining a separate compliance boundary for public sector traffic, Cloudflare has integrated government controls into its existing platform across three areas: traffic processing, management, and metadata storage.

This approach lets Cloudflare apply its global network—spanning more than 330 cities and interconnecting with roughly 13,000 network providers—to public sector workloads. Regional Services can handle global Layer 3 DDoS mitigation while decrypting traffic only inside certified boundaries, and the private backbone moves traffic from ingestion points to the nearest authorized processing location. The result, according to Cloudflare, is that customers can meet strict compliance requirements without sacrificing performance or user experience.

Expanding the FedRAMP Moderate catalog

Since receiving FedRAMP Moderate authorization in 2022, Cloudflare has widened the scope of accredited products. Additions to the program include:

  • API ShieldAPI security and abuse detection with data-driven analysis.
  • R2 — object storage for unstructured data without egress bandwidth fees.
  • Cache Reserve — a persistent data store built on top of R2.
  • Cloud Access Security Broker (CASB) — a Zero Trust component that scans SaaS applications for data leaks, misconfigurations, shadow IT, and risky sharing.

Two more products are slated to enter FedRAMP Moderate scope in 2025:

  • Hyperdrive — accelerates queries against existing databases regardless of user location.
  • Cloudflare Images — a cloud-native image pipeline for ingestion, storage, optimization, and delivery.

Cloudflare states that future compliance work will focus on bringing all generally available products into the most regulated environments. Products on the roadmap include Email Security, Cloudflare Calls, and Access for Infrastructure.

Boundary expansion and international reach

The Cloudflare for Government boundary currently operates from more than 30 data centers across 10 US cities. In 2025, the company plans to add eight international data centers and four new US data centers to the boundary. The expansion is intended to reduce latency for public sector customers outside the US while maintaining compliance with regional requirements.

unnamed (1)

Post-quantum progress and regional certifications

Cloudflare’s collaboration with NIST on post-quantum cryptography (PQC) has contributed to the rollout of ML-KEM, and the company reports that more than one-third of its eyeball traffic is now secured with PQC. This work, which brought PQC to FIPS in early 2023, reflects a broader commitment to research and to aligning with standards set by government partners.

On the certification front, Cloudflare has completed authorization for Spain’s ENS and is currently being assessed against IRAP PROTECTED for the Australian government. These country-specific certifications complement existing international accreditations including PCI, SOC2, and ISO 27001.

BLOG-2257 image 1

Cloudflare positions FedRAMP Moderate as an early milestone rather than an endpoint. The company’s stated direction is to continue expanding government compliance across multiple regimes and to make its platform available to public sector customers regardless of the complexity of their security requirements.