Cloudflare has achieved FedRAMP High authorization, enabling U.S. government entities to utilize its security, performance, and developer services for highly sensitive data. This rigorous certification allows Cloudflare to process High Impact information tied to national security and critical infrastructure within authorized U.S. boundaries.
Alongside this, Cloudflare announced GovRAMP Moderate authorization and intends to pursue Department of Defense Impact Level 4 (IL4) authorization. David Mihalchik, VP of U.S. Public Sector at Cloudflare, stated that FedRAMP High, GovRAMP Moderate, and the pursuit of DoD IL4 will allow the company to bring a platform to federal, state, local, and defense teams to advance their missions, retire legacy technologies, and accelerate their shifts to a more secure, efficient, and innovative future.
Cloudflare has secured FedRAMP High authorization, a certification that allows the company to process High Impact data, information crucial to national security, critical infrastructure, and financial systems, within a U.S. boundary spanning 15 metro areas. This rigorous certification signifies Cloudflare’s ability to safeguard highly sensitive government data where a breach could have severe or catastrophic consequences, and positions the company to serve a growing demand for modernized security infrastructure within the public sector.
The authorization extends beyond simply securing data; it enables agencies to scale operations quickly and reliably while maintaining domestic control over their most sensitive information. Cloudflare also announced GovRAMP Moderate authorization, demonstrating a multi-tiered approach to government compliance and broadening its potential client base to include state and local entities.
This dual authorization confirms Cloudflare for Government can satisfy mandates protecting sensitive workloads and meet state-specific data privacy requirements, a critical consideration for increasingly decentralized data governance. More than 100 U.S. government agencies currently utilize Cloudflare’s services to accelerate Zero Trust architectures, deliver resilient digital services, and meet Technical Reference Model 3.0 (TIC 3.0) requirements, including departments of Commerce, Energy, Health and Human Services, Homeland Security, Interior, Justice, and State.
David Mihalchik, VP of U.S. Public Sector at Cloudflare, explained that federal agencies, the Department of Defense, and highly-regulated organizations face increasing pressure to modernize technologies, deliver faster results, and reduce costs while protecting highly sensitive data from evolving threats.
IL4 represents a higher security standard than even FedRAMP High, signaling a commitment to protecting the nation’s most sensitive data across the Federal government and DoD. The company’s platform also incorporates post-quantum cryptography, protecting data in transit against emerging threats to conventional encryption methods.
Cloudflare for Government is built on the same software and architecture as the company’s global network, which spans over 335 cities in 125 countries, leveraging software-defined regionality to deliver consistent performance and security. Several cloud solutions, including Workday, New Relic, Armis Federal, Darktrace Federal and GitLab, already rely on Cloudflare for Government to deliver trustworthy cloud services to their government customers globally, further validating the platform’s security and reliability.
Federal agencies, the Department of Defense, and highly-regulated organizations face more pressure than ever to modernize technologies, deliver faster, and reduce costs while protecting highly sensitive data from evolving threats.
David Mihalchik, VP of U.S. Public Sector at Cloudflare
See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
