<a id="gov-cloud-fedramp-authorization"></a>

# FedRAMP Authorization Information for Confluent Cloud for Government

Confluent Cloud for Government satisfies the FedRAMP 20x public posting requirements
([ADS-CSO-PUB](https://www.fedramp.gov/docs/20x/authorization-data-sharing#public-information),
[ADS-CSO-SVC](https://www.fedramp.gov/docs/20x/authorization-data-sharing#service-list),
[ADS-UTC-PGD](https://www.fedramp.gov/docs/20x/authorization-data-sharing#public-guidance), and
[CCM-OAR-NRD](https://www.fedramp.gov/docs/20x/collaborative-continuous-monitoring#next-report-date)).
This page covers the authorization status, service profile, in-scope services,
and customer responsibilities. For contact information, service status, and
trust center access, see [Confluent Support for Confluent Cloud for Government](support/support.md#gov-cloud-support).

## Authorization status

Confluent Cloud for Government holds an active FedRAMP 20x Moderate authorization, with public
references in the FedRAMP Marketplace and
[Confluent’s Trust Center](https://confluent.safebase.us/?product=us-public-sector).

Impact level
: Moderate

FedRAMP Marketplace listing
: [Confluent Cloud for Government (CCG) | FedRAMP Marketplace](https://www.fedramp.gov/marketplace/products/FR2409863458XL/)

Authority to Operate (ATO) letter
: [Confluent Trust Center](https://confluent.safebase.us/?product=us-public-sector)
  US Public Sector Documents section

Next Ongoing Authorization Report (OAR) date
: June 16, 2026

## Service profile

Confluent Cloud for Government is offered with the following specifications:

Service model
: Software-as-a-Service (SaaS)

Deployment model
: Public cloud

Business category
: Analytics, Data Management, Storage, Cybersecurity & Risk Management

Unique Entity Identifier (UEI)
: GHN5M5CAYT69

For an overview of Confluent Cloud for Government supported features, cloud providers, and regions,
see [Confluent Cloud for Government](overview.md#gov-cloud-overview).

## Services in the FedRAMP Minimum Assessment Scope

The following Confluent Cloud for Government services handle federal data and metadata according to
the FedRAMP 20x Minimum Assessment Scope (KSI-MAS). Security objectives use
[FIPS 199 impact levels](https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/considerations/#impact-levels)
for Confidentiality, Integrity, and Availability (C/I/A).

| Service                 | Security objective (C/I/A)     | Status     |
|-------------------------|--------------------------------|------------|
| Dedicated Kafka Cluster | Moderate / Moderate / Moderate | Authorized |

Confluent Cloud for Government services that are not listed in the preceding table are not in
the Minimum Assessment Scope. Other Confluent offerings, including commercial
Confluent Cloud and Confluent Platform, are also not in the Confluent Cloud for Government Minimum Assessment Scope.

For applicable FedRAMP security controls and best practices for the in-scope
services, see [Manage Security for Confluent Cloud for Government](security/index.md#govcloud-security).

## Customer responsibilities and secure configuration

For a summary of customer responsibilities and secure configuration guidance,
see [Audit access control lists](security/fedramp.md#audit-access-control-lists) in the FedRAMP best practices guide.

## Related content

- [Manage Security for Confluent Cloud for Government](security/index.md#govcloud-security)
- [Confluent Cloud for Government](overview.md#gov-cloud-overview)
- [Confluent Support for Confluent Cloud for Government](support/support.md#gov-cloud-support)
