---
kind: "section"
citation: "44 U.S.C. § 3610"
title: "44"
title_heading: "Public Printing and Documents"
number: "3610"
heading: "FedRAMP Board"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/44/3610"
units:
  - "Chapter 36 — Management and Promotion of Electronic Government Services"
---

# §3610. FedRAMP Board

- (a) **Establishment.—** There is established a [FedRAMP Board](/usc/44/3607.md?p=b-9) to provide input and recommendations to the [Administrator](/usc/44/3601.md?p=1) regarding the requirements and guidelines for, and the prioritization of, security assessments of [cloud computing](/usc/44/3607.md?p=b-4) products and services.
- (b) **Membership.—** The [FedRAMP Board](/usc/44/3607.md?p=b-9) shall consist of not more than 7 senior officials or experts from agencies appointed by the Director, in consultation with the [Administrator](/usc/44/3601.md?p=1), from each of the following:
  - (1) The Department of Defense.
  - (2) The Department of Homeland Security.
  - (3) The General Services Administration.
  - (4) Such other agencies as determined by the Director, in consultation with the [Administrator](/usc/44/3601.md?p=1).
- (c) **Qualifications.—** Members of the [FedRAMP Board](/usc/44/3607.md?p=b-9) appointed under [subsection (b)](#b) shall have technical expertise in domains relevant to [FedRAMP](/usc/44/3607.md?p=b-6), such as—
  - (1) [cloud computing](/usc/44/3607.md?p=b-4);
  - (2) cybersecurity;
  - (3) privacy;
  - (4) risk management; and
  - (5) other competencies identified by the Director to support the secure authorization of cloud services and products.
- (d) **Duties.—** The [FedRAMP Board](/usc/44/3607.md?p=b-9) shall—
  - (1) in consultation with the [Administrator](/usc/44/3601.md?p=1), serve as a resource for best practices to accelerate the process for obtaining a [FedRAMP authorization](/usc/44/3607.md?p=b-7);
  - (2) establish and regularly update requirements and guidelines for security authorizations of [cloud computing](/usc/44/3607.md?p=b-4) products and services, consistent with standards and guidelines established by the Director of the National Institute of Standards and Technology, to be used in the determination of [FedRAMP authorizations](/usc/44/3607.md?p=b-7);
  - (3) monitor and oversee, to the greatest extent practicable, the processes and procedures by which agencies determine and validate requirements for a [FedRAMP authorization](/usc/44/3607.md?p=b-7), including periodic review of the agency determinations described in [section 3613(b)](/usc/44/3613.md?p=b);
  - (4) ensure consistency and transparency between agencies and [cloud service providers](/usc/44/3607.md?p=b-5) in a manner that minimizes confusion and engenders trust; and
  - (5) perform such other roles and responsibilities as the Director may assign, with concurrence from the [Administrator](/usc/44/3601.md?p=1).
- (e) **Determinations of Demand for Cloud Computing Products and Services.—** The [FedRAMP Board](/usc/44/3607.md?p=b-9) may consult with the Chief Information Officers [Council](/usc/44/3601.md?p=2) to establish a process, which may be made available on the website maintained under [section 3609(b)](/usc/44/3609.md?p=b), for prioritizing and accepting the [cloud computing](/usc/44/3607.md?p=b-4) products and services to be granted a [FedRAMP authorization](/usc/44/3607.md?p=b-7).

## Source credit

(Added Pub. L. 117–263, div. E, title LIX, § 5921(b), Dec. 23, 2022, 136 Stat. 3452.)

## Notes

### Repeal of Section

For repeal of section by section 5921(d)(1) of Pub. L. 117–263, see Effective Date of Repeal note below.

### Statutory Notes and Related Subsidiaries

### Effective Date of Repeal

Pub. L. 117–263, div. E, title LIX, § 5921(d)(1), Dec. 23, 2022, 136 Stat. 3458, provided that the repeal of this section is effective on the date that is 5 years after Dec. 23, 2022.

### Construction

For rule of construction regarding section 5921 of Pub. L. 117–263, see section 5921(e) of Pub. L. 117–263, set out as a note under section 3607 of this title.
