A FedRAMP gap assessment is the diagnostic that measures your cloud service against what FedRAMP actually requires before you commit to the formal authorization process, and it exists to answer one question: how far are you from authorized, and what will it take to close the distance. This guide explains what the assessment covers, what drives its cost, what it delivers, and how its findings map to your certification path, so you can tell a scoping conversation from a sales pitch when you go looking for one.
The reason this matters more in 2026 is that FedRAMP’s requirements changed shape. Under the Consolidated Rules for 2026, the program expresses its requirements as Key Security Indicators rather than a static control checklist, and the submission artifacts changed with them. A gap assessment built on the old baseline measures you against the wrong target, so understanding what a current gap assessment covers is the first step in buying one that is worth the money.
What a FedRAMP Gap Assessment Is and Is Not
A FedRAMP gap assessment is an advisory diagnostic. It reviews your cloud service as it exists today, compares that reality against the FedRAMP requirements you will be measured on, and produces a prioritized picture of what is missing. It is preparation work, done before you enter the formal process, and its purpose is to remove surprises from an assessment that is expensive to fail.
It is not the independent assessment that authorizes you. Under FedRAMP, an accredited third-party assessment organization performs the formal evaluation that leads to a FedRAMP Authorized designation, and that role is deliberately separate from advisory work. An advisor helps you get ready; the assessor independently judges whether you are. Elevate performs gap assessments as an advisor, which under the 2026 rules is a distinct and recognized role, and keeping that line clear protects the independence the formal assessment depends on. A firm that offers to both prepare you and independently assess you is blurring a line that FedRAMP draws on purpose.
It is also narrower than a readiness engagement. A gap assessment is the point-in-time diagnostic that finds the gaps; the broader work of preparing a service to succeed, including remediation and provider selection, is covered in FedRAMP readiness assessment services. The gap assessment is where that broader effort starts, because you cannot plan remediation you have not yet scoped.
What a FedRAMP Gap Assessment Covers
The assessment measures three things: the requirements you must meet, the boundary they apply to, and the evidence you can produce today. Each shapes the findings, and each is where an assessment can be scoped too narrowly or too broadly.
The Requirements It Measures Against
Current FedRAMP requirements are expressed as Key Security Indicators, grouped into families that span identity and access management, change management, incident response, monitoring and logging, cloud-native architecture, supply chain risk, and more. A gap assessment works through those indicators and asks, for each one, whether your service meets it, partially meets it, or does not. Because the ruleset is machine-readable and versioned, the assessment measures against the version in force at the time, which is why a current gap assessment cannot rely on a control list carried over from the previous FedRAMP model.
The Boundary It Examines
FedRAMP requirements apply to your authorization boundary, the defined set of components that make up the service being authorized. The gap assessment examines that boundary: what is inside it, how data flows across it, what it connects to, and what it inherits from an underlying authorized platform. A boundary that is loosely defined produces a loose assessment, so part of the diagnostic is pressure-testing the boundary itself before measuring what is inside it.
The Evidence It Reviews
FedRAMP is proven through evidence, so the gap assessment reviews what you can actually show. It looks at whether your implementation is documented in a form that will populate the Certification Package Overview and the Security Decision Record, the artifacts that replaced the standalone system security plan under the 2026 rules. Where a control is implemented but undocumented, that is a gap the assessment records, because in a FedRAMP evaluation an undocumented control is treated as an unmet one.
What Drives the Cost of a FedRAMP Gap Assessment
There is no single price for a FedRAMP gap assessment, because the effort scales with the service being assessed. Rather than quote a number that would not survive contact with your environment, the honest way to understand cost is through the factors that move it.
| Cost driver | Why it moves the cost |
|---|---|
| Boundary size and complexity | More components, integrations, and data flows mean more to review against each indicator |
| Cloud architecture | A cloud-native design maps to current requirements more directly than a lifted-and-shifted one |
| Current security maturity | Mature controls need confirmation; immature ones need discovery, which takes longer |
| Documentation state | Accurate existing documentation shortens the review; its absence lengthens it |
| Inherited controls | Building on an already-authorized platform reduces what must be assessed in your own boundary |
The pattern across these drivers is that cost tracks discovery, not size alone. A large but well-documented, cloud-native service can assess faster than a small one whose controls are real but unwritten, because the assessment spends its time finding and confirming rather than measuring. This is why an accurate quote requires a scoping conversation rather than a form: the drivers interact, and only your actual boundary determines where they land. The one thing that reliably raises cost is discovering late that the boundary was wrong, which is precisely what the assessment exists to prevent.
What a FedRAMP Gap Assessment Delivers
The output of a gap assessment is not a pass or fail; it is a plan. A useful one delivers two things you can act on and one thing you can decide with.
The Findings Report
The findings report records the state of each requirement: met, partially met, or unmet, with the evidence reviewed and the specific shortfall named. It is organized so that the gaps are prioritized by the effort and risk they carry, not listed alphabetically, because a report you have to re-analyze is only half a deliverable. The value of the report is that it turns an abstract standard into a concrete, ranked list of what your service is missing.
The Remediation Roadmap
The roadmap turns findings into sequence. It groups the gaps into a realistic order of work, flags the ones that block others, estimates the effort each will take, and identifies where a gap is better closed by a design change than a bolt-on control. This is where a gap assessment earns its cost, because the difference between a list of gaps and a sequenced plan is the difference between knowing you have work and knowing how to do it.
The Decision It Supports
Together, the report and roadmap support the decision that actually matters at this stage: whether, when, and how to enter the formal process. Some services finish a gap assessment ready to schedule an independent assessment; others learn they need a quarter of remediation first, or that a boundary change will save them more than any single control. Making that decision with evidence, before spending on the formal assessment, is the entire point.
How Gap Assessment Findings Map to Your Certification Path
A gap assessment is the first step in a sequence, and its findings are built to feed the next ones. The path runs from the diagnostic, through remediation, to the independent assessment, and then to the FedRAMP Authorized designation and the continuous monitoring that follows. The gap assessment sets that path up by producing the evidence and documentation the later steps consume.
The findings map forward in a specific way. The remediation roadmap becomes your work plan. The documentation the assessment identifies as missing becomes the content of your Certification Package Overview and Security Decision Record. And the boundary the assessment confirms becomes the boundary the independent assessor evaluates. Under the 2026 model, including the 20x path for new entrants, the entry requirements differ by route, and the gap assessment is where you learn which route fits your service and what each would demand. For the wider picture of how authorization works now, see what FedRAMP compliance involves and the FedRAMP 20x assessment model.
Elevate runs FedRAMP gap assessments as part of its FedRAMP advisory services, scoping the boundary, measuring against the current ruleset, and delivering a remediation roadmap you can execute, without crossing into the independent assessment that has to stay separate. To scope a gap assessment for your service, book a call with an Elevate advisor.
Conclusion
A FedRAMP gap assessment is worth what it saves you from: entering an expensive formal process without knowing where you stand. It covers the requirements you will be measured on, the boundary they apply to, and the evidence you can produce; its cost tracks how much discovery your environment demands; and it delivers a prioritized findings report and a sequenced remediation roadmap that together tell you whether, when, and how to proceed. Under the 2026 rules, where requirements are expressed as Key Security Indicators and the submission artifacts have changed, a current gap assessment is the difference between preparing against the right target and the wrong one.
The assessment is preparation, not authorization, and keeping that line clear is part of getting it right. Done well, it converts a daunting, ambiguous requirement into a plan you can execute and a decision you can defend. To scope one for your cloud service, book a call with an Elevate advisor.
Key Takeaways
A FedRAMP gap assessment is an advisory diagnostic that tells you how far your service is from authorized and what it will take to close the distance.
- It measures against current requirements: the 2026 rules express FedRAMP requirements as Key Security Indicators, so a current gap assessment measures against those, not a carried-over control list.
- It is preparation, not authorization: the gap assessment is advisory work that readies you, kept separate from the independent third-party assessment that authorizes you.
- Cost tracks discovery, not size: boundary complexity, architecture, maturity, and documentation state drive the effort, which is why an accurate quote needs a scoping conversation.
- The output is a plan, not a verdict: a prioritized findings report and a sequenced remediation roadmap, built to support the decision of whether and when to enter the formal process.
- Findings feed the path: the roadmap becomes your work plan, and the documentation identified becomes the content of your Certification Package Overview and Security Decision Record.
FAQs
Q1. What is a FedRAMP gap assessment? A FedRAMP gap assessment is an advisory diagnostic that compares your cloud service, as it exists today, against the FedRAMP requirements you will be measured on, and produces a prioritized picture of what is missing. It is done before the formal authorization process to remove surprises from an assessment that is costly to fail. It is preparation work, distinct from the independent assessment that actually grants a FedRAMP Authorized designation.
Q2. What does a FedRAMP gap assessment cover? It covers three things: the requirements you must meet, now expressed as the Key Security Indicators in the 2026 consolidated ruleset; the authorization boundary those requirements apply to; and the evidence you can produce today. For each requirement, the assessment records whether your service meets it, partially meets it, or does not, and whether the implementation is documented in a form that will support your submission artifacts.
Q3. How much does a FedRAMP gap assessment cost? There is no single price, because the effort scales with the service. The main cost drivers are the size and complexity of your authorization boundary, your cloud architecture, your current security maturity, the state of your existing documentation, and how much you inherit from an already-authorized platform. Cost tracks discovery rather than size, so a well-documented service can assess faster than a smaller one whose controls are undocumented, and an accurate quote requires a scoping conversation rather than a fixed rate.
Q4. What does a FedRAMP gap assessment deliver? It delivers a findings report that records the state of each requirement with the specific shortfall named and gaps prioritized by effort and risk, plus a remediation roadmap that sequences the work, flags blockers, and estimates effort. Together they support the decision of whether, when, and how to enter the formal process. The output is a plan you can execute, not a pass-or-fail verdict.
Q5. Is a gap assessment the same as a FedRAMP readiness assessment or the 3PAO assessment? No. A gap assessment is the point-in-time diagnostic that finds and prioritizes gaps. Readiness assessment services are broader, covering the full preparation of a service to succeed, including remediation and provider selection. The third-party assessment is the independent evaluation by an accredited assessor that leads to authorization, and it is deliberately kept separate from advisory work. In sequence, the gap assessment comes first, readiness work follows, and the independent assessment comes last.