Our FedRAMP Marketplace listing went live on August 27, 2026. Files.com earned Class A certification through the Program Certification path under FedRAMP 20x, the federal government's newly rebuilt cloud security program.
We are among the first two cloud services to earn Class A certification. The application pipeline opened on August 3, and our certification was granted 23 days later.
For our customers, this means there is now a public, government-published record of our security posture. For federal agencies and contractors evaluating Files.com, it provides a clearer and faster starting point for their own reviews.
FedRAMP, Rebuilt for Modern Cloud Services
FedRAMP stands for the Federal Risk and Authorization Management Program. Its purpose is straightforward: assess the security of a cloud service once and make the results available across the federal government.
Without FedRAMP, each agency would have to evaluate every cloud provider from scratch. FedRAMP creates a common standard and publishes the outcome so agencies can make informed decisions based on a consistent body of evidence.
Historically, earning a FedRAMP authorization could take years and cost millions of dollars. Providers produced hundreds of pages of control narratives, hired an accredited third-party assessment organization, and found a federal agency willing to sponsor the package. The process was so demanding that many otherwise capable cloud companies could not realistically participate.
FedRAMP 20x changes that model.
Rather than relying primarily on static documents, it asks providers to demonstrate specific, testable security outcomes called Key Security Indicators, or KSIs. The supporting evidence is machine-readable and revalidated over time, with stronger automation requirements at higher certification classes.
Class A requires providers to meet at least seven mandatory KSIs. They cover areas like change-management logging, network traffic restrictions, automated account management, and passwordless authentication.
That approach is much closer to how modern technical teams actually operate: measure the system, produce evidence directly from it, and keep that evidence current.
FedRAMP 20x also introduced new terminology. "FedRAMP Authorization" is now "FedRAMP Certification," and the former Low, Moderate, and High authorization levels are being replaced by Classes A through D. FedRAMP will show the legacy names in parentheses through December 31, 2026, before retiring them in January 2027.
What Class A Means
Class A is the entry point to FedRAMP 20x. Through the Program Certification path, certification comes directly from the FedRAMP program office and does not require an agency sponsor.
The process builds on an established external security assessment rather than beginning from zero. SOC 2 Type II is the first such framework accepted by FedRAMP, and Files.com has held SOC 2 Type II for years, audited by KirkpatrickPrice.
Class A is also designed as an on-ramp to the full FedRAMP assessment. The certification itself has no fixed expiration date. It stays in effect as long as Files.com continues to satisfy the Class A Ongoing Certification requirements, which we report on quarterly.
A FedRAMP certification class and a system's impact categorization are two different measures.
The certification class describes the assessment pathway and requirements a provider has completed. Impact categorization describes the potential consequences of a loss of confidentiality, integrity, or availability. Those consequences are rated Low, Moderate, or High, and the overall categorization is determined by the highest of the three ratings.
All four Files.com services are categorized Moderate for confidentiality, integrity, and availability. The overall offering is therefore categorized Moderate.
Class A also does not create a usage gate. FedRAMP does not require agencies to select services at or above a particular certification class.
We Are Already Working Toward Class B
Class A is a milestone, not the finish line. Our Class B upgrade is already underway.
Class B replaces the legacy FedRAMP Low and Li-SaaS designations. It covers approximately 156 controls and requires a complete FedRAMP assessment rather than using an existing framework as a bridge.
It also raises the bar for automation. At Class A, providers may automate the validation of each KSI. At Class B, providers are expected to have at least one automated validation method for every KSI.
That direction fits the way Files.com is built.
Our platform continuously generates much of the evidence assessors need because those capabilities are part of the product itself. Files.com maintains a complete audit log of logins, permission changes, file transfers, and other activity. That record is not something we construct just before an audit. It is available to our customers every day.
Where to Find Our Security Documents
The FedRAMP process highlighted something we needed to improve. Customers were having to chase us for basic security documentation.
It is one place to review our security and compliance materials. That includes our SOC 2 Type II reports and bridge letter, the PCI DSS v4 Attestation of Compliance for SAQ-D Service Providers, HIPAA documentation, penetration test completion letters dating back to 2022, the CSA STAR Consensus Assessments Initiative Questionnaire, our shared responsibility model, and our accessibility conformance report. The FedRAMP package is there too: the Class A Certification Report, the Mandatory Key Security Indicator Summary, and our Security Decision Record.
The Security Decision Record is available in two forms: one for people and one for machines.
That machine-readable version is a meaningful part of what separates FedRAMP 20x from the process it replaces. An agency or enterprise security team can retrieve our current security posture programmatically instead of emailing a vendor-management inbox and waiting for a PDF.
Documents that cannot be made public are also available through the Trust Center by request. Visitors can subscribe to receive updates when materials change.
Files.com speaks every protocol, connects to 50+ cloud and on-prem systems, automates every transfer, and keeps a complete audit trail.
For organizations accountable to regulators, auditors, or federal customers, the practical benefit is simple: the platform that moves the files also produces the evidence.
Every file transfer and administrative action lands in a log an auditor can read. Automated workflows replace manual file handling. Cloud and on-premises systems connect without a patchwork of scripts holding them together. And eight global data residency zones keep data in the region a contract requires.
Our broader compliance posture, including SOC 2 Type II, PCI DSS, HIPAA, and GDPR, is documented in the Files.com Compliance Center.
If you are evaluating Files.com for a federal agency, government contractor, or regulated workflow, start with our FedRAMP Marketplace listing and Trust Center. Both are public.
See it for yourself. Start a free trial. No credit card, live in minutes.
G2 reviewers named Files.com the #1 easiest-to-use Managed File Transfer platform. Here is why users praise the intuitive interface, fast setup, and automation-friendly workflows.
Files.com has been recognized as a G2 Grid® Leader for Spring 2025, earning high ratings in customer satisfaction and market presence. See why users trust us for secure, automated file transfer and cloud storage.
Files.com has been named a Fall 2025 Enterprise Leader on G2, recognized for high customer satisfaction and adoption across enterprise IT teams. Find out more what this award means and see the recognition Files.com earned this season.