Cloudflare said on August 10 that Cloudflare for Government achieved FedRAMP Class D, the High impact tier. The same release restated GovRAMP Moderate authorization for state and local buyers, which Cloudflare secured in April 2026. The FedRAMP Marketplace lists the High package as certified effective August 6, with 24 authorizations recorded against it. In the same release, Cloudflare said the systems built for High will serve as the foundation for a planned Impact Level 4 bid to the U.S. Department of Defense. The company has not published a target date for that authorization.
High is the tier FedRAMP reserves for sensitive unclassified data: law enforcement records, emergency response systems, financial infrastructure, national security. Cloudflare's own comparison, not a FedRAMP legal definition, states it in stark terms. A Moderate-tier breach might compromise something like a park service ticketing system. A High-tier breach could cost lives or threaten the country's economic security.
Most people still know Cloudflare as the "checking your browser" page that shows up mid-DDoS attack. W3Techs put Cloudflare in front of 24.9 percent of all websites it tracks as of August 28, 2026, and Cloudflare's own 2026 Threat Report says the company processes over 20 percent of the world's internet traffic.
The Same Network Reaches FedRAMP High
Most cloud providers that reach this tier build a separate environment for government traffic.
Most cloud providers that reach this tier build a separate environment for government traffic. Cloudflare made a different bet years before this certification existed. The company says every data center in its network, more than 335 cities across over 125 countries, runs the same software stack, and that FedRAMP High runs on those same machines.
The control Cloudflare points to is the Data Localization Suite, a software layer the company says keeps inspection and processing for federal High workloads inside U.S. data centers. Cloudflare's press release states a distinct fact: the actual High processing footprint is 15 U.S. metro areas, a narrower slice than the full commercial network of more than 335 cities. The boundary is a software control on shared hardware in those metros.
The control Cloudflare points to is the Data Localization Suite, a software layer the company says keeps inspection and processing for federal High workloads inside U.S. data centers. Cloudflare's press release states a distinct fact: the actual High processing footprint is 15 U.S. metro areas, a narrower slice than the full commercial network of more than 335 cities. The underlying hardware in those 15 metros still sits inside the same global fabric serving everyone else; the boundary is enforced in software.
NIST Is the Sponsoring Agency
Cloudflare credits the National Institute of Standards and Technology as its sponsoring agency. Under FedRAMP's agency-sponsored path, the sponsor completes the first agency authorization and accepts risk for its own systems, not for the rest of the federal government (FedRAMP, 2026). After certification, the sponsor continues its own ongoing monitoring the same way any other agency customer does for its own use. Other agencies that want to reuse the package still complete their own review and run their own ongoing monitoring before adopting Cloudflare's High package (FedRAMP, 2026).
NIST writes the security control catalogs the rest of the federal government builds its authorizations on. Here it is also the first agency customer accepting that risk on Cloudflare's High package, a role distinct from its usual part as the standards body behind the assessment.
Cloudflare Aims the Same Controls at DoD IL4
Cloudflare says the controls built to satisfy FedRAMP High are the same controls it will submit for DoD Impact Level 4, the Pentagon's standard for controlled unclassified information. No IL4 timeline is public. The Defense Department's review process, not Cloudflare's engineering schedule, sets that pace from here.
Moderate to High Took Under Four Years
Cloudflare reached FedRAMP Moderate in December 2022. High followed in August 2026, about three years and eight months later. Cloudflare says more than 100 U.S. government agencies already use its services, including the Departments of State and Commerce, though that figure describes existing Cloudflare usage overall, not confirmed adoption of the new High package. Cloudflare also names Workday, New Relic, and GitLab among the vendors that rely on Cloudflare for Government to reach their own federal customers.
What to ask next
FedRAMP will stop accepting new applications under the agency-sponsored Rev5 path on June 11, 2027, as the program shifts toward FedRAMP 20x and machine-readable Key Security Indicators. Existing Rev5 certifications, including a Class D package like Cloudflare's, stay active until at least December 31, 2028, unless FedRAMP directs otherwise (FedRAMP, 2026).
Public materials describe the Data Localization Suite and the 15-metro High footprint. A briefing should walk how that U.S. boundary is enforced day to day and how that evidence shows up in ongoing certification reports.
Cloudflare. "Cloudflare Achieves FedRAMP High Authorization to Secure and Accelerate the U.S. Government's Critical Missions." Press release, 10 Aug. 2026, https://www.cloudflare.com/press/press-releases/2026/cloudflare-achieves-fedramp-high-authorization-to-secure-and-accelerate-the-u-s-governments-critical-missions/.
Cloudflare. 2026 Threat Report. Cloudflare, 2026, https://cf-assets.www.cloudflare.com/slt3lc6tev37/sWDBUMNVtEJB9ZFLt1dUU/8d69e92de2edfb3bf59e7d21d57e7e1a/Cloudflare-2026-threat-report.pdf.
FedRAMP. "Cloudflare for Government - High." FedRAMP Marketplace, U.S. General Services Administration, 2026, https://www.fedramp.gov/marketplace/products/FR2000863987A/.
FedRAMP. "Sponsoring a FedRAMP Certification." FedRAMP Consolidated Rules for 2026, U.S. General Services Administration, 2026, https://www.fedramp.gov/2026/agencies/sponsoring/.
FedRAMP. "What's Changing in 2026." FedRAMP Consolidated Rules for 2026, U.S. General Services Administration, 2026, https://www.fedramp.gov/2026/providers/updating/changes/.
FedRAMP. "FedRAMP 20x." U.S. General Services Administration, 2026, https://www.fedramp.gov/20x.
W3Techs. "Usage Statistics and Market Share of Reverse Proxy Services for Websites." W3Techs, 28 Aug. 2026, https://w3techs.com/technologies/overview/proxy.
