Cloudflare Reaches FedRAMP High on Its Existing Global Network

Cloudflare Reaches FedRAMP High on Its Existing Global Network

Public Sector
Cloudflare qualified its commercial global network for FedRAMP High, restated its April 2026 GovRAMP Moderate authorization in the same release, and named the same systems as the foundation for a planned Defense Department bid.
By Shashi Bellamkonda · August 28, 2026
24
Authorizations listed on Cloudflare's High-tier Marketplace package (FedRAMP Marketplace, 2026)
Aug. 6
Date the certification took effect (FedRAMP Marketplace, 2026)
15
U.S. metro areas authorized to process FedRAMP High traffic (Cloudflare, 2026)
3 yr, 8 mo
Time between Moderate authorization and High certification (Cloudflare, 2026)
This is an agency-sponsored FedRAMP Class D certification, with NIST as sponsor. The Impact Level 4 bid in the same release is still an intent. Cloudflare has not given a date for it.

Cloudflare said on August 10 that Cloudflare for Government achieved FedRAMP Class D, the High impact tier. The same release restated GovRAMP Moderate authorization for state and local buyers, which Cloudflare secured in April 2026. The FedRAMP Marketplace lists the High package as certified effective August 6, with 24 authorizations recorded against it. In the same release, Cloudflare said the systems built for High will serve as the foundation for a planned Impact Level 4 bid to the U.S. Department of Defense. The company has not published a target date for that authorization.

High is the tier FedRAMP reserves for sensitive unclassified data: law enforcement records, emergency response systems, financial infrastructure, national security. Cloudflare's own comparison, not a FedRAMP legal definition, states it in stark terms. A Moderate-tier breach might compromise something like a park service ticketing system. A High-tier breach could cost lives or threaten the country's economic security.

Most people still know Cloudflare as the "checking your browser" page that shows up mid-DDoS attack. W3Techs put Cloudflare in front of 24.9 percent of all websites it tracks as of August 28, 2026, and Cloudflare's own 2026 Threat Report says the company processes over 20 percent of the world's internet traffic.

The Same Network Reaches FedRAMP High

Most cloud providers that reach this tier build a separate environment for government traffic.

Most cloud providers that reach this tier build a separate environment for government traffic. Cloudflare made a different bet years before this certification existed. The company says every data center in its network, more than 335 cities across over 125 countries, runs the same software stack, and that FedRAMP High runs on those same machines.

The control Cloudflare points to is the Data Localization Suite, a software layer the company says keeps inspection and processing for federal High workloads inside U.S. data centers. Cloudflare's press release states a distinct fact: the actual High processing footprint is 15 U.S. metro areas, a narrower slice than the full commercial network of more than 335 cities. The boundary is a software control on shared hardware in those metros.

The control Cloudflare points to is the Data Localization Suite, a software layer the company says keeps inspection and processing for federal High workloads inside U.S. data centers. Cloudflare's press release states a distinct fact: the actual High processing footprint is 15 U.S. metro areas, a narrower slice than the full commercial network of more than 335 cities. The underlying hardware in those 15 metros still sits inside the same global fabric serving everyone else; the boundary is enforced in software.

NIST Is the Sponsoring Agency

Cloudflare credits the National Institute of Standards and Technology as its sponsoring agency. Under FedRAMP's agency-sponsored path, the sponsor completes the first agency authorization and accepts risk for its own systems, not for the rest of the federal government (FedRAMP, 2026). After certification, the sponsor continues its own ongoing monitoring the same way any other agency customer does for its own use. Other agencies that want to reuse the package still complete their own review and run their own ongoing monitoring before adopting Cloudflare's High package (FedRAMP, 2026).

NIST writes the security control catalogs the rest of the federal government builds its authorizations on. Here it is also the first agency customer accepting that risk on Cloudflare's High package, a role distinct from its usual part as the standards body behind the assessment.

Cloudflare Aims the Same Controls at DoD IL4

Cloudflare says the controls built to satisfy FedRAMP High are the same controls it will submit for DoD Impact Level 4, the Pentagon's standard for controlled unclassified information. No IL4 timeline is public. The Defense Department's review process, not Cloudflare's engineering schedule, sets that pace from here.

Moderate to High Took Under Four Years

Cloudflare reached FedRAMP Moderate in December 2022. High followed in August 2026, about three years and eight months later. Cloudflare says more than 100 U.S. government agencies already use its services, including the Departments of State and Commerce, though that figure describes existing Cloudflare usage overall, not confirmed adoption of the new High package. Cloudflare also names Workday, New Relic, and GitLab among the vendors that rely on Cloudflare for Government to reach their own federal customers.

The Data Localization Suite decides where High-impact traffic gets inspected and processed. The hardware underneath still belongs to the same 335-city network Cloudflare sells to everyone else.
The certification confirms Cloudflare's shared-network design cleared FedRAMP's agency-sponsored High review, with NIST accepting the operational risk on its own systems. Every other agency that wants the package still has to run its own review before adopting it.

What to ask next

FedRAMP will stop accepting new applications under the agency-sponsored Rev5 path on June 11, 2027, as the program shifts toward FedRAMP 20x and machine-readable Key Security Indicators. Existing Rev5 certifications, including a Class D package like Cloudflare's, stay active until at least December 31, 2028, unless FedRAMP directs otherwise (FedRAMP, 2026).

Public materials describe the Data Localization Suite and the 15-metro High footprint. A briefing should walk how that U.S. boundary is enforced day to day and how that evidence shows up in ongoing certification reports.

CIO/CTO briefing note
Ask the vendor to show how the 15-metro U.S. boundary is enforced for High-impact workloads, and how that control is reflected in continuous monitoring. Get that walkthrough in writing as part of procurement diligence.
Cloudflare. "Serving the Most Critical Missions: Cloudflare for Government Achieves FedRAMP Class D (High) Certified Status." Cloudflare Blog, 10 Aug. 2026, https://blog.cloudflare.com/fedramp-class-d-certification/.
Cloudflare. "Cloudflare Achieves FedRAMP High Authorization to Secure and Accelerate the U.S. Government's Critical Missions." Press release, 10 Aug. 2026, https://www.cloudflare.com/press/press-releases/2026/cloudflare-achieves-fedramp-high-authorization-to-secure-and-accelerate-the-u-s-governments-critical-missions/.
Cloudflare. 2026 Threat Report. Cloudflare, 2026, https://cf-assets.www.cloudflare.com/slt3lc6tev37/sWDBUMNVtEJB9ZFLt1dUU/8d69e92de2edfb3bf59e7d21d57e7e1a/Cloudflare-2026-threat-report.pdf.
FedRAMP. "Cloudflare for Government - High." FedRAMP Marketplace, U.S. General Services Administration, 2026, https://www.fedramp.gov/marketplace/products/FR2000863987A/.
FedRAMP. "Sponsoring a FedRAMP Certification." FedRAMP Consolidated Rules for 2026, U.S. General Services Administration, 2026, https://www.fedramp.gov/2026/agencies/sponsoring/.
FedRAMP. "What's Changing in 2026." FedRAMP Consolidated Rules for 2026, U.S. General Services Administration, 2026, https://www.fedramp.gov/2026/providers/updating/changes/.
FedRAMP. "FedRAMP 20x." U.S. General Services Administration, 2026, https://www.fedramp.gov/20x.
W3Techs. "Usage Statistics and Market Share of Reverse Proxy Services for Websites." W3Techs, 28 Aug. 2026, https://w3techs.com/technologies/overview/proxy.
Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.