Since its introduction in 2011, the Federal Risk and Authorization Management Program (FedRAMP) has been required for all companies providing cloud-based services to the Federal government. FedRAMP was developed in order to address the lack of a standardized method for evaluating and monitoring the risk and security of providers of cloud-based services to Federal agencies. Meanwhile, System and Organization Controls (SOC) 2 assessment is often used by companies to demonstrate a secure baseline of operations as well as an enterprise sales tool to other businesses.