AWS adds IAM Identity Center to FedRAMP Class C
The useful part is narrower than the announcement sounds: identity management is now in scope, not magically settled for every workload.
TL;DR
AWS says IAM Identity Center is now in scope for FedRAMP Class C in US East (Ohio), US East (N. Virginia), US West (N. California), and US West (Oregon). Agencies and contractors can use it for workforce access to AWS accounts and applications subject to FedRAMP Class C compliance. The practical change is tooling eligibility, not a shortcut around the rest of the FedRAMP control burden.
AWS put IAM Identity Center inside its FedRAMP Class C scope for four commercial U.S. regions: Ohio, N. Virginia, N. California, and Oregon. That gives agencies and contractors using those regions a vendor-supported path to manage workforce access to AWS accounts and applications that are themselves subject to FedRAMP Class C requirements.
The announcement is useful, but bounded. IAM Identity Center being in scope means the identity service can be part of a FedRAMP Class C environment in those regions. It does not answer the harder questions for a customer system: which accounts are in scope, how access is configured, how evidence is collected, and whether the surrounding application environment meets the applicable requirements.
For practitioners, the Monday item is straightforward. If IAM Identity Center was previously an exception, compensating control, or procurement blocker in a FedRAMP Class C-bound AWS environment, revisit that architecture and evidence package. If it was not, this is a compliance mapping update, not an emergency migration plan.
Published ·Deep Fathom