AWS Elastic VMware Service clears FedRAMP Class C
The first VMware Cloud Foundation service to hit Class C on AWS removes the ATO barrier that kept federal VMware workloads pinned to on-prem data centers.
TL;DR
Amazon Elastic VMware Service (EVS) is now in scope for FedRAMP Class C (formerly the Moderate baseline) across all US commercial regions. It's the first VMware Cloud Foundation service on AWS to reach that authorization level. For defense contractors and civilian agencies still running aging on-premises VMware stacks, the news eliminates a critical procurement obstacle: workloads that require Class C no longer need a separate agency ATO. The authorization covers commercial US regions; EVS isn't yet listed for Class D (High) in GovCloud.
Amazon Elastic VMware Service on Tuesday received FedRAMP Class C authorization (formerly the Moderate baseline) across all US commercial regions. The milestone makes EVS the first VMware Cloud Foundation service on AWS to clear that bar, and it lands at a moment when federal contractors are under rising pressure to exit aging on-premises data centers.
The practical effect is straightforward: workloads that process Controlled Unclassified Information and require a FedRAMP-authorized environment can now run on EVS without the contracting officer needing to sponsor a separate agency Authority to Operate. That's the bottleneck Class C removes. For primes and mid-tier contractors still maintaining on-prem VMware clusters for CUI workloads, EVS now sits inside the compliance boundary they already rely on.
What the authorization doesn't cover, yet
FedRAMP Class C applies to commercial US regions. AWS GovCloud, which carries the Class D (High) designation needed for DoD Impact Level 4/5 workloads, does not yet list EVS as in scope. That's the gap. A contractor migrating classified workloads or anything requiring the DoD SRG's higher impact levels is still waiting.
The services-in-scope matrix last updated in late August 2026 shows the split clearly: the Class C column has EVS checked; the GovCloud Class D column, at time of writing, does not.
Why this matters for data center exits
Contractors on timelines to vacate data centers have had a VMware-shaped problem. They run VCF on-premises, they've built compliance documentation around it, and the cloud path (lift into a VMware environment they already know) was gated on the FedRAMP piece. EVS at Class C changes the arithmetic: the same VCF 9.0/9.1 stack, on EC2 bare metal, provisioned in hours, now inside the authorization boundary.
That doesn't mean every CUI workload lifts cleanly. The shared responsibility model still puts configuration, access control, and ongoing monitoring on the customer. But the authorization step (typically the one that stalls procurement) is now handled.
Published ·Deep Fathom