fedrampvendorNewsThe Broadside1 min read

AWS Transform lands FedRAMP Class C in Ohio

Agentic migration and modernization now carries a moderate authorization, but only in a single commercial region, GovCloud High and multi-region coverage aren't on the table yet.


TL;DR

AWS Transform, the company's agentic migration and modernization service, is now in scope for FedRAMP Class C (formerly Moderate baseline) in the US East (Ohio) Region. Federal agencies and contractors can now use Transform for workloads subject to Class C compliance requirements. The authorization covers one region (Ohio only) which means multi-region moderate architectures will need to wait for additional regions to enter scope. No Class D (High) authorization for GovCloud was announced.

AWS Transform is now in scope for FedRAMP Class C in the US East (Ohio) Region, making it one of the more notable AI-native services to cross the FedRAMP certification threshold. Transform is an agentic migration and modernization service, designed to handle large-scale infrastructure migrations and continuous modernization work that typically bogs down in manual handoffs and context loss.

The authorization is narrow: one region, one baseline, and no mention of GovCloud. That's not unusual for a first FedRAMP entry, but it does constrain the immediate addressable market. Federal contractors with multi-region Class C workloads, or anything touching the High baseline, can't rely on Transform yet.

The contrast with AWS Parallel Computing Service is instructive. PCS entered FedRAMP Class C in three commercial regions, Ohio, N. Virginia, and Oregon, and Class D in GovCloud in the same timeframe. Transform's single-region Class C entry suggests a more conservative rollout, or a service architecture that's still working through the multi-region certification pipeline.

The operational hook here is straightforward: if you're running FedRAMP Class C workloads in Ohio, Transform is now a compliance-eligible option for migration and modernization. If you're anywhere else, or at the High baseline, it's a watch-and-wait item. AWS's shared-responsibility model means customers can still assess and use services outside the listed scope, but that adds a documentation burden most compliance teams would rather avoid.


Published ·Deep Fathom

AWS Transform lands FedRAMP Class C in Ohio — The Broadside