Cloudflare announced on August 10, 2026 that Cloudflare for Government has achieved what it calls FedRAMP Class D (High) certified status, the clearance that lets a cloud service carry the most sensitive unclassified data the United States federal government holds. The sponsoring agency is the National Institute of Standards and Technology, the independent assessor was Schellman Compliance, and the FedRAMP Marketplace records the certification as effective August 6, four days before the announcement.

Two things separate this from routine compliance news. First, the architecture: Cloudflare says the government offering runs on the same public network and software stack that serve its commercial customers, not on a walled-off government replica. The Marketplace entry indeed lists the deployment model as public cloud. In FedRAMP’s top tier that is the exception rather than the rule. Second, the label: Cloudflare brands the milestone with FedRAMP’s new Class D vocabulary, and FedRAMP’s own roadmap says Class D certifications will only be piloted next fiscal year.

Key facts

  • What was announced. Cloudflare for Government achieved FedRAMP High, announced August 10 with NIST as sponsoring agency. The FedRAMP Marketplace lists the service at impact level High with certification effective August 6, 2026.
  • What High covers. In Cloudflare’s description, the nation’s most sensitive unclassified data: law enforcement, emergency services, financial systems and national security, where a compromise could be catastrophic.
  • How long it took. Cloudflare has held FedRAMP Moderate since December 2022. The Marketplace event log shows the High authorization entering process on November 12, 2025 and certifying on August 6, 2026, roughly nine months later.
  • The architecture claim. No separate government cloud. The High offering runs on Cloudflare’s global network through software-defined regionality, with its Data Localization Suite keeping all traffic inspection and processing for FedRAMP High services inside U.S. data centers.
  • How unusual that is. By our count of the Marketplace dataset, 92 services hold a High-level certification: 66 run as government community clouds and 18 as public clouds, with 8 hybrids.
  • The label is ahead of the program. Cloudflare calls it Class D, the High tier in FedRAMP’s new naming. The Marketplace records the certification as Rev5, the classic path, and FedRAMP’s roadmap schedules the Class D pilot for fiscal 2027.
  • Who already signed. The Marketplace lists 22 agency authorizations, including CISA, the Departments of State and Commerce, the Federal Reserve System, the Social Security Administration, the Census Bureau and the U.S. Election Assistance Commission.
  • What comes next. Cloudflare says the systems built for FedRAMP High are the foundation for pursuing Department of Defense Impact Level 4, the standard for controlled unclassified defense data. That is a commitment, not an achievement yet.

One Network Instead of a Government Island

The standard playbook for selling clouds to the U.S. government has been to build a separate, isolated environment for it. Cloudflare calls those environments technology islands and argues they lag years behind the commercial platforms they copy, forcing agencies to choose between modern features and stringent compliance. Its bet is the opposite: one global network, the same software stack in every data center, with compliance carved out in software rather than in separate buildings.

The mechanism is what Cloudflare calls software-defined regionality, applied through its Data Localization Suite. For FedRAMP High services, the company says, all traffic inspection and processing happens exclusively inside its U.S. data centers, while the platform itself stays the one commercial customers use. Back in 2022 the company put the FedRAMP scope at more than 30 U.S. data centers running its full stack locally. The pitch to agencies is that they get new Zero Trust, performance and developer features when they are released, not years later.

That suite is not a government one-off. It is the same product Cloudflare markets for data-locality obligations elsewhere, including in Europe. That makes this authorization a test of a broader proposition: that residency and sovereignty requirements can be met with rules on a shared networkrather than with separate infrastructure.

The Marketplace data shows how unusual that stance still is at the top tier. The entry for Cloudflare for Government – High lists the deployment model as public cloud. Of the 92 services certified at High, by our count, 66 run as government community clouds, 18 as public clouds and 8 as hybrids.

Nearly Four Years from Moderate to High

Cloudflare secured FedRAMP Moderate authorization in December 2022. Moving up to High is not an incremental step. Cloudflare describes it as a substantial increase in both the complexity of the requirements and the consequences of failing them. Its own illustration of the gap: Moderate suits something like a national park admission system, while High is where law enforcement, emergency services, financial systems and national security data live.

The Marketplace record puts dates on the climb. The High authorization entered Agency Authorization In Process status on November 12, 2025, passed review by the FedRAMP Program Management Office, and reached certified status on August 6, 2026. That is roughly nine months from formal start to finish, sponsored by NIST and assessed by Schellman Compliance. Cloudflare’s announcement followed four days later.

The Class D Label Runs Ahead of FedRAMP’s Calendar

FedRAMP is in the middle of an overhaul it calls FedRAMP 20x, and part of the overhaul is new vocabulary. Certifications are being reorganized into classes, and the mapping to the familiar baselines is direct.

20x classCorresponds toStatus per fedramp.gov
Class APilot certificationRules finalized, available now
Class BLowRules finalized, available now
Class CModerateRules finalized, available now
Class DHighTo be developed in Phase 4; pilot estimated for fiscal 2027

That last row is the catch. FedRAMP’s 20x page states that Class D certifications will be developed during Phase 4 of the program, with the Class D (High) pilot estimated for the first half of fiscal 2027. The Marketplace, meanwhile, records Cloudflare’s new authorization as Rev5, the classic certification path, which FedRAMP will keep accepting until June 11, 2027 before transitioning everyone to the new model.

The dataset makes the same point in numbers. It already carries 28 services certified under the 20x model, 14 at Low and 14 at Moderate, with another 19 listed in initial implementation. Not one 20x certification is at High.

None of this makes the authorization less real. It is listed, at High, with a federal sponsor and a named assessor. But precision matters in a story about compliance labels: what Cloudflare achieved is a Rev5 High authorization, and Class D is the program’s forthcoming name for that tier, adopted early in Cloudflare’s marketing rather than issued by FedRAMP. Agencies reading the announcement against the Marketplace will notice the difference.

Twenty-Two Agencies On Board, and the Defense Market Next

The authorization does not start from zero. The Marketplace lists 22 agency authorizations for Cloudflare for Government. The roster runs from CISA and the Departments of State and Commerce to the Federal Reserve System, and takes in national laboratories like Argonne and Fermilab. For scale: of the 513 services listed with certified status in the Marketplace dataset, 92 hold High, so Cloudflare joins a tier that fewer than one in five certified services reaches.

The next move is aimed at the defense market. Cloudflare says the systems it built for FedRAMP High were designed with Department of Defense Impact Level 4 controls in mind and will be the backbone of a pursued IL4 authorization, the Pentagon’s standard for controlled unclassified data. If the same no-island architecture clears that bar too, the argument that government workloads require separate clouds gets harder to make. Until then, IL4 remains a stated commitment, and the certified reality is FedRAMP High.

About the Data

Marketplace figures in this article come from the dataset published on fedramp.gov, retrieved on August 10, 2026. They cover the Cloudflare for Government – High record (status, dates, certification type, assessor, deployment model, agency list) and our own counts of unique service records, filtered to certified status, by impact level, certification type and deployment model. Timeline dates are decoded from the record’s event log. Descriptions of the architecture, the class definitions and the IL4 plans are attributed to Cloudflare’s announcements and FedRAMP’s program pages.