FedRAMP Authorized — Moderate Impact

Rackspace Government Cloud by Rackspace. 6 compliance features verified.

Infrastructure as a Service

Rackspace Government Cloud

by Rackspace

Moderate ImpactAuthorized

Impact Level

Moderate

Status

Authorized

Pricing

mid market

Authorization Date: November 8, 2016 | Sponsoring Agency: DoD

Overview

Rackspace Government Cloud provides managed cloud hosting with a focus on personalized support and hybrid cloud solutions for government agencies. It offers dedicated hosting environments with FedRAMP Moderate authorization and managed security services. The platform excels at complex multi-cloud management.

Key Features

FedRAMP Moderate baseline controls
Managed security services
Dedicated hosting environments
Hybrid cloud management
24/7 government support teams
Fanatical Support for Government

Certifications & Authorizations

FedRAMP Moderate Authorization (JAB P-ATO)SOC 2 Type IIISO 27001:2013PCI DSS Level 1 Service ProviderHIPAA compliance frameworkSSAE 18 SOC 1 Type IIDoD SRG Impact Level 2 (IL2) compliant architecture

Deployment Options

Rackspace Government Cloud — Dedicated hosted infrastructure in FedRAMP-authorized data centers
Hybrid cloud integration with AWS GovCloud (US-East/US-West) through Rackspace Managed AWS
Private cloud deployment with dedicated bare metal servers and network isolation
Multi-tenant FedRAMP Moderate environment with logical separation
Dedicated VMware vSphere clusters with government-only tenancy
Managed OpenStack private cloud with dedicated compute and storage resources

NIST 800-171 Compliance Coverage

87% of controls covered

How to Procure Rackspace Government Cloud for Defense Contracts

Rackspace Government Cloud is available through GSA Multiple Award Schedule (MAS) under SIN 518210C (Cloud Computing Services) and SEWP V contracts. Government pricing typically includes volume discounts of 15-25% compared to commercial rates, with additional savings through committed use agreements. The authorization boundary encompasses Rackspace's dedicated government data centers, managed services platform, and customer support infrastructure - all documented in the FedRAMP SSP available through the FedRAMP Marketplace. Contracting officers must approve the cloud service agreement, data processing addendum, and incident response procedures that align with agency-specific requirements. Procurement timeline averages 60-90 days including technical evaluation, security assessment review, and contract negotiation. For CMMC compliance, include Rackspace Government Cloud within your assessment boundary as a Critical Service Provider (CSP), ensuring their FedRAMP authorization covers your CUI processing requirements. The service inherits 147 of 320 NIST 800-171 controls, reducing your implementation burden. Coordinate with Rackspace's government compliance team early in procurement to validate control inheritance mapping and establish monitoring agreements required for continuous compliance demonstration.

Compliance Cross-References

Rackspace Government Cloud's FedRAMP Moderate authorization directly satisfies DFARS 252.204-7012 requirements for adequate security on contractor information systems processing CUI. The service meets DFARS 252.239-7010 cloud computing security requirements through JAB-authorized controls and dedicated government infrastructure. NIST 800-171 control families are substantially inherited: Access Control (AC) through identity management and RBAC, System and Communications Protection (SC) via boundary protection and encryption, and Audit and Accountability (AU) through comprehensive logging and SIEM capabilities. For CMMC Level 2 compliance, the platform addresses Asset Management (AM), Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), Incident Response (IR), Risk Assessment (RA), Security Assessment (CA), and System and Communications Protection (SC) domains through inherited controls. DoD Cloud Computing SRG Impact Level 2 requirements are met through the FedRAMP baseline plus additional DoD-specific controls for data location, personnel screening, and incident reporting protocols.

Defense Contractor Use Case

Defense contractors use Rackspace Government Cloud when they need managed cloud services with dedicated support, particularly for complex multi-cloud or hybrid deployments with moderate sensitivity data.

Frequently Asked Questions

What is the FedRAMP authorization level for Rackspace Government Cloud?

Rackspace Government Cloud is authorized at the FedRAMP Moderate impact level, with authorization granted on 2016-11-08 sponsored by DoD. The FedRAMP Moderate baseline includes approximately 325 security controls covering confidentiality, integrity, and availability.

Can defense contractors use Rackspace Government Cloud for CUI?

Rackspace Government Cloud is authorized at the FedRAMP Moderate baseline. While FedRAMP Moderate covers a broad range of government data, defense contractors handling CUI should carefully evaluate whether Moderate controls meet their specific DFARS 252.204-7012 and NIST 800-171 requirements. Some CUI categories may require FedRAMP High authorization depending on the sensitivity of the data and contract requirements.

How does Rackspace Government Cloud pricing compare to commercial?

Rackspace Government Cloud government pricing is generally competitive with commercial pricing, though the government edition may carry a premium of 10-20% to cover FedRAMP compliance and dedicated infrastructure costs. Mid-market organizations can often access government pricing through GSA Schedule contracts or reseller partners. Contact Rackspace for a quote tailored to your organization size and requirements.

Browse All FedRAMP Authorized Tools

Search and filter 80+ FedRAMP authorized products for your defense contracting needs.

Open FedRAMP Finder

Get a defensible CUI architecture

This Rackspace Government Cloud FedRAMP profile flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures