Once Atlassian achieves its FedRAMP certification what marketplace apps will be available in the public sector cloud? Will all the apps currently available still be accessible or will each marketplace app also have to obtain a separate FedRAMP certification? We have plans to move to the public sector cloud once FedRAMP certification is achieved but also need to be able to continue to use several of the marketplace apps for Jira.
Welcome to the Atlassian Community!
My understanding is that because the apps are not provided by Atlassian, they will need to get their own certifications.
At the moment, there's no point - they run on top of a non-certified platform, so they can't be certified until after Atlassian is.
Thanks for your response. I definitely understand that there isn't much point to having the certification until after Atlassian gets certified but my concern is that the FedRAMP certification process is extremely lengthy and the vendors that I've spoken with that offer a Jira plugin version of their application do not even have FedRAMP on their roadmap. So if the tools we currently use within Jira are not FedRAMP certified it would delay the timeline that we could move to the public sector which opens a different can of worms for us in terms of future planning.
I agree with you, it disappoints me to think vendors are not even looking at the process. It does not make a lot of sense to me for a vendor to be thinking "we'll start our compliance journey when the platform we build for gets their certification".
But I understand that we can be a bit stuck. There's no point applying until we can say "the underlying platform complies"; we're bound by the process. But we can design and code for it, so we can start the process the day Atlassian gets their certification, or even apply now for something with "this is only valid after the platform gets it too"