How to Meet FedRAMP Wi-Fi Security Requirements with Keytos
What is FedRAMP and Am I Subject to It?
FedRAMP, or the Federal Risk and Authorization Management Program, is a US government program that holds cloud service offerings to strict security standards before they can be used by federal agencies. It helps make sure that these cloud offerings meet rigorous security requirements and protect sensitive government data.
If you are a cloud service provider (CSP) looking to sell to US federal agencies, you will need to understand and comply with FedRAMP requirements. This includes implementing the necessary security controls, undergoing the required assessments, and obtaining authorization before your cloud service offering can be used by federal agencies.
What Are the FedRAMP Impact Levels and Certification Classes?
An Impact Level in FedRAMP represents the potential impact on an organization if the cloud service offering were to experience a security breach or failure, rated as either Low, Moderate, High. It determines the stringency of the security controls that must be met for a specific CSP, and helps agencies assess the risk associated with using that cloud service offering. For example, a cloud service that handles highly sensitive government data would be assigned a High impact level, where a cloud service handling anonymous or less sensitive data might be assigned a Low impact level.
Certification Classes, on the other hand, describe the level of assurance a cloud service provider commits to supply regarding their security controls and practices. They are labeled from A, B, C, or D and are not directly tied to the impact levels, meaning a higher certification class does not necessarily indicate a more secure cloud service offering. At a high level:
- Class A: Adequate for use in pilots, during configuration and testing, or for extremely low or negligible risk use cases such as processing public information or getting started with very few users.
- Class B: Adequate for use in most Low impact agency information systems and some Moderate or High impact agency information systems with appropriate compensating controls.
- Class C: Adequate for use in most Low or Moderate impact agency information systems and some High impact agency information systems with appropriate compensating controls.
- Class D: Adequate for use in most agency information systems regardless of the impact level, especially when deployed with appropriate compensating controls.
We’ll cover this more in a bit, but when it comes to network security and Wi-Fi, the impact level and certification class will influence the specific controls and measures you need to implement to ensure compliance and protect sensitive data.
What Changed With FedRAMP 20x and the 2026 Consolidated Rules?
If you’ve been paying attention to the FedRAMP space over the past year or two, you’ve probably heard the term “FedRAMP 20x” being thrown around. This refers to the updated framework and guidelines that FedRAMP has introduced, which aim to streamline the authorization process and enhance security measures for cloud service providers.
While the previous Revision 5 (Rev5) framework included multiple network and authentication controls, FedRAMP 20x introduces several new Key Security Indicators (KSIs) relevant to Wi-Fi/network auth:
- KSI-IAM: Enforces identity and access management controls, including multi-factor authentication and zero trust principles.
- KSI-MLA: Enforces monitoring, logging, and auditing controls to ensure continuous oversight and accountability of cloud service activities.
- KSI-NET: Enforces network security controls, including encryption of network traffic and segmentation of sensitive data.
- KSI-AUT: Enforces authentication controls, ensuring that only authorized users and devices can access the network and cloud services.
Does FedRAMP Apply to My Corporate Wi-Fi?
We get this question a lot from organizations trying to understand the scope of FedRAMP compliance for their corporate Wi-Fi networks. While you should always consult with your 3PAO (Third Party Assessment Organization) or compliance advisor, here are some general guidelines to help you determine if your corporate Wi-Fi falls within the FedRAMP authorization boundary.
- Determine if your Wi-Fi is part of the authorization boundary: The first step is to assess whether your corporate Wi-Fi network is included in the FedRAMP authorization boundary. If it connects to systems that handle federal data or are part of the authorized environment, it is likely in scope.
- Assess network segmentation: If your corporate Wi-Fi is segmented from the systems within the authorization boundary, it may be considered out of scope. However, you must be able to demonstrate and document this segmentation to your assessors.
- Consult with your 3PAO or compliance advisor: Ultimately, the determination of whether your corporate Wi-Fi is in scope for FedRAMP should be made in consultation with your 3PAO or compliance advisor. They can help you interpret the guidelines and ensure that your network is properly assessed.
At the end of the day, it’s actually much easier to move to strong EAP-TLS certificate-based Wi-Fi authentication for all your networks, even those that are currently considered out of scope for FedRAMP. This approach not only simplifies compliance but also enhances overall network security.
Does FedRAMP Require FIPS 140 Validated Encryption for Wi-Fi?
When it comes to Wi-Fi encryption, FedRAMP requires the use of FIPS 140-validated cryptographic modules to ensure that data transmitted over wireless networks is protected according to federal standards. This typically means using WPA2 or WPA3 Enterprise with AES encryption, backed by FIPS 140-3 validated cryptographic modules in access points, controllers, and RADIUS servers.
Ok, but what does that actually mean in practice? When selecting hardware and software for your Wi-Fi network, you need to verify that each component performing cryptographic operations (for example your CA issuing/signing certificates) uses an FIPS 140-3 validated cryptographic module. EZCA by Keytos is an example provider that offers FIPS 140-3 validated certificates that are backed by a FIPS 140-3 validated Hardware Security Module (HSM). It can then be used with EZRADIUS for secure, FIPS 140-3 compliant Wi-Fi authentication.
Looking for both FIPS 140-3 validated certificates and a compliant cloud RADIUS solution? Keytos Shield provides an integrated solution for secure, FedRAMP-compliant Wi-Fi authentication that combines Keytos’ cloud PKI and cloud RADIUS solutions in a single, easy-to-deploy platform.
Why Is EAP-TLS the Best Wi-Fi Authentication for FedRAMP?
EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) is widely regarded as the most secure method for Wi-Fi authentication in FedRAMP environments. It leverages certificate-based authentication, which eliminates passwords and phishing risks, ensuring that only devices with valid certificates can connect to the network.
When backed by a Trusted Platform Module (TPM), the certificates used for EAP-TLS authentication are securely stored and protected from extraction or tampering, further enhancing the security of the Wi-Fi network. Even if an attacker gains physical access to the device, they would not be able to easily extract the private key, making unauthorized network access significantly more difficult.
Why Is Active Directory Certificate Services (AD CS) a Challenge for FedRAMP?
If you’re running your own Active Directory Certificate Services (AD CS) environment, you may face several challenges in meeting FedRAMP requirements. The largest challenge is ensuring you’re using FIPS 140-3 validated cryptographic modules for all certificate operations, which can be complex and costly to implement and maintain, as this typically requires a Hardware Security Module (HSM) that is FIPS 140-3 validated. Additionally, managing the lifecycle of certificates, ensuring proper revocation, and maintaining compliance with FedRAMP controls can add significant operational overhead.
A cloud-hosted PKI solution, such as Keytos Shield or EZCA, can help mitigate these challenges by providing FIPS 140-3 validated cryptographic modules and simplifying certificate management, revocation, and compliance with FedRAMP controls.
Why Is Windows NPS a Problem for FedRAMP Environments?
Your first instinct might be to deploy Windows NPS for Wi-Fi authentication, but this approach actually complicates your FedRAMP compliance efforts due to the additional infrastructure, management, and security requirements it introduces. From deploying and patching Windows Servers to collecting and maintaining audit logs, every aspect of the NPS deployment adds to your compliance burden. We’ve worked with customers who have spent tens of thousands of dollars and countless hours managing NPS infrastructure, only to realize that they missed critical compliance controls or faced unexpected security gaps in their on-premises deployments. Even when running in Azure or Azure GCC High, NPS does not natively use Entra ID as its identity store, and classic RADIUS over UDP can be constrained by Azure networking limitations.
At the end of the day, a cloud-based RADIUS solution like EZRADIUS can significantly reduce this burden while maintaining strong security and compliance posture.
How Do I Move to Cloud RADIUS in a FedRAMP Environment?
If you’re considering a cloud-hosted PKI and cloud RADIUS solution for your FedRAMP environment, the process generally involves setting up a secure PKI for issuing device certificates, configuring your cloud RADIUS server to trust the issuing CA, and deploying Wi-Fi profiles to your devices using a mobile device management (MDM) solution like Intune. This approach minimizes on-prem infrastructure while ensuring strong security and compliance at every step.
For related guidance, review Keytos solutions for GCC High, the CMMC network authentication and PKI requirements, and our cloud RADIUS service comparison.
Step 1: How Do I Scope and Document Wireless Access?
Before setting up your PKI and cloud RADIUS, it’s important to scope and document your wireless access. This includes inventorying SSIDs, authentication methods in use, device types (managed, BYOD, IoT/MAB), and which SSIDs touch the boundary. Having a clear picture of which devices need to connect to which SSIDs will help you design your PKI and RADIUS configuration more effectively.
Step 2: How Do I Set Up a PKI for Wi-Fi Certificates in GCC High?
Since Microsoft Cloud PKI isn’t available in GCC High as of this writing, you’ll need to use an alternative PKI solution such as Keytos Shield, EZCA or an existing AD CS environment. This ensures that you can issue and manage certificates for your Wi-Fi authentication.
Once you have your PKI environment ready, you can leverage an MDM solution like Microsoft Intune to issue certificates from the CA to your devices, enabling them to authenticate to your Wi-Fi network using EAP-TLS. Refer to this guide for detailed instructions on distributing network profiles with Intune.
Step 3: How Do I Configure Cloud RADIUS for EAP-TLS?
Now that your PKI is set up and your devices have the necessary certificates, you can configure your cloud RADIUS server to authenticate Wi-Fi clients using EAP-TLS. A RADIUS server connects to your WPA Enterprise network to validate the client certificate presented by each device during the authentication process. Keytos Shield and EZRADIUS are both great options for a GCC High deployment.
Refer to the same Intune guide for onboarding to cloud RADIUS and distributing network profiles with Intune.
Step 4: How Do I Push Wi-Fi Profiles to Devices With Intune?
Now that your cloud RADIUS server is configured and your devices have the necessary certificates, you can push Wi-Fi profiles to your devices using Intune. This ensures that all devices are correctly set up to authenticate to your Wi-Fi network using EAP-TLS. The same Intune guide provides detailed instructions on how to deploy Wi-Fi profiles to complete the process. At this point your devices can now successfully connect to your Wi-Fi network using certificate-based authentication.
Step 5: How Do I Collect Audit Evidence for Assessors?
To prove compliance and provide audit evidence for assessors, you should collect and maintain logs from your cloud RADIUS server, including authentication attempts, certificate validation results, and any revocation checks. Additionally, document your Wi-Fi profile deployment process, PKI configuration, and any changes made to your network policies. This evidence will help demonstrate that your organization is following proper security practices and meeting relevant FedRAMP requirements.
To manually collect audit evidence, you can refer to this guide for detailed instructions on accessing and exporting audit logs from your cloud RADIUS server.
To streamline the audit evidence collection process, consider integrating your cloud RADIUS server with a centralized logging solution such as Microsoft Sentinel or Splunk. This allows for automated collection, correlation, and retention of authentication logs, making it easier to provide comprehensive evidence during audits. Refer to this guide for more information.
Step 6: How Do I Cut Over From NPS or PSK Without Downtime?
If you’re migrating from NPS or a pre-shared key (PSK) setup, it’s important to plan the cutover carefully to avoid downtime. Start by running a parallel SSID or pilot group with the new cloud RADIUS configuration. Gradually migrate devices by group, ensuring that each group can successfully authenticate using EAP-TLS. Once all devices have been migrated, retire the NPS servers or shared credential and remove the old SSID.
Is Keytos FedRAMP Authorized?
While Keytos offers a robust cloud RADIUS solution that is SOC 2 Type 2 compliant and ISO 27001 certified, it is important to note that it is not FedRAMP authorized itself at this time. This means that organizations using Keytos for cloud RADIUS must still ensure their overall environment meets FedRAMP requirements and should work with their assessors to determine how Keytos fits into their compliance strategy.
Keytos Shield, EZCA, and EZRADIUS can help you implement a secure and compliant cloud RADIUS solution, even in environments that require adherence to stringent security standards like FedRAMP, such as GCC High.
How Do I Get Started With Secure Wi-Fi Authentication for FedRAMP?
If you are looking to secure your Wi-Fi and network authentication in your GCC High or other FedRAMP-regulated environments, Keytos Shield, EZCA, and EZRADIUS provide the necessary tools and infrastructure to help you implement a secure and compliant cloud RADIUS solution. Every solution provides a free 1-month trial, with tutorials and video guides to help you get started quickly.
Want to talk to the Keytos team about your specific requirements and how our solutions can help you achieve a secure and compliant cloud RADIUS setup? You can book a free consultation and get personalized guidance on implementing cloud RADIUS in your environment.