- Q01Has Bubble ever pursued FedRAMP authorisation or GovCloud hosting?
- No. FedRAMP is not mentioned anywhere on bubble.io. There is no entry on marketplace.fedramp.gov. Bubble Enterprise dedicated lets you pick from commercial AWS regions — Tel Aviv, Mexico, N. California, N. Virginia — but no GovCloud, Azure Government, or GCP Assured Workloads option. The position has been silent for the entire history of the product and there is no indication that's on the roadmap.
- Q02Could a plugin or wrapper bring Bubble inside a FedRAMP boundary?
- No. FedRAMP assesses the environment and its operating controls, not a JavaScript shim on top. Plugins run inside Bubble's browser runtime and Bubble's server runtime — neither is FedRAMP-authorised, neither can be enumerated inside an agency authorising official's boundary, and the 3PAO has no mechanism to accept either as evidence. Plugins make the boundary problem worse, not better.
- Q03Is there any hybrid that keeps Bubble in a federal architecture?
- No. Federal data cannot transit a non-authorised commercial multi-tenant runtime. Even when the intent is to keep federal data elsewhere, Bubble's plugin runtime can read any page data, shared logs capture access events, and continuous backups retain data the developer thought was scoped out. Authorising officials cannot draw a defensible boundary around any of that.
- Q04How long does a FedRAMP-friendly rebuild take?
- For Rev5 the rule of thumb is roughly 12 months for Low, 12–18 months for Moderate, and 18–36 months for High end-to-end, including the agency sponsor's ATO. The FedRAMP 20x programme announced on March 24, 2025 targets 3–6 months for Low and Moderate authorisations on cloud-native rebuilds, with the first pilot completed in 119 days. The Phase 1 (Low) cohort closed in 2025 with 26 CSPs authorised; Phase 2 (Moderate) launched November 2025.
- Q05Does FedRAMP overlap with CMMC, FISMA, or StateRAMP / GovRAMP?
- Heavily. FedRAMP and CMMC both reach back to NIST control libraries — FedRAMP to 800-53 and CMMC Level 2 to 800-171 (a tailored subset of 800-53). The DoD has signalled FedRAMP / CMMC reciprocity as a goal of the FedRAMP 20x programme. FISMA covers federal agencies' own systems; FedRAMP is the cloud-services lane underneath. GovRAMP (formerly StateRAMP) reuses much of the FedRAMP toolkit at the SLED level and supports reciprocity with FedRAMP Moderate.
- Q06Can you sign anything covering FedRAMP on our behalf?
- Bubble will not — they have no FedRAMP posture. AWS GovCloud, Azure Government, and GCP Assured Workloads sign the federal contracts that inherit FedRAMP High posture for the underlying infrastructure; the cloud service offering's own ATO is signed by the sponsoring agency's authorising official (or by the FedRAMP PMO under 20x). As the engineering partner we sign the contractor agreements covering our access during the build; the production ATO is signed against the rebuilt environment, not against us.