{"version":"v1","site":{"name":"expectedwrong","url":"https://expectedwrong.com"},"links":{"collection":"https://expectedwrong.com/api/public/posts","rss":"https://expectedwrong.com/rss.xml","llms":"https://expectedwrong.com/llms.txt"},"post":{"slug":"cloudflare-ate-the-compliance-layer","title":"Cloudflare Ate the Compliance Layer","subtitle":"FedRAMP Moderate covers Cloudflare's entire service architecture, which means something wild for anyone building on it.","url":"https://expectedwrong.com/cloudflare-ate-the-compliance-layer","api_url":"https://expectedwrong.com/api/public/posts/cloudflare-ate-the-compliance-layer","published_at":1753272000,"published_at_iso":"2025-07-23T12:00:00.000Z","updated_at":1771557918,"updated_at_iso":"2026-02-20T03:25:18.000Z","tags":["cloudflare","fedramp","compliance","government","infrastructure"],"excerpt":"FedRAMP Moderate covers Cloudflare's entire service architecture, which means something wild for anyone building on it.","meta_description":"FedRAMP Moderate covers Cloudflare's entire service architecture, which means something wild for anyone building on it.","reading_time_minutes":2,"word_count":256,"engagement":{"signals":0,"counterpoints":0},"body_markdown":"FedRAMP is the federal government's way of making sure cloud services are secure enough to touch unclassified data — a years-long, extremely expensive authorization process that most startups treat the way most people treat dental work: necessary eventually, painful now, easy to defer.\n\nCloudflare authorized their entire service architecture under FedRAMP Moderate.\n\nNot a product. Not a subset of products. The architecture. Workers, the network, the platform underneath everything. Which means that if you build your app on Cloudflare — actually build it there, not just route traffic through it — you're inheriting a significant chunk of the compliance posture your government customer is going to ask about.\n\nThis is not how anyone expected this to work. The normal move is to build your thing, then spend eighteen months and several hundred thousand dollars getting FedRAMP'd individually, then discover the authorization scope doesn't cover the one service you actually needed.\n\nCloudflare skipped that step on behalf of everyone building on them. The floor is already certified. You're placing your application on top of a surface that federal agencies have already evaluated and accepted for CUI and other unclassified use cases.\n\nThe cynical read is that this is an extremely smart enterprise sales motion dressed up as infrastructure. The less cynical read is that it's the same thing, and it also genuinely removes a real barrier for small teams trying to sell into sectors that have historically required a compliance budget larger than their engineering budget.\n\nBoth reads are correct. This is how good platform decisions work.","body_text":"FedRAMP is the federal government's way of making sure cloud services are secure enough to touch unclassified data — a years-long, extremely expensive authorization process that most startups treat the way most people treat dental work: necessary eventually, painful now, easy to defer. Cloudflare authorized their entire service architecture under FedRAMP Moderate. Not a product. Not a subset of products. The architecture. Workers, the network, the platform underneath everything. Which means that if you build your app on Cloudflare — actually build it there, not just route traffic through it — you're inheriting a significant chunk of the compliance posture your government customer is going to ask about. This is not how anyone expected this to work. The normal move is to build your thing, then spend eighteen months and several hundred thousand dollars getting FedRAMP'd individually, then discover the authorization scope doesn't cover the one service you actually needed. Cloudflare skipped that step on behalf of everyone building on them. The floor is already certified. You're placing your application on top of a surface that federal agencies have already evaluated and accepted for CUI and other unclassified use cases. The cynical read is that this is an extremely smart enterprise sales motion dressed up as infrastructure. The less cynical read is that it's the same thing, and it also genuinely removes a real barrier for small teams trying to sell into sectors that have historically required a compliance budget larger than their engineering budget. Both reads are correct. This is how good platform decisions work.","hindsight":{"verdict":"right","note":"FedRAMP for the whole architecture, not just a product. The compliance layer becoming something you inherit by building on Cloudflare — that was a genuine unlock for the startup ecosystem.","links":[],"at":1739980800,"at_iso":"2025-02-19T16:00:00.000Z"}}}