Dev News Daily ENDE

Amazon EVS enters FedRAMP Class C scope across the US Regions

AWS has placed Amazon Elastic VMware Service in scope for FedRAMP Class C in all United States Regions. The notice is dated 21 September 2026, and it records a naming change worth noting on its own: Class C is what the programme previously called the Moderate baseline.

Amazon EVS runs VMware Cloud Foundation directly inside a customer's own VPC on EC2 bare-metal instances. AWS describes standing up a complete VCF environment in a few hours, with the stated purpose of moving existing workloads off ageing infrastructure and out of a data centre on a deadline.

FedRAMP is the US government-wide scheme for security assessment, authorisation and continuous monitoring of cloud services. Being in scope is an entry in the programme's services list, not a property of any particular deployment.

Amazon EVS enters FedRAMP Class C scope across the US Regions
Amazon EVS enters FedRAMP Class C scope across the US Regions — Dev News Daily

What it means

For a team running a VMware estate under a federal compliance obligation, this changes the shape of a migration argument rather than the technology. The lift-and-shift path was already available; what was missing was the paperwork that lets it be proposed in an environment with an authorisation boundary.

Two cautions are worth carrying. In scope is not authorised: the customer's own system still has to be assessed, and inheritance of controls has to be documented rather than assumed. And the rename from Moderate to Class C will outlive this announcement — internal policies, contract language and control matrices that quote the old baseline name will need a pass, and that work is easy to defer until an auditor finds it.

Written by Victoria Shinder.