Software that runs inside customer-managed infrastructure creates a particular challenge at the FedRAMP High baseline. It still has to meet the applicable security and compliance requirements, even though the vendor does not control the surrounding operating system, libraries, network configuration, or maintenance practices. For Datadog, that challenge centers on the Datadog Agent, which runs directly on customer-managed hosts to collect logs, metrics, traces, and security signals.
The scale of those requirements is substantial. The current Rev. 5 FedRAMP High baseline defines more than 400 controls that have to be implemented, documented, and supported with evidence over time. Meeting those requirements involved significant engineering and operational work, along with ongoing responsibility for maintaining compliance. That commitment also helps explain why organizations operating at this level often have fewer options for critical capabilities such as observability and security monitoring.
Meeting that bar required more than extending the architecture we had developed for FedRAMP Moderate. The Agent needed to use the required cryptography across its Go and Python runtimes, remain within clearly defined cryptographic boundaries, and fail predictably if those requirements could not be met. Those guarantees also needed to be maintained as customer environments and the Agent itself changed over time.







