Skip to main content

FedRAMP High

This page describes FedRAMP High compliance controls in Databricks.

FedRAMP High overview​

FedRAMP High is a U.S. federal program that standardizes security assessment, authorization, and continuous monitoring for cloud products and services at the high impact level. It applies to cloud systems where a security breach could have severe or catastrophic effects on federal operations, assets, or individuals.

What FedRAMP High covers​

  • Applies to cloud services handling sensitive federal data at the high impact level.
  • Requires compliance with NIST SP 800-53 high baseline controls.
  • Requires strict access controls, including encryption in transit and at rest.

Enable FedRAMP High compliance controls​

The FedRAMP High authorization status of Databricks on AWS GovCloud is Authorized. Customers are responsible for implementing and operating applicable FedRAMP High compliance controls as documented in the Control Implementation Summary / Customer Responsibility Matrix in SSP Appendix J of the Databricks FedRAMP authorization documentation package. US Government agencies can obtain access to the Databricks FedRAMP High authorization documentation through the FedRAMP package access request form. Follow the instructions on the Databricks FedRAMP Marketplace listing (package ID: FR2324740262).

FedRAMP High compliance controls are available on Databricks on AWS GovCloud. The compliance security profile is enabled by default on all AWS GovCloud workspaces, which adds monitoring agents, provides a hardened compute image, and enforces Nitro instance types for inter-node encryption. Automatic cluster update and enhanced security monitoring are also enabled. For setup requirements, see Databricks on AWS GovCloud.

note

Serverless compute availability on AWS GovCloud:

  • Serverless SQL warehouses: Public Preview
  • Serverless compute for notebooks, jobs, and Lakeflow pipelines: Public Preview

You are solely responsible for verifying that sensitive information is never entered in customer-defined input fields, such as workspace names, compute resource names, tags, job names, job run names, network names, credential names, storage account names, and Git repository IDs or URLs. These fields might be stored, processed, or accessed outside the compliance boundary.

Regional support for features​

This table shows feature availability for the selected compliance standard across all supported Databricks regions. Some features may be listed as available before they are actually released.

Feature

us-gov-west-1

ABAC GRANT policies

✓

ABAC on Views

✓

AI Classify

AI Diagnose

AI Extract

AI Extract Precision Mode

AI Functions REST API

AI ParseDocument

AI Prep Search

AI Query for Custom Models and External Models

AI Search: Quality Evaluation

Access management privilege (‘MANAGE ACCESS CONTROL’)

✓

Advanced metadata viewing privilege ('READ METADATA')

✓

Agent Bricks - AI Functions

Agent Framework: On-Behalf-Of-User Authorization

✓

Agent Mode APIs for Genie Agents

✓

Ai Enrich

✓

Alert Job Task

✓

Alerts System Table

✓

Anomaly Detection

Apps Horizontal Scaling

✓

Attribute Based Access Control

✓

Auto-CDF (Change Data Feed)

✓

Backfills in Workflows

✓

Budget for Unity AI Gateway

Chat in Genie One

✓

Classic Compute

✓

Clean Room JAR Task

Clean Rooms

Cleanroom Identity Resolution Partners creation

Cluster Log Delivery to UC Volumes

✓

Collaborate on Databricks Asset Bundles from the workspace

✓

Comments on Foreign Tables

✓

Compute: Dedicated group clusters

✓

Context-based Ingress Control

Continuous Declarative Pipelines: Standard mode and improved notifications

✓

Cross-Platform View Sharing

✓

Cross-engine ABAC

✓

Custom JDBC on UC Compute

✓

Custom LLM Serving for Databricks Model Serving

✓

Custom bundle templates in the workspace

✓

DCS-vNext

✓

DLT Direct Publishing Mode

✓

Dashboard Genie Default Enabled

Data Classification

Data Room (Govcloud)

✓

Databricks Apps

✓

Databricks Apps - App Spaces

✓

Databricks Apps - Configure App Compute Size

✓

Databricks Apps - Install Apps from Git

✓

Databricks Apps - On-Behalf-Of User Authorization

✓

Databricks Apps - Webhook-Triggered Deployments (GitHub, Azure DevOps)

✓

Databricks Apps V2

✓

Databricks Genie for Microsoft Teams

Databricks Genie for Slack

Default Python package repositories in Spark Declarative Pipelines

✓

Default Python package repositories in clusters created via API

✓

Default Python package repositories in clusters created via UI

✓

Default Storage

Default warehouse setting

✓

Disabled tasks in Lakeflow Jobs

✓

Discover Page

✓

Domain Recommendations

Domains and Discover

✓

Embed Genie as an iframe

✓

Enable Dashboard Local Metric Views in AI/BI Dashboards

✓

Enable Extended Models

✓

Enables remote query table-valued function (remote_query).

✓

Enhanced Python UDFs in Unity Catalog

✓

EventBridge support for file events

✓

Excel Add-In

✓

Excel File Format Support

✓

Expiring personal access token notifications

✓

Expiring service principal access token notifications

✓

Extend Data Classification with Custom Classifiers

External Access to Unity Catalog Managed Delta Table

External secrets for Unity Catalog

✓

Feature Store Streaming Feature Views

✓

Feature Views (Batch)

✓

File type

✓

Fine-Grained DML Privileges

✓

Focused notebook & file editor for Git folders

✓

Foreign Delta Table Sharing

✓

Full Page Genie Code

✓

Genie Agent Mode

✓

Genie Chat Sharing

✓

Genie Code

✓

Genie Code Agent Mode

✓

Genie Code Scheduled Tasks

✓

Genie Code for dashboard authoring

✓

Genie Data Sampling

✓

Genie Inspect Answer

Genie One

✓

Genie One Mcp

Genie One Memory

✓

Genie Space Manager Sharing

✓

Genie Spaces

✓

Git CLI support for Git folders

✓

Google Drive Permission Connector

✓

Hubspot Connector CRM Hub Objects

✓

Iceberg Rest Catalog Federation

Iceberg V3

✓

Import from External BI to AI/BI

✓

Ip Functions

✓

Join Pushdown for Federated Queries

Knowledge Assistant

LTAP Direct Writes

LakeFlow Connect for Integrated Cdc MySQL Connector

✓

LakeFlow Connect for Integrated Cdc Oracle Connector

✓

LakeFlow Connect for Integrated Cdc Sql Server Connector

✓

Lakebase

Lakebase CDF

Lakebase Search

Lakeflow Connect - Confluence

✓

Lakeflow Connect - GA4

✓

Lakeflow Connect - Google Ads

✓

Lakeflow Connect - HubSpot

✓

Lakeflow Connect - Meta Ads

✓

Lakeflow Connect - MySQL

✓

Lakeflow Connect - PostgreSQL

✓

Lakeflow Connect - SFTP

✓

Lakeflow Connect - Salesforce

✓

Lakeflow Connect - ServiceNow

✓

Lakeflow Connect - TikTok Ads

✓

Lakeflow Connect - Workday HCM

✓

Lakeflow Connect - Workday Reports (RaaS)

✓

Lakeflow Connect - Zendesk Support

✓

Lakeflow Connect - Zerobus Ingest

Lakeflow Connect API Source Connectors

✓

Lakeflow Connect Community Connectors

✓

Lakeflow Connect Query Based Connectors

✓

Lakeflow Connect for Aha!

✓

Lakeflow Connect for Amplitude

✓

Lakeflow Connect for Anaplan

✓

Lakeflow Connect for Anthropic

✓

Lakeflow Connect for Anysphere Audit Logs

✓

Lakeflow Connect for Anysphere Org

✓

Lakeflow Connect for Atlassian Audit Logs

✓

Lakeflow Connect for Celigo

✓

Lakeflow Connect for Dynamics 365

Lakeflow Connect for Github

✓

Lakeflow Connect for Google Drive

✓

Lakeflow Connect for Google Search Console

✓

Lakeflow Connect for Google Workspace

✓

Lakeflow Connect for Ironclad

✓

Lakeflow Connect for Island Management Console

✓

Lakeflow Connect for Jira

✓

Lakeflow Connect for Kafka

✓

Lakeflow Connect for Monday.com

✓

Lakeflow Connect for Netskope Logs

✓

Lakeflow Connect for Netsuite

✓

Lakeflow Connect for OpenAI

✓

Lakeflow Connect for Outlook

✓

Lakeflow Connect for PagerDuty

✓

Lakeflow Connect for Pendo

✓

Lakeflow Connect for Salesforce Marketing Cloud

✓

Lakeflow Connect for SendGrid

✓

Lakeflow Connect for Sharepoint

✓

Lakeflow Connect for Slack Access and Integration Logs

✓

Lakeflow Connect for Smartsheet

✓

Lakeflow Connect for Square

✓

Lakeflow Connect for Strac

✓

Lakeflow Connect for Verkada

✓

Lakeflow Connect for Vimeo

✓

Lakeflow Connect for Wiz Audit Logs

✓

Lakeflow Connect for Workiva

✓

Lakeflow Connect for Zip

✓

Lakeflow Connect for Zoho Books

✓

Lakeflow Connect for Zoom Logs

✓

Lakeflow Designer

✓

Lakeflow Integrations

✓

Lakeflow Jobs

✓

Lakeflow Jobs Health

✓

Lakeflow Pipeline Events System Table

✓

Lakeflow Pipelines Editor

✓

Lakehouse Federation Sharing

Lakehouse Monitoring

✓

MLflow on Databricks

✓

MV and ST in Serverless Notebooks and Jobs

✓

Managed Disaster Recovery

Managed MCP Servers

✓

Managed MLflow Prompt Registry

✓

Marketplace - Install Databricks Apps

✓

Metric View Sharing

✓

Model Serving - AI Gateway (v1)

✓

Model Serving - AI Guardrail

Model Serving - AI Playground

Model Serving - Custom Models

✓

Model Serving - External Models

✓

Model Serving - Foundation Models AI Function (ai_query)

Model Serving - Foundation Models Pay-Per-Token

✓

Model update job triggers

✓

Models in Unity Catalog: Deployment Jobs

✓

Multiple Git Credentials

✓

Network Accept Logs

✓

New compute policy form

✓

OAuth Custom Identity Claim

✓

OpenSharing

✓

OpenSharing SecureConnect

OpenSharing for Default Storage – Expanded Access

OpenTelemetry for Databricks Apps

✓

OpenTelemetry for Databricks Model Serving

✓

OpenTelemetry on Databricks

Packaged Clean Rooms Mode

Pages

Partial runs in Workflows

✓

Personal access tokens auto-scoping

✓

Power BI task type

✓

Predictive Optimization

✓

Private Connectivity for Performance-Intensive Services

Production Monitoring for MLflow

✓

Query History & Profile for DLT

✓

Query performance insights

✓

Remote data sources write support on serverless compute

✓

Role-based access control (RBAC)

✓

Role-based access control (RBAC) account-level enablement

✓

SQL Alerts V2

✓

Salesforce Data Cloud file sharing federation

✓

Sample Data Exploration with Assistant

✓

Scala and Java UDFs in Unity Catalog

✓

Scoped personal access tokens

✓

Secrets in Unity Catalog

✓

Serverless Compute Access Control

✓

Serverless Compute Rate Limit

✓

Serverless DLT/Lakeflow Workspace Preview

✓

Serverless Forecast Python SDK

✓

Serverless GPU Compute

Serverless GPU Compute API Remote H100s

Serverless JARs

✓

Serverless Jobs/Notebooks Workspace Preview

✓

Serverless Jobs/Workflows/Notebooks

✓

Serverless Lakeflow Pipelines

✓

Serverless Private Git

✓

Serverless SQL warehouses

✓

Serverless Workspace

Sharepoint Permission Connector

✓

Sharing To Iceberg Clients

✓

Supervisor Agent

System Tables Configurable Retention

✓

Table Update Triggers on OpenSharing (Provider)

✓

Table Update Triggers on OpenSharing (Recipient)

✓

Tag Automations

✓

Tag Propagation

✓

Tag Propagation - Account Wide

✓

Tagging support for workspace scoped assets

✓

Third Party Connectors for Agents

✓

Time data type

✓

Transactions

✓

U2M For Service Principal

✓

Unified Runs List

✓

Unity AI Gateway

✓

Unity Ai Gateway Service Policies

Variant Shredding for Optimized Read Performance on Semi-Structured Data

Vector Search (Standard)

✓

Vector Search (Storage Optimized)

Vector Search High QPS

✓

Vector Search Reranker

✓

Vector Search: Full-Text Search

Visual authoring: UI <> YAML Sync for DABs in the Workspace

✓

Warehouse Activity Details

✓

Warehouse Statement Timeout

✓

Widget Data Attachments for Dashboard Subscriptions

✓

Workspace base environments for serverless compute

✓

Feature

us-gov-west-1

ABAC GRANT policies

✓

ABAC on Views

✓

AI Classify

AI Diagnose

AI Extract

AI Extract Precision Mode

AI Functions REST API

AI ParseDocument

AI Prep Search

AI Query for Custom Models and External Models

AI Search: Quality Evaluation

Access management privilege (‘MANAGE ACCESS CONTROL’)

✓

Advanced metadata viewing privilege ('READ METADATA')

✓

Agent Bricks - AI Functions

Agent Framework: On-Behalf-Of-User Authorization

✓

Agent Mode APIs for Genie Agents

✓

Ai Enrich

✓

Alert Job Task

✓

Alerts System Table

✓

Anomaly Detection

Apps Horizontal Scaling

✓

Attribute Based Access Control

✓

Auto-CDF (Change Data Feed)

✓

Backfills in Workflows

✓

Budget for Unity AI Gateway

Chat in Genie One

✓

Classic Compute

✓

Clean Room JAR Task

Clean Rooms

Cleanroom Identity Resolution Partners creation

Cluster Log Delivery to UC Volumes

✓

Collaborate on Databricks Asset Bundles from the workspace

✓

Comments on Foreign Tables

✓

Compute: Dedicated group clusters

✓

Context-based Ingress Control

Continuous Declarative Pipelines: Standard mode and improved notifications

✓

Cross-Platform View Sharing

✓

Cross-engine ABAC

✓

Custom JDBC on UC Compute

✓

Custom LLM Serving for Databricks Model Serving

✓

Custom bundle templates in the workspace

✓

DCS-vNext

✓

DLT Direct Publishing Mode

✓

Dashboard Genie Default Enabled

Data Classification

Data Room (Govcloud)

✓

Databricks Apps

✓

Databricks Apps - App Spaces

✓

Databricks Apps - Configure App Compute Size

✓

Databricks Apps - Install Apps from Git

✓

Databricks Apps - On-Behalf-Of User Authorization

✓

Databricks Apps - Webhook-Triggered Deployments (GitHub, Azure DevOps)

✓

Databricks Apps V2

✓

Databricks Genie for Microsoft Teams

Databricks Genie for Slack

Default Python package repositories in Spark Declarative Pipelines

✓

Default Python package repositories in clusters created via API

✓

Default Python package repositories in clusters created via UI

✓

Default Storage

Default warehouse setting

✓

Disabled tasks in Lakeflow Jobs

✓

Discover Page

✓

Domain Recommendations

Domains and Discover

✓

Embed Genie as an iframe

✓

Enable Dashboard Local Metric Views in AI/BI Dashboards

✓

Enable Extended Models

✓

Enables remote query table-valued function (remote_query).

✓

Enhanced Python UDFs in Unity Catalog

✓

EventBridge support for file events

✓

Excel Add-In

✓

Excel File Format Support

✓

Expiring personal access token notifications

✓

Expiring service principal access token notifications

✓

Extend Data Classification with Custom Classifiers

External Access to Unity Catalog Managed Delta Table

External secrets for Unity Catalog

✓

Feature Store Streaming Feature Views

✓

Feature Views (Batch)

✓

File type

✓

Fine-Grained DML Privileges

✓

Focused notebook & file editor for Git folders

✓

Foreign Delta Table Sharing

✓

Full Page Genie Code

✓

Genie Agent Mode

✓

Genie Chat Sharing

✓

Genie Code

✓

Genie Code Agent Mode

✓

Genie Code Scheduled Tasks

✓

Genie Code for dashboard authoring

✓

Genie Data Sampling

✓

Genie Inspect Answer

Genie One

✓

Genie One Mcp

Genie One Memory

✓

Genie Space Manager Sharing

✓

Genie Spaces

✓

Git CLI support for Git folders

✓

Google Drive Permission Connector

✓

Hubspot Connector CRM Hub Objects

✓

Iceberg Rest Catalog Federation

Iceberg V3

✓

Import from External BI to AI/BI

✓

Ip Functions

✓

Join Pushdown for Federated Queries

Knowledge Assistant

LTAP Direct Writes

LakeFlow Connect for Integrated Cdc MySQL Connector

✓

LakeFlow Connect for Integrated Cdc Oracle Connector

✓

LakeFlow Connect for Integrated Cdc Sql Server Connector

✓

Lakebase

Lakebase CDF

Lakebase Search

Lakeflow Connect - Confluence

✓

Lakeflow Connect - GA4

✓

Lakeflow Connect - Google Ads

✓

Lakeflow Connect - HubSpot

✓

Lakeflow Connect - Meta Ads

✓

Lakeflow Connect - MySQL

✓

Lakeflow Connect - PostgreSQL

✓

Lakeflow Connect - SFTP

✓

Lakeflow Connect - Salesforce

✓

Lakeflow Connect - ServiceNow

✓

Lakeflow Connect - TikTok Ads

✓

Lakeflow Connect - Workday HCM

✓

Lakeflow Connect - Workday Reports (RaaS)

✓

Lakeflow Connect - Zendesk Support

✓

Lakeflow Connect - Zerobus Ingest

Lakeflow Connect API Source Connectors

✓

Lakeflow Connect Community Connectors

✓

Lakeflow Connect Query Based Connectors

✓

Lakeflow Connect for Aha!

✓

Lakeflow Connect for Amplitude

✓

Lakeflow Connect for Anaplan

✓

Lakeflow Connect for Anthropic

✓

Lakeflow Connect for Anysphere Audit Logs

✓

Lakeflow Connect for Anysphere Org

✓

Lakeflow Connect for Atlassian Audit Logs

✓

Lakeflow Connect for Celigo

✓

Lakeflow Connect for Dynamics 365

Lakeflow Connect for Github

✓

Lakeflow Connect for Google Drive

✓

Lakeflow Connect for Google Search Console

✓

Lakeflow Connect for Google Workspace

✓

Lakeflow Connect for Ironclad

✓

Lakeflow Connect for Island Management Console

✓

Lakeflow Connect for Jira

✓

Lakeflow Connect for Kafka

✓

Lakeflow Connect for Monday.com

✓

Lakeflow Connect for Netskope Logs

✓

Lakeflow Connect for Netsuite

✓

Lakeflow Connect for OpenAI

✓

Lakeflow Connect for Outlook

✓

Lakeflow Connect for PagerDuty

✓

Lakeflow Connect for Pendo

✓

Lakeflow Connect for Salesforce Marketing Cloud

✓

Lakeflow Connect for SendGrid

✓

Lakeflow Connect for Sharepoint

✓

Lakeflow Connect for Slack Access and Integration Logs

✓

Lakeflow Connect for Smartsheet

✓

Lakeflow Connect for Square

✓

Lakeflow Connect for Strac

✓

Lakeflow Connect for Verkada

✓

Lakeflow Connect for Vimeo

✓

Lakeflow Connect for Wiz Audit Logs

✓

Lakeflow Connect for Workiva

✓

Lakeflow Connect for Zip

✓

Lakeflow Connect for Zoho Books

✓

Lakeflow Connect for Zoom Logs

✓

Lakeflow Designer

✓

Lakeflow Integrations

✓

Lakeflow Jobs

✓

Lakeflow Jobs Health

✓

Lakeflow Pipeline Events System Table

✓

Lakeflow Pipelines Editor

✓

Lakehouse Federation Sharing

Lakehouse Monitoring

✓

MLflow on Databricks

✓

MV and ST in Serverless Notebooks and Jobs

✓

Managed Disaster Recovery

Managed MCP Servers

✓

Managed MLflow Prompt Registry

✓

Marketplace - Install Databricks Apps

✓

Metric View Sharing

✓

Model Serving - AI Gateway (v1)

✓

Model Serving - AI Guardrail

Model Serving - AI Playground

Model Serving - Custom Models

✓

Model Serving - External Models

✓

Model Serving - Foundation Models AI Function (ai_query)

Model Serving - Foundation Models Pay-Per-Token

✓

Model update job triggers

✓

Models in Unity Catalog: Deployment Jobs

✓

Multiple Git Credentials

✓

Network Accept Logs

✓

New compute policy form

✓

OAuth Custom Identity Claim

✓

OpenSharing

✓

OpenSharing SecureConnect

OpenSharing for Default Storage – Expanded Access

OpenTelemetry for Databricks Apps

✓

OpenTelemetry for Databricks Model Serving

✓

OpenTelemetry on Databricks

Packaged Clean Rooms Mode

Pages

Partial runs in Workflows

✓

Personal access tokens auto-scoping

✓

Power BI task type

✓

Predictive Optimization

✓

Private Connectivity for Performance-Intensive Services

Production Monitoring for MLflow

✓

Query History & Profile for DLT

✓

Query performance insights

✓

Remote data sources write support on serverless compute

✓

Role-based access control (RBAC)

✓

Role-based access control (RBAC) account-level enablement

✓

SQL Alerts V2

✓

Salesforce Data Cloud file sharing federation

✓

Sample Data Exploration with Assistant

✓

Scala and Java UDFs in Unity Catalog

✓

Scoped personal access tokens

✓

Secrets in Unity Catalog

✓

Serverless Compute Access Control

✓

Serverless Compute Rate Limit

✓

Serverless DLT/Lakeflow Workspace Preview

✓

Serverless Forecast Python SDK

✓

Serverless GPU Compute

Serverless GPU Compute API Remote H100s

Serverless JARs

✓

Serverless Jobs/Notebooks Workspace Preview

✓

Serverless Jobs/Workflows/Notebooks

✓

Serverless Lakeflow Pipelines

✓

Serverless Private Git

✓

Serverless SQL warehouses

✓

Serverless Workspace

Sharepoint Permission Connector

✓

Sharing To Iceberg Clients

✓

Supervisor Agent

System Tables Configurable Retention

✓

Table Update Triggers on OpenSharing (Provider)

✓

Table Update Triggers on OpenSharing (Recipient)

✓

Tag Automations

✓

Tag Propagation

✓

Tag Propagation - Account Wide

✓

Tagging support for workspace scoped assets

✓

Third Party Connectors for Agents

✓

Time data type

✓

Transactions

✓

U2M For Service Principal

✓

Unified Runs List

✓

Unity AI Gateway

✓

Unity Ai Gateway Service Policies

Variant Shredding for Optimized Read Performance on Semi-Structured Data

Vector Search (Standard)

✓

Vector Search (Storage Optimized)

Vector Search High QPS

✓

Vector Search Reranker

✓

Vector Search: Full-Text Search

Visual authoring: UI <> YAML Sync for DABs in the Workspace

✓

Warehouse Activity Details

✓

Warehouse Statement Timeout

✓

Widget Data Attachments for Dashboard Subscriptions

✓

Workspace base environments for serverless compute

✓