Claude for Government is GA. FedRAMP High covers the platform, not your app
Anthropic's government platform left public beta on September 30 with usage billing and a hard spending cap. The authorization covers Anthropic's environment. Each agency still signs its own ATO for what runs on it.
No seat fees, a hard not-to-exceed cap, and one OMB rule that a FedRAMP High badge does not waive.
Anthropic made Claude for Government generally available to federal and state agencies on September 30, 2026. The platform had been in public beta since July. In Anthropic's words, it delivers Claude's coding and agentic work capabilities "through a FedRAMP High authorized environment."
Usage blocks with a hard ceiling
There are no seat fees. Per the announcement, "Agencies pay for usage in fixed increments with a hard not-to-exceed cap, so spend does not exceed what an agency has obligated." Administrators define user tiers with spend and model limits per group, track usage by user and by model, and get burndown alerts before a balance runs low.
The spend tree goes down a level. Department administrators allocate prepaid usage to sub-agencies, and each sub-agency manages its own users. Agencies connect their own identity provider for single sign-on, and SCIM group mappings set the rate limits, dollar caps, and allowed models for each seat tier.
ExecutiveBiz reports that Anthropic is open to contracting with agencies directly, outside existing cloud provider agreements. Agencies can also buy through the General Services Administration.
Claude Code and Microsoft 365, early access
Two more products are rolling out in early access: the Claude Code command-line interface and Claude for Microsoft 365. Anthropic says they run in the same FedRAMP High environment, under the same administrative controls.
Administrative actions go into an audit log that organization administrators can review. Sensitive operations on Anthropic's side require two-person approval. Usage exports are metering data only. On the desktop app, conversation history stays local on the agency-managed device.
High, by the numbers
FedRAMP's own explainer on impact levels reserves High for law enforcement, emergency services, financial, and health systems, "and any other system where loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals."
The High baseline is 410 security controls from NIST SP 800-53 Rev. 5, against 323 at Moderate, per Secureframe's breakdown. The security package an agency reviews belongs to that specific cloud service offering.
The ATO still belongs to the agency
FedRAMP's quick guide on reusing authorizations lists what an agency does with an already authorized product. It reviews the provider's security package and monthly continuous monitoring deliverables. It reads the Customer Implementation Summary and the Customer Responsibility Matrix for "how to implement customer responsibilities." It checks whether its own data types or mission add requirements. Then it issues its own Authority to Operate.
The guide states the rule in one line: "OMB Circular A-130 requires agencies to individually authorize operation of an information system and to explicitly accept the risk."
Anthropic's announcement uses the same frame. "Security teams and authorizing officials get audit logs and documentation that supports the agency ATO process," it says. An internal tool a team writes with Claude Code, the systems that tool sends data to, and the way an agency maps staff into SCIM groups are agency decisions with agency owners.
One limit on this read. Anthropic says its FedRAMP Secure Configuration Guide is available through its trust center, and we have not seen it or a customer responsibility matrix for this service. So the exact split of controls between Anthropic and an agency is not something we can state here.
Why a build studio cares
In our Deep Audit, the data-flow map is the step where this boundary gets drawn. We trace each hop a record takes and mark which hops sit inside a certified environment and which do not. On a Claude for Government build, the platform hop would sit inside. The agency's own app, anything it exports, and the conversation history held on each managed device would each get a separate line on the map, with a named owner.
The Full Audit governance checks cover the rest: who holds access, where secrets live, and what breaks if one person leaves. A dollar cap per SCIM group limits spend. It says nothing about whether a credential for a tool built with the Claude Code CLI sits in plain text in that tool's repo. That check has to run on the agency's code, and the platform's authorization letter does not run it.
Next step: read Anthropic's announcement for the billing and admin details, then FedRAMP's reuse quick guide for the steps an agency runs before it signs. If your vendor answers security questions with a platform certificate, write to us at hello@gattyworks.com and we will map where that certificate stops.