There are different types of FedRAMP solutions to be familiar with.
The FedRAMP solution you choose will dictate the cost and amount of security effort you will need to do on your side.
FedRAMP Options | Cost Among Options | Client Security Package Effort |
IaaS | Lowest | Highest |
PaaS | Moderate | Moderate |
SaaS | Highest | Lowest |
Specifically, depending on the solution you select:
Note that even with SaaS, you are still responsible for aspects of your security that are beyond the provider such as Personnel, Physical, Configuration Management and so on. (Ref NIST 800-53)
The cost for any FedRAMP is going to be significantly higher than other simple hosting or SaaS solutions. You are paying for the security and rigidity of the solution and the efforts taken by the provider and the effort it takes to maintain it.