Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Classes at a Glance

Somebody has told you the company needs FedRAMP, and named a class. This page turns that one letter into the work it implies: the rules that bind you, which of them FedRAMP actually watches, how much of that a machine can prove for you — and the command that proves it. Follow the chain first; the exact figures are underneath it.

Follow one class through

One question at a time, in order. Each box holds a set of controlOne numbered security requirement — AC-02, “account management” — from NIST SP 800-53, the catalogue FedRAMP draws its baselines from.— press one to read what it is and what it asks of you. The plain heading is what the box means; the smaller line under it is the word FedRAMP and the rest of this site use for the same thing.

Three words carry the whole picture. Your baselineThe set of controls one impact level requires. FedRAMP Rev5 publishes three, and which one binds you is the whole question of scope. is the set of controls your class owes; the reading beside each class is the Rev5 impact levelFedRAMP’s three-way sizing of a system — Low, Moderate or High — set by what the data would cost if it leaked. It picks your baseline. it approximates, which is the scheme most people were quoted first. Each control is then either reached by a Key Security Indicator (KSI)FedRAMP 20x’s unit of assurance: a question asked of the running system — “is MFA enforced?” — that a machine can answer, grouped into themes. or it is not, and reached controls are the ones an authored recipeThis product’s unit of collection, and its own coinage: an authored command, plus what one pass of it proves and how often to re-run it. can collect for you.

A box marked opens. Press it and the next band appears — which part of security the work sits in, and then the calls themselves, each one a real command you can run. Press it again to close it. The picture gets wide once you are two levels down; use Full screen at the top right of the diagram.

Your class

Class A carries no Rev5 baseline, so there is no chain to draw for it — an absence of a rulebook, not a rulebook of zero controls.

Where do you start?

What binds you?

What is FedRAMP watching?

Can a machine prove it?

How does the machine prove it?

Class C322 controls in the class C baseline

You state a certification class once, and everything downstream is a consequence of it. The 2026 rules say Class C and never "Moderate" — the reading beside it is an interpretation this site makes, not a name the ruleset uses.

In this box
  • recipe94
  • KSI only105
  • orphan123
and 282 more

The hollow ones have no page of their own — no indicator reaches them, so they are argued in writing in your Security Decision Record. Coverage lists them by class.

Class D is still being written

Pendingspecification incomplete

Three places in the rules say so, and all three are read from the dataset rather than from a schedule — so this notice comes down on its own when the text fills in. What IS written for this class is worth building against; what is missing is not a gap in your programme.

A rule says the specifics are not set yet

Providers with 20x Class D Certifications MUST significantly supersede the minimum requirements for lower Classes, with specifics to be set during the 20x Phase 4 Pilot.

Indicators that state nothing at this class — stated at class C
A clock with no row at this class — stated at class C

The same for every class

FedRAMP writes the Key Security Indicators — the things it watches for — once, and every class is measured against the same ones. There is no Class D indicator set. What moves between classes is how much proof each indicator wants, not what it asks.

KSI themes
10
The areas of security FedRAMP watches — KSI-IAM, KSI-MLA, and eight more. Written theme in the data.
Indicators
46
The measurable statements inside those areas.
Controls reached
209
Distinct NIST controls any indicator maps to.

What changes by class

Two things grow with your class, and they do not grow together. The list of controls that binds you gets longer at every step, and the number of machine checks FedRAMP wants goes up too. But the part of your list that an indicator watches stops growing after Class C — so a Class D provider is asked for twice the automation across no extra watched controls, and the coverage figure falls precisely where the demand rises. That is the reading, not a fault in the data.

ClassReads asBaselineKSI-coveredOrphansAutomationPer KSIOwed · indicatorsOwed · themes
A no Rev5 baseline, so no impact level to read Class A carries no Rev5 baseline no baseline to cover no baselineMAY permitted, but no minimum is stated no minimum to multiply no minimum to multiply
BLow1559560SHOULD14610
CModerate322199123MUST29220
DHigh409199210MUST416440

Baseline is everything that binds you; KSI-covered is the part an indicator watches; and Orphansis the rest — still yours, just argued in writing rather than through an indicator. All three count NIST SP 800-53 controls. Per KSI and the two Owed columns count automated methods instead, which are a different unit: a method is not a control, and the two never sum.

Which unit “for each Key Security Indicator” counts is not stated in the rules. The rules never say whether “each Key Security Indicator” means one of the 10 themes or one of the 46 indicators. FedRAMP’s own schema names the 46 “ksi_indicator” and the 10 “ksi_theme”, so the indicator is the reading published here — with the theme reading shown beside it, because the two are 4.6× apart and no automation number means anything without its unit. The indicator column is scoped to the indicators that state something at that class, which is why it is not the same multiplication at every row.

Reads-as is an interpretation, not dataset fact: the 2026 rules say Class B/C/D and never Low/Moderate/High. Automation force and the per-KSI minimum are read from FRC-CSX-VVK; the class column’s em-dashes mark an absence, never a zero.

What this site can automate today

One row per area, counting the evidence recipes written in this repository. How many exist is a fact about our work and not about your class — the same recipes are measured against every class’s bar, so the bar is the only thing that moves between them. FedRAMP publishes no list of which controls a machine can satisfy; this is our reading, not theirs.

Below quotaClass B: 1 of 10 areas short · Class C: 1 of 10 areas short · Class D: 3 of 10 areas short. An area with methods to spare does not cover for one that is short — FedRAMP counts them area by area, not as a total.

Methods we have written, by area64 recipes across 10 areas
  • CED Cybersecurity Education0Clears no class
  • CMT Change Management10Clears class B, C, D
  • CNA Cloud Native Architecture10Clears class B, C, D
  • IAM Identity and Access Management18Clears class B, C, D
  • INR Incident Response3Clears class B, C
  • MLA Monitoring, Logging, and Auditing9Clears class B, C, D
  • PIY Policy and Inventory5Clears class B, C, D
  • RPL Recovery Planning2Clears class B, C
  • SCR Supply Chain Risk11Clears class B, C, D
  • SVC Service Configuration17Clears class B, C, D

= this area has enough methods for class B, C, D, in that order. The numeral is how many we have written. The bar runs to 4, the most any class asks for, and the notches in it are where each class’s own requirement falls — so a bar that fills the track satisfies every class, and one that stops before the first notch satisfies none. Class A sets no minimum and is not graded here.

The rule, verbatim, per class
A
Providers seeking 20x Class A Certification MAY implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators.
B
Providers seeking 20x Class B Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 1 automated method for each Key Security Indicator.
C
Providers seeking 20x Class C Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 2 automated methods for each Key Security Indicator.
D
Providers seeking 20x Class D Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 4 automated methods for each Key Security Indicator.