Class B → C
Moving from class B to class C — our reading: Rev5 Low to our reading: Rev5 Moderate. The step has two halves and only one of them is a control list: the scope it adds, and the per-class clocks that tighten underneath it. The rules name only classes. Low, Moderate and High are Rev5's, and pairing them with a class is our reading rather than something the rules state.
Class B → Cfour measurements, four denominators — deliberately never summed into one number
controls the class C baseline adds
104 / 167 reached by a Key Security Indicator
46 are in the annual independent-assessment subset. 75 tighten a base control a recipe already covers — a prerequisite, never partial credit — and those collapse onto 39 mechanisms. 78 have nothing behind them at all.
Key Security Indicators, out of those in scope at class C— never a total
27 / 46 indicators carry at least 2 distinct authored methods, against 1 at class B.
The set of things to automate does not grow; the number of independent methods per thing does. Four queries against one API returning one fact is one method with extra steps. FRC-CSX-VVK states both levels; the wording is in the panel below.
unit: indicator ×46 or theme ×10 → 9
The rules never say whether “each Key Security Indicator” means one of the 10 themes or one of the 46 indicators. FedRAMP’s own schema names the 46 “ksi_indicator” and the 10 “ksi_theme”, so the indicator is the reading published here — with the theme reading shown beside it, because the two are 4.6× apart and no automation number means anything without its unit.
a date, per indicator — never a fraction
Measured from your own earliest retained persistent-validation record, which this product does not hold and will not invent. The window is stated per class by FRC-CSX-MOT, and it is the one requirement on this page that no amount of engineering shortens: methods can be built, bought or re-pointed later, and history cannot be back-filled. The most useful thing you can do about this row is start retaining today.
a measured distribution against each target rate — never a pass
7 per-class clocks move across this step and every one of them is a rate, measurable from your own workflow schedules and scanner run history. Report each as a distribution with its target beside it, on its own lookback window — the targets below span a single day to six months, so no one window can judge them all. A cron that exists and a job that ran are different facts.
63 of the 167 controls this step adds are orphans: no 20x Key Security Indicator reaches them. The consequence is structural rather than editorial — the control graph this site is built on is assembled from indicator edges, so an orphan has no node, no /control/ permalink, and cannot be dispositioned on the automation frontier, whose universe is the KSI-reached set. They are enumerated here and nowhere else on the site, and the ids below are deliberately not links.
Added controls grouped by the recipe that reaches the control or, for an enhancement, the base control it tightens. A recipe on a base control is a lead for scoping, never evidence for the enhancement — a covered base is why the lower authorization is held. Each control is listed once, under whichever candidate mechanism carries the most of this step, so the counts partition the added set rather than double-count it. Where a control has more than one candidate, the full set is in its row of the table below.
- 6config-threat-monitoring-enabledawssi-4.1 · si-4.2 · si-4.4 · si-4.16 · si-4.18 · si-4.23
- 6iam-account-authorization-detailsawsac-2.1 · ac-2.5 · ac-2.7 · ac-2.9 · ac-2.12 · ac-6.1
- 5identity-center-jit-elevation-workflowawsac-6 · ac-6.2 · ac-6.5 · ac-6.9 · ac-6.10
- 5securityhub-incident-review-proceduresawsir-4.1 · ir-6.1 · ir-6.3 · ir-7.1 · si-4.5
- 4config-network-boundary-protectionawssc-7.7 · sc-7.8 · sc-7.12 · sc-7.18
- 4iam-credential-reportawsia-2.5 · ia-2.6 · ia-5.2 · ia-5.7
- 4patch-and-vulnerability-remediationawsra-5.3 · ra-5.5 · si-2.2 · si-2.3
- 4remote-access-authorization-and-monitoringawsac-17.1 · ac-17.2 · ac-17.3 · ac-17.4
- 3boundary-access-points-and-default-denyawssc-7.3 · sc-7.4 · sc-7.5
- 3config-least-functionalityawscm-7.1 · cm-7.2 · cm-7.5
- 3ssm-configuration-baseline-enforcedawscm-2.3 · cm-2.7 · cm-6.1
- 3static-analysis-coverage-and-flaw-dispositionpipelinesa-11 · sa-11.1 · sa-11.2
- 2audit-reduction-and-report-generationawsau-7 · au-7.1
- 2change-authority-restrictions-and-enforcementawscm-5.1 · cm-5.5
- 2cloudtrail-config-change-historyawscm-3 · cm-3.2
- 2cloudwatch-log-review-alertingawsau-6.1 · au-6.3
- 2config-asset-inventoryawscm-2.2 · cm-8.1
- 2config-data-backup-enabledawscp-9.1 · cp-9.8
- 2external-access-inventory-and-trust-boundaryawsac-20.1 · ac-20.2
- 2guardduty-incident-after-actionawsir-3 · ir-3.2
- 2guardduty-suspicious-iam-activity-responseawsac-2.4 · ac-2.13
- 2iam-access-analyzer-unused-accessawsac-2.3 · ac-6.7
- 2information-location-and-classificationawscm-12 · cm-12.1
- 2integrity-verification-and-immutabilityawssi-7 · si-7.1
- 1backup-restore-testingawscp-10.2
- 1build-provenance-attestation-verificationpipelinesi-7.7
- 1change-verification-status-checks-and-run-recordspipelinecm-4.2
- 1config-cloudtrail-audit-loggingawsau-9.4
- 1dependency-vulnerability-monitoringpipelinesr-6
- 1developer-change-control-and-integritypipelinesa-10
- 1error-handling-information-exposure-scanningpipelinesi-11
- 1identifier-assignment-and-reuse-preventionawsia-4.4
- 1input-validation-taint-analysis-coveragepipelinesi-10
- 1mobile-code-admission-and-bundle-provenancepipelinesc-18
- 1secret-exposure-detection-and-push-protectionpipelineia-5.6
- 1security-representative-change-approvalpipelinecm-3.4
- 1session-authenticity-tls-terminationawssc-23
- 1temporary-account-automatic-revocationawsac-2.2
- 1unauthorized-component-detection-and-responseawscm-8.3
No mechanism anywhere in the overlays (78)
Neither plane reaches these, nor their base controls. This is the residue — kept in rather than rounded away, and the honest size of what a scan of the estate or the pipeline cannot currently witness.
ac-4 · ac-4.21 · ac-5 · ac-11 · ac-11.1 · ac-12 · ac-18.1 · ac-18.3 · ac-19.5 · ac-21 · at-2.3 · au-3.1 · ca-2.3 · ca-7.1 · ca-8.1 · ca-8.2 · cm-9 · cp-2.1 · cp-2.3 · cp-2.8 · cp-4.1 · cp-6 · cp-6.1 · cp-6.3 · cp-7 · cp-7.1 · cp-7.2 · cp-7.3 · cp-8 · cp-8.1 · cp-8.2 · ia-3 · ia-12 · ia-12.2 · ia-12.3 · ia-12.5 · ir-9 · ir-9.2 · ir-9.3 · ir-9.4 · ma-3 · ma-3.1 · ma-3.2 · ma-3.3 · ma-5.1 · ma-6 · mp-3 · mp-4 · mp-5 · pe-4 · pe-5 · pe-6.1 · pe-9 · pe-10 · pe-11 · pe-13.1 · pe-13.2 · pe-17 · ps-3.3 · ra-9 · sa-4.1 · sa-4.2 · sa-4.9 · sa-9.1 · sa-9.2 · sa-9.5 · sa-15 · sa-15.3 · sc-2 · sc-4 · sc-10 · sc-17 · sc-45 · sc-45.1 · si-6 · si-8 · si-8.2 · si-16
Requirements whose timeframe is stated per class and differs across this step. A baseline diff cannot see these: the requirement id is identical in both classes and only the number moves. Units are the dataset’s own and are never converted.
| Requirement | Class B | Class C | What it is |
|---|---|---|---|
| CPO-CSX-CPM | 1 month | 2 weeks | Certification Package Maintenance for 20x |
| VDR-TFR-MVX | 7 days | 3 days | Persistent Machine Verification and Validation for 20x |
| VDR-TFR-PCD | 6 months | 1 month | Persistently Complete Detection |
| VDR-TFR-PDD | 1 month | 14 days | Persistent Drift Detection |
| VDR-TFR-PSD | 7 days | 3 days | Persistent Sample Detection |
| VER-TFR-EVU | 7 days | 5 days | Evaluate Vulnerabilities Quickly |
| VER-TFR-MRH | 1 month | 14 days | Historical Activity |
The rest of the per-class rules: requirements whose class levels differ in force or in wording and carry no timeframe to diff. The clock table above cannot see these, and for the step to the highest class they are where the machine-automation requirement actually lives — the quota is stated as a count and the history window as prose, so neither is a number a clock diff can compare. Statements are the dataset’s own and are never paraphrased. A requirement that names its own class and is otherwise identical at both is counted as unchanged.
- Class B
- Providers with Class B Certifications MAY use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
- Class C
- Providers with Class C Certifications SHOULD use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
- Class B
- Providers seeking 20x Class B Certification SHOULD supply historical metrics for Key Security Indicators.
- Class C
- Providers seeking 20x Class C Certification MUST supply historical metrics including status from persistent validation over at least the past 6 months for all Key Security Indicators.
- Class B
- Providers seeking 20x Class B Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 1 automated method for each Key Security Indicator.
- Class C
- Providers seeking 20x Class C Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 2 automated methods for each Key Security Indicator.
- VDR-TFR-PVRMitigation and Remediation Expectations
- Class B
- Providers with Class B Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
- Class C
- Providers with Class C Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
- Class B
- Providers with Class B Certifications MAY treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.
- Class C
- Providers with Class C Certifications SHOULD treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.
- AC 32
- CM 18
- SI 18
- CP 17
- SC 15
- SA 12
- IA 11
- IR 10
- PE 9
- AU 6
- MA 6
- CA 4
- MP 3
- RA 3
- AT 1
- PS 1
- SR 1
| Control | Family | Tightens | Reached by |
|---|---|---|---|
| AC-02 (01)annual | AC | ac-2 | base: iam-account-authorization-details |
| AC-02 (02)annual | AC | ac-2 | temporary-account-automatic-revocation |
| AC-02 (03)annual | AC | ac-2 | iam-access-analyzer-unused-access |
| AC-02 (04)annual | AC | ac-2 | guardduty-suspicious-iam-activity-response |
| AC-02 (05)annual | AC | ac-2 | base: iam-account-authorization-details |
| AC-02 (07)annual | AC | ac-2 | base: iam-account-authorization-details |
| AC-02 (09)annual | AC | ac-2 | base: iam-account-authorization-details |
| AC-02 (12)annual | AC | ac-2 | base: iam-account-authorization-details |
| AC-02 (13)annual | AC | ac-2 | guardduty-suspicious-iam-activity-response |
| AC-04 | AC | — | — |
| AC-04 (21) | AC | ac-4(new base) | — |
| AC-05 | AC | — | — |
| AC-06annual | AC | — | config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow |
| AC-06 (01) | AC | ac-6(new base) | iam-account-authorization-details |
| AC-06 (02)annual | AC | ac-6(new base) | base: config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow |
| AC-06 (05)annual | AC | ac-6(new base) | identity-center-jit-elevation-workflow |
| AC-06 (07) | AC | ac-6(new base) | iam-access-analyzer-unused-access |
| AC-06 (09) | AC | ac-6(new base) | base: config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow |
| AC-06 (10)annual | AC | ac-6(new base) | base: config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow |
| AC-11 | AC | — | — |
| AC-11 (01) | AC | ac-11(new base) | — |
| AC-12 | AC | — | — |
| AC-17 (01) | AC | ac-17 | remote-access-authorization-and-monitoring |
| AC-17 (02)annual | AC | ac-17 | remote-access-authorization-and-monitoring |
| AC-17 (03) | AC | ac-17 | remote-access-authorization-and-monitoring |
| AC-17 (04) | AC | ac-17 | base: remote-access-authorization-and-monitoring |
| AC-18 (01) | AC | ac-18 | — |
| AC-18 (03) | AC | ac-18 | — |
| AC-19 (05) | AC | ac-19 | — |
| AC-20 (01) | AC | ac-20 | base: external-access-inventory-and-trust-boundary |
| AC-20 (02) | AC | ac-20 | base: external-access-inventory-and-trust-boundary |
| AC-21 | AC | — | — |
| AT-02 (03) | AT | at-2 | — |
| AU-03 (01)annual | AU | au-3 | — |
| AU-06 (01)annual | AU | au-6 | cloudwatch-log-review-alerting |
| AU-06 (03)annual | AU | au-6 | base: cloudwatch-log-review-alerting |
| AU-07 | AU | — | audit-reduction-and-report-generation |
| AU-07 (01) | AU | au-7(new base) | audit-reduction-and-report-generation |
| AU-09 (04) | AU | au-9 | base: config-cloudtrail-audit-logging |
| CA-02 (03) | CA | ca-2 | — |
| CA-07 (01) | CA | ca-7 | — |
| CA-08 (01)annual | CA | ca-8 | — |
| CA-08 (02)annual | CA | ca-8 | — |
| CM-02 (02) | CM | cm-2 | config-asset-inventory |
| CM-02 (03) | CM | cm-2 | base: ssm-configuration-baseline-enforced |
| CM-02 (07) | CM | cm-2 | base: ssm-configuration-baseline-enforced |
| CM-03 | CM | — | cloudtrail-config-change-history |
| CM-03 (02) | CM | cm-3(new base) | base: cloudtrail-config-change-history |
| CM-03 (04) | CM | cm-3(new base) | security-representative-change-approval |
| CM-04 (02) | CM | cm-4 | change-verification-status-checks-and-run-records |
| CM-05 (01) | CM | cm-5 | base: change-authority-restrictions-and-enforcement |
| CM-05 (05) | CM | cm-5 | base: change-authority-restrictions-and-enforcement |
| CM-06 (01)annual | CM | cm-6 | base: ssm-configuration-baseline-enforced |
| CM-07 (01)annual | CM | cm-7 | config-least-functionality |
| CM-07 (02)annual | CM | cm-7 | base: config-least-functionality |
| CM-07 (05)annual | CM | cm-7 | base: config-least-functionality |
| CM-08 (01) | CM | cm-8 | config-asset-inventory |
| CM-08 (03) | CM | cm-8 | unauthorized-component-detection-and-response |
| CM-09 | CM | — | — |
| CM-12 | CM | — | information-location-and-classification |
| CM-12 (01) | CM | cm-12(new base) | information-location-and-classification |
| CP-02 (01) | CP | cp-2 | — |
| CP-02 (03) | CP | cp-2 | — |
| CP-02 (08) | CP | cp-2 | — |
| CP-04 (01) | CP | cp-4 | — |
| CP-06 | CP | — | — |
| CP-06 (01) | CP | cp-6(new base) | — |
| CP-06 (03) | CP | cp-6(new base) | — |
| CP-07 | CP | — | — |
| CP-07 (01) | CP | cp-7(new base) | — |
| CP-07 (02) | CP | cp-7(new base) | — |
| CP-07 (03) | CP | cp-7(new base) | — |
| CP-08 | CP | — | — |
| CP-08 (01) | CP | cp-8(new base) | — |
| CP-08 (02) | CP | cp-8(new base) | — |
| CP-09 (01) | CP | cp-9 | base: config-data-backup-enabled |
| CP-09 (08) | CP | cp-9 | base: config-data-backup-enabled |
| CP-10 (02) | CP | cp-10 | backup-restore-testing |
| IA-02 (05)annual | IA | ia-2 | base: config-mfa-enabled-console-access · iam-credential-report · identity-sources-and-root-credential-lockdown |
| IA-02 (06)annual | IA | ia-2 | base: config-mfa-enabled-console-access · iam-credential-report · identity-sources-and-root-credential-lockdown |
| IA-03 | IA | — | — |
| IA-04 (04) | IA | ia-4 | base: identifier-assignment-and-reuse-prevention |
| IA-05 (02) | IA | ia-5 | base: config-access-keys-rotated · iam-credential-report |
| IA-05 (06) | IA | ia-5 | secret-exposure-detection-and-push-protection |
| IA-05 (07) | IA | ia-5 | base: config-access-keys-rotated · iam-credential-report |
| IA-12 | IA | — | — |
| IA-12 (02) | IA | ia-12(new base) | — |
| IA-12 (03) | IA | ia-12(new base) | — |
| IA-12 (05) | IA | ia-12(new base) | — |
| IR-03annual | IR | — | guardduty-incident-after-action · guardduty-pattern-review-past-incidents |
| IR-03 (02) | IR | ir-3(new base) | base: guardduty-incident-after-action · guardduty-pattern-review-past-incidents |
| IR-04 (01)annual | IR | ir-4 | guardduty-incident-after-action · guardduty-pattern-review-past-incidents · securityhub-incident-review-procedures |
| IR-06 (01) | IR | ir-6 | securityhub-incident-review-procedures |
| IR-06 (03) | IR | ir-6 | securityhub-incident-review-procedures |
| IR-07 (01) | IR | ir-7 | securityhub-incident-review-procedures |
| IR-09 | IR | — | — |
| IR-09 (02) | IR | ir-9(new base) | — |
| IR-09 (03) | IR | ir-9(new base) | — |
| IR-09 (04) | IR | ir-9(new base) | — |
| MA-03 | MA | — | — |
| MA-03 (01) | MA | ma-3(new base) | — |
| MA-03 (02)annual | MA | ma-3(new base) | — |
| MA-03 (03) | MA | ma-3(new base) | — |
| MA-05 (01) | MA | ma-5 | — |
| MA-06 | MA | — | — |
| MP-03 | MP | — | — |
| MP-04 | MP | — | — |
| MP-05 | MP | — | — |
| PE-04 | PE | — | — |
| PE-05 | PE | — | — |
| PE-06 (01) | PE | pe-6 | — |
| PE-09 | PE | — | — |
| PE-10 | PE | — | — |
| PE-11 | PE | — | — |
| PE-13 (01) | PE | pe-13 | — |
| PE-13 (02) | PE | pe-13 | — |
| PE-17 | PE | — | — |
| PS-03 (03) | PS | ps-3 | — |
| RA-05 (03)annual | RA | ra-5 | base: patch-and-vulnerability-remediation |
| RA-05 (05) | RA | ra-5 | base: patch-and-vulnerability-remediation |
| RA-09 | RA | — | — |
| SA-04 (01) | SA | sa-4 | — |
| SA-04 (02) | SA | sa-4 | — |
| SA-04 (09) | SA | sa-4 | — |
| SA-09 (01) | SA | sa-9 | — |
| SA-09 (02) | SA | sa-9 | — |
| SA-09 (05) | SA | sa-9 | — |
| SA-10 | SA | — | developer-change-control-and-integrity |
| SA-11 | SA | — | static-analysis-coverage-and-flaw-disposition |
| SA-11 (01)annual | SA | sa-11(new base) | base: static-analysis-coverage-and-flaw-disposition |
| SA-11 (02) | SA | sa-11(new base) | base: static-analysis-coverage-and-flaw-disposition |
| SA-15 | SA | — | — |
| SA-15 (03) | SA | sa-15(new base) | — |
| SC-02 | SC | — | — |
| SC-04 | SC | — | — |
| SC-07 (03)annual | SC | sc-7 | boundary-access-points-and-default-deny |
| SC-07 (04)annual | SC | sc-7 | boundary-access-points-and-default-deny |
| SC-07 (05)annual | SC | sc-7 | boundary-access-points-and-default-deny |
| SC-07 (07)annual | SC | sc-7 | base: config-network-boundary-protection |
| SC-07 (08)annual | SC | sc-7 | base: config-network-boundary-protection |
| SC-07 (12)annual | SC | sc-7 | base: config-network-boundary-protection |
| SC-07 (18)annual | SC | sc-7 | base: config-network-boundary-protection |
| SC-10 | SC | — | — |
| SC-17 | SC | — | — |
| SC-18 | SC | — | mobile-code-admission-and-bundle-provenance |
| SC-23 | SC | — | session-authenticity-tls-termination |
| SC-45 | SC | — | — |
| SC-45 (01)annual | SC | sc-45(new base) | — |
| SI-02 (02) | SI | si-2 | base: patch-and-vulnerability-remediation |
| SI-02 (03) | SI | si-2 | base: patch-and-vulnerability-remediation |
| SI-04 (01)annual | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (02)annual | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (04) | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (05) | SI | si-4 | securityhub-incident-review-procedures |
| SI-04 (16)annual | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (18) | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (23)annual | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-06annual | SI | — | — |
| SI-07annual | SI | — | integrity-verification-and-immutability |
| SI-07 (01)annual | SI | si-7(new base) | integrity-verification-and-immutability |
| SI-07 (07) | SI | si-7(new base) | build-provenance-attestation-verification |
| SI-08 | SI | — | — |
| SI-08 (02) | SI | si-8(new base) | — |
| SI-10annual | SI | — | input-validation-taint-analysis-coverage |
| SI-11 | SI | — | error-handling-information-exposure-scanning |
| SI-16 | SI | — | — |
| SR-06 | SR | — | dependency-vulnerability-monitoring |