Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Class BC

Moving from class B to class C our reading: Rev5 Low to our reading: Rev5 Moderate. The step has two halves and only one of them is a control list: the scope it adds, and the per-class clocks that tighten underneath it. The rules name only classes. Low, Moderate and High are Rev5's, and pairing them with a class is our reading rather than something the rules state.

Class BCfour measurements, four denominators — deliberately never summed into one number

Row AScope

controls the class C baseline adds

104 / 167 reached by a Key Security Indicator

46 are in the annual independent-assessment subset. 75 tighten a base control a recipe already covers — a prerequisite, never partial credit — and those collapse onto 39 mechanisms. 78 have nothing behind them at all.

Row BAutomation depth

Key Security Indicators, out of those in scope at class C— never a total

27 / 46 indicators carry at least 2 distinct authored methods, against 1 at class B.

The set of things to automate does not grow; the number of independent methods per thing does. Four queries against one API returning one fact is one method with extra steps. FRC-CSX-VVK states both levels; the wording is in the panel below.

unit: indicator ×46 or theme ×10 9

The rules never say whether “each Key Security Indicator” means one of the 10 themes or one of the 46 indicators. FedRAMP’s own schema names the 46 “ksi_indicator” and the 10 “ksi_theme”, so the indicator is the reading published here — with the theme reading shown beside it, because the two are 4.6× apart and no automation number means anything without its unit.

Row CAccumulation

a date, per indicator — never a fraction

Measured from your own earliest retained persistent-validation record, which this product does not hold and will not invent. The window is stated per class by FRC-CSX-MOT, and it is the one requirement on this page that no amount of engineering shortens: methods can be built, bought or re-pointed later, and history cannot be back-filled. The most useful thing you can do about this row is start retaining today.

Row DCadence

a measured distribution against each target rate — never a pass

7 per-class clocks move across this step and every one of them is a rate, measurable from your own workflow schedules and scanner run history. Report each as a distribution with its target beside it, on its own lookback window — the targets below span a single day to six months, so no one window can judge them all. A cron that exists and a job that ran are different facts.

Read this before the numbers below

63 of the 167 controls this step adds are orphans: no 20x Key Security Indicator reaches them. The consequence is structural rather than editorial — the control graph this site is built on is assembled from indicator edges, so an orphan has no node, no /control/ permalink, and cannot be dispositioned on the automation frontier, whose universe is the KSI-reached set. They are enumerated here and nowhere else on the site, and the ids below are deliberately not links.

Where the work concentrates39 mechanisms

Added controls grouped by the recipe that reaches the control or, for an enhancement, the base control it tightens. A recipe on a base control is a lead for scoping, never evidence for the enhancement — a covered base is why the lower authorization is held. Each control is listed once, under whichever candidate mechanism carries the most of this step, so the counts partition the added set rather than double-count it. Where a control has more than one candidate, the full set is in its row of the table below.

No mechanism anywhere in the overlays (78)

Neither plane reaches these, nor their base controls. This is the residue — kept in rather than rounded away, and the honest size of what a scan of the estate or the pipeline cannot currently witness.

ac-4 · ac-4.21 · ac-5 · ac-11 · ac-11.1 · ac-12 · ac-18.1 · ac-18.3 · ac-19.5 · ac-21 · at-2.3 · au-3.1 · ca-2.3 · ca-7.1 · ca-8.1 · ca-8.2 · cm-9 · cp-2.1 · cp-2.3 · cp-2.8 · cp-4.1 · cp-6 · cp-6.1 · cp-6.3 · cp-7 · cp-7.1 · cp-7.2 · cp-7.3 · cp-8 · cp-8.1 · cp-8.2 · ia-3 · ia-12 · ia-12.2 · ia-12.3 · ia-12.5 · ir-9 · ir-9.2 · ir-9.3 · ir-9.4 · ma-3 · ma-3.1 · ma-3.2 · ma-3.3 · ma-5.1 · ma-6 · mp-3 · mp-4 · mp-5 · pe-4 · pe-5 · pe-6.1 · pe-9 · pe-10 · pe-11 · pe-13.1 · pe-13.2 · pe-17 · ps-3.3 · ra-9 · sa-4.1 · sa-4.2 · sa-4.9 · sa-9.1 · sa-9.2 · sa-9.5 · sa-15 · sa-15.3 · sc-2 · sc-4 · sc-10 · sc-17 · sc-45 · sc-45.1 · si-6 · si-8 · si-8.2 · si-16

Clocks that move7 unchanged

Requirements whose timeframe is stated per class and differs across this step. A baseline diff cannot see these: the requirement id is identical in both classes and only the number moves. Units are the dataset’s own and are never converted.

RequirementClass BClass CWhat it is
CPO-CSX-CPM1 month2 weeksCertification Package Maintenance for 20x
VDR-TFR-MVX7 days3 daysPersistent Machine Verification and Validation for 20x
VDR-TFR-PCD6 months1 monthPersistently Complete Detection
VDR-TFR-PDD1 month14 daysPersistent Drift Detection
VDR-TFR-PSD7 days3 daysPersistent Sample Detection
VER-TFR-EVU7 days5 daysEvaluate Vulnerabilities Quickly
VER-TFR-MRH1 month14 daysHistorical Activity
Obligations that move without a clock10 unchanged

The rest of the per-class rules: requirements whose class levels differ in force or in wording and carry no timeframe to diff. The clock table above cannot see these, and for the step to the highest class they are where the machine-automation requirement actually lives — the quota is stated as a count and the history window as prose, so neither is a number a clock diff can compare. Statements are the dataset’s own and are never paraphrased. A requirement that names its own class and is otherwise identical at both is counted as unchanged.

  • CMU-CSO-UVMUsing Validated Cryptographic ModulesMAYSHOULD
    Class B
    Providers with Class B Certifications MAY use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
    Class C
    Providers with Class C Certifications SHOULD use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
  • FRC-CSX-MOTMetrics Over Time for Key Security IndicatorsSHOULDMUST
    Class B
    Providers seeking 20x Class B Certification SHOULD supply historical metrics for Key Security Indicators.
    Class C
    Providers seeking 20x Class C Certification MUST supply historical metrics including status from persistent validation over at least the past 6 months for all Key Security Indicators.
  • FRC-CSX-VVKAutomated Verification and Validation of Key Security IndicatorsSHOULDMUST
    Class B
    Providers seeking 20x Class B Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 1 automated method for each Key Security Indicator.
    Class C
    Providers seeking 20x Class C Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 2 automated methods for each Key Security Indicator.
  • VDR-TFR-PVRMitigation and Remediation Expectations
    Class B
    Providers with Class B Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
    Class C
    Providers with Class C Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
  • VER-TFR-IRIInternet-Reachable IncidentsMAYSHOULD
    Class B
    Providers with Class B Certifications MAY treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.
    Class C
    Providers with Class C Certifications SHOULD treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.
By family17 families
  • AC 32
  • CM 18
  • SI 18
  • CP 17
  • SC 15
  • SA 12
  • IA 11
  • IR 10
  • PE 9
  • AU 6
  • MA 6
  • CA 4
  • MP 3
  • RA 3
  • AT 1
  • PS 1
  • SR 1
Every control added167 controls
ControlFamilyTightensReached by
AC-02 (01)annualACac-2base: iam-account-authorization-details
AC-02 (02)annualACac-2temporary-account-automatic-revocation
AC-02 (03)annualACac-2iam-access-analyzer-unused-access
AC-02 (04)annualACac-2guardduty-suspicious-iam-activity-response
AC-02 (05)annualACac-2base: iam-account-authorization-details
AC-02 (07)annualACac-2base: iam-account-authorization-details
AC-02 (09)annualACac-2base: iam-account-authorization-details
AC-02 (12)annualACac-2base: iam-account-authorization-details
AC-02 (13)annualACac-2guardduty-suspicious-iam-activity-response
AC-04AC
AC-04 (21)ACac-4(new base)
AC-05AC
AC-06annualACconfig-iam-policy-no-admin-access · identity-center-jit-elevation-workflow
AC-06 (01)ACac-6(new base)iam-account-authorization-details
AC-06 (02)annualACac-6(new base)base: config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow
AC-06 (05)annualACac-6(new base)identity-center-jit-elevation-workflow
AC-06 (07)ACac-6(new base)iam-access-analyzer-unused-access
AC-06 (09)ACac-6(new base)base: config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow
AC-06 (10)annualACac-6(new base)base: config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow
AC-11AC
AC-11 (01)ACac-11(new base)
AC-12AC
AC-17 (01)ACac-17remote-access-authorization-and-monitoring
AC-17 (02)annualACac-17remote-access-authorization-and-monitoring
AC-17 (03)ACac-17remote-access-authorization-and-monitoring
AC-17 (04)ACac-17base: remote-access-authorization-and-monitoring
AC-18 (01)ACac-18
AC-18 (03)ACac-18
AC-19 (05)ACac-19
AC-20 (01)ACac-20base: external-access-inventory-and-trust-boundary
AC-20 (02)ACac-20base: external-access-inventory-and-trust-boundary
AC-21AC
AT-02 (03)ATat-2
AU-03 (01)annualAUau-3
AU-06 (01)annualAUau-6cloudwatch-log-review-alerting
AU-06 (03)annualAUau-6base: cloudwatch-log-review-alerting
AU-07AUaudit-reduction-and-report-generation
AU-07 (01)AUau-7(new base)audit-reduction-and-report-generation
AU-09 (04)AUau-9base: config-cloudtrail-audit-logging
CA-02 (03)CAca-2
CA-07 (01)CAca-7
CA-08 (01)annualCAca-8
CA-08 (02)annualCAca-8
CM-02 (02)CMcm-2config-asset-inventory
CM-02 (03)CMcm-2base: ssm-configuration-baseline-enforced
CM-02 (07)CMcm-2base: ssm-configuration-baseline-enforced
CM-03CMcloudtrail-config-change-history
CM-03 (02)CMcm-3(new base)base: cloudtrail-config-change-history
CM-03 (04)CMcm-3(new base)security-representative-change-approval
CM-04 (02)CMcm-4change-verification-status-checks-and-run-records
CM-05 (01)CMcm-5base: change-authority-restrictions-and-enforcement
CM-05 (05)CMcm-5base: change-authority-restrictions-and-enforcement
CM-06 (01)annualCMcm-6base: ssm-configuration-baseline-enforced
CM-07 (01)annualCMcm-7config-least-functionality
CM-07 (02)annualCMcm-7base: config-least-functionality
CM-07 (05)annualCMcm-7base: config-least-functionality
CM-08 (01)CMcm-8config-asset-inventory
CM-08 (03)CMcm-8unauthorized-component-detection-and-response
CM-09CM
CM-12CMinformation-location-and-classification
CM-12 (01)CMcm-12(new base)information-location-and-classification
CP-02 (01)CPcp-2
CP-02 (03)CPcp-2
CP-02 (08)CPcp-2
CP-04 (01)CPcp-4
CP-06CP
CP-06 (01)CPcp-6(new base)
CP-06 (03)CPcp-6(new base)
CP-07CP
CP-07 (01)CPcp-7(new base)
CP-07 (02)CPcp-7(new base)
CP-07 (03)CPcp-7(new base)
CP-08CP
CP-08 (01)CPcp-8(new base)
CP-08 (02)CPcp-8(new base)
CP-09 (01)CPcp-9base: config-data-backup-enabled
CP-09 (08)CPcp-9base: config-data-backup-enabled
CP-10 (02)CPcp-10backup-restore-testing
IA-02 (05)annualIAia-2base: config-mfa-enabled-console-access · iam-credential-report · identity-sources-and-root-credential-lockdown
IA-02 (06)annualIAia-2base: config-mfa-enabled-console-access · iam-credential-report · identity-sources-and-root-credential-lockdown
IA-03IA
IA-04 (04)IAia-4base: identifier-assignment-and-reuse-prevention
IA-05 (02)IAia-5base: config-access-keys-rotated · iam-credential-report
IA-05 (06)IAia-5secret-exposure-detection-and-push-protection
IA-05 (07)IAia-5base: config-access-keys-rotated · iam-credential-report
IA-12IA
IA-12 (02)IAia-12(new base)
IA-12 (03)IAia-12(new base)
IA-12 (05)IAia-12(new base)
IR-03annualIRguardduty-incident-after-action · guardduty-pattern-review-past-incidents
IR-03 (02)IRir-3(new base)base: guardduty-incident-after-action · guardduty-pattern-review-past-incidents
IR-04 (01)annualIRir-4guardduty-incident-after-action · guardduty-pattern-review-past-incidents · securityhub-incident-review-procedures
IR-06 (01)IRir-6securityhub-incident-review-procedures
IR-06 (03)IRir-6securityhub-incident-review-procedures
IR-07 (01)IRir-7securityhub-incident-review-procedures
IR-09IR
IR-09 (02)IRir-9(new base)
IR-09 (03)IRir-9(new base)
IR-09 (04)IRir-9(new base)
MA-03MA
MA-03 (01)MAma-3(new base)
MA-03 (02)annualMAma-3(new base)
MA-03 (03)MAma-3(new base)
MA-05 (01)MAma-5
MA-06MA
MP-03MP
MP-04MP
MP-05MP
PE-04PE
PE-05PE
PE-06 (01)PEpe-6
PE-09PE
PE-10PE
PE-11PE
PE-13 (01)PEpe-13
PE-13 (02)PEpe-13
PE-17PE
PS-03 (03)PSps-3
RA-05 (03)annualRAra-5base: patch-and-vulnerability-remediation
RA-05 (05)RAra-5base: patch-and-vulnerability-remediation
RA-09RA
SA-04 (01)SAsa-4
SA-04 (02)SAsa-4
SA-04 (09)SAsa-4
SA-09 (01)SAsa-9
SA-09 (02)SAsa-9
SA-09 (05)SAsa-9
SA-10SAdeveloper-change-control-and-integrity
SA-11SAstatic-analysis-coverage-and-flaw-disposition
SA-11 (01)annualSAsa-11(new base)base: static-analysis-coverage-and-flaw-disposition
SA-11 (02)SAsa-11(new base)base: static-analysis-coverage-and-flaw-disposition
SA-15SA
SA-15 (03)SAsa-15(new base)
SC-02SC
SC-04SC
SC-07 (03)annualSCsc-7boundary-access-points-and-default-deny
SC-07 (04)annualSCsc-7boundary-access-points-and-default-deny
SC-07 (05)annualSCsc-7boundary-access-points-and-default-deny
SC-07 (07)annualSCsc-7base: config-network-boundary-protection
SC-07 (08)annualSCsc-7base: config-network-boundary-protection
SC-07 (12)annualSCsc-7base: config-network-boundary-protection
SC-07 (18)annualSCsc-7base: config-network-boundary-protection
SC-10SC
SC-17SC
SC-18SCmobile-code-admission-and-bundle-provenance
SC-23SCsession-authenticity-tls-termination
SC-45SC
SC-45 (01)annualSCsc-45(new base)
SI-02 (02)SIsi-2base: patch-and-vulnerability-remediation
SI-02 (03)SIsi-2base: patch-and-vulnerability-remediation
SI-04 (01)annualSIsi-4base: config-threat-monitoring-enabled
SI-04 (02)annualSIsi-4base: config-threat-monitoring-enabled
SI-04 (04)SIsi-4base: config-threat-monitoring-enabled
SI-04 (05)SIsi-4securityhub-incident-review-procedures
SI-04 (16)annualSIsi-4base: config-threat-monitoring-enabled
SI-04 (18)SIsi-4base: config-threat-monitoring-enabled
SI-04 (23)annualSIsi-4base: config-threat-monitoring-enabled
SI-06annualSI
SI-07annualSIintegrity-verification-and-immutability
SI-07 (01)annualSIsi-7(new base)integrity-verification-and-immutability
SI-07 (07)SIsi-7(new base)build-provenance-attestation-verification
SI-08SI
SI-08 (02)SIsi-8(new base)
SI-10annualSIinput-validation-taint-analysis-coverage
SI-11SIerror-handling-information-exposure-scanning
SI-16SI
SR-06SRdependency-vulnerability-monitoring