Class C → D
Moving from class C to class D — our reading: Rev5 Moderate to our reading: Rev5 High. The step has two halves and only one of them is a control list: the scope it adds, and the per-class clocks that tighten underneath it. The rules name only classes. Low, Moderate and High are Rev5's, and pairing them with a class is our reading rather than something the rules state.
Class D is still being written
Pendingspecification incomplete
Three places in the rules say so, and all three are read from the dataset rather than from a schedule — so this notice comes down on its own when the text fills in. What IS written for this class is worth building against; what is missing is not a gap in your programme.
- A rule says the specifics are not set yet
“Providers with 20x Class D Certifications MUST significantly supersede the minimum requirements for lower Classes, with specifics to be set during the 20x Phase 4 Pilot.”
- Indicators that state nothing at this class — stated at class C
- A clock with no row at this class — stated at class C
Class C → Dfour measurements, four denominators — deliberately never summed into one number
controls the class D baseline adds
0 / 87 reached by a Key Security Indicator — by construction, not by neglect. Climbing a class does not add automatable controls.
21 are in the annual independent-assessment subset. 46 tighten a base control a recipe already covers — a prerequisite, never partial credit — and those collapse onto 18 mechanisms. 41 have nothing behind them at all.
Key Security Indicators, out of those in scope at class D— never a total
9 / 41 indicators carry at least 4 distinct authored methods, against 2 at class C.
The set of things to automate does not grow; the number of independent methods per thing does. Four queries against one API returning one fact is one method with extra steps. FRC-CSX-VVK states both levels; the wording is in the panel below.
unit: indicator ×41 or theme ×10 → 7
The rules never say whether “each Key Security Indicator” means one of the 10 themes or one of the 46 indicators. FedRAMP’s own schema names the 46 “ksi_indicator” and the 10 “ksi_theme”, so the indicator is the reading published here — with the theme reading shown beside it, because the two are 4.6× apart and no automation number means anything without its unit.
a date, per indicator — never a fraction
Measured from your own earliest retained persistent-validation record, which this product does not hold and will not invent. The window is stated per class by FRC-CSX-MOT, and it is the one requirement on this page that no amount of engineering shortens: methods can be built, bought or re-pointed later, and history cannot be back-filled. The most useful thing you can do about this row is start retaining today.
a measured distribution against each target rate — never a pass
7 per-class clocks move across this step and every one of them is a rate, measurable from your own workflow schedules and scanner run history. Report each as a distribution with its target beside it, on its own lookback window — the targets below span a single day to six months, so no one window can judge them all. A cron that exists and a job that ran are different facts.
87 of the 87 controls this step adds are orphans: no 20x Key Security Indicator reaches them. The consequence is structural rather than editorial — the control graph this site is built on is assembled from indicator edges, so an orphan has no node, no /control/ permalink, and cannot be dispositioned on the automation frontier, whose universe is the KSI-reached set. They are enumerated here and nowhere else on the site, and the ids below are deliberately not links.
Added controls grouped by the recipe that reaches the control or, for an enhancement, the base control it tightens. A recipe on a base control is a lead for scoping, never evidence for the enhancement — a covered base is why the lower authorization is held. Each control is listed once, under whichever candidate mechanism carries the most of this step, so the counts partition the added set rather than double-count it. Where a control has more than one candidate, the full set is in its row of the table below.
- 7config-threat-monitoring-enabledawssi-4.10 · si-4.11 · si-4.12 · si-4.14 · si-4.19 · si-4.20 · si-4.22
- 5guardduty-pattern-review-past-incidentsawsir-4.2 · ir-4.4 · ir-4.6 · ir-4.11 · ir-5.1
- 4cloudwatch-log-review-alertingawsau-6.4 · au-6.5 · au-6.6 · au-6.7
- 4config-cloudtrail-audit-loggingawsau-9.2 · au-9.3 · au-12.1 · au-12.3
- 3config-data-backup-enabledawscp-9.2 · cp-9.3 · cp-9.5
- 3config-network-boundary-protectionawssc-7.10 · sc-7.20 · sc-7.21
- 3integrity-verification-and-immutabilityawssi-7.2 · si-7.5 · si-7.15
- 2audit-log-retention-and-delivery-failureawsau-5.1 · au-5.2
- 2cloudtrail-config-change-historyawscm-3.1 · cm-3.6
- 2config-access-keys-rotatedawsia-5.8 · ia-5.13
- 2config-asset-inventoryawscm-8.2 · cm-8.4
- 2config-iam-policy-no-admin-accessawsac-6.3 · ac-6.8
- 2patch-and-vulnerability-remediationawsra-5.4 · ra-5.8
- 1backup-restore-testingawscp-10.4
- 1iam-account-authorization-detailsawsac-2.11
- 1personnel-separation-access-revocationawsps-4.2
- 1security-advisories-receipt-and-disseminationawssi-5.1
- 1ssm-configuration-baseline-enforcedawscm-6.2
No mechanism anywhere in the overlays (41)
Neither plane reaches these, nor their base controls. This is the residue — kept in rather than rounded away, and the honest size of what a scan of the estate or the pipeline cannot currently witness.
ac-4.4 · ac-10 · ac-18.4 · ac-18.5 · au-10 · ca-2.2 · ca-3.6 · cm-4.1 · cm-14 · cp-2.2 · cp-2.5 · cp-3.1 · cp-4.2 · cp-6.2 · cp-7.4 · cp-8.3 · cp-8.4 · ia-12.4 · ir-2.1 · ir-2.2 · ma-2.2 · ma-4.3 · mp-6.1 · mp-6.2 · mp-6.3 · pe-3.1 · pe-6.4 · pe-8.1 · pe-11.1 · pe-14.2 · pe-15.1 · pe-18 · sa-4.5 · sa-16 · sa-17 · sa-21 · sc-3 · sc-12.1 · sc-24 · sr-9 · sr-9.1
Requirements whose timeframe is stated per class and differs across this step. A baseline diff cannot see these: the requirement id is identical in both classes and only the number moves. Units are the dataset’s own and are never converted.
| Requirement | Class C | Class D | What it is |
|---|---|---|---|
| CPO-CSF-CPM | 1 year | 6 months | Certification Package Maintenance for Rev5 |
| CPO-CSX-CPM | 2 weeks | 1 week | Certification Package Maintenance for 20x |
| VDR-TFR-MVX | 3 days | — | Persistent Machine Verification and Validation for 20x — not stated for class D. |
| VDR-TFR-PDD | 14 days | 7 days | Persistent Drift Detection |
| VDR-TFR-PSD | 3 days | 1 day | Persistent Sample Detection |
| VER-TFR-EVU | 5 days | 2 days | Evaluate Vulnerabilities Quickly |
| VER-TFR-MRH | 14 days | 7 days | Historical Activity |
The rest of the per-class rules: requirements whose class levels differ in force or in wording and carry no timeframe to diff. The clock table above cannot see these, and for the step to the highest class they are where the machine-automation requirement actually lives — the quota is stated as a count and the history window as prose, so neither is a number a clock diff can compare. Statements are the dataset’s own and are never paraphrased. A requirement that names its own class and is otherwise identical at both is counted as unchanged.
- Class C
- Providers with Class C Certifications MAY supply per-service FedRAMP Certification materials.
- Class D
- Providers with Class D Certifications MUST supply per-service FedRAMP Certification materials.
- Class C
- Providers with Class C Certifications SHOULD use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
- Class D
- Providers with Class D Certifications MUST use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
- FRC-CSX-MOTMetrics Over Time for Key Security Indicators
- Class C
- Providers seeking 20x Class C Certification MUST supply historical metrics including status from persistent validation over at least the past 6 months for all Key Security Indicators.
- Class D
- Providers seeking 20x Class D Certification MUST provide historical metrics including status from persistent validation over at least the past 18 months for all Key Security Indicators.
- FRC-CSX-VVKAutomated Verification and Validation of Key Security Indicators
- Class C
- Providers seeking 20x Class C Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 2 automated methods for each Key Security Indicator.
- Class D
- Providers seeking 20x Class D Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 4 automated methods for each Key Security Indicator.
- SDR-CSX-KMTKey Security Indicator Metrics
- Class C
- Providers with 20x Class C Certifications MUST also include historical metrics in their Security Decision Record, supplying at least the following information for each applicable Key Security Indicator:
- Class D
- Providers with 20x Class D Certifications MUST significantly supersede the minimum requirements for lower Classes, with specifics to be set during the 20x Phase 4 Pilot.
- VDR-TFR-PVRMitigation and Remediation Expectations
- Class C
- Providers with Class C Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
- Class D
- Providers with Class D Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the maximum timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
- Class C
- Providers with Class C Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.
- Class D
- Providers with Class D Certifications SHOULD treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.
- CP 12
- AU 11
- SI 11
- AC 7
- CM 7
- IR 7
- PE 7
- SC 6
- SA 4
- IA 3
- MP 3
- CA 2
- MA 2
- RA 2
- SR 2
- PS 1
| Control | Family | Tightens | Reached by |
|---|---|---|---|
| AC-02 (11)annual | AC | ac-2 | base: iam-account-authorization-details |
| AC-04 (04) | AC | ac-4 | — |
| AC-06 (03)annual | AC | ac-6 | base: config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow |
| AC-06 (08)annual | AC | ac-6 | base: config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow |
| AC-10 | AC | — | — |
| AC-18 (04) | AC | ac-18 | — |
| AC-18 (05) | AC | ac-18 | — |
| AU-05 (01)annual | AU | au-5 | base: audit-log-retention-and-delivery-failure |
| AU-05 (02)annual | AU | au-5 | base: audit-log-retention-and-delivery-failure |
| AU-06 (04)annual | AU | au-6 | base: cloudwatch-log-review-alerting |
| AU-06 (05)annual | AU | au-6 | base: cloudwatch-log-review-alerting |
| AU-06 (06)annual | AU | au-6 | base: cloudwatch-log-review-alerting |
| AU-06 (07)annual | AU | au-6 | base: cloudwatch-log-review-alerting |
| AU-09 (02) | AU | au-9 | base: config-cloudtrail-audit-logging |
| AU-09 (03) | AU | au-9 | base: config-cloudtrail-audit-logging |
| AU-10annual | AU | — | — |
| AU-12 (01)annual | AU | au-12 | base: config-cloudtrail-audit-logging |
| AU-12 (03)annual | AU | au-12 | base: config-cloudtrail-audit-logging |
| CA-02 (02) | CA | ca-2 | — |
| CA-03 (06) | CA | ca-3 | — |
| CM-03 (01) | CM | cm-3 | base: cloudtrail-config-change-history |
| CM-03 (06) | CM | cm-3 | base: cloudtrail-config-change-history |
| CM-04 (01) | CM | cm-4 | — |
| CM-06 (02)annual | CM | cm-6 | base: ssm-configuration-baseline-enforced |
| CM-08 (02) | CM | cm-8 | base: config-asset-inventory |
| CM-08 (04) | CM | cm-8 | base: config-asset-inventory |
| CM-14 | CM | — | — |
| CP-02 (02) | CP | cp-2 | — |
| CP-02 (05) | CP | cp-2 | — |
| CP-03 (01) | CP | cp-3 | — |
| CP-04 (02) | CP | cp-4 | — |
| CP-06 (02) | CP | cp-6 | — |
| CP-07 (04) | CP | cp-7 | — |
| CP-08 (03) | CP | cp-8 | — |
| CP-08 (04) | CP | cp-8 | — |
| CP-09 (02) | CP | cp-9 | base: config-data-backup-enabled |
| CP-09 (03) | CP | cp-9 | base: config-data-backup-enabled |
| CP-09 (05) | CP | cp-9 | base: config-data-backup-enabled |
| CP-10 (04) | CP | cp-10 | base: backup-restore-testing |
| IA-05 (08) | IA | ia-5 | base: config-access-keys-rotated · iam-credential-report |
| IA-05 (13) | IA | ia-5 | base: config-access-keys-rotated · iam-credential-report |
| IA-12 (04) | IA | ia-12 | — |
| IR-02 (01) | IR | ir-2 | — |
| IR-02 (02) | IR | ir-2 | — |
| IR-04 (02)annual | IR | ir-4 | base: guardduty-incident-after-action · guardduty-pattern-review-past-incidents · securityhub-incident-review-procedures |
| IR-04 (04)annual | IR | ir-4 | base: guardduty-incident-after-action · guardduty-pattern-review-past-incidents · securityhub-incident-review-procedures |
| IR-04 (06)annual | IR | ir-4 | base: guardduty-incident-after-action · guardduty-pattern-review-past-incidents · securityhub-incident-review-procedures |
| IR-04 (11) | IR | ir-4 | base: guardduty-incident-after-action · guardduty-pattern-review-past-incidents · securityhub-incident-review-procedures |
| IR-05 (01) | IR | ir-5 | base: guardduty-pattern-review-past-incidents |
| MA-02 (02) | MA | ma-2 | — |
| MA-04 (03) | MA | ma-4 | — |
| MP-06 (01) | MP | mp-6 | — |
| MP-06 (02) | MP | mp-6 | — |
| MP-06 (03) | MP | mp-6 | — |
| PE-03 (01) | PE | pe-3 | — |
| PE-06 (04) | PE | pe-6 | — |
| PE-08 (01) | PE | pe-8 | — |
| PE-11 (01) | PE | pe-11 | — |
| PE-14 (02) | PE | pe-14 | — |
| PE-15 (01) | PE | pe-15 | — |
| PE-18 | PE | — | — |
| PS-04 (02) | PS | ps-4 | base: personnel-separation-access-revocation |
| RA-05 (04) | RA | ra-5 | base: patch-and-vulnerability-remediation |
| RA-05 (08) | RA | ra-5 | base: patch-and-vulnerability-remediation |
| SA-04 (05) | SA | sa-4 | — |
| SA-16 | SA | — | — |
| SA-17 | SA | — | — |
| SA-21 | SA | — | — |
| SC-03 | SC | — | — |
| SC-07 (10) | SC | sc-7 | base: config-network-boundary-protection |
| SC-07 (20)annual | SC | sc-7 | base: config-network-boundary-protection |
| SC-07 (21)annual | SC | sc-7 | base: config-network-boundary-protection |
| SC-12 (01) | SC | sc-12 | — |
| SC-24 | SC | — | — |
| SI-04 (10)annual | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (11) | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (12) | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (14) | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (19)annual | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (20)annual | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-04 (22) | SI | si-4 | base: config-threat-monitoring-enabled |
| SI-05 (01) | SI | si-5 | base: security-advisories-receipt-and-dissemination |
| SI-07 (02) | SI | si-7 | base: integrity-verification-and-immutability |
| SI-07 (05) | SI | si-7 | base: integrity-verification-and-immutability |
| SI-07 (15) | SI | si-7 | base: integrity-verification-and-immutability |
| SR-09 | SR | — | — |
| SR-09 (01) | SR | sr-9(new base) | — |