Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Class CD

Moving from class C to class D our reading: Rev5 Moderate to our reading: Rev5 High. The step has two halves and only one of them is a control list: the scope it adds, and the per-class clocks that tighten underneath it. The rules name only classes. Low, Moderate and High are Rev5's, and pairing them with a class is our reading rather than something the rules state.

Class D is still being written

Pendingspecification incomplete

Three places in the rules say so, and all three are read from the dataset rather than from a schedule — so this notice comes down on its own when the text fills in. What IS written for this class is worth building against; what is missing is not a gap in your programme.

A rule says the specifics are not set yet

Providers with 20x Class D Certifications MUST significantly supersede the minimum requirements for lower Classes, with specifics to be set during the 20x Phase 4 Pilot.

Indicators that state nothing at this class — stated at class C
A clock with no row at this class — stated at class C

Class CDfour measurements, four denominators — deliberately never summed into one number

Row AScope

controls the class D baseline adds

0 / 87 reached by a Key Security Indicator — by construction, not by neglect. Climbing a class does not add automatable controls.

21 are in the annual independent-assessment subset. 46 tighten a base control a recipe already covers — a prerequisite, never partial credit — and those collapse onto 18 mechanisms. 41 have nothing behind them at all.

Row BAutomation depth

Key Security Indicators, out of those in scope at class D— never a total

9 / 41 indicators carry at least 4 distinct authored methods, against 2 at class C.

The set of things to automate does not grow; the number of independent methods per thing does. Four queries against one API returning one fact is one method with extra steps. FRC-CSX-VVK states both levels; the wording is in the panel below.

unit: indicator ×41 or theme ×10 7

The rules never say whether “each Key Security Indicator” means one of the 10 themes or one of the 46 indicators. FedRAMP’s own schema names the 46 “ksi_indicator” and the 10 “ksi_theme”, so the indicator is the reading published here — with the theme reading shown beside it, because the two are 4.6× apart and no automation number means anything without its unit.

Row CAccumulation

a date, per indicator — never a fraction

Measured from your own earliest retained persistent-validation record, which this product does not hold and will not invent. The window is stated per class by FRC-CSX-MOT, and it is the one requirement on this page that no amount of engineering shortens: methods can be built, bought or re-pointed later, and history cannot be back-filled. The most useful thing you can do about this row is start retaining today.

Row DCadence

a measured distribution against each target rate — never a pass

7 per-class clocks move across this step and every one of them is a rate, measurable from your own workflow schedules and scanner run history. Report each as a distribution with its target beside it, on its own lookback window — the targets below span a single day to six months, so no one window can judge them all. A cron that exists and a job that ran are different facts.

Read this before the numbers below

87 of the 87 controls this step adds are orphans: no 20x Key Security Indicator reaches them. The consequence is structural rather than editorial — the control graph this site is built on is assembled from indicator edges, so an orphan has no node, no /control/ permalink, and cannot be dispositioned on the automation frontier, whose universe is the KSI-reached set. They are enumerated here and nowhere else on the site, and the ids below are deliberately not links.

Where the work concentrates18 mechanisms

Added controls grouped by the recipe that reaches the control or, for an enhancement, the base control it tightens. A recipe on a base control is a lead for scoping, never evidence for the enhancement — a covered base is why the lower authorization is held. Each control is listed once, under whichever candidate mechanism carries the most of this step, so the counts partition the added set rather than double-count it. Where a control has more than one candidate, the full set is in its row of the table below.

No mechanism anywhere in the overlays (41)

Neither plane reaches these, nor their base controls. This is the residue — kept in rather than rounded away, and the honest size of what a scan of the estate or the pipeline cannot currently witness.

ac-4.4 · ac-10 · ac-18.4 · ac-18.5 · au-10 · ca-2.2 · ca-3.6 · cm-4.1 · cm-14 · cp-2.2 · cp-2.5 · cp-3.1 · cp-4.2 · cp-6.2 · cp-7.4 · cp-8.3 · cp-8.4 · ia-12.4 · ir-2.1 · ir-2.2 · ma-2.2 · ma-4.3 · mp-6.1 · mp-6.2 · mp-6.3 · pe-3.1 · pe-6.4 · pe-8.1 · pe-11.1 · pe-14.2 · pe-15.1 · pe-18 · sa-4.5 · sa-16 · sa-17 · sa-21 · sc-3 · sc-12.1 · sc-24 · sr-9 · sr-9.1

Clocks that move7 unchanged

Requirements whose timeframe is stated per class and differs across this step. A baseline diff cannot see these: the requirement id is identical in both classes and only the number moves. Units are the dataset’s own and are never converted.

RequirementClass CClass DWhat it is
CPO-CSF-CPM1 year6 monthsCertification Package Maintenance for Rev5
CPO-CSX-CPM2 weeks1 weekCertification Package Maintenance for 20x
VDR-TFR-MVX3 daysPersistent Machine Verification and Validation for 20x — not stated for class D.
VDR-TFR-PDD14 days7 daysPersistent Drift Detection
VDR-TFR-PSD3 days1 dayPersistent Sample Detection
VER-TFR-EVU5 days2 daysEvaluate Vulnerabilities Quickly
VER-TFR-MRH14 days7 daysHistorical Activity
Obligations that move without a clock8 unchanged

The rest of the per-class rules: requirements whose class levels differ in force or in wording and carry no timeframe to diff. The clock table above cannot see these, and for the step to the highest class they are where the machine-automation requirement actually lives — the quota is stated as a count and the history window as prose, so neither is a number a clock diff can compare. Statements are the dataset’s own and are never paraphrased. A requirement that names its own class and is otherwise identical at both is counted as unchanged.

  • CDS-CSO-PSMPer-Service Certification MaterialsMAYMUST
    Class C
    Providers with Class C Certifications MAY supply per-service FedRAMP Certification materials.
    Class D
    Providers with Class D Certifications MUST supply per-service FedRAMP Certification materials.
  • CMU-CSO-UVMUsing Validated Cryptographic ModulesSHOULDMUST
    Class C
    Providers with Class C Certifications SHOULD use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
    Class D
    Providers with Class D Certifications MUST use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
  • FRC-CSX-MOTMetrics Over Time for Key Security Indicators
    Class C
    Providers seeking 20x Class C Certification MUST supply historical metrics including status from persistent validation over at least the past 6 months for all Key Security Indicators.
    Class D
    Providers seeking 20x Class D Certification MUST provide historical metrics including status from persistent validation over at least the past 18 months for all Key Security Indicators.
  • FRC-CSX-VVKAutomated Verification and Validation of Key Security Indicators
    Class C
    Providers seeking 20x Class C Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 2 automated methods for each Key Security Indicator.
    Class D
    Providers seeking 20x Class D Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 4 automated methods for each Key Security Indicator.
  • SDR-CSX-KMTKey Security Indicator Metrics
    Class C
    Providers with 20x Class C Certifications MUST also include historical metrics in their Security Decision Record, supplying at least the following information for each applicable Key Security Indicator:
    Class D
    Providers with 20x Class D Certifications MUST significantly supersede the minimum requirements for lower Classes, with specifics to be set during the 20x Phase 4 Pilot.
  • VDR-TFR-PVRMitigation and Remediation Expectations
    Class C
    Providers with Class C Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
    Class D
    Providers with Class D Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the maximum timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
  • VER-TFR-NRINon-Internet-Reachable IncidentsMAYSHOULD
    Class C
    Providers with Class C Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.
    Class D
    Providers with Class D Certifications SHOULD treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.
By family16 families
  • CP 12
  • AU 11
  • SI 11
  • AC 7
  • CM 7
  • IR 7
  • PE 7
  • SC 6
  • SA 4
  • IA 3
  • MP 3
  • CA 2
  • MA 2
  • RA 2
  • SR 2
  • PS 1
Every control added87 controls
ControlFamilyTightensReached by
AC-02 (11)annualACac-2base: iam-account-authorization-details
AC-04 (04)ACac-4
AC-06 (03)annualACac-6base: config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow
AC-06 (08)annualACac-6base: config-iam-policy-no-admin-access · identity-center-jit-elevation-workflow
AC-10AC
AC-18 (04)ACac-18
AC-18 (05)ACac-18
AU-05 (01)annualAUau-5base: audit-log-retention-and-delivery-failure
AU-05 (02)annualAUau-5base: audit-log-retention-and-delivery-failure
AU-06 (04)annualAUau-6base: cloudwatch-log-review-alerting
AU-06 (05)annualAUau-6base: cloudwatch-log-review-alerting
AU-06 (06)annualAUau-6base: cloudwatch-log-review-alerting
AU-06 (07)annualAUau-6base: cloudwatch-log-review-alerting
AU-09 (02)AUau-9base: config-cloudtrail-audit-logging
AU-09 (03)AUau-9base: config-cloudtrail-audit-logging
AU-10annualAU
AU-12 (01)annualAUau-12base: config-cloudtrail-audit-logging
AU-12 (03)annualAUau-12base: config-cloudtrail-audit-logging
CA-02 (02)CAca-2
CA-03 (06)CAca-3
CM-03 (01)CMcm-3base: cloudtrail-config-change-history
CM-03 (06)CMcm-3base: cloudtrail-config-change-history
CM-04 (01)CMcm-4
CM-06 (02)annualCMcm-6base: ssm-configuration-baseline-enforced
CM-08 (02)CMcm-8base: config-asset-inventory
CM-08 (04)CMcm-8base: config-asset-inventory
CM-14CM
CP-02 (02)CPcp-2
CP-02 (05)CPcp-2
CP-03 (01)CPcp-3
CP-04 (02)CPcp-4
CP-06 (02)CPcp-6
CP-07 (04)CPcp-7
CP-08 (03)CPcp-8
CP-08 (04)CPcp-8
CP-09 (02)CPcp-9base: config-data-backup-enabled
CP-09 (03)CPcp-9base: config-data-backup-enabled
CP-09 (05)CPcp-9base: config-data-backup-enabled
CP-10 (04)CPcp-10base: backup-restore-testing
IA-05 (08)IAia-5base: config-access-keys-rotated · iam-credential-report
IA-05 (13)IAia-5base: config-access-keys-rotated · iam-credential-report
IA-12 (04)IAia-12
IR-02 (01)IRir-2
IR-02 (02)IRir-2
IR-04 (02)annualIRir-4base: guardduty-incident-after-action · guardduty-pattern-review-past-incidents · securityhub-incident-review-procedures
IR-04 (04)annualIRir-4base: guardduty-incident-after-action · guardduty-pattern-review-past-incidents · securityhub-incident-review-procedures
IR-04 (06)annualIRir-4base: guardduty-incident-after-action · guardduty-pattern-review-past-incidents · securityhub-incident-review-procedures
IR-04 (11)IRir-4base: guardduty-incident-after-action · guardduty-pattern-review-past-incidents · securityhub-incident-review-procedures
IR-05 (01)IRir-5base: guardduty-pattern-review-past-incidents
MA-02 (02)MAma-2
MA-04 (03)MAma-4
MP-06 (01)MPmp-6
MP-06 (02)MPmp-6
MP-06 (03)MPmp-6
PE-03 (01)PEpe-3
PE-06 (04)PEpe-6
PE-08 (01)PEpe-8
PE-11 (01)PEpe-11
PE-14 (02)PEpe-14
PE-15 (01)PEpe-15
PE-18PE
PS-04 (02)PSps-4base: personnel-separation-access-revocation
RA-05 (04)RAra-5base: patch-and-vulnerability-remediation
RA-05 (08)RAra-5base: patch-and-vulnerability-remediation
SA-04 (05)SAsa-4
SA-16SA
SA-17SA
SA-21SA
SC-03SC
SC-07 (10)SCsc-7base: config-network-boundary-protection
SC-07 (20)annualSCsc-7base: config-network-boundary-protection
SC-07 (21)annualSCsc-7base: config-network-boundary-protection
SC-12 (01)SCsc-12
SC-24SC
SI-04 (10)annualSIsi-4base: config-threat-monitoring-enabled
SI-04 (11)SIsi-4base: config-threat-monitoring-enabled
SI-04 (12)SIsi-4base: config-threat-monitoring-enabled
SI-04 (14)SIsi-4base: config-threat-monitoring-enabled
SI-04 (19)annualSIsi-4base: config-threat-monitoring-enabled
SI-04 (20)annualSIsi-4base: config-threat-monitoring-enabled
SI-04 (22)SIsi-4base: config-threat-monitoring-enabled
SI-05 (01)SIsi-5base: security-advisories-receipt-and-dissemination
SI-07 (02)SIsi-7base: integrity-verification-and-immutability
SI-07 (05)SIsi-7base: integrity-verification-and-immutability
SI-07 (15)SIsi-7base: integrity-verification-and-immutability
SR-09SR
SR-09 (01)SRsr-9(new base)