Evidence & Artifact Planner
What the rules require you to produce, not just to satisfy. The evidence obligation lives on FRR rather than KSI — no KSI indicator carries an artifacts key, which is why this looks absent if you only check the indicators.
Owed by every rule (5)
info.default_artifacts — these apply to all 246 FRR requirements, so they are stated once here and never repeated per rule. A requirement with no specific artifacts still owes these five.
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
A further 5 defaults apply to every KSI indicator. No KSI indicator carries artifacts of its own — the rule-specific evidence below is entirely FRR.
Distinct artifacts (51)
60 of the 246 requirements demand evidence beyond the defaults — 53 at rule level and 7 only inside a certification class. Those 60 demands collapse to 51 distinct artifacts, so the build list is shorter than the rule list.
3 of them have an authored AWS recipe that produces part of the evidence — see the evidence plan. The rest are collected by hand. That gap is real and shown, not filled in with plausible-looking mappings.
| Rules | Artifact | Demanded by |
|---|---|---|
| 7 | Explanation of how to access this information | SCG-CSO-PUBSCG-CSO-SDFSCG-ENH-APISCG-ENH-CMPSCG-ENH-EXPSCG-ENH-MRGSCG-ENH-VRHProviders |
| 7 | or explanation why this functionality is not available | SCG-CSO-PUBSCG-CSO-SDFSCG-ENH-APISCG-ENH-CMPSCG-ENH-EXPSCG-ENH-MRGSCG-ENH-VRHProviders |
| 5 | URL to the human-readable data. | CDS-CSO-PUBCDS-CSO-SVCMKT-CAS-WEBMKT-IAS-WEBSCG-CSO-RSCAdvisorsAssessorsProviders |
| 4 | A human readable explanation of how the machine readable output is derived. | MAS-CSO-FLOMAS-CSO-IIRMAS-CSO-MDIMAS-CSO-TPRProviders |
| 4 | The code for the automated process used to generate the machine readable output. | MAS-CSO-FLOMAS-CSO-IIRMAS-CSO-MDIMAS-CSO-TPRProviders |
| 4 | URL to the machine-readable data. | CDS-CSO-PUBMKT-CAS-WEBMKT-IAS-WEBSCG-CSO-RSCAdvisorsAssessorsProviders |
| 3 | A recent vulnerability report or a sample vulnerability report | VER-RPT-AVIVER-RPT-VDTVER-TFR-MHRProviders |
| 3 | Explanation of how FedRAMP can obtain this information. | CDS-TRC-AAISCN-CSO-HISSCN-CSO-MARProviders |
| 3 | Explanation of how the provider decides whether or not to share these materials or other related policies. | CDS-UTC-AGASCG-CSO-AUPSCN-CSO-HRMProviders |
| 3 | URL or explanation of how to request these materials. | CDS-UTC-AGASCG-CSO-AUPSCN-CSO-HRMProviders |
| 2 | An incident log showing an example of one or more incidents being evaluated including the reason for the determination. The log can be from real incidents, simulated incidents, or a combination of sources. | IEC-CSO-EFIIEC-CSO-EFRProviders |
| 2 | Automated validation to check FSI mailbox configuration | AFC-CSO-EMRAFC-CSO-TFGProviders |
| 2 | Configuration settings for FSI mailbox | AFC-CSO-EMRAFC-CSO-TFGProviders |
| 2 | Explanation of how to access this information. | CDS-CSO-HADCDS-CSO-IRPProviders |
| 2 | List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.Class A, B, C, D only. | CMU-CSO-CMDCMU-CSO-UVMProviders |
| 1 | A machine readable output containing all required data of the components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering. | MAS-CSO-IIRProviders |
| 1 | A machine readable output containing all required data of the metadata collected or maintained by the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering. | MAS-CSO-MDIProviders |
| 1 | A machine readable output containing all required data of the permitted connections between components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering. | MAS-CSO-FLOProviders |
| 1 | A machine readable output containing all required data of the third-party information resources of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering. | MAS-CSO-TPRProviders |
| 1 | A recent Significant Change Notification or sample Significant Change Notification | SCN-CSO-INFProviders |
| 1 | An Final Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.Class A, B, C, D only. | IEC-CSO-FIRProviders |
| 1 | An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.Class A, B, C, D only. | IEC-CSO-IIRProviders |
| 1 | An Ongoing Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.Class A, B, C, D only. | IEC-CSO-OIRProviders |
| 1 | At least the most recent after verification SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required. | SCN-TRF-NAVProviders |
| 1 | At least the most recent final SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required. | SCN-TRF-NFPProviders |
| 1 | At least the most recent initial SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required. | SCN-TRF-NIPProviders |
| 1 | At least the most recent post deployment SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required. | SCN-TRF-NAFProviders |
| 1 | At least the most recent SCN notification including the date it was sent and the date the change was applied. Additional examples may be provided. If no SCN notifications have been sent then this artifact is not required. | SCN-ADP-NTFProviders |
| 1 | Current list of available notification mechanisms | SCN-CSO-NOMProviders |
| 1 | Date of the most recent transformative change and the date of the corresponding documentation update. If no documentation updates were required as the result of this change, explain how this was determined. | SCN-TRF-UPDProviders |
| 1 | Email address to receive messages from FedRAMP | AFC-CSO-INBProviders |
| 1 | Evidence of significant change evaluation including a description fo the change, the determined type, and an explanation for the decision. At least one example must be provided for each type of change. Real examples are prefered but the provider may use fictitious examples as long as the example provides evidence of the decision making process. | SCN-CSO-EVAProviders |
| 1 | Explanation of how the appropriate parties can obtain this log information. | CDS-TRC-ACLProviders |
| 1 | Explanation of if and how this information is shared with other parties. | CDS-CSO-RPSProviders |
| 1 | Explanation of the supplied materials, including how to access and use them.Class A, B, C, D only. | CDS-CSO-PSMProviders |
| 1 | How the report will be delivered | CCM-OCR-AVLProviders |
| 1 | How the summary will be delivered | CCM-OCR-AFSProviders |
| 1 | How to access the feedback mechanism. | CCM-OCR-FBMProviders |
| 1 | List of cryptographic modules used by default including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules. | CMU-CSO-CATProviders |
| 1 | Most recent Ongoing Certification Report. If the report is not available, the provider MUST provide a sample report that includes all required information. | CCM-OCR-AVLProviders |
| 1 | or an explanation of why machine readable content is not being providedClass B, C, D only. | VER-TFR-MRHProviders |
| 1 | Process, manual or automated, to notify FedRAMP of changes in the FedRAMP Security Inbox | AFC-CSO-NOCProviders |
| 1 | selected ordinal recurrence for the Ongoing Certification Report cycle if applicable OR explanation for why Ongoing Certification Reports are not being delivered.Class B only. | CCM-QTR-MTGProviders |
| 1 | selected ordinal recurrence for the Ongoing Certification Report cycle.Class C, D only. | CCM-QTR-MTGProviders |
| 1 | selected ordinal recurrence for the synchronous Quarterly Review cycle if applicable.Class A only. | CCM-QTR-MTGProviders |
| 1 | Third Party assesment report OR explanation why a third party assessor was not engaged | SCN-TRF-TPRProviders |
| 1 | URL and access instructions for historical vulnerability detection and response activity in machine readable formatClass A, B, C, D only. | VER-TFR-MRHProviders |
| 1 | URL or explanation how to access documentation of these features and capabilities. | CDS-TRC-SSMProviders |
| 1 | URL to the documentation for programmatic access. | CDS-TRC-PACProviders |
| 1 | URL to the machine-readable data (if applicable). | CDS-CSO-SVCProviders |
| 1 | URL to the registration page or calendar file. | CCM-QTR-REGProviders |