Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Evidence & Artifact Planner

What the rules require you to produce, not just to satisfy. The evidence obligation lives on FRR rather than KSI — no KSI indicator carries an artifacts key, which is why this looks absent if you only check the indicators.

Owed by every rule (5)

info.default_artifacts — these apply to all 246 FRR requirements, so they are stated once here and never repeated per rule. A requirement with no specific artifacts still owes these five.

  1. Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
  2. Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
  3. Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
  4. Independent verification.
  5. Independent validation.

A further 5 defaults apply to every KSI indicator. No KSI indicator carries artifacts of its own — the rule-specific evidence below is entirely FRR.

Distinct artifacts (51)

60 of the 246 requirements demand evidence beyond the defaults — 53 at rule level and 7 only inside a certification class. Those 60 demands collapse to 51 distinct artifacts, so the build list is shorter than the rule list.

3 of them have an authored AWS recipe that produces part of the evidence — see the evidence plan. The rest are collected by hand. That gap is real and shown, not filled in with plausible-looking mappings.

RulesArtifactDemanded by
7Explanation of how to access this informationSCG-CSO-PUBSCG-CSO-SDFSCG-ENH-APISCG-ENH-CMPSCG-ENH-EXPSCG-ENH-MRGSCG-ENH-VRHProviders
7or explanation why this functionality is not availableSCG-CSO-PUBSCG-CSO-SDFSCG-ENH-APISCG-ENH-CMPSCG-ENH-EXPSCG-ENH-MRGSCG-ENH-VRHProviders
5URL to the human-readable data.CDS-CSO-PUBCDS-CSO-SVCMKT-CAS-WEBMKT-IAS-WEBSCG-CSO-RSCAdvisorsAssessorsProviders
4A human readable explanation of how the machine readable output is derived.MAS-CSO-FLOMAS-CSO-IIRMAS-CSO-MDIMAS-CSO-TPRProviders
4The code for the automated process used to generate the machine readable output.MAS-CSO-FLOMAS-CSO-IIRMAS-CSO-MDIMAS-CSO-TPRProviders
4URL to the machine-readable data.CDS-CSO-PUBMKT-CAS-WEBMKT-IAS-WEBSCG-CSO-RSCAdvisorsAssessorsProviders
3A recent vulnerability report or a sample vulnerability reportVER-RPT-AVIVER-RPT-VDTVER-TFR-MHRProviders
3Explanation of how FedRAMP can obtain this information.CDS-TRC-AAISCN-CSO-HISSCN-CSO-MARProviders
3Explanation of how the provider decides whether or not to share these materials or other related policies.CDS-UTC-AGASCG-CSO-AUPSCN-CSO-HRMProviders
3URL or explanation of how to request these materials.CDS-UTC-AGASCG-CSO-AUPSCN-CSO-HRMProviders
2An incident log showing an example of one or more incidents being evaluated including the reason for the determination. The log can be from real incidents, simulated incidents, or a combination of sources.IEC-CSO-EFIIEC-CSO-EFRProviders
2Automated validation to check FSI mailbox configurationAFC-CSO-EMRAFC-CSO-TFGProviders
2Configuration settings for FSI mailboxAFC-CSO-EMRAFC-CSO-TFGProviders
2Explanation of how to access this information.CDS-CSO-HADCDS-CSO-IRPProviders
2List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.Class A, B, C, D only.CMU-CSO-CMDCMU-CSO-UVMProviders
1A machine readable output containing all required data of the components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-IIRProviders
1A machine readable output containing all required data of the metadata collected or maintained by the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-MDIProviders
1A machine readable output containing all required data of the permitted connections between components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-FLOProviders
1A machine readable output containing all required data of the third-party information resources of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-TPRProviders
1A recent Significant Change Notification or sample Significant Change NotificationSCN-CSO-INFProviders
1An Final Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.Class A, B, C, D only.IEC-CSO-FIRProviders
1An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.Class A, B, C, D only.IEC-CSO-IIRProviders
1An Ongoing Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.Class A, B, C, D only.IEC-CSO-OIRProviders
1At least the most recent after verification SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NAVProviders
1At least the most recent final SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NFPProviders
1At least the most recent initial SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NIPProviders
1At least the most recent post deployment SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NAFProviders
1At least the most recent SCN notification including the date it was sent and the date the change was applied. Additional examples may be provided. If no SCN notifications have been sent then this artifact is not required.SCN-ADP-NTFProviders
1Current list of available notification mechanismsSCN-CSO-NOMProviders
1Date of the most recent transformative change and the date of the corresponding documentation update. If no documentation updates were required as the result of this change, explain how this was determined.SCN-TRF-UPDProviders
1Email address to receive messages from FedRAMPAFC-CSO-INBProviders
1Evidence of significant change evaluation including a description fo the change, the determined type, and an explanation for the decision. At least one example must be provided for each type of change. Real examples are prefered but the provider may use fictitious examples as long as the example provides evidence of the decision making process.SCN-CSO-EVAProviders
1Explanation of how the appropriate parties can obtain this log information.CDS-TRC-ACLProviders
1Explanation of if and how this information is shared with other parties.CDS-CSO-RPSProviders
1Explanation of the supplied materials, including how to access and use them.Class A, B, C, D only.CDS-CSO-PSMProviders
1How the report will be deliveredCCM-OCR-AVLProviders
1How the summary will be deliveredCCM-OCR-AFSProviders
1How to access the feedback mechanism.CCM-OCR-FBMProviders
1List of cryptographic modules used by default including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.CMU-CSO-CATProviders
1Most recent Ongoing Certification Report. If the report is not available, the provider MUST provide a sample report that includes all required information.CCM-OCR-AVLProviders
1or an explanation of why machine readable content is not being providedClass B, C, D only.VER-TFR-MRHProviders
1Process, manual or automated, to notify FedRAMP of changes in the FedRAMP Security InboxAFC-CSO-NOCProviders
1selected ordinal recurrence for the Ongoing Certification Report cycle if applicable OR explanation for why Ongoing Certification Reports are not being delivered.Class B only.CCM-QTR-MTGProviders
1selected ordinal recurrence for the Ongoing Certification Report cycle.Class C, D only.CCM-QTR-MTGProviders
1selected ordinal recurrence for the synchronous Quarterly Review cycle if applicable.Class A only.CCM-QTR-MTGProviders
1Third Party assesment report OR explanation why a third party assessor was not engagedSCN-TRF-TPRProviders
1URL and access instructions for historical vulnerability detection and response activity in machine readable formatClass A, B, C, D only.VER-TFR-MRHProviders
1URL or explanation how to access documentation of these features and capabilities.CDS-TRC-SSMProviders
1URL to the documentation for programmatic access.CDS-TRC-PACProviders
1URL to the machine-readable data (if applicable).CDS-CSO-SVCProviders
1URL to the registration page or calendar file.CCM-QTR-REGProviders