Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

The FedRAMP Program

Rules FedRAMP imposes on itself: how the program publishes, reviews, and maintains the certification machinery. Useful to everyone else as a service-level expectation — what you are entitled to expect back from the program, and on what clock.

Requirements binding you
16
of 246 across the whole ruleset
Deadlines yours
1
tightest: 10 business days
Documents
6
of 17 FRR documents mention you

Force of your requirements

Requirement-level force only — per-class overrides are not tallied here.

MUST · 9MAY · 4MUST NOT · 3

Your deadlines (1)

DeadlineRequirementClassForce
10 business daysAFC-FRP-PNT Public Notice of Emergency TestsallMUST

Full context for each deadline lives in the Obligation Clock, pre-filtered to FedRAMP.

Your requirements, by document

AFC Addressing FedRAMP Communication8
  • AFC-FRP-CDSCriticality DesignatorsMUST

    FedRAMP MUST convey the criticality of the message in the subject line, IF the message requires an elevated reaction, using one of the following designators:

  • AFC-FRP-CORExplain Corrective ActionsMUST

    FedRAMP MUST clearly specify the corrective actions that will result from failure to complete the required actions in the body of messages that require an elevated reaction; such actions may vary from negative ratings in the FedRAMP Marketplace to suspension of FedRAMP Certification depending on the severity of the event.

  • AFC-FRP-ERTElevated Reaction TimeframesMUST

    FedRAMP MUST clearly specify the expected timeframe for completing required actions in the body of messages that require an elevated reaction; timeframes for actions will vary depending on the situation but the default timeframes to provide an estimated resolution time for Emergency and Emergency Test designated messages will be as follows:

  • AFC-FRP-PNTPublic Notice of Emergency TestsMUST

    FedRAMP MUST post a public notice at least 10 business days in advance of sending an Emergency Test message; such notices MUST include explanation of the likely expected actions and timeframes for the Emergency Test message.

  • AFC-FRP-RPMReaction MetricsMAY

    FedRAMP MAY track and publicly share the time required by cloud service providers to take the actions specified in messages that require an elevated reaction.

  • AFC-FRP-RQARequired ActionsMUST

    FedRAMP MUST clearly specify the required actions in the body of messages that require an elevated reaction.

  • AFC-FRP-UFSUse FedRAMP_Security Email in EmergenciesMUST

    FedRAMP MUST send Emergency and Emergency Test designated messages from fedramp_security@gsa.gov OR fedramp_security@fedramp.gov.

  • AFC-FRP-VREVerified EmailsMUST

    FedRAMP MUST send messages to cloud service providers using an official @fedramp.gov or @gsa.gov email address with properly configured Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication Reporting and Conformance (DMARC) email authentication.

REC FedRAMP Recognition of Independent Assessment Services3
  • REC-FRP-DRDDouble Revocation DisqualificationMUST NOT

    FedRAMP MUST NOT restore FedRAMP Recognition for an assessor after FedRAMP has revoked that assessor's FedRAMP Recognition 2 times.

  • REC-FRP-FOCForeign Ownership CollectionMUST

    FedRAMP MUST maintain a process to collect foreign ownership, control, or influence declarations from FedRAMP Recognized assessors and updates to those declarations.

  • REC-FRP-RAORecognized Assessors OnlyMUST NOT

    FedRAMP MUST NOT accept verification, validation, or other attestations from independent assessors who are not FedRAMP Recognized.

VER Vulnerability Evaluation and Reporting2
  • VER-FRP-ADVSensitive DetailsMAY

    FedRAMP MAY require providers to share additional information or details about vulnerabilities, including sensitive information that would likely lead to exploitation, as part of review, response or investigation by necessary parties.

  • VER-FRP-ARPAdditional RequirementsMAY

    FedRAMP MAY require providers to share additional vulnerability information, alternative reports, or to report at an alternative frequency as a condition of a FedRAMP Corrective Action Plan or other agreements with federal agencies.

IEC Incident Evaluation and Communication1
  • IEC-FRP-ORVOngoing ReviewMUST

    FedRAMP MUST periodically review FedRAMP Incident Evaluation and Communication implementation with providers based on lack of reporting or other information.

MKT Marketplace Listing1
  • MKT-FRP-SOFScope of FedRAMPMUST NOT

    FedRAMP MUST NOT list cloud service offerings in the Marketplace or perform any FedRAMP Certification activities unless it determines the cloud service offering is within the scope of FedRAMP.

SCN Significant Change Notification1
  • SCN-FRP-CAPCorrective Action Plan ConditionsMAY

    FedRAMP MAY require providers to delay significant changes beyond the standard Significant Change Notification period and/or submit significant changes for approval in advance as a condition of a formal FedRAMP Corrective Action Plan or other agreement.