Cloud Service Providers
You build and operate the cloud service seeking FedRAMP certification. The bulk of the ruleset is yours — implementation, evidence production, continuous reporting, incident handling, and every vulnerability clock. If a deadline in this dataset bites, it almost certainly bites you first.
Force of your requirements
Requirement-level force only — per-class overrides are not tallied here.
Your deadlines (61)
| Deadline | Requirement | Class | Force |
|---|---|---|---|
| 1 day | VDR-TFR-PSD Persistent Sample Detection | D | SHOULD |
| 2 days | VER-TFR-EVU Evaluate Vulnerabilities Quickly | D | SHOULD |
| 3 days | VDR-TFR-MVX Persistent Machine Verification and Validation for 20x | C | MUST |
| 3 days | VDR-TFR-PSD Persistent Sample Detection | C | SHOULD |
| 5 days | VER-TFR-EVU Evaluate Vulnerabilities Quickly | C | SHOULD |
| 5 business days | CDS-UTC-AAD Agency Access Denial | all | MUST |
| 1 week | CPO-CSX-CPM Certification Package Maintenance for 20x | D | MUST |
| 5 business days | SCN-TRF-NAF Notification After Finishing | all | MUST |
| 5 business days | SCN-TRF-NAV Notification After Verification | all | MUST |
| 7 days | VDR-TFR-MVX Persistent Machine Verification and Validation for 20x | B | MUST |
| 7 days | VDR-TFR-PDD Persistent Drift Detection | D | SHOULD |
| 7 days | VDR-TFR-PSD Persistent Sample Detection | B | SHOULD |
| 7 days | VER-TFR-EVU Evaluate Vulnerabilities Quickly | B | SHOULD |
| 7 days | VER-TFR-MRH Historical Activity | D | SHOULD |
| 2 weeks | CDS-CSO-FRC FedRAMP Certification Reports | all | MUST |
| 2 weeks | CPO-CSX-CPM Certification Package Maintenance for 20x | C | MUST |
| 10 business days | SCN-ADP-NTF Notification Requirements | all | MUST |
| 10 business days | SCN-TRF-NFP Notification of Final Plans | all | MUST |
| 14 days | VDR-TFR-PDD Persistent Drift Detection | C | SHOULD |
| 14 days | VDR-TFR-PSD Persistent Sample Detection | A | SHOULD |
| 14 days | VER-TFR-EVU Evaluate Vulnerabilities Quickly | A | SHOULD |
| 14 days | VER-TFR-MRH Historical Activity | C | SHOULD |
| 1 month | CPO-CSX-CPM Certification Package Maintenance for 20x | B | MUST |
| 1 month | VDR-TFR-MVF Persistent Machine Verification and Validation for Rev5 | B | SHOULD |
| 1 month | VDR-TFR-MVF Persistent Machine Verification and Validation for Rev5 | C | MUST |
| 1 month | VDR-TFR-MVF Persistent Machine Verification and Validation for Rev5 | D | MUST |
| 1 month | VDR-TFR-MVX Persistent Machine Verification and Validation for 20x | A | SHOULD |
| 1 month | VDR-TFR-PCD Persistently Complete Detection | C | SHOULD |
| 1 month | VDR-TFR-PCD Persistently Complete Detection | D | SHOULD |
| 1 month | VDR-TFR-PDD Persistent Drift Detection | B | SHOULD |
| 1 month | VER-TFR-MHR Monthly Activity Report | all | MUST |
| 1 month | VER-TFR-MRH Historical Activity | A | MAY |
| 1 month | VER-TFR-MRH Historical Activity | B | SHOULD |
| 30 business days | SCN-TRF-NIP Notification of Initial Plans | all | MUST |
| 30 business days | SCN-TRF-UPD Update Documentation | all | MUST |
| 3 months | CCM-QTR-MTG Quarterly Review Meeting | A | MAY |
| 3 months | CCM-QTR-MTG Quarterly Review Meeting | B | SHOULD |
| 3 months | CCM-QTR-MTG Quarterly Review Meeting | C | MUST |
| 3 months | CCM-QTR-MTG Quarterly Review Meeting | D | MUST |
| 3 months | CPO-CSX-CPM Certification Package Maintenance for 20x | A | SHOULD |
| 3 months | FRC-APP-FIA Fresh Independent Assessment | A | MAY |
| 3 months | FRC-APP-FIA Fresh Independent Assessment | B | MUST |
| 3 months | FRC-APP-FIA Fresh Independent Assessment | C | MUST |
| 3 months | FRC-APP-FIA Fresh Independent Assessment | D | MUST |
| 3 months | VDR-TFR-PDD Persistent Drift Detection | A | SHOULD |
| 6 months | CPO-CSF-CPM Certification Package Maintenance for Rev5 | D | MUST |
| 6 months | VDR-TFR-PCD Persistently Complete Detection | A | SHOULD |
| 6 months | VDR-TFR-PCD Persistently Complete Detection | B | SHOULD |
| 192 days | VER-TFR-MAV Mark Accepted Vulnerabilities | all | MUST |
| 1 year | CPO-CSF-CPM Certification Package Maintenance for Rev5 | B | MUST |
| 1 year | CPO-CSF-CPM Certification Package Maintenance for Rev5 | C | MUST |
| 1 year | IVV-CSF-AIA Annual Independent Assessments for Rev5 | B | MUST |
| 1 year | IVV-CSF-AIA Annual Independent Assessments for Rev5 | C | MUST |
| 1 year | IVV-CSF-AIA Annual Independent Assessments for Rev5 | D | MUST |
| 1 year | IVV-CSO-FIA FedRAMP Independent Assessments | A | MAY |
| 1 year | IVV-CSO-FIA FedRAMP Independent Assessments | B | MUST |
| 1 year | IVV-CSO-FIA FedRAMP Independent Assessments | C | MUST |
| 1 year | IVV-CSO-FIA FedRAMP Independent Assessments | D | MUST |
| 1 year | IVV-CSX-AIA Annual Independent Assessments for 20x | B | MUST |
| 1 year | IVV-CSX-AIA Annual Independent Assessments for 20x | C | MUST |
| 1 year | IVV-CSX-AIA Annual Independent Assessments for 20x | D | MUST |
Full context for each deadline lives in the Obligation Clock, pre-filtered to Providers.
Your requirements, by document
FRC FedRAMP Certification29
Providers MUST complete the FedRAMP Certification Application Form in full to request an initial assessment by FedRAMP.
Providers MUST supply a fresh initial FedRAMP Certification Package that shows the current status of the cloud service offering as verified and validated by the provider within the previous 7 days.
- FRC-APP-FIAFresh Independent Assessment
Providers MUST be listed in the FedRAMP Marketplace before applying for FedRAMP Certification, including:
Providers MUST NOT use a third party to apply for a FedRAMP Certification on their behalf; this includes independent assessment services.
Providers MAY freshen a stale initial independent verification and validation assessment by having a FedRAMP Recognized independent assessment service review any changes between the original assessment and the current status of the cloud service offering in place of a full re-assessment, UNLESS the stale assessment is more than 9 months old.
Providers seeking a FedRAMP Rev5 Agency Certification MUST have completed the Authorization to Operate (ATO) process with their agency sponsor for the cloud service offering, concluding with a formal signed ATO letter that the agency has sent over official government channels to FedRAMP.
Providers MUST apply for a new FedRAMP Certification to downgrade their Certification Class.
Providers SHOULD notify all necessary parties at least 120 days in advance of an intended downgrade or cancellation of FedRAMP Certification.
Providers MUST apply for a new FedRAMP Certification to upgrade their Certification Class; all applicable requirements MUST be met in advance.
Providers seeking a FedRAMP Class A Certification MUST have completed a certification or equivalent process, including an independent assessment if applicable, from one of the following alternative security frameworks within the past 12 months:
Providers seeking a FedRAMP Class A Certification MUST supply the following materials from their alternative security framework assessment to all necessary parties:
Providers seeking a FedRAMP Class A Certification MAY have the FedRAMP Certification Package independently verified and validated by a FedRAMP Recognized assessor before submission to FedRAMP.
Providers seeking a Class A FedRAMP Certification MUST address all rules in this FedRAMP Class A Certification subset (FRC-CLA) AND the following additional FedRAMP Class A rules; the appropriate artifacts or information mapping for all rules MUST be supplied in the FedRAMP Certification Package.
Providers seeking a Class A FedRAMP Certification MAY address the following additional optional FedRAMP Class A rules (if applicable):
Providers seeking a Class A FedRAMP Certification SHOULD address the following additional recommended FedRAMP Class A rules (if applicable):
Providers MUST assign all organization-defined control parameters, following FedRAMP Rev5 Controls Guidance, and ensure that all control parameter assignments are documented in the Security Decision Record (SDR).
- FRC-CSF-BSLFedRAMP Rev5 Baselines
Providers MUST follow FedRAMP Rev5 Controls Guidance for the implementation and documentation of all applicable controls.
Providers with FedRAMP Rev5 Ready status MUST convert to a FedRAMP Certification by whichever of the follow dates is later: the expiration of their annual assessment or November 17, 2026 (the legacy FedRAMP Ready status will be entirely removed on December 31, 2027).
Providers MUST identify a target FedRAMP Certification Profile and apply all relevant FedRAMP Practices to the cloud service offering.
Providers MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule.
Providers MUST maintain responsibility and accountability for the accuracy and completeness of all information in the FedRAMP Certification Package, especially when they engage a third party (such as an independent assessor, advisory service, or external tools) to supply information on their behalf.
Providers seeking a Certification MUST supply a complete FedRAMP Certification Package to FedRAMP for initial certification; the FedRAMP Certification Package MUST include at least the following information:
Providers MUST NOT seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering; pick one type.
Providers SHOULD apply ALL Key Security Indicators to ALL aspects of their cloud service offering that are within the FedRAMP Minimum Assessment Scope.
- FRC-CSX-MOTMetrics Over Time for Key Security Indicators
- FRC-CSX-VVKAutomated Verification and Validation of Key Security Indicators
- FRC-CSX-VVRAutomated Verification and Validation of FedRAMP Rules
CDS Certification Data Sharing21
Providers MUST notify all necessary parties when migrating to a trust center and MUST provide information in their existing USDA Connect Community Portal secure folders explaining how to use the trust center to obtain FedRAMP Certification Data.
- CDS-CSO-AVRAvailability Reporting
Providers MUST use automation to ensure information remains consistent between human-readable and machine-readable formats when FedRAMP Certification Data is provided in both formats.
Providers MUST always include the FedRAMP ID of the related cloud service offering in all FedRAMP Certification Data once assigned, including all reports, notifications, and other communication that results from FedRAMP rules.
Providers MUST include FedRAMP Certification Reports with their FedRAMP Certification Data without inappropriate modifications, and make such reports available within 2 weeks of receiving the materials from FedRAMP.
Providers MUST supply snapshots of FedRAMP Certification Data aligned to Ongoing Certification Reports to all necessary parties; these snapshots MUST be available for the duration of FedRAMP Certification.
Providers MUST supply all relevant policies and procedures in the FedRAMP Certification Data, including a human-readable and machine-readable reference that explains at least the following about each included policy and procedure:
Providers MUST publicly share up-to-date information about the cloud service offering in both human-readable and JSON formats, including at least the following information that is available and applicable:
Providers MUST provide sufficient information in FedRAMP Certification Data to support agency authorization decisions but SHOULD NOT include sensitive information that would likely enable a threat actor to gain unauthorized access, cause harm, disrupt operations, or otherwise have a negative adverse impact on the cloud service offering.
Providers MAY responsibly share some or all of the information in a FedRAMP Certification Package publicly or with other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.
Providers MUST publicly share a detailed list of specific services and their security categories that are included in the cloud service offering using clear feature or service names that align with standard public marketing materials; this list MUST be complete enough for a potential customer to determine which services are and are not included in the FedRAMP Minimum Assessment Scope without requesting access to underlying FedRAMP Certification Data.
Providers MUST use a FedRAMP-compatible trust center to store and share FedRAMP Certification Data with all necessary parties.
Trust centers MUST maintain an inventory and history of federal agency users or systems with access to FedRAMP Certification Data and MUST make this information available to FedRAMP upon request.
Trust centers MUST log access to FedRAMP Certification Data and store summaries of access for at least six months; such information, as it pertains to specific parties, SHOULD be made available upon request by those parties.
Trust centers SHOULD make FedRAMP Certification Data available to view and download in both human-readable and machine-readable formats.
Trust centers MUST provide documented programmatic access to all FedRAMP Certification Data, including programmatic access to human-readable materials.
Trust centers SHOULD include features that encourage all necessary parties to provision and manage access to FedRAMP Certification Data for their users and services directly.
Trust centers MUST share FedRAMP Certification Data with all necessary parties without interruption.
Providers MUST notify FedRAMP within 5 business days of denying an agency access request for FedRAMP Certification Data.
Providers SHOULD supply access to the FedRAMP Certification Package with agencies upon request.
VER Vulnerability Evaluation and Reporting19
Providers MUST assume the exploitation of vulnerabilities can be automated UNLESS they have evidence proving otherwise.
Providers SHOULD consider at least the following factors when considering the context of the cloud service offering to evaluate detected vulnerabilities:
Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are false positive vulnerabilities.
Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are internet-reachable vulnerabilities.
Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are likely exploitable vulnerabilities.
Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to estimate the potential agency impact of exploitation on government customers AND assign one of the following Potential Agency Impact N-ratings (PAIN):
Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to identify logical groupings of affected information resources that may improve the efficiency and effectiveness of vulnerability response by consolidating further activity; FedRAMP Vulnerability Detection and Response rules are then applied to these consolidated groupings of vulnerabilities instead of each individual detected instance.
Providers MUST include the following information on accepted vulnerabilities when reporting on vulnerability detection and response activity:
Providers SHOULD include high-level overviews of ALL vulnerability detection and response activities conducted during this period for the cloud service offering; this includes vulnerability disclosure programs, bug bounty programs, penetration testing, assessments, etc.
Providers MUST NOT irresponsibly disclose specific sensitive information about vulnerabilities that would likely lead to exploitation, but MUST disclose sufficient information for informed risk-based decision-making to all necessary parties.
Providers MUST report vulnerability detection and response activity (including persistent verification and validation) to all necessary parties persistently, summarizing ALL activity since the previous report; these reports are FedRAMP Certification Data and are subject to FedRAMP Certification Data Sharing rules.
Providers MAY responsibly disclose vulnerabilities publicly or with other parties if the provider determines doing so will NOT likely lead to exploitation.
Providers MUST include the following information (if applicable) on detected vulnerabilities when reporting on vulnerability detection and response activity, UNLESS it is an accepted vulnerability:
- VER-TFR-EVUEvaluate Vulnerabilities Quickly
- VER-TFR-IRIInternet-Reachable Incidents
Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability.
Providers MUST report vulnerability detection and response activity to all necessary parties in a consistent format that is human readable at least monthly.
- VER-TFR-NRINon-Internet-Reachable Incidents
VDR Vulnerability Detection and Response18
Providers SHOULD use automated services to improve and streamline vulnerability detection and response.
Providers SHOULD NOT deploy or otherwise activate new machine-based information resources with Known Exploited Vulnerabilities.
Providers SHOULD automatically perform vulnerability detection on representative samples of new or significantly changed information resources.
Providers MUST systematically, persistently, and promptly discover and identify vulnerabilities within their cloud service offering using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities; this process is called vulnerability detection. Vulnerability detection includes persistently verifying and validating that information resources and processes are operating as intended and documented for FedRAMP Practices.
Providers SHOULD make design and architecture decisions for their cloud service offering that mitigate the risk of vulnerabilities by default AND decrease the risk and complexity of vulnerability detection and response.
Providers MUST treat problems or failures with their vulnerability detection and response processes as vulnerabilities.
Providers SHOULD NOT weaken the security of information resources to facilitate vulnerability scanning, detection, or assessment activities.
Providers MUST systematically, persistently, and promptly track, evaluate, monitor, mitigate, remediate, assess exploitation of, report, and otherwise manage all detected vulnerabilities within their cloud service offering; this process is called vulnerability response.
Providers MAY sample effectively identical information resources, especially machine-based information resources, when performing vulnerability detection UNLESS doing so would decrease the efficiency or effectiveness of vulnerability detection.
Providers SHOULD remediate Known Exploited Vulnerabilities according to the due dates in the CISA Known Exploited Vulnerabilities Catalog (even if the vulnerability has been fully mitigated) as required by CISA Binding Operational Directive (BOD) 26-04 or any successor guidance from CISA.
- VDR-TFR-MVFPersistent Machine Verification and Validation for Rev5
- VDR-TFR-MVXPersistent Machine Verification and Validation for 20x
Providers MUST verify and validate the status of non-machine-based information resources at least once every 3 months.
- VDR-TFR-PCDPersistently Complete Detection
- VDR-TFR-PDDPersistent Drift Detection
- VDR-TFR-PSDPersistent Sample Detection
- VDR-TFR-PVRMitigation and Remediation Expectations
Providers SHOULD mitigate or remediate remaining vulnerabilities during routine operations as determined necessary by the provider.
CCM Collaborative Continuous Monitoring17
Providers MUST supply an anonymized and desensitized summary of the feedback, questions, and answers about each Ongoing Certification Report as an addendum to the Ongoing Certification Report OR in the next Ongoing Certification Report.
Providers MUST supply an Ongoing Certification Report to all necessary parties every 3 months, covering the entire period since the previous summary, in a consistent format that is human readable; this report MUST include high-level summaries of at least the following information:
Providers MUST supply an asynchronous mechanism for all necessary parties to provide feedback or ask questions about each Ongoing Certification Report.
Providers MUST NOT irresponsibly disclose sensitive information in an Ongoing Certification Report that would likely have an adverse effect on the cloud service offering.
Providers MUST supply the target date for their next Ongoing Certification Report with other public FedRAMP Certification Data.
Providers MAY responsibly supply some or all of the information an Ongoing Certification Report to the public or other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.
Providers SHOULD establish a regular 3 month cycle for Ongoing Certification Reports that is spread out from the beginning, middle, or end of each quarter.
Providers SHOULD supply additional information in Quarterly Reviews that the provider determines is of interest, use, or otherwise relevant to agencies.
Providers MUST NOT irresponsibly disclose sensitive information in a Quarterly Review that would likely have an adverse effect on the cloud service offering.
Providers MUST publicly supply the target date for their next Quarterly Review with other public FedRAMP Certification Data.
Providers MUST supply either a registration link or a downloadable calendar file with meeting information for Quarterly Reviews to all necessary parties.
Providers SHOULD NOT invite third parties to attend Quarterly Reviews intended for agencies unless they have specific relevance.
Providers SHOULD record or transcribe Quarterly Reviews and supply them to all necessary parties.
Providers SHOULD regularly schedule Quarterly Reviews to occur at least 3 business days after releasing an Ongoing Certification Report AND within 10 business days of such release.
Providers MAY responsibly supply content prepared for a Quarterly Review to the public or other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.
Providers MAY responsibly supply recordings or transcriptions of Quarterly Reviews to the public or other parties ONLY if the provider removes all agency information (comments, questions, names, etc.) AND determines doing so will NOT likely have an adverse effect on the cloud service offering.
SCN Significant Change Notification16
Providers MUST notify all necessary parties within 10 business days after finishing adaptive changes, also including the following information:
Providers MAY include additional relevant information in Significant Change Notifications.
Providers MAY execute significant changes (including transformative changes) during an emergency or incident without following the Significant Change Notification rules in advance. In such emergencies, providers MUST follow all relevant procedures, notify all necessary parties, retroactively provide all Significant Change Notification materials, and complete appropriate assessment after the incident.
Providers MUST evaluate all potential significant changes to determine the type of significant change and follow the appropriate Significant Change Notification rules.
Providers MUST keep 12 months of historical Significant Change Notifications available with their FedRAMP Certification Data.
Providers MUST make ALL Significant Change Notifications and related audit records available in human-readable and JSON formats.
Providers MUST include at least the following information in Significant Change Notifications:
Providers MUST maintain auditable records of the significant change evaluation activities required by SCN-CSO-EVA (Evaluate Changes) and make them available to FedRAMP as requested.
Providers MAY notify necessary parties in a variety of ways as long as the mechanism for notification is clearly documented in the FedRAMP Certification Package and easily accessible.
Providers SHOULD NOT make formal Significant Change Notifications for routine recurring changes; this type of change is exempted from notification requirements.
Providers MUST notify all necessary parties within 5 business days after finishing transformative changes, including updates to all previously sent information.
Providers MUST notify all necessary parties within 5 business days after completing the verification, assessment, and/or validation of transformative changes, also including the following information:
Providers MUST notify all necessary parties of final plans for transformative changes at least 10 business days before starting transformative changes, including updates to all previously sent information.
Providers MUST notify all necessary parties of initial plans for transformative changes at least 30 business days before starting transformative changes, including a summary of any likely security impacts or changes in risk.
Providers SHOULD engage a third-party assessor to review the scope and impact of the planned change before starting transformative changes if human validation is necessary; such reviews SHOULD be limited to security decisions that require human validation.
Providers MUST publish updated service documentation and other materials to reflect transformative changes within 30 business days after finishing transformative changes.
IVV Independent Verification and Validation13
Providers MUST have Rev5 Controls with negative findings from the previous FedRAMP independent assessment included in the next FedRAMP independent assessment.
- IVV-CSF-AIAAnnual Independent Assessments for Rev5
Providers MUST have all applicable Rev5 Controls included in FedRAMP independent assessments every 3 years but are not required to have all Rev5 Controls included in the same FedRAMP independent assessment.
Providers SHOULD include all applicable Rev5 Controls in each FedRAMP independent assessment.
Providers MUST document and explain the use of representative samples during verification and validation when using representative samples as allowed by IVV-CSO-USR (Use Representative Samples).
- IVV-CSO-FIAFedRAMP Independent Assessments
Providers MUST supply the results of FedRAMP independent assessments in their FedRAMP Certification Package without inappropriate modification.
Providers MAY ask for and accept advice from their assessor during assessment regarding techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their verification, validation and reporting procedures, UNLESS doing so is likely to compromise the objectivity and integrity of the assessment.
Providers MUST supply evidence to all necessary assessors of the effectiveness of the measures that have been implemented to meet FedRAMP Practices; this evidence is the result of validation.
Providers MUST supply evidence to all necessary assessors of the implementation of the measures that have been documented to meet FedRAMP Practices; this evidence is the result of verification.
Providers SHOULD supply all necessary assessors with technical explanations, demonstrations, and other relevant supporting information about the technical capabilities they employ to address FedRAMP rules; this SHOULD be supplied as necessary to ensure the assessor can effectively complete verification and validation.
Providers MAY use representative samples as appropriate during verification and validation.
- IVV-CSX-AIAAnnual Independent Assessments for 20x
SCG Secure Configuration Guide9
Providers MUST include instructions in the FedRAMP Certification Package that explain how to obtain and use the Secure Configuration Guide.
Providers SHOULD make the Secure Configuration Guide available publicly.
Providers MUST create, maintain, and make available recommendations for securely configuring their cloud services (the Secure Configuration Guide) that includes at least the following information:
Providers SHOULD set all settings to their recommended secure defaults for top-level administrative accounts and privileged accounts when initially provisioned.
Providers SHOULD offer the capability to view and adjust security settings via an API or similar capability.
Providers SHOULD offer the capability to compare all current settings for top-level administrative accounts and privileged accounts to the recommended secure defaults.
Providers SHOULD offer the capability to export all security settings in a machine-readable format.
Providers SHOULD also provide the Secure Configuration Guide in a machine-readable format that can be used by customers or third-party tools to compare against current settings.
Providers SHOULD provide versioning and a release history for recommended secure default settings for top-level administrative accounts and privileged accounts as they are adjusted over time.
AFC Addressing FedRAMP Communication8
Providers SHOULD promptly and automatically acknowledge the receipt of messages received from FedRAMP in their FedRAMP Security Inbox.
Providers MUST complete the required actions in Emergency or Emergency Test designated messages sent by FedRAMP within the timeframe included in the message.
Providers MUST route Emergency designated messages sent by FedRAMP to a senior security official for their awareness.
Providers SHOULD complete the required actions in Important designated messages sent by FedRAMP within the timeframe specified in the message.
Providers MUST establish and maintain an email address to receive messages from FedRAMP; this inbox is a FedRAMP Security Inbox (FSI).
Providers MUST immediately notify FedRAMP of any changes to the email address for their FedRAMP Security Inbox.
Providers MUST receive and react to email messages from FedRAMP without disruption and without requiring additional actions from FedRAMP.
Providers MUST treat any email originating from an @fedramp.gov or @gsa.gov email address as if it was sent from FedRAMP by default; if such a message is confirmed to originate from someone other than FedRAMP then the FedRAMP Security Inbox rules no longer apply.
IEC Incident Evaluation and Communication7
Providers SHOULD use automation to minimize human intervention in the process of reporting FedRAMP Reportable Incidents to all affected parties.
Providers MUST treat FedRAMP Reportable Incidents as if they have a Potential Agency Impact N-rating (PAIN) of 5 UNLESS they promptly estimate the PAIN rating following the rule in IEC-CSO-EFI (Estimate Federal Impact).
Providers SHOULD promptly estimate the likely adverse impact of an incident on agency customers to assign a Potential Agency Impact N-rating; this step is called Incident Rating.
Providers MUST promptly evaluate incidents to determine if they affect confidentiality or integrity of federal customer data or are likely to affect confidentiality or integrity of federal customer data; such incidents are FedRAMP Reportable Incidents and must be reported following the FedRAMP Incident Evaluation and Communication rules.
CPO Certification Package Overview5
- CPO-CSF-CPMCertification Package Maintenance for Rev5
Providers MUST also include the following basic metadata in their Certification Package Overview:
- CPO-CSO-OSAOverall Summary of Assessment in Certification Package
Providers MUST supply a Certification Package Overview within their FedRAMP Certification Package, in both human-readable and JSON formats, that includes at least all of the information required by the following rules:
- CPO-CSX-CPMCertification Package Maintenance for 20x
MAS Minimum Assessment Scope5
Providers MUST clearly identify, document, and explain information flows and security categories for ALL information resources or sets of information resources in the cloud service offering.
Providers MUST identify a set of information resources to assess for FedRAMP Certification that includes all information resources that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering; this set of information resources is the cloud service offering.
Providers MUST include metadata (including metadata about federal customer data) in the Minimum Assessment Scope ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES.
Providers MAY include additional materials about other information resources that are not part of the cloud service offering in a FedRAMP Certification Package supplement; these resources will not be FedRAMP Certified and MUST be clearly marked and separated from the cloud service offering.
Providers MUST address the potential impact to federal customer data from third-party information resources used by the cloud service offering, ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES, by documenting the following information about each applicable third-party information resource:
MKT Marketplace Listing5
Providers MUST address at least these FedRAMP rules to apply for a new FedRAMP Marketplace listing OR to request updates to an existing listing:
Providers MUST notify FedRAMP using the FedRAMP Marketplace Providing Listing Request Form to request a listing in the FedRAMP Marketplace.
Providers MUST demonstrate that a cloud service offering is intended for one of the following use cases:
Providers MUST demonstrate continuous progress towards a FedRAMP Certification, documented in their Trust Center or website and updated at least quarterly; progress is measured by the provider against documented goals and milestones.
Providers MUST demonstrate that an assessment for a FedRAMP Certification Class B, C, or D has been scheduled within 2 years of initial listing in the Initial Implementation Phase.
SDR Security Decision Record5
Providers MUST also include short and simple high-level summaries of at least the following for each applicable Rev5 Control:
Providers MUST supply a Security Decision Record, in both human-readable and JSON formats, that includes at least all of the following information for each applicable FedRAMP rule:
Providers MUST also include the following basic metadata in their Security Decision Record:
- SDR-CSX-KMTKey Security Indicator Metrics
Providers MUST also include short and simple high-level summaries of at least the following for each applicable Key Security Indicator:
CMU Cryptographic Module Use3
Providers SHOULD configure agency tenants by default to use cryptographic services that use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when such modules are available.
Providers MUST document the cryptographic modules used in each service (or groups of services that use the same modules) where cryptographic services are used to protect federal customer data, including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.