Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Cloud Service Providers

You build and operate the cloud service seeking FedRAMP certification. The bulk of the ruleset is yours — implementation, evidence production, continuous reporting, incident handling, and every vulnerability clock. If a deadline in this dataset bites, it almost certainly bites you first.

Requirements binding you
180
of 246 across the whole ruleset
Deadlines yours
61
tightest: 1 day
Documents
15
of 17 FRR documents mention you

Force of your requirements

Requirement-level force only — per-class overrides are not tallied here.

MUST · 93SHOULD · 34MUST NOT · 5MAY · 15SHOULD NOT · 4

Your deadlines (61)

DeadlineRequirementClassForce
1 dayVDR-TFR-PSD Persistent Sample DetectionDSHOULD
2 daysVER-TFR-EVU Evaluate Vulnerabilities QuicklyDSHOULD
3 daysVDR-TFR-MVX Persistent Machine Verification and Validation for 20xCMUST
3 daysVDR-TFR-PSD Persistent Sample DetectionCSHOULD
5 daysVER-TFR-EVU Evaluate Vulnerabilities QuicklyCSHOULD
5 business daysCDS-UTC-AAD Agency Access DenialallMUST
1 weekCPO-CSX-CPM Certification Package Maintenance for 20xDMUST
5 business daysSCN-TRF-NAF Notification After FinishingallMUST
5 business daysSCN-TRF-NAV Notification After VerificationallMUST
7 daysVDR-TFR-MVX Persistent Machine Verification and Validation for 20xBMUST
7 daysVDR-TFR-PDD Persistent Drift DetectionDSHOULD
7 daysVDR-TFR-PSD Persistent Sample DetectionBSHOULD
7 daysVER-TFR-EVU Evaluate Vulnerabilities QuicklyBSHOULD
7 daysVER-TFR-MRH Historical ActivityDSHOULD
2 weeksCDS-CSO-FRC FedRAMP Certification ReportsallMUST
2 weeksCPO-CSX-CPM Certification Package Maintenance for 20xCMUST
10 business daysSCN-ADP-NTF Notification RequirementsallMUST
10 business daysSCN-TRF-NFP Notification of Final PlansallMUST
14 daysVDR-TFR-PDD Persistent Drift DetectionCSHOULD
14 daysVDR-TFR-PSD Persistent Sample DetectionASHOULD
14 daysVER-TFR-EVU Evaluate Vulnerabilities QuicklyASHOULD
14 daysVER-TFR-MRH Historical ActivityCSHOULD
1 monthCPO-CSX-CPM Certification Package Maintenance for 20xBMUST
1 monthVDR-TFR-MVF Persistent Machine Verification and Validation for Rev5BSHOULD
1 monthVDR-TFR-MVF Persistent Machine Verification and Validation for Rev5CMUST
1 monthVDR-TFR-MVF Persistent Machine Verification and Validation for Rev5DMUST
1 monthVDR-TFR-MVX Persistent Machine Verification and Validation for 20xASHOULD
1 monthVDR-TFR-PCD Persistently Complete DetectionCSHOULD
1 monthVDR-TFR-PCD Persistently Complete DetectionDSHOULD
1 monthVDR-TFR-PDD Persistent Drift DetectionBSHOULD
1 monthVER-TFR-MHR Monthly Activity ReportallMUST
1 monthVER-TFR-MRH Historical ActivityAMAY
1 monthVER-TFR-MRH Historical ActivityBSHOULD
30 business daysSCN-TRF-NIP Notification of Initial PlansallMUST
30 business daysSCN-TRF-UPD Update DocumentationallMUST
3 monthsCCM-QTR-MTG Quarterly Review MeetingAMAY
3 monthsCCM-QTR-MTG Quarterly Review MeetingBSHOULD
3 monthsCCM-QTR-MTG Quarterly Review MeetingCMUST
3 monthsCCM-QTR-MTG Quarterly Review MeetingDMUST
3 monthsCPO-CSX-CPM Certification Package Maintenance for 20xASHOULD
3 monthsFRC-APP-FIA Fresh Independent AssessmentAMAY
3 monthsFRC-APP-FIA Fresh Independent AssessmentBMUST
3 monthsFRC-APP-FIA Fresh Independent AssessmentCMUST
3 monthsFRC-APP-FIA Fresh Independent AssessmentDMUST
3 monthsVDR-TFR-PDD Persistent Drift DetectionASHOULD
6 monthsCPO-CSF-CPM Certification Package Maintenance for Rev5DMUST
6 monthsVDR-TFR-PCD Persistently Complete DetectionASHOULD
6 monthsVDR-TFR-PCD Persistently Complete DetectionBSHOULD
192 daysVER-TFR-MAV Mark Accepted VulnerabilitiesallMUST
1 yearCPO-CSF-CPM Certification Package Maintenance for Rev5BMUST
1 yearCPO-CSF-CPM Certification Package Maintenance for Rev5CMUST
1 yearIVV-CSF-AIA Annual Independent Assessments for Rev5BMUST
1 yearIVV-CSF-AIA Annual Independent Assessments for Rev5CMUST
1 yearIVV-CSF-AIA Annual Independent Assessments for Rev5DMUST
1 yearIVV-CSO-FIA FedRAMP Independent AssessmentsAMAY
1 yearIVV-CSO-FIA FedRAMP Independent AssessmentsBMUST
1 yearIVV-CSO-FIA FedRAMP Independent AssessmentsCMUST
1 yearIVV-CSO-FIA FedRAMP Independent AssessmentsDMUST
1 yearIVV-CSX-AIA Annual Independent Assessments for 20xBMUST
1 yearIVV-CSX-AIA Annual Independent Assessments for 20xCMUST
1 yearIVV-CSX-AIA Annual Independent Assessments for 20xDMUST

Full context for each deadline lives in the Obligation Clock, pre-filtered to Providers.

Your requirements, by document

FRC FedRAMP Certification29
  • FRC-APP-AFCApplying for FedRAMP CertificationMUST

    Providers MUST complete the FedRAMP Certification Application Form in full to request an initial assessment by FedRAMP.

  • FRC-APP-FCPFresh FedRAMP Certification PackageMUST

    Providers MUST supply a fresh initial FedRAMP Certification Package that shows the current status of the cloud service offering as verified and validated by the provider within the previous 7 days.

  • FRC-APP-FIAFresh Independent Assessment
  • FRC-APP-MLFMarketplace Listing FirstMUST

    Providers MUST be listed in the FedRAMP Marketplace before applying for FedRAMP Certification, including:

  • FRC-APP-NTPNo Third-Party ApplicantsMUST NOT

    Providers MUST NOT use a third party to apply for a FedRAMP Certification on their behalf; this includes independent assessment services.

  • FRC-APP-USAUpdating Stale AssessmentsMAY

    Providers MAY freshen a stale initial independent verification and validation assessment by having a FedRAMP Recognized independent assessment service review any changes between the original assessment and the current status of the cloud service offering in place of a full re-assessment, UNLESS the stale assessment is more than 9 months old.

  • FRC-APS-ATOAgency Authorization to OperateMUST

    Providers seeking a FedRAMP Rev5 Agency Certification MUST have completed the Authorization to Operate (ATO) process with their agency sponsor for the cloud service offering, concluding with a formal signed ATO letter that the agency has sent over official government channels to FedRAMP.

  • FRC-CCL-DCCDowngrading Certification ClassMUST

    Providers MUST apply for a new FedRAMP Certification to downgrade their Certification Class.

  • FRC-CCL-DNPDowngrade Notification PeriodSHOULD

    Providers SHOULD notify all necessary parties at least 120 days in advance of an intended downgrade or cancellation of FedRAMP Certification.

  • FRC-CCL-UCCUpgrading Certification ClassMUST

    Providers MUST apply for a new FedRAMP Certification to upgrade their Certification Class; all applicable requirements MUST be met in advance.

  • FRC-CLA-ASFApproved Alternative Security FrameworksMUST

    Providers seeking a FedRAMP Class A Certification MUST have completed a certification or equivalent process, including an independent assessment if applicable, from one of the following alternative security frameworks within the past 12 months:

  • FRC-CLA-EAMExternal Assessment MaterialsMUST

    Providers seeking a FedRAMP Class A Certification MUST supply the following materials from their alternative security framework assessment to all necessary parties:

  • FRC-CLA-IVVOptional Independent Verification and ValidationMAY

    Providers seeking a FedRAMP Class A Certification MAY have the FedRAMP Certification Package independently verified and validated by a FedRAMP Recognized assessor before submission to FedRAMP.

  • FRC-CLA-MFRMandatory FedRAMP Rules for Class AMUST

    Providers seeking a Class A FedRAMP Certification MUST address all rules in this FedRAMP Class A Certification subset (FRC-CLA) AND the following additional FedRAMP Class A rules; the appropriate artifacts or information mapping for all rules MUST be supplied in the FedRAMP Certification Package.

  • FRC-CLA-OFRAddress Optional FedRAMP Rules for Class AMAY

    Providers seeking a Class A FedRAMP Certification MAY address the following additional optional FedRAMP Class A rules (if applicable):

  • FRC-CLA-RFRRecommended FedRAMP Rules for Class ASHOULD

    Providers seeking a Class A FedRAMP Certification SHOULD address the following additional recommended FedRAMP Class A rules (if applicable):

  • FRC-CSF-ACPAssign Control ParametersMUST

    Providers MUST assign all organization-defined control parameters, following FedRAMP Rev5 Controls Guidance, and ensure that all control parameter assignments are documented in the Security Decision Record (SDR).

  • FRC-CSF-BSLFedRAMP Rev5 Baselines
  • FRC-CSF-FFGFollow FedRAMP Rev5 Controls GuidanceMUST

    Providers MUST follow FedRAMP Rev5 Controls Guidance for the implementation and documentation of all applicable controls.

  • FRC-CSF-RDYFedRAMP Ready ConversionMUST

    Providers with FedRAMP Rev5 Ready status MUST convert to a FedRAMP Certification by whichever of the follow dates is later: the expiration of their annual assessment or November 17, 2026 (the legacy FedRAMP Ready status will be entirely removed on December 31, 2027).

  • FRC-CSO-FCPFedRAMP Certification ProfileMUST

    Providers MUST identify a target FedRAMP Certification Profile and apply all relevant FedRAMP Practices to the cloud service offering.

  • FRC-CSO-JSNFedRAMP JSON SchemasMUST

    Providers MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule.

  • FRC-CSO-MRAMaintain Responsibility and AccountabilityMUST

    Providers MUST maintain responsibility and accountability for the accuracy and completeness of all information in the FedRAMP Certification Package, especially when they engage a third party (such as an independent assessor, advisory service, or external tools) to supply information on their behalf.

  • FRC-CSO-PKGFedRAMP Certification PackageMUST

    Providers seeking a Certification MUST supply a complete FedRAMP Certification Package to FedRAMP for initial certification; the FedRAMP Certification Package MUST include at least the following information:

  • FRC-CSO-POPPick One Program Certification TypeMUST NOT

    Providers MUST NOT seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering; pick one type.

  • FRC-CSX-MASApplication within MASSHOULD

    Providers SHOULD apply ALL Key Security Indicators to ALL aspects of their cloud service offering that are within the FedRAMP Minimum Assessment Scope.

  • FRC-CSX-MOTMetrics Over Time for Key Security Indicators
  • FRC-CSX-VVKAutomated Verification and Validation of Key Security Indicators
  • FRC-CSX-VVRAutomated Verification and Validation of FedRAMP Rules
CDS Certification Data Sharing21
  • CDS-CSF-TCMTrust Center MigrationMUST

    Providers MUST notify all necessary parties when migrating to a trust center and MUST provide information in their existing USDA Connect Community Portal secure folders explaining how to use the trust center to obtain FedRAMP Certification Data.

  • CDS-CSO-AVRAvailability Reporting
  • CDS-CSO-CBFConsistency Between FormatsMUST

    Providers MUST use automation to ensure information remains consistent between human-readable and machine-readable formats when FedRAMP Certification Data is provided in both formats.

  • CDS-CSO-FIDAlways Include FedRAMP IDMUST

    Providers MUST always include the FedRAMP ID of the related cloud service offering in all FedRAMP Certification Data once assigned, including all reports, notifications, and other communication that results from FedRAMP rules.

  • CDS-CSO-FRCFedRAMP Certification ReportsMUST

    Providers MUST include FedRAMP Certification Reports with their FedRAMP Certification Data without inappropriate modifications, and make such reports available within 2 weeks of receiving the materials from FedRAMP.

  • CDS-CSO-HADHistorical FedRAMP Certification DataMUST1 artifact

    Providers MUST supply snapshots of FedRAMP Certification Data aligned to Ongoing Certification Reports to all necessary parties; these snapshots MUST be available for the duration of FedRAMP Certification.

  • CDS-CSO-IRPInclude Relevant PoliciesMUST1 artifact

    Providers MUST supply all relevant policies and procedures in the FedRAMP Certification Data, including a human-readable and machine-readable reference that explains at least the following about each included policy and procedure:

  • CDS-CSO-PSMPer-Service Certification Materials4 artifacts
  • CDS-CSO-PUBPublic InformationMUST2 artifacts

    Providers MUST publicly share up-to-date information about the cloud service offering in both human-readable and JSON formats, including at least the following information that is available and applicable:

  • CDS-CSO-RISResponsible Information SharingMUST

    Providers MUST provide sufficient information in FedRAMP Certification Data to support agency authorization decisions but SHOULD NOT include sensitive information that would likely enable a threat actor to gain unauthorized access, cause harm, disrupt operations, or otherwise have a negative adverse impact on the cloud service offering.

  • CDS-CSO-RPSResponsible Public Package SharingMAY1 artifact

    Providers MAY responsibly share some or all of the information in a FedRAMP Certification Package publicly or with other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.

  • CDS-CSO-SVCPublic Service ListMUST2 artifacts

    Providers MUST publicly share a detailed list of specific services and their security categories that are included in the cloud service offering using clear feature or service names that align with standard public marketing materials; this list MUST be complete enough for a potential customer to determine which services are and are not included in the FedRAMP Minimum Assessment Scope without requesting access to underlying FedRAMP Certification Data.

  • CDS-CSO-UTCUse Trust CentersMUST

    Providers MUST use a FedRAMP-compatible trust center to store and share FedRAMP Certification Data with all necessary parties.

  • CDS-TRC-AAIAgency Access InventoryMUST1 artifact

    Trust centers MUST maintain an inventory and history of federal agency users or systems with access to FedRAMP Certification Data and MUST make this information available to FedRAMP upon request.

  • CDS-TRC-ACLAccess LoggingMUST1 artifact

    Trust centers MUST log access to FedRAMP Certification Data and store summaries of access for at least six months; such information, as it pertains to specific parties, SHOULD be made available upon request by those parties.

  • CDS-TRC-HMRHuman and Machine-Readable Certification DataSHOULD

    Trust centers SHOULD make FedRAMP Certification Data available to view and download in both human-readable and machine-readable formats.

  • CDS-TRC-PACProgrammatic AccessMUST1 artifact

    Trust centers MUST provide documented programmatic access to all FedRAMP Certification Data, including programmatic access to human-readable materials.

  • CDS-TRC-SSMSelf-Service Access ManagementSHOULD1 artifact

    Trust centers SHOULD include features that encourage all necessary parties to provision and manage access to FedRAMP Certification Data for their users and services directly.

  • CDS-TRC-USHUninterrupted SharingMUST

    Trust centers MUST share FedRAMP Certification Data with all necessary parties without interruption.

  • CDS-UTC-AADAgency Access DenialMUST

    Providers MUST notify FedRAMP within 5 business days of denying an agency access request for FedRAMP Certification Data.

  • CDS-UTC-AGAAgency AccessSHOULD2 artifacts

    Providers SHOULD supply access to the FedRAMP Certification Package with agencies upon request.

VER Vulnerability Evaluation and Reporting19
  • VER-EVA-AIAAssume It's AutomatableMUST

    Providers MUST assume the exploitation of vulnerabilities can be automated UNLESS they have evidence proving otherwise.

  • VER-EVA-EFAEvaluation FactorsSHOULD

    Providers SHOULD consider at least the following factors when considering the context of the cloud service offering to evaluate detected vulnerabilities:

  • VER-EVA-EFPEvaluate False PositivesSHOULD

    Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are false positive vulnerabilities.

  • VER-EVA-EIREvaluate Internet-ReachabilityMUST

    Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are internet-reachable vulnerabilities.

  • VER-EVA-ELXEvaluate ExploitabilityMUST

    Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are likely exploitable vulnerabilities.

  • VER-EVA-EPAEstimate Potential Agency ImpactMUST

    Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to estimate the potential agency impact of exploitation on government customers AND assign one of the following Potential Agency Impact N-ratings (PAIN):

  • VER-EVA-GRVGroup VulnerabilitiesSHOULD

    Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to identify logical groupings of affected information resources that may improve the efficiency and effectiveness of vulnerability response by consolidating further activity; FedRAMP Vulnerability Detection and Response rules are then applied to these consolidated groupings of vulnerabilities instead of each individual detected instance.

  • VER-RPT-AVIAccepted Vulnerability InfoMUST1 artifact

    Providers MUST include the following information on accepted vulnerabilities when reporting on vulnerability detection and response activity:

  • VER-RPT-HLOHigh-Level OverviewsSHOULD

    Providers SHOULD include high-level overviews of ALL vulnerability detection and response activities conducted during this period for the cloud service offering; this includes vulnerability disclosure programs, bug bounty programs, penetration testing, assessments, etc.

  • VER-RPT-NIDResponsible DisclosureMUST NOT

    Providers MUST NOT irresponsibly disclose specific sensitive information about vulnerabilities that would likely lead to exploitation, but MUST disclose sufficient information for informed risk-based decision-making to all necessary parties.

  • VER-RPT-PERPersistent ReportingMUST

    Providers MUST report vulnerability detection and response activity (including persistent verification and validation) to all necessary parties persistently, summarizing ALL activity since the previous report; these reports are FedRAMP Certification Data and are subject to FedRAMP Certification Data Sharing rules.

  • VER-RPT-RPDResponsible Public DisclosureMAY

    Providers MAY responsibly disclose vulnerabilities publicly or with other parties if the provider determines doing so will NOT likely lead to exploitation.

  • VER-RPT-VDTVulnerability DetailsMUST1 artifact

    Providers MUST include the following information (if applicable) on detected vulnerabilities when reporting on vulnerability detection and response activity, UNLESS it is an accepted vulnerability:

  • VER-TFR-EVUEvaluate Vulnerabilities Quickly
  • VER-TFR-IRIInternet-Reachable Incidents
  • VER-TFR-MAVMark Accepted VulnerabilitiesMUST

    Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability.

  • VER-TFR-MHRMonthly Activity ReportMUST1 artifact

    Providers MUST report vulnerability detection and response activity to all necessary parties in a consistent format that is human readable at least monthly.

  • VER-TFR-MRHHistorical Activity7 artifacts
  • VER-TFR-NRINon-Internet-Reachable Incidents
VDR Vulnerability Detection and Response18
  • VDR-CSO-ADTAutomate DetectionSHOULD

    Providers SHOULD use automated services to improve and streamline vulnerability detection and response.

  • VDR-CSO-AKEAvoid KEVsSHOULD NOT

    Providers SHOULD NOT deploy or otherwise activate new machine-based information resources with Known Exploited Vulnerabilities.

  • VDR-CSO-DACDetect After ChangesSHOULD

    Providers SHOULD automatically perform vulnerability detection on representative samples of new or significantly changed information resources.

  • VDR-CSO-DETVulnerability DetectionMUST

    Providers MUST systematically, persistently, and promptly discover and identify vulnerabilities within their cloud service offering using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities; this process is called vulnerability detection. Vulnerability detection includes persistently verifying and validating that information resources and processes are operating as intended and documented for FedRAMP Practices.

  • VDR-CSO-DFRDesign For ResilienceSHOULD

    Providers SHOULD make design and architecture decisions for their cloud service offering that mitigate the risk of vulnerabilities by default AND decrease the risk and complexity of vulnerability detection and response.

  • VDR-CSO-FAVFailures Are VulnerabilitiesMUST

    Providers MUST treat problems or failures with their vulnerability detection and response processes as vulnerabilities.

  • VDR-CSO-MSPMaintain SecuritySHOULD NOT

    Providers SHOULD NOT weaken the security of information resources to facilitate vulnerability scanning, detection, or assessment activities.

  • VDR-CSO-RESVulnerability ResponseMUST

    Providers MUST systematically, persistently, and promptly track, evaluate, monitor, mitigate, remediate, assess exploitation of, report, and otherwise manage all detected vulnerabilities within their cloud service offering; this process is called vulnerability response.

  • VDR-CSO-SIRSamplingMAY

    Providers MAY sample effectively identical information resources, especially machine-based information resources, when performing vulnerability detection UNLESS doing so would decrease the efficiency or effectiveness of vulnerability detection.

  • VDR-TFR-KEVRemediate KEVsSHOULD

    Providers SHOULD remediate Known Exploited Vulnerabilities according to the due dates in the CISA Known Exploited Vulnerabilities Catalog (even if the vulnerability has been fully mitigated) as required by CISA Binding Operational Directive (BOD) 26-04 or any successor guidance from CISA.

  • VDR-TFR-MVFPersistent Machine Verification and Validation for Rev5
  • VDR-TFR-MVXPersistent Machine Verification and Validation for 20x
  • VDR-TFR-NMVNon-Machine Verification and ValidationMUST

    Providers MUST verify and validate the status of non-machine-based information resources at least once every 3 months.

  • VDR-TFR-PCDPersistently Complete Detection
  • VDR-TFR-PDDPersistent Drift Detection
  • VDR-TFR-PSDPersistent Sample Detection
  • VDR-TFR-PVRMitigation and Remediation Expectations
  • VDR-TFR-RMNRemaining VulnerabilitiesSHOULD

    Providers SHOULD mitigate or remediate remaining vulnerabilities during routine operations as determined necessary by the provider.

CCM Collaborative Continuous Monitoring17
  • CCM-OCR-AFSAnonymized Feedback SummaryMUST1 artifact

    Providers MUST supply an anonymized and desensitized summary of the feedback, questions, and answers about each Ongoing Certification Report as an addendum to the Ongoing Certification Report OR in the next Ongoing Certification Report.

  • CCM-OCR-AVLReport AvailabilityMUST2 artifacts

    Providers MUST supply an Ongoing Certification Report to all necessary parties every 3 months, covering the entire period since the previous summary, in a consistent format that is human readable; this report MUST include high-level summaries of at least the following information:

  • CCM-OCR-FBMFeedback MechanismMUST1 artifact

    Providers MUST supply an asynchronous mechanism for all necessary parties to provide feedback or ask questions about each Ongoing Certification Report.

  • CCM-OCR-LSILimit Sensitive InformationMUST NOT

    Providers MUST NOT irresponsibly disclose sensitive information in an Ongoing Certification Report that would likely have an adverse effect on the cloud service offering.

  • CCM-OCR-NRDNext Report DateMUST

    Providers MUST supply the target date for their next Ongoing Certification Report with other public FedRAMP Certification Data.

  • CCM-OCR-RPSResponsible Public Certification Report SharingMAY

    Providers MAY responsibly supply some or all of the information an Ongoing Certification Report to the public or other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.

  • CCM-OCR-SORSpread Out ReportsSHOULD

    Providers SHOULD establish a regular 3 month cycle for Ongoing Certification Reports that is spread out from the beginning, middle, or end of each quarter.

  • CCM-QTR-ACTAdditional ContentSHOULD

    Providers SHOULD supply additional information in Quarterly Reviews that the provider determines is of interest, use, or otherwise relevant to agencies.

  • CCM-QTR-MTGQuarterly Review Meeting4 artifacts
  • CCM-QTR-NIDNo Irresponsible DisclosureMUST NOT

    Providers MUST NOT irresponsibly disclose sensitive information in a Quarterly Review that would likely have an adverse effect on the cloud service offering.

  • CCM-QTR-NRDNext Review DateMUST

    Providers MUST publicly supply the target date for their next Quarterly Review with other public FedRAMP Certification Data.

  • CCM-QTR-REGMeeting Registration InfoMUST1 artifact

    Providers MUST supply either a registration link or a downloadable calendar file with meeting information for Quarterly Reviews to all necessary parties.

  • CCM-QTR-RTPRestrict Third PartiesSHOULD NOT

    Providers SHOULD NOT invite third parties to attend Quarterly Reviews intended for agencies unless they have specific relevance.

  • CCM-QTR-RTRRecord/Transcribe ReviewsSHOULD

    Providers SHOULD record or transcribe Quarterly Reviews and supply them to all necessary parties.

  • CCM-QTR-SARSchedule Around ReportsSHOULD

    Providers SHOULD regularly schedule Quarterly Reviews to occur at least 3 business days after releasing an Ongoing Certification Report AND within 10 business days of such release.

  • CCM-QTR-SCRShare Content ResponsiblyMAY

    Providers MAY responsibly supply content prepared for a Quarterly Review to the public or other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.

  • CCM-QTR-SRRShare Recordings ResponsiblyMAY

    Providers MAY responsibly supply recordings or transcriptions of Quarterly Reviews to the public or other parties ONLY if the provider removes all agency information (comments, questions, names, etc.) AND determines doing so will NOT likely have an adverse effect on the cloud service offering.

SCN Significant Change Notification16
  • SCN-ADP-NTFNotification RequirementsMUST1 artifact

    Providers MUST notify all necessary parties within 10 business days after finishing adaptive changes, also including the following information:

  • SCN-CSO-ARIAdditional Relevant InformationMAY

    Providers MAY include additional relevant information in Significant Change Notifications.

  • SCN-CSO-EMGEmergency ChangesMAY

    Providers MAY execute significant changes (including transformative changes) during an emergency or incident without following the Significant Change Notification rules in advance. In such emergencies, providers MUST follow all relevant procedures, notify all necessary parties, retroactively provide all Significant Change Notification materials, and complete appropriate assessment after the incident.

  • SCN-CSO-EVAEvaluate ChangesMUST1 artifact

    Providers MUST evaluate all potential significant changes to determine the type of significant change and follow the appropriate Significant Change Notification rules.

  • SCN-CSO-HISHistorical NotificationsMUST1 artifact

    Providers MUST keep 12 months of historical Significant Change Notifications available with their FedRAMP Certification Data.

  • SCN-CSO-HRMHuman and Machine-Readable NotificationsMUST2 artifacts

    Providers MUST make ALL Significant Change Notifications and related audit records available in human-readable and JSON formats.

  • SCN-CSO-INFRequired InformationMUST1 artifact

    Providers MUST include at least the following information in Significant Change Notifications:

  • SCN-CSO-MARMaintain Audit RecordsMUST1 artifact

    Providers MUST maintain auditable records of the significant change evaluation activities required by SCN-CSO-EVA (Evaluate Changes) and make them available to FedRAMP as requested.

  • SCN-CSO-NOMNotification MechanismsMAY1 artifact

    Providers MAY notify necessary parties in a variety of ways as long as the mechanism for notification is clearly documented in the FedRAMP Certification Package and easily accessible.

  • SCN-RTR-NNRNo Notification RequirementsSHOULD NOT

    Providers SHOULD NOT make formal Significant Change Notifications for routine recurring changes; this type of change is exempted from notification requirements.

  • SCN-TRF-NAFNotification After FinishingMUST1 artifact

    Providers MUST notify all necessary parties within 5 business days after finishing transformative changes, including updates to all previously sent information.

  • SCN-TRF-NAVNotification After VerificationMUST1 artifact

    Providers MUST notify all necessary parties within 5 business days after completing the verification, assessment, and/or validation of transformative changes, also including the following information:

  • SCN-TRF-NFPNotification of Final PlansMUST1 artifact

    Providers MUST notify all necessary parties of final plans for transformative changes at least 10 business days before starting transformative changes, including updates to all previously sent information.

  • SCN-TRF-NIPNotification of Initial PlansMUST1 artifact

    Providers MUST notify all necessary parties of initial plans for transformative changes at least 30 business days before starting transformative changes, including a summary of any likely security impacts or changes in risk.

  • SCN-TRF-TPRThird-Party ReviewSHOULD1 artifact

    Providers SHOULD engage a third-party assessor to review the scope and impact of the planned change before starting transformative changes if human validation is necessary; such reviews SHOULD be limited to security decisions that require human validation.

  • SCN-TRF-UPDUpdate DocumentationMUST1 artifact

    Providers MUST publish updated service documentation and other materials to reflect transformative changes within 30 business days after finishing transformative changes.

IVV Independent Verification and Validation13
  • IVV-CSF-ACFAssessment of Rev5 Controls with FindingsMUST

    Providers MUST have Rev5 Controls with negative findings from the previous FedRAMP independent assessment included in the next FedRAMP independent assessment.

  • IVV-CSF-AIAAnnual Independent Assessments for Rev5
  • IVV-CSF-MCAMandatory Control AssessmentMUST

    Providers MUST have all applicable Rev5 Controls included in FedRAMP independent assessments every 3 years but are not required to have all Rev5 Controls included in the same FedRAMP independent assessment.

  • IVV-CSF-PCAPreferred Control AssessmentSHOULD

    Providers SHOULD include all applicable Rev5 Controls in each FedRAMP independent assessment.

  • IVV-CSO-DUSDocument Use of Representative SamplesMUST

    Providers MUST document and explain the use of representative samples during verification and validation when using representative samples as allowed by IVV-CSO-USR (Use Representative Samples).

  • IVV-CSO-FIAFedRAMP Independent Assessments
  • IVV-CSO-ICPInclusion in Certification PackageMUST

    Providers MUST supply the results of FedRAMP independent assessments in their FedRAMP Certification Package without inappropriate modification.

  • IVV-CSO-RAAReceiving Assessor AdviceMAY

    Providers MAY ask for and accept advice from their assessor during assessment regarding techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their verification, validation and reporting procedures, UNLESS doing so is likely to compromise the objectivity and integrity of the assessment.

  • IVV-CSO-SEESupply Evidence of EffectivenessMUST

    Providers MUST supply evidence to all necessary assessors of the effectiveness of the measures that have been implemented to meet FedRAMP Practices; this evidence is the result of validation.

  • IVV-CSO-SEISupply Evidence of ImplementationMUST

    Providers MUST supply evidence to all necessary assessors of the implementation of the measures that have been documented to meet FedRAMP Practices; this evidence is the result of verification.

  • IVV-CSO-STESupply Technical ExplanationsSHOULD

    Providers SHOULD supply all necessary assessors with technical explanations, demonstrations, and other relevant supporting information about the technical capabilities they employ to address FedRAMP rules; this SHOULD be supplied as necessary to ensure the assessor can effectively complete verification and validation.

  • IVV-CSO-USRUse Representative SamplesMAY

    Providers MAY use representative samples as appropriate during verification and validation.

  • IVV-CSX-AIAAnnual Independent Assessments for 20x
SCG Secure Configuration Guide9
  • SCG-CSO-AUPUse InstructionsMUST2 artifacts

    Providers MUST include instructions in the FedRAMP Certification Package that explain how to obtain and use the Secure Configuration Guide.

  • SCG-CSO-PUBPublic Secure Configuration GuidanceSHOULD2 artifacts

    Providers SHOULD make the Secure Configuration Guide available publicly.

  • SCG-CSO-RSCRecommended Secure ConfigurationMUST2 artifacts

    Providers MUST create, maintain, and make available recommendations for securely configuring their cloud services (the Secure Configuration Guide) that includes at least the following information:

  • SCG-CSO-SDFSecure DefaultsSHOULD2 artifacts

    Providers SHOULD set all settings to their recommended secure defaults for top-level administrative accounts and privileged accounts when initially provisioned.

  • SCG-ENH-APIAPI CapabilitySHOULD2 artifacts

    Providers SHOULD offer the capability to view and adjust security settings via an API or similar capability.

  • SCG-ENH-CMPComparison CapabilitySHOULD2 artifacts

    Providers SHOULD offer the capability to compare all current settings for top-level administrative accounts and privileged accounts to the recommended secure defaults.

  • SCG-ENH-EXPExport CapabilitySHOULD2 artifacts

    Providers SHOULD offer the capability to export all security settings in a machine-readable format.

  • SCG-ENH-MRGMachine-Readable GuidanceSHOULD2 artifacts

    Providers SHOULD also provide the Secure Configuration Guide in a machine-readable format that can be used by customers or third-party tools to compare against current settings.

  • SCG-ENH-VRHVersioning and Release HistorySHOULD2 artifacts

    Providers SHOULD provide versioning and a release history for recommended secure default settings for top-level administrative accounts and privileged accounts as they are adjusted over time.

AFC Addressing FedRAMP Communication8
  • AFC-CSO-ACKAcknowledge ReceiptSHOULD

    Providers SHOULD promptly and automatically acknowledge the receipt of messages received from FedRAMP in their FedRAMP Security Inbox.

  • AFC-CSO-CRAComplete Required ActionsMUST

    Providers MUST complete the required actions in Emergency or Emergency Test designated messages sent by FedRAMP within the timeframe included in the message.

  • AFC-CSO-EMREmergency Message RoutingMUST2 artifacts

    Providers MUST route Emergency designated messages sent by FedRAMP to a senior security official for their awareness.

  • AFC-CSO-IMAImportant Message ActionsSHOULD

    Providers SHOULD complete the required actions in Important designated messages sent by FedRAMP within the timeframe specified in the message.

  • AFC-CSO-INBMaintain a FedRAMP Security InboxMUST1 artifact

    Providers MUST establish and maintain an email address to receive messages from FedRAMP; this inbox is a FedRAMP Security Inbox (FSI).

  • AFC-CSO-NOCNotification of ChangesMUST1 artifact

    Providers MUST immediately notify FedRAMP of any changes to the email address for their FedRAMP Security Inbox.

  • AFC-CSO-RCVReceive Email Without DisruptionMUST

    Providers MUST receive and react to email messages from FedRAMP without disruption and without requiring additional actions from FedRAMP.

  • AFC-CSO-TFGTrust @fedramp.gov and @gsa.govMUST2 artifacts

    Providers MUST treat any email originating from an @fedramp.gov or @gsa.gov email address as if it was sent from FedRAMP by default; if such a message is confirmed to originate from someone other than FedRAMP then the FedRAMP Security Inbox rules no longer apply.

IEC Incident Evaluation and Communication7
  • IEC-CSO-AIRAutomated Incident ReportingSHOULD

    Providers SHOULD use automation to minimize human intervention in the process of reporting FedRAMP Reportable Incidents to all affected parties.

  • IEC-CSO-DPRDefault PAIN RatingMUST

    Providers MUST treat FedRAMP Reportable Incidents as if they have a Potential Agency Impact N-rating (PAIN) of 5 UNLESS they promptly estimate the PAIN rating following the rule in IEC-CSO-EFI (Estimate Federal Impact).

  • IEC-CSO-EFIEstimate Federal ImpactSHOULD1 artifact

    Providers SHOULD promptly estimate the likely adverse impact of an incident on agency customers to assign a Potential Agency Impact N-rating; this step is called Incident Rating.

  • IEC-CSO-EFREvaluate FedRAMP ReportabilityMUST1 artifact

    Providers MUST promptly evaluate incidents to determine if they affect confidentiality or integrity of federal customer data or are likely to affect confidentiality or integrity of federal customer data; such incidents are FedRAMP Reportable Incidents and must be reported following the FedRAMP Incident Evaluation and Communication rules.

  • IEC-CSO-FIRFinal Incident Report4 artifacts
  • IEC-CSO-IIRInitial Incident Report4 artifacts
  • IEC-CSO-OIROngoing Incident Reports4 artifacts
CPO Certification Package Overview5
  • CPO-CSF-CPMCertification Package Maintenance for Rev5
  • CPO-CSO-MTDCertification Package Overview MetadataMUST

    Providers MUST also include the following basic metadata in their Certification Package Overview:

  • CPO-CSO-OSAOverall Summary of Assessment in Certification Package
  • CPO-CSO-OVROverview of the Cloud Service OfferingMUST

    Providers MUST supply a Certification Package Overview within their FedRAMP Certification Package, in both human-readable and JSON formats, that includes at least all of the information required by the following rules:

  • CPO-CSX-CPMCertification Package Maintenance for 20x
MAS Minimum Assessment Scope5
  • MAS-CSO-FLOInformation Flows and Security CategoriesMUST3 artifacts

    Providers MUST clearly identify, document, and explain information flows and security categories for ALL information resources or sets of information resources in the cloud service offering.

  • MAS-CSO-IIRIdentify Information ResourcesMUST3 artifacts

    Providers MUST identify a set of information resources to assess for FedRAMP Certification that includes all information resources that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering; this set of information resources is the cloud service offering.

  • MAS-CSO-MDIMetadata InclusionMUST3 artifacts

    Providers MUST include metadata (including metadata about federal customer data) in the Minimum Assessment Scope ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES.

  • MAS-CSO-SUPSupplemental InformationMAY

    Providers MAY include additional materials about other information resources that are not part of the cloud service offering in a FedRAMP Certification Package supplement; these resources will not be FedRAMP Certified and MUST be clearly marked and separated from the cloud service offering.

  • MAS-CSO-TPRThird-Party Information ResourcesMUST3 artifacts

    Providers MUST address the potential impact to federal customer data from third-party information resources used by the cloud service offering, ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES, by documenting the following information about each applicable third-party information resource:

MKT Marketplace Listing5
  • MKT-CSO-MLRMarketplace Listing RequirementsMUST

    Providers MUST address at least these FedRAMP rules to apply for a new FedRAMP Marketplace listing OR to request updates to an existing listing:

  • MKT-CSO-PMLProvider Marketplace Listing RequestsMUST

    Providers MUST notify FedRAMP using the FedRAMP Marketplace Providing Listing Request Form to request a listing in the FedRAMP Marketplace.

  • MKT-IIP-AGUAgency Use CasesMUST

    Providers MUST demonstrate that a cloud service offering is intended for one of the following use cases:

  • MKT-IIP-DCPDemonstrating Continuous ProgressMUST

    Providers MUST demonstrate continuous progress towards a FedRAMP Certification, documented in their Trust Center or website and updated at least quarterly; progress is measured by the provider against documented goals and milestones.

  • MKT-IIP-DLADeadline for AssessmentMUST

    Providers MUST demonstrate that an assessment for a FedRAMP Certification Class B, C, or D has been scheduled within 2 years of initial listing in the Initial Implementation Phase.

SDR Security Decision Record5
  • SDR-CSF-CTFRev5 ControlsMUST

    Providers MUST also include short and simple high-level summaries of at least the following for each applicable Rev5 Control:

  • SDR-CSO-FRRFedRAMP RulesMUST

    Providers MUST supply a Security Decision Record, in both human-readable and JSON formats, that includes at least all of the following information for each applicable FedRAMP rule:

  • SDR-CSO-MTDSecurity Decision Record MetadataMUST

    Providers MUST also include the following basic metadata in their Security Decision Record:

  • SDR-CSX-KMTKey Security Indicator Metrics
  • SDR-CSX-KSIKey Security IndicatorsMUST

    Providers MUST also include short and simple high-level summaries of at least the following for each applicable Key Security Indicator:

CMU Cryptographic Module Use3
  • CMU-CSO-CATConfiguration of Agency TenantsSHOULD1 artifact

    Providers SHOULD configure agency tenants by default to use cryptographic services that use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when such modules are available.

  • CMU-CSO-CMDCryptographic Module DocumentationMUST1 artifact

    Providers MUST document the cryptographic modules used in each service (or groups of services that use the same modules) where cryptographic services are used to protect federal customer data, including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.

  • CMU-CSO-UVMUsing Validated Cryptographic Modules4 artifacts