Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Learn FedRAMP, step by step

For the engineer who was handed “get us FedRAMP evidence” and has never read a compliance document. 13 steps, each ending in something you do — a sort, a rating, a verdict — on the same live dataset the rest of this site renders. Progress is stored in this browser only.

Rendered from FedRAMP Consolidated Rules for 2026 version 2026.07.14.01 · dataset last updated 2026-07-14
The course0 of 13 marked done
  1. 1Where you are

    What FedRAMP is, what changed with 20x, and what a certification class commits you to — the thirty-minute orientation for an engineer with no compliance background.

    Afterwards you can: Name the class your team is pursuing and the Rev5 baseline that pairs with it — including the class that has none.

  2. 2Two vocabularies, one join

    NIST 800-53 controls and FedRAMP Key Security Indicators are different objects that join. Walk the join in both directions before anything else, because every later claim traverses it.

    Afterwards you can: Take an indicator and name the controls it is evidence for — in the right direction.

  3. 3Three senses of “machine-automatable”

    “Machine-automatable” means three different things — a property of the control, a fact about the KSI graph, or a rule that mandates automation — and most confusing FedRAMP conversations are two people using two of them.

    Afterwards you can: Hear a sentence about automation and say which sense it is using.

  4. 4What a gap actually is

    The number your team quotes is a set intersection, a gap is the distance between the evidence you hold and the evidence an assessor can confirm on demand, and it comes in four shapes — only one of which is “the config is wrong”. Each shape has a plane it lives on and a tool class that finds it.

    Afterwards you can: Take a customer's control and say which shape of gap it has, which plane the evidence lives on, and which class of tool reaches it.

  5. 5From an indicator to a command

    Two real evidence recipes, read end to end: what the indicator asks, the commands that fetch the evidence, and the controls the output traces to — one from the cloud estate, one from the build pipeline.

    Afterwards you can: Read a recipe and say what its output proves, and for which controls.

  6. 6Rate the evidence like an assessor

    The three-way honesty rating — full, partial, narrative — and a drill: three real recipes, commands visible and verdicts hidden, rated against the same bar this site's own corpus is held to.

    Afterwards you can: Rate a proposed collector full, partial or narrative, and defend the rating.

  7. 7Four ways a green check lies

    The empty result, the adjacent claim, the vacuous pass and the dashboard: four collector failure modes that read as passing, each presented as a verdict for you to call before the reveal.

    Afterwards you can: Name three reasons a green check can be wrong, starting with the empty result.

  8. 8The clocks you cannot sprint

    The automation rules are depth-and-history requirements, not scope: automated methods per indicator, metrics windows measured in months, and detection cadences measured in days — per class, verbatim from the rules.

    Afterwards you can: State what your team must start retaining today to answer the metrics rule at its class.

  9. 9One control, taken apart

    “Are we FIPS compliant?” is not one question — it is five, and four of them a scan answers while the fifth is a document you maintain. The worked case that shows why one encryption control rates full and its neighbour rates partial.

    Afterwards you can: Split a cryptography question into the limbs a scan answers and the limb that is cited, and name which scan reaches each.

  10. 10The limb the indicator is named for

    “What do we scan to prove just-in-time access?” splits into limbs a rule settles, one an inventory hands to a reviewer, and one — the just-in-time part itself — that lives in an approval record no API returns. Two IAM recipes, same service, different ratings, show where the line falls.

    Afterwards you can: Split an access question into what a rule measures, what an inventory only lists, and what an approval record has to say — and name which recipe reaches each.

  11. 11The column that says TRUE for both

    “What do we scan to prove passwordless?” splits into limbs a rule settles, one an inventory hands to a reviewer, and two that no AWS API holds — whether the second factor is phishing-resistant, and whether the identity is one person. Two MFA recipes, same rule engine, different ratings, show where the line falls.

    Afterwards you can: Split an authentication question into what a rule measures, what an inventory only counts, what the identity provider alone can say, and what a personnel record has to say — and name which recipe reaches each.

  12. 12The pipe is measured; the reading is a record

    “What do we scan to prove we operate a SIEM?” splits into limbs a rule settles — the trail exists and is tamper-evident — one an inventory hands to a reviewer, one the log itself answers, and one the indicator turns on: “persistently reviewed”, which lives in a case record no API returns. Two logging recipes, same plane, same rule engine, different ratings, show where the line falls.

    Afterwards you can: Split a logging question into what a rule measures, what an inventory only lists, what a query over the log can say about the past, and what a review record has to say — and name which recipe reaches each.

  13. 13The residue is the product

    The honest end of the course: the controls a machine can prove today, the ones still owed a recipe, and the ones that close as documents — with the register that names each, so nothing has to be taken on faith.

    Afterwards you can: Name controls in your baseline that no machine can prove — without being embarrassed about it.

The steps assume nothing and build strictly forward; take them in order the first time. Returning readers deep-link freely — every step stands on the dataset, not on the one before it.