Learn FedRAMP, step by step
For the engineer who was handed “get us FedRAMP evidence” and has never read a compliance document. 13 steps, each ending in something you do — a sort, a rating, a verdict — on the same live dataset the rest of this site renders. Progress is stored in this browser only.
1Where you are
What FedRAMP is, what changed with 20x, and what a certification class commits you to — the thirty-minute orientation for an engineer with no compliance background.
Afterwards you can: Name the class your team is pursuing and the Rev5 baseline that pairs with it — including the class that has none.
2Two vocabularies, one join
NIST 800-53 controls and FedRAMP Key Security Indicators are different objects that join. Walk the join in both directions before anything else, because every later claim traverses it.
Afterwards you can: Take an indicator and name the controls it is evidence for — in the right direction.
3Three senses of “machine-automatable”
“Machine-automatable” means three different things — a property of the control, a fact about the KSI graph, or a rule that mandates automation — and most confusing FedRAMP conversations are two people using two of them.
Afterwards you can: Hear a sentence about automation and say which sense it is using.
4What a gap actually is
The number your team quotes is a set intersection, a gap is the distance between the evidence you hold and the evidence an assessor can confirm on demand, and it comes in four shapes — only one of which is “the config is wrong”. Each shape has a plane it lives on and a tool class that finds it.
Afterwards you can: Take a customer's control and say which shape of gap it has, which plane the evidence lives on, and which class of tool reaches it.
5From an indicator to a command
Two real evidence recipes, read end to end: what the indicator asks, the commands that fetch the evidence, and the controls the output traces to — one from the cloud estate, one from the build pipeline.
Afterwards you can: Read a recipe and say what its output proves, and for which controls.
6Rate the evidence like an assessor
The three-way honesty rating — full, partial, narrative — and a drill: three real recipes, commands visible and verdicts hidden, rated against the same bar this site's own corpus is held to.
Afterwards you can: Rate a proposed collector full, partial or narrative, and defend the rating.
7Four ways a green check lies
The empty result, the adjacent claim, the vacuous pass and the dashboard: four collector failure modes that read as passing, each presented as a verdict for you to call before the reveal.
Afterwards you can: Name three reasons a green check can be wrong, starting with the empty result.
8The clocks you cannot sprint
The automation rules are depth-and-history requirements, not scope: automated methods per indicator, metrics windows measured in months, and detection cadences measured in days — per class, verbatim from the rules.
Afterwards you can: State what your team must start retaining today to answer the metrics rule at its class.
9One control, taken apart
“Are we FIPS compliant?” is not one question — it is five, and four of them a scan answers while the fifth is a document you maintain. The worked case that shows why one encryption control rates full and its neighbour rates partial.
Afterwards you can: Split a cryptography question into the limbs a scan answers and the limb that is cited, and name which scan reaches each.
10The limb the indicator is named for
“What do we scan to prove just-in-time access?” splits into limbs a rule settles, one an inventory hands to a reviewer, and one — the just-in-time part itself — that lives in an approval record no API returns. Two IAM recipes, same service, different ratings, show where the line falls.
Afterwards you can: Split an access question into what a rule measures, what an inventory only lists, and what an approval record has to say — and name which recipe reaches each.
11The column that says TRUE for both
“What do we scan to prove passwordless?” splits into limbs a rule settles, one an inventory hands to a reviewer, and two that no AWS API holds — whether the second factor is phishing-resistant, and whether the identity is one person. Two MFA recipes, same rule engine, different ratings, show where the line falls.
Afterwards you can: Split an authentication question into what a rule measures, what an inventory only counts, what the identity provider alone can say, and what a personnel record has to say — and name which recipe reaches each.
12The pipe is measured; the reading is a record
“What do we scan to prove we operate a SIEM?” splits into limbs a rule settles — the trail exists and is tamper-evident — one an inventory hands to a reviewer, one the log itself answers, and one the indicator turns on: “persistently reviewed”, which lives in a case record no API returns. Two logging recipes, same plane, same rule engine, different ratings, show where the line falls.
Afterwards you can: Split a logging question into what a rule measures, what an inventory only lists, what a query over the log can say about the past, and what a review record has to say — and name which recipe reaches each.
13The residue is the product
The honest end of the course: the controls a machine can prove today, the ones still owed a recipe, and the ones that close as documents — with the register that names each, so nothing has to be taken on faith.
Afterwards you can: Name controls in your baseline that no machine can prove — without being embarrassed about it.
The steps assume nothing and build strictly forward; take them in order the first time. Returning readers deep-link freely — every step stands on the dataset, not on the one before it.