Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

What a gap actually is

The number your team quotes is a set intersection, a gap is the distance between the evidence you hold and the evidence an assessor can confirm on demand, and it comes in four shapes — only one of which is “the config is wrong”. Each shape has a plane it lives on and a tool class that finds it.

Rendered from FedRAMP Consolidated Rules for 2026 version 2026.07.14.01

Teams quote one number for “the automated controls” and argue about it for an hour. Here is the number, drawn as what it is: the part of a class’s baseline that at least one Key Security Indicator reaches — sense 2 from the last step, not a promise that a machine can prove any of it.

Baseline ∩ indicator-reached, per class
  1. Class B baseline95 reached · 60 orphans · 155 in baseline

  2. Class C baseline199 reached · 123 orphans · 322 in baseline

  3. Class D baseline199 reached · 210 orphans · 409 in baseline

The step BC adds104 reached · 167 added · 0 removed

The step CD adds0 reached · 87 added · 0 removed

Lit: reached by at least one indicator, of the 209 controls any indicator names. Dim: in the baseline, reached by none. Bars share one scale, so the same lit length on two rows is the same set of controls — read the two upper classes against each other, and each step against the class it climbs to.

Two things to take from the picture. The lit segment on the two upper classes is the same set — climbing a class adds controls, and the step’s own bar shows how many of the added ones any indicator reaches. And the dim remainder is not “manual”: it is scope that 20x’s machinery has no opinion about, which is a different sentence and needs a different plan.

Now the word the number is usually quoted next to. A gap is the distance between the evidence you hold today and the evidence an assessor can confirm — and re-confirm on demand. It takes four shapes, and only the first is what a dashboard means by the word.

What a gap is, and its four shapes
  1. Present statethe evidence you hold today
  2. The gapone of 4 shapes, below
  3. Satisfiedconfirmable, and re-confirmable
Gap shapes4 shapes a gap can take
  1. AFinding

    Something is wrong, and you can see exactly what.

    The evidence exists and it says non-compliant. The estate is wrong; engineering fixes it. The only shape most dashboards can show.

    For example, a query lists every database instance in the account with its storage-encryption setting, and two come back false. SC-28 asks for encryption at rest; those two rows are its answer.

    ask can you point at the row that failed? · closed by engineering changes the estate

  2. BUncollected

    It may well be fine. You just cannot show that it is.

    The control may well be met, but nothing collects proof — or the proof is a screenshot rather than something regenerable on demand. Nobody knows the state.

    For example, AU-06 asks that someone reviews the audit records. Your team genuinely does, every Monday, in a meeting. Nothing you could re-run on a Tuesday afternoon produces a record of that review.

    ask if an assessor asked for this today, what would you run? · closed by a collector is built, on the plane the evidence lives on

  3. CNot automatable

    No machine will ever show it. A human artifact has to.

    No machine can produce probative evidence: the control is about people, documents, physical space or a third party. Its gap is document currency and assessor review, and the honest tool output is “narrative”.

    For example, PE-03 asks who may physically enter the room holding the hardware. You rent that room. No API call you can make proves it; the provider’s attestation, and the date on it, is the evidence.

    ask could any machine, ever, produce this? · closed by a written artifact, tracked for freshness

  4. DScope unverified

    The check passed. Nobody knows how much of the estate it looked at.

    The check passed over a population the scanner chose for itself. “No non-compliant device” is the output of a well-run fleet and of a fleet with one device enrolled. Until an independent inventory is reconciled, the green is unearned.

    For example, a vulnerability scan reports no critical findings across your instances for RA-05. It reads an agent baked into the golden image — and three older instances predate that image and never got the agent. They are not in the pass, not in the fail, and not in the report at all.

    ask how many things did that check look at, and who wrote that list? · closed by an inventory the scanner does not control

Three of those are states your evidence is in; one is a property of the control itself. A single control moves from B to A to satisfied as you build the collector and then fix what it finds — and slides to D the day the estate grows something the collector was never pointed at. C never moves. No collector is coming for a background check, and a plan that budgets engineering time to close it is budgeting for nothing.

The two that get mixed up are B and D, and one question separates them. B has no answer at all; D has an answer, it is green, and the list it is green over is a list the scanner wrote for itself. B looks like a hole in the report — which is why it gets found. D looks like a pass, which is why it does not. FedRAMP has a control for exactly this problem: CM-08asks for a system component inventory, so “reconcile against a list the scanner does not control” is an obligation you already owe, not a nicety this site invented.

One scan, two estates, one verdict
  1. Every instance carries the agent

    the scan prints no critical findings · it read 12 of 12 · 0 never reached

    every instance in the account was launched from the golden image, and the image carries the scanner’s agent. The verdict is true of the whole estate.

  2. Every instance launched since the image changed carries the agent

    the scan prints no critical findings · it read 9 of 12 · 3 never reached

    three instances predate that golden image and never got the agent. They are not in the pass, not in the fail, and not in the report — a check cannot report a machine it never reached.

Lit: read by the check, and compliant. Empty: never read — neither in the pass nor in the fail, and absent from the report entirely. Both rows print the same verdict, so no amount of re-running the scan separates them. The honest reading of the second is not “compliant” but “compliant over 9, unknown over 3”.

Nothing in the scan’s own output separates those two, and re-running it will not help: a check cannot count what it never reached, and it does not know that it did not reach it. The difference is visible only against a list the scanner did not write — the account’s own instance inventory, the repository list from the source-control API, the HR headcount behind a laptop fleet — reconciled against the set the check reported on.

Which makes the habit that closes D a small one: never quote a green without its denominator and the name of the list that denominator came from. “No non-compliant devices” is not a reading. “No non-compliant devices, over every name in this morning’s HR headcount” is. If you cannot name the list, you have not measured the estate — you have measured the scanner.

Asked in order rather than read as a menu, only one question has to be answered at a time:

Which shape is it?
  1. Could any machine ever produce probative evidence — or is the subject matter a person, a document, a building or a third party?

    If no machine can, the shape is C Not automatable. Otherwise, next question.

  2. Is something collecting it today, and could you re-run that collection on demand and get the same kind of answer?

    If nothing collects it, or the proof is a rendering, the shape is B Uncollected. Otherwise, next question.

  3. What does the collected evidence say?

    If non-compliant, the shape is A Finding. Otherwise, next question.

  4. It passed — over what population, and who wrote that list?

    If the scanner wrote it, or nobody can say, the shape is D Scope unverified. Otherwise, read on.

Answer past all four — something collects it, you can re-run that collection, it comes back compliant, and it comes back compliant over a population an independent inventory confirms — and there is no gap. That is what “satisfied” meant at the top of this step.

Which tool finds them? No single one. Evidence lives on planes — the cloud control plane, the pipeline that builds it, the identity provider people actually live in, the device fleet, the systems that hold training and screening records — and each plane has its own scanner class and, crucially, its own inventory. A scanner cannot report what it was never pointed at, which is shape D, and it is defeated only by an inventory the scanner does not control.

Where evidence lives, and what reads itthe planes this site authors →
Evidence planes, the tool class that reads each, the control families it mostly answers, and the gap shapes it finds.
PlaneTool classFamiliesFindsHere
Cloud control planeresource configuration, encryption, network boundaries, logging, backup settings, IAM policyCloud configuration compliance (CSPM)AWS Config rules and conformance packs, Security Hub, IAM Access Analyzer; Azure Policy; WizAC · AU · CM · CP · IA · SC · SIA BAWS plane · 51 recipes
Code and pipelinesource, dependencies, secrets, infrastructure templates, build provenance, review and approval recordsSAST · SCA · secret scanning · IaC scanning · attestationCodeQL, Dependabot, secret scanning, artifact attestations, repository rulesets; Semgrep, Trivy, Checkov, SigstoreSA · SI · SR · CM · IAA B Dpipeline plane · 13 recipes
Infrastructure and workloadsOS packages, images, patch state, malware, host integrityVulnerability management · endpoint detectionAmazon Inspector, Systems Manager Patch Manager, GuardDuty runtime; Tenable, QualysRA · SI · CMA DAWS plane · 51 recipes
Identity providerhuman accounts, MFA enrolment, session policy, joiners and leavers, privileged elevationIdentity provider APIs · identity governanceIAM Identity Center, Okta, Entra IDIA · AC · PSA B Dnamed, not yet authored
Endpoint fleetdevice compliance, disk encryption, wireless configurationDevice management (MDM / UEM)Intune, Jamf, KandjiAC · CM · RAA Dnamed, not yet authored
People and process systemstraining completion, screening, signed agreements, plans, exercise recordsLearning, HR and ticketing systems · GRCan LMS, an HRIS, a ticket tracker, a GRC platformAT · PS · PL · CP · IR · CACnamed, not yet authored
Shared responsibilitywhat the cloud provider or platform vendor does on your behalfProvider authorizations and inheritanceAWS Artifact, the platform's own FedRAMP packageSR · SC · SA · CA · ACCnamed, not yet authored

One consequence worth saying out loud: every plane you add to close a control is a new external system, and external systems are themselves controls — the plane that closes a supply-chain control raises the supply-chain question about the plane. Honest coverage counts that cost. Now call the shape on eight scenarios — the drill is the step:

  1. Scenario 1 of 8

    The IAM credential report lists four active access keys last rotated more than ninety days ago. The recipe's assertion for AC-02 (01) fails on those rows.

  2. Scenario 2 of 8

    Backups run nightly and the team is confident a restore would work. No restore-testing job has ever been configured, so there is no run history to hand an assessor for CP-10.

  3. Scenario 3 of 8

    AT-02 asks that every user completed security awareness training. The learning system holds the roster and completion dates; AWS holds nothing about who was trained.

  4. Scenario 4 of 8

    Code scanning reports zero critical findings across the organisation. The organisation has forty repositories; scanning is enabled on two.

  5. Scenario 5 of 8

    A Config rule for public access evaluates every bucket in the account and flags one whose policy grants anonymous read.

  6. Scenario 6 of 8

    PS-03 requires personnel screening before access is granted. Screening happens in an HR vendor's system; the account only ever sees the principal that was created afterwards.

  7. Scenario 7 of 8

    For SI-04 the evidence folder holds a screenshot of the monitoring dashboard taken last quarter. Nobody can say what query produced the tiles.

  8. Scenario 8 of 8

    The device manager reports every enrolled laptop has disk encryption on. Enrolment is voluntary and nobody has compared its list to the HR headcount.

Exit check — a stakeholder asks “what percentage of the gaps are closed?”

Four columns, never one: findings (A), uncollected (B), not automatable (C), scope unverified (D) — each with its plane and its denominator stated. A single percentage folds B and D into whichever side flatters it. The register at /automation is this site’s own four-column answer for the surface it reaches.