Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Class B readinessour reading: Rev5 Low — not a dataset fact

What binds a class B cloud service, in the order you will meet it: the baseline, the automated-coverage split, the evidence, the clocks — then the whole thing as JSON.

1Your control baseline

A baseline is a named subset of the NIST 800-53 Rev5 catalog, and membership is the whole relationship: these 155 controls bind a class B system, spread over 18 control families.

Baseline controls
155
class B our reading: Rev5 Low
Control families
18
of the 20 in NIST 800-53
Annual assessment subset
35
assessed independently every year

2Automated vs hand-argued

A KSI reaching a control means machine-validated 20x evidence can double as your control evidence. What no KSI reaches — the orphans — stays narrative: that residue is the real writing workload.

95 KSI-covered60 orphans
61% of the baseline has at least one KSI edge
ACATAUCACMCPIAIRMAMPPEPLPSRASASCSISR
6480906756836986250029893867868345

MP and PE are reached by no KSI at all — 14 controls of pure narrative evidence, not a data gap.

The 60 orphan controls — your Security Decision Record scope
ac-8ac-18ac-19ac-22at-1au-1ca-1ca-6ca-8cm-1cm-4cm-10cm-11cp-1ia-1ia-2.12ia-8.1ia-8.2ia-8.4ir-1ma-1ma-4ma-5mp-1mp-2mp-6mp-7pe-1pe-2pe-3pe-6pe-8pe-12pe-13pe-14pe-15pe-16pl-1pl-2pl-4pl-4.1pl-11ps-1ra-1ra-2ra-3ra-5.2ra-7sa-1sa-4sa-4.10sc-1sc-15si-1sr-1sr-2sr-3sr-11sr-11.2sr-12

3The evidence you owe

49 distinct artifacts are named by specific requirements in scope for class B, on top of 5 boilerplate artifacts every FRR requirement owes and 5 every KSI indicator owes. Defaults are listed once, never multiplied in.

Owed by every requirement

  • Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
  • Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
  • Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
  • Independent verification.
  • Independent validation.

Owed by every KSI indicator

  • Explanation of measures (and their objectives) that demonstrate the Key Security Indicator, or an explanation of the reason and resulting risk to customers for not having measures available for that Key Security Indicator.
  • Explanation of the cycle for any measures that are implemented persistently (if applicable).
  • Verification that the measures demonstrate the Key Security Indicator, or that the reason for not having them is accepted.
  • Verification that the automation in place is accurate and sufficient to demonstrate appropriate measures for the Key Security Indicator, or that automation is not necessary for each measure.
  • Validation that the measures are accurately produced and are in place and working as intended, or that the reason for not having them is valid.
Rule-specific artifacts (49), most widely demanded first
  • Explanation of how to access this informationSCG-CSO-PUB SCG-CSO-SDF SCG-ENH-API SCG-ENH-CMP SCG-ENH-EXP SCG-ENH-MRG SCG-ENH-VRH
  • or explanation why this functionality is not availableSCG-CSO-PUB SCG-CSO-SDF SCG-ENH-API SCG-ENH-CMP SCG-ENH-EXP SCG-ENH-MRG SCG-ENH-VRH
  • URL to the human-readable data.CDS-CSO-PUB CDS-CSO-SVC MKT-CAS-WEB MKT-IAS-WEB SCG-CSO-RSC
  • A human readable explanation of how the machine readable output is derived.MAS-CSO-FLO MAS-CSO-IIR MAS-CSO-MDI MAS-CSO-TPR
  • The code for the automated process used to generate the machine readable output.MAS-CSO-FLO MAS-CSO-IIR MAS-CSO-MDI MAS-CSO-TPR
  • URL to the machine-readable data.CDS-CSO-PUB MKT-CAS-WEB MKT-IAS-WEB SCG-CSO-RSC
  • A recent vulnerability report or a sample vulnerability reportVER-RPT-AVI VER-RPT-VDT VER-TFR-MHR
  • Explanation of how FedRAMP can obtain this information.CDS-TRC-AAI SCN-CSO-HIS SCN-CSO-MAR
  • Explanation of how the provider decides whether or not to share these materials or other related policies.CDS-UTC-AGA SCG-CSO-AUP SCN-CSO-HRM
  • URL or explanation of how to request these materials.CDS-UTC-AGA SCG-CSO-AUP SCN-CSO-HRM
  • An incident log showing an example of one or more incidents being evaluated including the reason for the determination. The log can be from real incidents, simulated incidents, or a combination of sources.IEC-CSO-EFI IEC-CSO-EFR
  • Automated validation to check FSI mailbox configurationAFC-CSO-EMR AFC-CSO-TFG
  • Configuration settings for FSI mailboxAFC-CSO-EMR AFC-CSO-TFG
  • Explanation of how to access this information.CDS-CSO-HAD CDS-CSO-IRP
  • List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.CMU-CSO-CMD CMU-CSO-UVMclass A, B, C, D only
  • A machine readable output containing all required data of the components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-IIR
  • A machine readable output containing all required data of the metadata collected or maintained by the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-MDI
  • A machine readable output containing all required data of the permitted connections between components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-FLO
  • A machine readable output containing all required data of the third-party information resources of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-TPR
  • A recent Significant Change Notification or sample Significant Change NotificationSCN-CSO-INF
  • An Final Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.IEC-CSO-FIRclass A, B, C, D only
  • An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.IEC-CSO-IIRclass A, B, C, D only
  • An Ongoing Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.IEC-CSO-OIRclass A, B, C, D only
  • At least the most recent after verification SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NAV
  • At least the most recent final SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NFP
  • At least the most recent initial SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NIP
  • At least the most recent post deployment SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NAF
  • At least the most recent SCN notification including the date it was sent and the date the change was applied. Additional examples may be provided. If no SCN notifications have been sent then this artifact is not required.SCN-ADP-NTF
  • Current list of available notification mechanismsSCN-CSO-NOM
  • Date of the most recent transformative change and the date of the corresponding documentation update. If no documentation updates were required as the result of this change, explain how this was determined.SCN-TRF-UPD
  • Email address to receive messages from FedRAMPAFC-CSO-INB
  • Evidence of significant change evaluation including a description fo the change, the determined type, and an explanation for the decision. At least one example must be provided for each type of change. Real examples are prefered but the provider may use fictitious examples as long as the example provides evidence of the decision making process.SCN-CSO-EVA
  • Explanation of how the appropriate parties can obtain this log information.CDS-TRC-ACL
  • Explanation of if and how this information is shared with other parties.CDS-CSO-RPS
  • Explanation of the supplied materials, including how to access and use them.CDS-CSO-PSMclass A, B, C, D only
  • How the report will be deliveredCCM-OCR-AVL
  • How the summary will be deliveredCCM-OCR-AFS
  • How to access the feedback mechanism.CCM-OCR-FBM
  • List of cryptographic modules used by default including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.CMU-CSO-CAT
  • Most recent Ongoing Certification Report. If the report is not available, the provider MUST provide a sample report that includes all required information.CCM-OCR-AVL
  • or an explanation of why machine readable content is not being providedVER-TFR-MRHclass B, C, D only
  • Process, manual or automated, to notify FedRAMP of changes in the FedRAMP Security InboxAFC-CSO-NOC
  • selected ordinal recurrence for the Ongoing Certification Report cycle if applicable OR explanation for why Ongoing Certification Reports are not being delivered.CCM-QTR-MTGclass B only
  • Third Party assesment report OR explanation why a third party assessor was not engagedSCN-TRF-TPR
  • URL and access instructions for historical vulnerability detection and response activity in machine readable formatVER-TFR-MRHclass A, B, C, D only
  • URL or explanation how to access documentation of these features and capabilities.CDS-TRC-SSM
  • URL to the documentation for programmatic access.CDS-TRC-PAC
  • URL to the machine-readable data (if applicable).CDS-CSO-SVC
  • URL to the registration page or calendar file.CCM-QTR-REG

Both projections — by requirement and by artifact — live in the Evidence Planner.

4Your clocks

24 deadlines bind Providers at class B10 class-independent plus 14scoped to this class. Units are the dataset’s own, never converted: “48 hours” and “2 days” are different obligations. The tightest is CDS-UTC-AAD at 5 business days.

DeadlineRequirementScopeForce
5 business daysCDS-UTC-AAD Agency Access Denialall classesMUST
5 business daysSCN-TRF-NAF Notification After Finishingall classesMUST
5 business daysSCN-TRF-NAV Notification After Verificationall classesMUST
7 daysVDR-TFR-MVX Persistent Machine Verification and Validation for 20xclass BMUST
7 daysVDR-TFR-PSD Persistent Sample Detectionclass BSHOULD
7 daysVER-TFR-EVU Evaluate Vulnerabilities Quicklyclass BSHOULD
2 weeksCDS-CSO-FRC FedRAMP Certification Reportsall classesMUST
10 business daysSCN-ADP-NTF Notification Requirementsall classesMUST
10 business daysSCN-TRF-NFP Notification of Final Plansall classesMUST
1 monthCPO-CSX-CPM Certification Package Maintenance for 20xclass BMUST
1 monthVDR-TFR-MVF Persistent Machine Verification and Validation for Rev5class BSHOULD
1 monthVDR-TFR-PDD Persistent Drift Detectionclass BSHOULD
1 monthVER-TFR-MHR Monthly Activity Reportall classesMUST
1 monthVER-TFR-MRH Historical Activityclass BSHOULD
30 business daysSCN-TRF-NIP Notification of Initial Plansall classesMUST
30 business daysSCN-TRF-UPD Update Documentationall classesMUST
3 monthsCCM-QTR-MTG Quarterly Review Meetingclass BSHOULD
3 monthsFRC-APP-FIA Fresh Independent Assessmentclass BMUST
6 monthsVDR-TFR-PCD Persistently Complete Detectionclass BSHOULD
192 daysVER-TFR-MAV Mark Accepted Vulnerabilitiesall classesMUST
1 yearCPO-CSF-CPM Certification Package Maintenance for Rev5class BMUST
1 yearIVV-CSF-AIA Annual Independent Assessments for Rev5class BMUST
1 yearIVV-CSO-FIA FedRAMP Independent Assessmentsclass BMUST
1 yearIVV-CSX-AIA Annual Independent Assessments for 20xclass BMUST

Assessor and FedRAMP clocks are deliberately excluded here; the full set, with PAIN grids and the rollout calendar, is the Obligation Clock.

5Take it with you

Everything on this page, machine-readable, with the dataset version in the envelope — so scoping done against these numbers records exactly which ruleset it was true of.

Download readiness JSONGET /api/readiness · all classes · envelope carries dataset_version