Class C readinessour reading: Rev5 Moderate — not a dataset fact
What binds a class C cloud service, in the order you will meet it: the baseline, the automated-coverage split, the evidence, the clocks — then the whole thing as JSON.
1Your control baseline
A baseline is a named subset of the NIST 800-53 Rev5 catalog, and membership is the whole relationship: these 322 controls bind a class C system, spread over 18 control families.
2Automated vs hand-argued
A KSI reaching a control means machine-validated 20x evidence can double as your control evidence. What no KSI reaches — the orphans — stays narrative: that residue is the real writing workload.
| AC | AT | AU | CA | CM | CP | IA | IR | MA | MP | PE | PL | PS | RA | SA | SC | SI | SR |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 67 | 83 | 94 | 54 | 74 | 96 | 70 | 71 | 10 | 0 | 0 | 29 | 80 | 36 | 43 | 79 | 71 | 50 |
MP and PE are reached by no KSI at all — 26 controls of pure narrative evidence, not a data gap.
The 123 orphan controls — your Security Decision Record scope
3The evidence you owe
49 distinct artifacts are named by specific requirements in scope for class C, on top of 5 boilerplate artifacts every FRR requirement owes and 5 every KSI indicator owes. Defaults are listed once, never multiplied in.
Owed by every requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Owed by every KSI indicator
- Explanation of measures (and their objectives) that demonstrate the Key Security Indicator, or an explanation of the reason and resulting risk to customers for not having measures available for that Key Security Indicator.
- Explanation of the cycle for any measures that are implemented persistently (if applicable).
- Verification that the measures demonstrate the Key Security Indicator, or that the reason for not having them is accepted.
- Verification that the automation in place is accurate and sufficient to demonstrate appropriate measures for the Key Security Indicator, or that automation is not necessary for each measure.
- Validation that the measures are accurately produced and are in place and working as intended, or that the reason for not having them is valid.
Rule-specific artifacts (49), most widely demanded first
- Explanation of how to access this informationSCG-CSO-PUB SCG-CSO-SDF SCG-ENH-API SCG-ENH-CMP SCG-ENH-EXP SCG-ENH-MRG SCG-ENH-VRH
- or explanation why this functionality is not availableSCG-CSO-PUB SCG-CSO-SDF SCG-ENH-API SCG-ENH-CMP SCG-ENH-EXP SCG-ENH-MRG SCG-ENH-VRH
- URL to the human-readable data.CDS-CSO-PUB CDS-CSO-SVC MKT-CAS-WEB MKT-IAS-WEB SCG-CSO-RSC
- A human readable explanation of how the machine readable output is derived.MAS-CSO-FLO MAS-CSO-IIR MAS-CSO-MDI MAS-CSO-TPR
- The code for the automated process used to generate the machine readable output.MAS-CSO-FLO MAS-CSO-IIR MAS-CSO-MDI MAS-CSO-TPR
- URL to the machine-readable data.CDS-CSO-PUB MKT-CAS-WEB MKT-IAS-WEB SCG-CSO-RSC
- A recent vulnerability report or a sample vulnerability reportVER-RPT-AVI VER-RPT-VDT VER-TFR-MHR
- Explanation of how FedRAMP can obtain this information.CDS-TRC-AAI SCN-CSO-HIS SCN-CSO-MAR
- Explanation of how the provider decides whether or not to share these materials or other related policies.CDS-UTC-AGA SCG-CSO-AUP SCN-CSO-HRM
- URL or explanation of how to request these materials.CDS-UTC-AGA SCG-CSO-AUP SCN-CSO-HRM
- An incident log showing an example of one or more incidents being evaluated including the reason for the determination. The log can be from real incidents, simulated incidents, or a combination of sources.IEC-CSO-EFI IEC-CSO-EFR
- Automated validation to check FSI mailbox configurationAFC-CSO-EMR AFC-CSO-TFG
- Configuration settings for FSI mailboxAFC-CSO-EMR AFC-CSO-TFG
- Explanation of how to access this information.CDS-CSO-HAD CDS-CSO-IRP
- List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.CMU-CSO-CMD CMU-CSO-UVMclass A, B, C, D only
- A machine readable output containing all required data of the components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-IIR
- A machine readable output containing all required data of the metadata collected or maintained by the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-MDI
- A machine readable output containing all required data of the permitted connections between components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-FLO
- A machine readable output containing all required data of the third-party information resources of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.MAS-CSO-TPR
- A recent Significant Change Notification or sample Significant Change NotificationSCN-CSO-INF
- An Final Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.IEC-CSO-FIRclass A, B, C, D only
- An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.IEC-CSO-IIRclass A, B, C, D only
- An Ongoing Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.IEC-CSO-OIRclass A, B, C, D only
- At least the most recent after verification SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NAV
- At least the most recent final SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NFP
- At least the most recent initial SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NIP
- At least the most recent post deployment SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required.SCN-TRF-NAF
- At least the most recent SCN notification including the date it was sent and the date the change was applied. Additional examples may be provided. If no SCN notifications have been sent then this artifact is not required.SCN-ADP-NTF
- Current list of available notification mechanismsSCN-CSO-NOM
- Date of the most recent transformative change and the date of the corresponding documentation update. If no documentation updates were required as the result of this change, explain how this was determined.SCN-TRF-UPD
- Email address to receive messages from FedRAMPAFC-CSO-INB
- Evidence of significant change evaluation including a description fo the change, the determined type, and an explanation for the decision. At least one example must be provided for each type of change. Real examples are prefered but the provider may use fictitious examples as long as the example provides evidence of the decision making process.SCN-CSO-EVA
- Explanation of how the appropriate parties can obtain this log information.CDS-TRC-ACL
- Explanation of if and how this information is shared with other parties.CDS-CSO-RPS
- Explanation of the supplied materials, including how to access and use them.CDS-CSO-PSMclass A, B, C, D only
- How the report will be deliveredCCM-OCR-AVL
- How the summary will be deliveredCCM-OCR-AFS
- How to access the feedback mechanism.CCM-OCR-FBM
- List of cryptographic modules used by default including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.CMU-CSO-CAT
- Most recent Ongoing Certification Report. If the report is not available, the provider MUST provide a sample report that includes all required information.CCM-OCR-AVL
- or an explanation of why machine readable content is not being providedVER-TFR-MRHclass B, C, D only
- Process, manual or automated, to notify FedRAMP of changes in the FedRAMP Security InboxAFC-CSO-NOC
- selected ordinal recurrence for the Ongoing Certification Report cycle.CCM-QTR-MTGclass C, D only
- Third Party assesment report OR explanation why a third party assessor was not engagedSCN-TRF-TPR
- URL and access instructions for historical vulnerability detection and response activity in machine readable formatVER-TFR-MRHclass A, B, C, D only
- URL or explanation how to access documentation of these features and capabilities.CDS-TRC-SSM
- URL to the documentation for programmatic access.CDS-TRC-PAC
- URL to the machine-readable data (if applicable).CDS-CSO-SVC
- URL to the registration page or calendar file.CCM-QTR-REG
Both projections — by requirement and by artifact — live in the Evidence Planner.
4Your clocks
24 deadlines bind Providers at class C — 10 class-independent plus 14scoped to this class. Units are the dataset’s own, never converted: “48 hours” and “2 days” are different obligations. The tightest is VDR-TFR-MVX at 3 days.
| Deadline | Requirement | Scope | Force |
|---|---|---|---|
| 3 days | VDR-TFR-MVX Persistent Machine Verification and Validation for 20x | class C | MUST |
| 3 days | VDR-TFR-PSD Persistent Sample Detection | class C | SHOULD |
| 5 days | VER-TFR-EVU Evaluate Vulnerabilities Quickly | class C | SHOULD |
| 5 business days | CDS-UTC-AAD Agency Access Denial | all classes | MUST |
| 5 business days | SCN-TRF-NAF Notification After Finishing | all classes | MUST |
| 5 business days | SCN-TRF-NAV Notification After Verification | all classes | MUST |
| 2 weeks | CDS-CSO-FRC FedRAMP Certification Reports | all classes | MUST |
| 2 weeks | CPO-CSX-CPM Certification Package Maintenance for 20x | class C | MUST |
| 10 business days | SCN-ADP-NTF Notification Requirements | all classes | MUST |
| 10 business days | SCN-TRF-NFP Notification of Final Plans | all classes | MUST |
| 14 days | VDR-TFR-PDD Persistent Drift Detection | class C | SHOULD |
| 14 days | VER-TFR-MRH Historical Activity | class C | SHOULD |
| 1 month | VDR-TFR-MVF Persistent Machine Verification and Validation for Rev5 | class C | MUST |
| 1 month | VDR-TFR-PCD Persistently Complete Detection | class C | SHOULD |
| 1 month | VER-TFR-MHR Monthly Activity Report | all classes | MUST |
| 30 business days | SCN-TRF-NIP Notification of Initial Plans | all classes | MUST |
| 30 business days | SCN-TRF-UPD Update Documentation | all classes | MUST |
| 3 months | CCM-QTR-MTG Quarterly Review Meeting | class C | MUST |
| 3 months | FRC-APP-FIA Fresh Independent Assessment | class C | MUST |
| 192 days | VER-TFR-MAV Mark Accepted Vulnerabilities | all classes | MUST |
| 1 year | CPO-CSF-CPM Certification Package Maintenance for Rev5 | class C | MUST |
| 1 year | IVV-CSF-AIA Annual Independent Assessments for Rev5 | class C | MUST |
| 1 year | IVV-CSO-FIA FedRAMP Independent Assessments | class C | MUST |
| 1 year | IVV-CSX-AIA Annual Independent Assessments for 20x | class C | MUST |
Assessor and FedRAMP clocks are deliberately excluded here; the full set, with PAIN grids and the rollout calendar, is the Obligation Clock.
5Take it with you
Everything on this page, machine-readable, with the dataset version in the envelope — so scoping done against these numbers records exactly which ruleset it was true of.
GET /api/readiness · all classes · envelope carries dataset_version