Which FedRAMP rules apply to me
Certification type, path and class decide which requirements are yours. Pick yours and get the list.
FedRAMP expresses applicability in three separate places (the ruleset container, the subset's applicability block, and per-requirement class variations), so the rulebook never states plainly which requirements are yours. This resolves all three.
204 requirements apply, 11 of them verifiable by automated check.
Addressing FedRAMP Communication
AFC-CSO-ACK: Acknowledge ReceiptAFC-CSO-CRA: Complete Required ActionsAFC-CSO-EMR: Emergency Message RoutingAFC-CSO-IMA: Important Message ActionsAFC-CSO-INB: Maintain a FedRAMP Security InboxAFC-CSO-NOC: Notification of ChangesAFC-CSO-RCV: Receive Email Without DisruptionAFC-CSO-TFG: Trust @fedramp.gov and @gsa.gov
Certification Data Sharing
CDS-CSO-AVR: Availability ReportingCDS-CSO-CBF: Consistency Between FormatsCDS-CSO-FID: Always Include FedRAMP IDCDS-CSO-FRC: FedRAMP Certification ReportsCDS-CSO-HAD: Historical FedRAMP Certification DataCDS-CSO-IRP: Include Relevant PoliciesCDS-CSO-PSM: Per-Service Certification MaterialsCDS-CSO-PUB: Public InformationCDS-CSO-RIS: Responsible Information SharingCDS-CSO-RPS: Responsible Public Package SharingCDS-CSO-SVC: Public Service ListCDS-CSO-UTC: Use Trust CentersCDS-TRC-AAI: Agency Access InventoryCDS-TRC-ACL: Access LoggingCDS-TRC-HMR: Human and Machine-Readable Certification DataCDS-TRC-PAC: Programmatic AccessCDS-TRC-SSM: Self-Service Access ManagementCDS-TRC-USH: Uninterrupted SharingCDS-UTC-AAD: Agency Access DenialCDS-UTC-AGA: Agency Access
Certification Package Overview
CPO-CSO-MTD: Certification Package Overview MetadataCPO-CSO-OSA: Overall Summary of Assessment in Certification PackageCPO-CSO-OVR: Overview of the Cloud Service OfferingCPO-CSX-CPM: Certification Package Maintenance for 20x
Change Management
KSI-CMT-LMC: Logging ChangesKSI-CMT-RMV: Redeploying vs ModifyingKSI-CMT-RVP: Reviewing Change ProceduresKSI-CMT-VTD: Validating Throughout Deployment
Cloud Native Architecture
KSI-CNA-DFP: Defining Functionality and PrivilegesKSI-CNA-EIS: Enforcing Intended StateKSI-CNA-IBP: Implementing Best PracticesKSI-CNA-MAT: Minimizing Attack SurfaceKSI-CNA-OFA: Optimizing for AvailabilityKSI-CNA-RNT: Restricting Network TrafficKSI-CNA-RVP: Reviewing ProtectionsKSI-CNA-ULN: Using Logical Networking
Collaborative Continuous Monitoring
CCM-OCR-AFS: Anonymized Feedback SummaryCCM-OCR-AVL: Report AvailabilityCCM-OCR-FBM: Feedback MechanismCCM-OCR-LSI: Limit Sensitive InformationCCM-OCR-NRD: Next Report DateCCM-OCR-RPS: Responsible Public Certification Report SharingCCM-OCR-SOR: Spread Out ReportsCCM-QTR-ACT: Additional ContentCCM-QTR-MTG: Quarterly Review MeetingCCM-QTR-NID: No Irresponsible DisclosureCCM-QTR-NRD: Next Review DateCCM-QTR-REG: Meeting Registration InfoCCM-QTR-RTP: Restrict Third PartiesCCM-QTR-RTR: Record/Transcribe ReviewsCCM-QTR-SAR: Schedule Around ReportsCCM-QTR-SCR: Share Content ResponsiblyCCM-QTR-SRR: Share Recordings Responsibly
Cryptographic Module Use
CMU-CSO-CAT: Configuration of Agency TenantsCMU-CSO-CMD: Cryptographic Module DocumentationCMU-CSO-UVM: Using Validated Cryptographic Modules
Cybersecurity Education
KSI-CED-RAT: Reviewing All Training
FedRAMP Certification
FRC-APP-AFC: Applying for FedRAMP CertificationFRC-APP-FCP: Fresh FedRAMP Certification PackageFRC-APP-FIA: Fresh Independent AssessmentFRC-APP-MLF: Marketplace Listing FirstFRC-APP-NTP: No Third-Party ApplicantsFRC-APP-USA: Updating Stale AssessmentsFRC-CSO-FCP: FedRAMP Certification ProfileFRC-CSO-JSN: FedRAMP JSON SchemasFRC-CSO-MRA: Maintain Responsibility and AccountabilityFRC-CSO-PKG: FedRAMP Certification PackageFRC-CSO-POP: Pick One Program Certification TypeFRC-CSX-MAS: Application within MASFRC-CSX-MOT: Metrics Over Time for Key Security IndicatorsFRC-CSX-VVK: Automated Verification and Validation of Key Security IndicatorsFRC-CSX-VVR: Automated Verification and Validation of FedRAMP Rules
Identity and Access Management
KSI-IAM-AAM: Automating Account ManagementKSI-IAM-APM: Adopting Passwordless MethodsKSI-IAM-ELP: Ensuring Least PrivilegeKSI-IAM-JIT: Authorizing Just-in-TimeKSI-IAM-SNU: Securing Non-User AuthenticationKSI-IAM-SUS: Responding to Suspicious Activity
Incident Evaluation and Communication
IEC-CSO-AIR: Automated Incident ReportingIEC-CSO-DPR: Default PAIN RatingIEC-CSO-EFI: Estimate Federal ImpactIEC-CSO-EFR: Evaluate FedRAMP ReportabilityIEC-CSO-FIR: Final Incident ReportIEC-CSO-IIR: Initial Incident ReportIEC-CSO-OIR: Ongoing Incident Reports
Incident Response
KSI-INR-AAR: Generating After Action ReportsKSI-INR-RIR: Reviewing Incident Response ProceduresKSI-INR-RPI: Reviewing Past Incidents
Independent Verification and Validation
IVV-CSO-DUS: Document Use of Representative SamplesIVV-CSO-FIA: FedRAMP Independent AssessmentsIVV-CSO-ICP: Inclusion in Certification PackageIVV-CSO-RAA: Receiving Assessor AdviceIVV-CSO-SEE: Supply Evidence of EffectivenessIVV-CSO-SEI: Supply Evidence of ImplementationIVV-CSO-STE: Supply Technical ExplanationsIVV-CSO-USR: Use Representative SamplesIVV-CSX-AIA: Annual Independent Assessments for 20x
Marketplace Listing
MKT-CSO-MLR: Marketplace Listing RequirementsMKT-CSO-PML: Provider Marketplace Listing RequestsMKT-IIP-AGU: Agency Use CasesMKT-IIP-DCP: Demonstrating Continuous ProgressMKT-IIP-DLA: Deadline for Assessment
Minimum Assessment Scope
MAS-CSO-FLO: Information Flows and Security CategoriesMAS-CSO-IIR: Identify Information ResourcesMAS-CSO-MDI: Metadata InclusionMAS-CSO-SUP: Supplemental InformationMAS-CSO-TPR: Third-Party Information Resources
Monitoring, Logging, and Auditing
KSI-MLA-ALA: Authorizing Log AccessKSI-MLA-EVC: Evaluating ConfigurationsKSI-MLA-LET: Logging Event TypesKSI-MLA-OSM: Operating SIEM CapabilityKSI-MLA-RVL: Reviewing Logs
Policy and Inventory
KSI-PIY-GIV: Generating InventoriesKSI-PIY-RES: Reviewing Executive SupportKSI-PIY-RIS: Reviewing Investments in SecurityKSI-PIY-RSD: Reviewing Security in the SDLCKSI-PIY-RVD: Reviewing Vulnerability Disclosures
Recovery Planning
KSI-RPL-ABO: Aligning Backups with ObjectivesKSI-RPL-ARP: Aligning Recovery PlanKSI-RPL-RRO: Reviewing Recovery ObjectivesKSI-RPL-TRC: Testing Recovery Capabilities
Secure Configuration Guide
SCG-CSO-AUP: Use InstructionsSCG-CSO-PUB: Public Secure Configuration GuidanceSCG-CSO-RSC: Recommended Secure ConfigurationSCG-CSO-SDF: Secure DefaultsSCG-ENH-API: API CapabilitySCG-ENH-CMP: Comparison CapabilitySCG-ENH-EXP: Export CapabilitySCG-ENH-MRG: Machine-Readable GuidanceSCG-ENH-VRH: Versioning and Release History
Security Decision Record
SDR-CSO-FRR: FedRAMP RulesSDR-CSO-MTD: Security Decision Record MetadataSDR-CSX-KMT: Key Security Indicator MetricsSDR-CSX-KSI: Key Security Indicators
Service Configuration
KSI-SVC-ACM: Automating Configuration ManagementKSI-SVC-ASM: Automating Secret ManagementKSI-SVC-EIS: Evaluating and Improving SecurityKSI-SVC-PRR: Preventing Residual RiskKSI-SVC-RUD: Removing Unwanted DataKSI-SVC-SIN: Securing InformationKSI-SVC-VCM: Validating CommunicationsKSI-SVC-VRI: Validating Resource Integrity
Significant Change Notification
SCN-ADP-NTF: Notification RequirementsSCN-CSO-ARI: Additional Relevant InformationSCN-CSO-EMG: Emergency ChangesSCN-CSO-EVA: Evaluate ChangesSCN-CSO-HIS: Historical NotificationsSCN-CSO-HRM: Human and Machine-Readable NotificationsSCN-CSO-INF: Required InformationSCN-CSO-MAR: Maintain Audit RecordsSCN-CSO-NOM: Notification MechanismsSCN-RTR-NNR: No Notification RequirementsSCN-TRF-NAF: Notification After FinishingSCN-TRF-NAV: Notification After VerificationSCN-TRF-NFP: Notification of Final PlansSCN-TRF-NIP: Notification of Initial PlansSCN-TRF-TPR: Third-Party ReviewSCN-TRF-UPD: Update Documentation
Supply Chain Risk
KSI-SCR-MIT: Mitigating Supply Chain RiskKSI-SCR-MON: Monitoring Supply Chain Risk
Vulnerability Detection and Response
VDR-CSO-ADT: Automate DetectionVDR-CSO-AKE: Avoid KEVsVDR-CSO-DAC: Detect After ChangesVDR-CSO-DET: Vulnerability DetectionVDR-CSO-DFR: Design For ResilienceVDR-CSO-FAV: Failures Are VulnerabilitiesVDR-CSO-MSP: Maintain SecurityVDR-CSO-RES: Vulnerability ResponseVDR-CSO-SIR: SamplingVDR-TFR-KEV: Remediate KEVsVDR-TFR-MVX: Persistent Machine Verification and Validation for 20xVDR-TFR-NMV: Non-Machine Verification and ValidationVDR-TFR-PCD: Persistently Complete DetectionVDR-TFR-PDD: Persistent Drift DetectionVDR-TFR-PSD: Persistent Sample DetectionVDR-TFR-PVR: Mitigation and Remediation ExpectationsVDR-TFR-RMN: Remaining Vulnerabilities
Vulnerability Evaluation and Reporting
VER-EVA-AIA: Assume It's AutomatableVER-EVA-EFA: Evaluation FactorsVER-EVA-EFP: Evaluate False PositivesVER-EVA-EIR: Evaluate Internet-ReachabilityVER-EVA-ELX: Evaluate ExploitabilityVER-EVA-EPA: Estimate Potential Agency ImpactVER-EVA-GRV: Group VulnerabilitiesVER-RPT-AVI: Accepted Vulnerability InfoVER-RPT-HLO: High-Level OverviewsVER-RPT-NID: Responsible DisclosureVER-RPT-PER: Persistent ReportingVER-RPT-RPD: Responsible Public DisclosureVER-RPT-VDT: Vulnerability DetailsVER-TFR-EVU: Evaluate Vulnerabilities QuicklyVER-TFR-IRI: Internet-Reachable IncidentsVER-TFR-MAV: Mark Accepted VulnerabilitiesVER-TFR-MHR: Monthly Activity ReportVER-TFR-MRH: Historical ActivityVER-TFR-NRI: Non-Internet-Reachable Incidents
Stop assembling this by hand.
Zenibit tracks these requirements against your live infrastructure, publishes a trust center as your public front door, and gives agency reviewers private access to the full package. Get in touch.