Which FedRAMP rules apply to me
Certification type, path and class decide which requirements are yours. Pick yours and get the list.
FedRAMP expresses applicability in three separate places — the ruleset container, the subset's applicability block, and per-requirement class variations — so the rulebook never states plainly which requirements are yours. This resolves all three.
204 requirements apply, 3 of them verifiable by automated check.
Addressing FedRAMP Communication
AFC-CSO-ACK— Acknowledge ReceiptAFC-CSO-CRA— Complete Required ActionsAFC-CSO-EMR— Emergency Message RoutingAFC-CSO-IMA— Important Message ActionsAFC-CSO-INB— Maintain a FedRAMP Security InboxAFC-CSO-NOC— Notification of ChangesAFC-CSO-RCV— Receive Email Without DisruptionAFC-CSO-TFG— Trust @fedramp.gov and @gsa.gov
Certification Data Sharing
CDS-CSO-AVR— Availability ReportingCDS-CSO-CBF— Consistency Between FormatsCDS-CSO-FID— Always Include FedRAMP IDCDS-CSO-FRC— FedRAMP Certification ReportsCDS-CSO-HAD— Historical FedRAMP Certification DataCDS-CSO-IRP— Include Relevant PoliciesCDS-CSO-PSM— Per-Service Certification MaterialsCDS-CSO-PUB— Public InformationCDS-CSO-RIS— Responsible Information SharingCDS-CSO-RPS— Responsible Public Package SharingCDS-CSO-SVC— Public Service ListCDS-CSO-UTC— Use Trust CentersCDS-TRC-AAI— Agency Access InventoryCDS-TRC-ACL— Access LoggingCDS-TRC-HMR— Human and Machine-Readable Certification DataCDS-TRC-PAC— Programmatic AccessCDS-TRC-SSM— Self-Service Access ManagementCDS-TRC-USH— Uninterrupted SharingCDS-UTC-AAD— Agency Access DenialCDS-UTC-AGA— Agency Access
Certification Package Overview
CPO-CSO-MTD— Certification Package Overview MetadataCPO-CSO-OSA— Overall Summary of Assessment in Certification PackageCPO-CSO-OVR— Overview of the Cloud Service OfferingCPO-CSX-CPM— Certification Package Maintenance for 20x
Change Management
KSI-CMT-LMC— Logging ChangesKSI-CMT-RMV— Redeploying vs ModifyingKSI-CMT-RVP— Reviewing Change ProceduresKSI-CMT-VTD— Validating Throughout Deployment
Cloud Native Architecture
KSI-CNA-DFP— Defining Functionality and PrivilegesKSI-CNA-EIS— Enforcing Intended StateKSI-CNA-IBP— Implementing Best PracticesKSI-CNA-MAT— Minimizing Attack SurfaceKSI-CNA-OFA— Optimizing for AvailabilityKSI-CNA-RNT— Restricting Network TrafficKSI-CNA-RVP— Reviewing ProtectionsKSI-CNA-ULN— Using Logical Networking
Collaborative Continuous Monitoring
CCM-OCR-AFS— Anonymized Feedback SummaryCCM-OCR-AVL— Report AvailabilityCCM-OCR-FBM— Feedback MechanismCCM-OCR-LSI— Limit Sensitive InformationCCM-OCR-NRD— Next Report DateCCM-OCR-RPS— Responsible Public Certification Report SharingCCM-OCR-SOR— Spread Out ReportsCCM-QTR-ACT— Additional ContentCCM-QTR-MTG— Quarterly Review MeetingCCM-QTR-NID— No Irresponsible DisclosureCCM-QTR-NRD— Next Review DateCCM-QTR-REG— Meeting Registration InfoCCM-QTR-RTP— Restrict Third PartiesCCM-QTR-RTR— Record/Transcribe ReviewsCCM-QTR-SAR— Schedule Around ReportsCCM-QTR-SCR— Share Content ResponsiblyCCM-QTR-SRR— Share Recordings Responsibly
Cryptographic Module Use
CMU-CSO-CAT— Configuration of Agency TenantsCMU-CSO-CMD— Cryptographic Module DocumentationCMU-CSO-UVM— Using Validated Cryptographic Modules
Cybersecurity Education
KSI-CED-RAT— Reviewing All Training
FedRAMP Certification
FRC-APP-AFC— Applying for FedRAMP CertificationFRC-APP-FCP— Fresh FedRAMP Certification PackageFRC-APP-FIA— Fresh Independent AssessmentFRC-APP-MLF— Marketplace Listing FirstFRC-APP-NTP— No Third-Party ApplicantsFRC-APP-USA— Updating Stale AssessmentsFRC-CSO-FCP— FedRAMP Certification ProfileFRC-CSO-JSN— FedRAMP JSON SchemasFRC-CSO-MRA— Maintain Responsibility and AccountabilityFRC-CSO-PKG— FedRAMP Certification PackageFRC-CSO-POP— Pick One Program Certification TypeFRC-CSX-MAS— Application within MASFRC-CSX-MOT— Metrics Over Time for Key Security IndicatorsFRC-CSX-VVK— Automated Verification and Validation of Key Security IndicatorsFRC-CSX-VVR— Automated Verification and Validation of FedRAMP Rules
Identity and Access Management
KSI-IAM-AAM— Automating Account ManagementKSI-IAM-APM— Adopting Passwordless MethodsKSI-IAM-ELP— Ensuring Least PrivilegeKSI-IAM-JIT— Authorizing Just-in-TimeKSI-IAM-SNU— Securing Non-User AuthenticationKSI-IAM-SUS— Responding to Suspicious Activity
Incident Evaluation and Communication
IEC-CSO-AIR— Automated Incident ReportingIEC-CSO-DPR— Default PAIN RatingIEC-CSO-EFI— Estimate Federal ImpactIEC-CSO-EFR— Evaluate FedRAMP ReportabilityIEC-CSO-FIR— Final Incident ReportIEC-CSO-IIR— Initial Incident ReportIEC-CSO-OIR— Ongoing Incident Reports
Incident Response
KSI-INR-AAR— Generating After Action ReportsKSI-INR-RIR— Reviewing Incident Response ProceduresKSI-INR-RPI— Reviewing Past Incidents
Independent Verification and Validation
IVV-CSO-DUS— Document Use of Representative SamplesIVV-CSO-FIA— FedRAMP Independent AssessmentsIVV-CSO-ICP— Inclusion in Certification PackageIVV-CSO-RAA— Receiving Assessor AdviceIVV-CSO-SEE— Supply Evidence of EffectivenessIVV-CSO-SEI— Supply Evidence of ImplementationIVV-CSO-STE— Supply Technical ExplanationsIVV-CSO-USR— Use Representative SamplesIVV-CSX-AIA— Annual Independent Assessments for 20x
Marketplace Listing
MKT-CSO-MLR— Marketplace Listing RequirementsMKT-CSO-PML— Provider Marketplace Listing RequestsMKT-IIP-AGU— Agency Use CasesMKT-IIP-DCP— Demonstrating Continuous ProgressMKT-IIP-DLA— Deadline for Assessment
Minimum Assessment Scope
MAS-CSO-FLO— Information Flows and Security CategoriesMAS-CSO-IIR— Identify Information ResourcesMAS-CSO-MDI— Metadata InclusionMAS-CSO-SUP— Supplemental InformationMAS-CSO-TPR— Third-Party Information Resources
Monitoring, Logging, and Auditing
KSI-MLA-ALA— Authorizing Log AccessKSI-MLA-EVC— Evaluating ConfigurationsKSI-MLA-LET— Logging Event TypesKSI-MLA-OSM— Operating SIEM CapabilityKSI-MLA-RVL— Reviewing Logs
Policy and Inventory
KSI-PIY-GIV— Generating InventoriesKSI-PIY-RES— Reviewing Executive SupportKSI-PIY-RIS— Reviewing Investments in SecurityKSI-PIY-RSD— Reviewing Security in the SDLCKSI-PIY-RVD— Reviewing Vulnerability Disclosures
Recovery Planning
KSI-RPL-ABO— Aligning Backups with ObjectivesKSI-RPL-ARP— Aligning Recovery PlanKSI-RPL-RRO— Reviewing Recovery ObjectivesKSI-RPL-TRC— Testing Recovery Capabilities
Secure Configuration Guide
SCG-CSO-AUP— Use InstructionsSCG-CSO-PUB— Public Secure Configuration GuidanceSCG-CSO-RSC— Recommended Secure ConfigurationSCG-CSO-SDF— Secure DefaultsSCG-ENH-API— API CapabilitySCG-ENH-CMP— Comparison CapabilitySCG-ENH-EXP— Export CapabilitySCG-ENH-MRG— Machine-Readable GuidanceSCG-ENH-VRH— Versioning and Release History
Security Decision Record
SDR-CSO-FRR— FedRAMP RulesSDR-CSO-MTD— Security Decision Record MetadataSDR-CSX-KMT— Key Security Indicator MetricsSDR-CSX-KSI— Key Security Indicators
Service Configuration
KSI-SVC-ACM— Automating Configuration ManagementKSI-SVC-ASM— Automating Secret ManagementKSI-SVC-EIS— Evaluating and Improving SecurityKSI-SVC-PRR— Preventing Residual RiskKSI-SVC-RUD— Removing Unwanted DataKSI-SVC-SIN— Securing InformationKSI-SVC-VCM— Validating CommunicationsKSI-SVC-VRI— Validating Resource Integrity
Significant Change Notification
SCN-ADP-NTF— Notification RequirementsSCN-CSO-ARI— Additional Relevant InformationSCN-CSO-EMG— Emergency ChangesSCN-CSO-EVA— Evaluate ChangesSCN-CSO-HIS— Historical NotificationsSCN-CSO-HRM— Human and Machine-Readable NotificationsSCN-CSO-INF— Required InformationSCN-CSO-MAR— Maintain Audit RecordsSCN-CSO-NOM— Notification MechanismsSCN-RTR-NNR— No Notification RequirementsSCN-TRF-NAF— Notification After FinishingSCN-TRF-NAV— Notification After VerificationSCN-TRF-NFP— Notification of Final PlansSCN-TRF-NIP— Notification of Initial PlansSCN-TRF-TPR— Third-Party ReviewSCN-TRF-UPD— Update Documentation
Supply Chain Risk
KSI-SCR-MIT— Mitigating Supply Chain RiskKSI-SCR-MON— Monitoring Supply Chain Risk
Vulnerability Detection and Response
VDR-CSO-ADT— Automate DetectionVDR-CSO-AKE— Avoid KEVsVDR-CSO-DAC— Detect After ChangesVDR-CSO-DET— Vulnerability DetectionVDR-CSO-DFR— Design For ResilienceVDR-CSO-FAV— Failures Are VulnerabilitiesVDR-CSO-MSP— Maintain SecurityVDR-CSO-RES— Vulnerability ResponseVDR-CSO-SIR— SamplingVDR-TFR-KEV— Remediate KEVsVDR-TFR-MVX— Persistent Machine Verification and Validation for 20xVDR-TFR-NMV— Non-Machine Verification and ValidationVDR-TFR-PCD— Persistently Complete DetectionVDR-TFR-PDD— Persistent Drift DetectionVDR-TFR-PSD— Persistent Sample DetectionVDR-TFR-PVR— Mitigation and Remediation ExpectationsVDR-TFR-RMN— Remaining Vulnerabilities
Vulnerability Evaluation and Reporting
VER-EVA-AIA— Assume It's AutomatableVER-EVA-EFA— Evaluation FactorsVER-EVA-EFP— Evaluate False PositivesVER-EVA-EIR— Evaluate Internet-ReachabilityVER-EVA-ELX— Evaluate ExploitabilityVER-EVA-EPA— Estimate Potential Agency ImpactVER-EVA-GRV— Group VulnerabilitiesVER-RPT-AVI— Accepted Vulnerability InfoVER-RPT-HLO— High-Level OverviewsVER-RPT-NID— Responsible DisclosureVER-RPT-PER— Persistent ReportingVER-RPT-RPD— Responsible Public DisclosureVER-RPT-VDT— Vulnerability DetailsVER-TFR-EVU— Evaluate Vulnerabilities QuicklyVER-TFR-IRI— Internet-Reachable IncidentsVER-TFR-MAV— Mark Accepted VulnerabilitiesVER-TFR-MHR— Monthly Activity ReportVER-TFR-MRH— Historical ActivityVER-TFR-NRI— Non-Internet-Reachable Incidents
Stop assembling this by hand.
Zenibit tracks these requirements against your live infrastructure and publishes a trust center agencies can verify themselves. Get in touch.