zenibit

FedRAMP reference

Which FedRAMP rules apply to me

Certification type, path and class decide which requirements are yours. Pick yours and get the list.

FedRAMP expresses applicability in three separate places — the ruleset container, the subset's applicability block, and per-requirement class variations — so the rulebook never states plainly which requirements are yours. This resolves all three.

204 requirements apply, 3 of them verifiable by automated check.

Addressing FedRAMP Communication

Certification Data Sharing

Certification Package Overview

Change Management

Cloud Native Architecture

Collaborative Continuous Monitoring

Cryptographic Module Use

Cybersecurity Education

FedRAMP Certification

Identity and Access Management

Incident Evaluation and Communication

Incident Response

Independent Verification and Validation

Marketplace Listing

Minimum Assessment Scope

Monitoring, Logging, and Auditing

Policy and Inventory

Recovery Planning

Secure Configuration Guide

Security Decision Record

Service Configuration

Significant Change Notification

Supply Chain Risk

Vulnerability Detection and Response

Vulnerability Evaluation and Reporting

Stop assembling this by hand.

Zenibit tracks these requirements against your live infrastructure and publishes a trust center agencies can verify themselves. Get in touch.