zenibit

FedRAMP reference

FedRAMP rules

Every FRR requirement, by ruleset, with its force, its corrective actions, and the class variations the rulebook buries.

FedRAMP Requirements are grouped into rulesets, each with its own effective dates. Force is load-bearing: MUST is an obligation, SHOULD is an expectation you can be asked to justify departing from, and MAY is permission. Where a requirement is worded differently for different impact classes, every wording is shown with the classes it applies to.

Addressing FedRAMP Communication · AFC

8 requirements, 0 verifiable by automated check.

AFC-CSO-ACK

Acknowledge Receipt

Providers SHOULD promptly and automatically acknowledge the receipt of messages received from FedRAMP in their FedRAMP Security Inbox.

SHOULDEvidence required

AFC-CSO-CRA

Complete Required Actions

Providers MUST complete the required actions in Emergency or Emergency Test designated messages sent by FedRAMP within the timeframe included in the message.

Timeframes may vary by FedRAMP Certification class.

MUSTEvidence required

AFC-CSO-EMR

Emergency Message Routing

Providers MUST route Emergency designated messages sent by FedRAMP to a senior security official for their awareness.

Senior security officials are determined by the provider.

MUSTEvidence required

AFC-CSO-IMA

Important Message Actions

Providers SHOULD complete the required actions in Important designated messages sent by FedRAMP within the timeframe specified in the message.

Timeframes may vary by FedRAMP Certification class.

SHOULDEvidence required

AFC-CSO-INB

Maintain a FedRAMP Security Inbox

Providers MUST establish and maintain an email address to receive messages from FedRAMP; this inbox is a FedRAMP Security Inbox (FSI).

Unless otherwise notified, FedRAMP will use the listed Security Email on the Marketplace for these notifications.

If a provider establishes a new inbox in reaction to this guidance that is different from the Security Email then they must follow the AFC-CSO-NOC (Notification of Changes) rules to notify FedRAMP.

MUSTEvidence required

AFC-CSO-NOC

Notification of Changes

Providers MUST immediately notify FedRAMP of any changes to the email address for their FedRAMP Security Inbox.

MUSTEvidence required

AFC-CSO-RCV

Receive Email Without Disruption

Providers MUST receive and react to email messages from FedRAMP without disruption and without requiring additional actions from FedRAMP.

This requirement is intended to prevent cloud service providers from requiring FedRAMP to complete a CAPTCHA, log into a customer portal, or otherwise take service-specific actions that might prevent the security team from receiving the message.

MUSTEvidence required

AFC-CSO-TFG

Trust @fedramp.gov and @gsa.gov

Providers MUST treat any email originating from an @fedramp.gov or @gsa.gov email address as if it was sent from FedRAMP by default; if such a message is confirmed to originate from someone other than FedRAMP then the FedRAMP Security Inbox rules no longer apply.

MUSTEvidence required

Collaborative Continuous Monitoring · CCM

17 requirements, 0 verifiable by automated check.

CCM-OCR-AFS

Anonymized Feedback Summary

Providers MUST supply an anonymized and desensitized summary of the feedback, questions, and answers about each Ongoing Certification Report as an addendum to the Ongoing Certification Report OR in the next Ongoing Certification Report.

This is intended to encourage sharing of information and decrease the burden on the cloud service provider - providing this summary will reduce duplicate questions from agencies and ensure FedRAMP has access to this information. It is generally in the provider's interest to update this addendum frequently throughout the quarter.

MUSTEvidence required

CCM-OCR-AVL

Report Availability

Providers MUST supply an Ongoing Certification Report to all necessary parties every 3 months, covering the entire period since the previous summary, in a consistent format that is human readable; this report MUST include high-level summaries of at least the following information:

MUSTEvidence required

CCM-OCR-FBM

Feedback Mechanism

Providers MUST supply an asynchronous mechanism for all necessary parties to provide feedback or ask questions about each Ongoing Certification Report.

This could be email by default but providers are encouraged to consider something more interactive as appropriate.

MUSTEvidence required

CCM-OCR-LSI

Limit Sensitive Information

Providers MUST NOT irresponsibly disclose sensitive information in an Ongoing Certification Report that would likely have an adverse effect on the cloud service offering.

MUST NOTEvidence required

CCM-OCR-NRD

Next Report Date

Providers MUST supply the target date for their next Ongoing Certification Report with other public FedRAMP Certification Data.

MUSTEvidence required

CCM-OCR-RPS

Responsible Public Certification Report Sharing

Providers MAY responsibly supply some or all of the information an Ongoing Certification Report to the public or other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.

MAYEvidence required

CCM-OCR-SOR

Spread Out Reports

Providers SHOULD establish a regular 3 month cycle for Ongoing Certification Reports that is spread out from the beginning, middle, or end of each quarter.

This recommendation is intended to discourage hundreds of cloud service providers from releasing their Ongoing Certification Reports during the first or last week of each quarter because that is the easiest way for a single provider to track this deliverable; the result would overwhelm agencies with many cloud services. Widely used cloud service providers are encouraged to work with their customers to identify ideal timeframes for this cycle.

SHOULDEvidence required

CCM-QTR-ACT

Additional Content

Providers SHOULD supply additional information in Quarterly Reviews that the provider determines is of interest, use, or otherwise relevant to agencies.

SHOULDEvidence required

CCM-QTR-MTG

Quarterly Review Meeting

Class B

Providers with Class B Certifications SHOULD host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.

Class C

Providers with Class C Certifications MUST host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.

Class D

Providers with Class D Certifications MUST host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.

SHOULDEvidence required

CCM-QTR-NID

No Irresponsible Disclosure

Providers MUST NOT irresponsibly disclose sensitive information in a Quarterly Review that would likely have an adverse effect on the cloud service offering.

MUST NOTEvidence required

CCM-QTR-NRD

Next Review Date

Providers MUST publicly supply the target date for their next Quarterly Review with other public FedRAMP Certification Data.

MUSTEvidence required

CCM-QTR-REG

Meeting Registration Info

Providers MUST supply either a registration link or a downloadable calendar file with meeting information for Quarterly Reviews to all necessary parties.

MUSTEvidence required

CCM-QTR-RTP

Restrict Third Parties

Providers SHOULD NOT invite third parties to attend Quarterly Reviews intended for agencies unless they have specific relevance.

This is because agencies are less likely to actively participate in meetings with third parties; the cloud service provider's independent assessor should be considered relevant by default.

SHOULD NOTEvidence required

CCM-QTR-RTR

Record/Transcribe Reviews

Providers SHOULD record or transcribe Quarterly Reviews and supply them to all necessary parties.

SHOULDEvidence required

CCM-QTR-SAR

Schedule Around Reports

Providers SHOULD regularly schedule Quarterly Reviews to occur at least 3 business days after releasing an Ongoing Certification Report AND within 10 business days of such release.

SHOULDEvidence required

CCM-QTR-SCR

Share Content Responsibly

Providers MAY responsibly supply content prepared for a Quarterly Review to the public or other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.

MAYEvidence required

CCM-QTR-SRR

Share Recordings Responsibly

Providers MAY responsibly supply recordings or transcriptions of Quarterly Reviews to the public or other parties ONLY if the provider removes all agency information (comments, questions, names, etc.) AND determines doing so will NOT likely have an adverse effect on the cloud service offering.

MAYEvidence required

Certification Data Sharing · CDS

21 requirements, 0 verifiable by automated check.

CDS-CSF-TCM

Trust Center Migration

Providers MUST notify all necessary parties when migrating to a trust center and MUST provide information in their existing USDA Connect Community Portal secure folders explaining how to use the trust center to obtain FedRAMP Certification Data.

MUSTEvidence required

CDS-CSO-AVR

Availability Reporting

Class B

Providers with Class B Certifications MUST maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service MUST be available even if the primary cloud service offering is unavailable.

This service may be separate from the trust center.

Class C

Providers with Class C Certifications MUST maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service MUST be available even if the primary cloud service offering is unavailable.

This service may be separate from the trust center.

Class D

Providers with Class D Certifications MUST maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service MUST be available even if the primary cloud service offering is unavailable.

This service may be separate from the trust center.

MUSTEvidence required

CDS-CSO-CBF

Consistency Between Formats

Providers MUST use automation to ensure information remains consistent between human-readable and machine-readable formats when FedRAMP Certification Data is provided in both formats.

MUSTEvidence required

CDS-CSO-FID

Always Include FedRAMP ID

Providers MUST always include the FedRAMP ID of the related cloud service offering in all FedRAMP Certification Data once assigned, including all reports, notifications, and other communication that results from FedRAMP rules.

The FedRAMP ID is supplied by FedRAMP after a cloud service offering is registered to be listed on the FedRAMP Marketplace - providers will need to use a placeholder until the FedRAMP ID is assigned.

Many providers have multiple cloud service offerings or use internal names that don't align to public materials; using the FedRAMP ID ensures we can easily align the communication with a specific cloud service offering.

MUSTEvidence required

CDS-CSO-FRC

FedRAMP Certification Reports

Providers MUST include FedRAMP Certification Reports with their FedRAMP Certification Data without inappropriate modifications, and make such reports available within 2 weeks of receiving the materials from FedRAMP.

FedRAMP provides Certification Reports for all cloud service offerings following the Program Certification path as part of the initial and ongoing FedRAMP Certification process, and may provide Certification Reports for cloud service offerings following the Agency Certification path.

MUSTEvidence required

CDS-CSO-HAD

Historical FedRAMP Certification Data

Providers MUST supply snapshots of FedRAMP Certification Data aligned to Ongoing Certification Reports to all necessary parties; these snapshots MUST be available for the duration of FedRAMP Certification.

Historical snapshots do not need to be reconstructed for periods before the provider's first Ongoing Certification Report, but should be maintained for all subsequent Ongoing Certification Reports.

MUSTEvidence required

CDS-CSO-IRP

Include Relevant Policies

Providers MUST supply all relevant policies and procedures in the FedRAMP Certification Data, including a human-readable and machine-readable reference that explains at least the following about each included policy and procedure:

MUSTEvidence required

CDS-CSO-PSM

Per-Service Certification Materials

Class B

Providers with Class B Certifications MAY supply per-service FedRAMP Certification materials.

Providers determine what they consider to be separate services, based on maximizing the customer experience for agencies who may only adopt some services and not others.

Providers are encouraged to provide a single comprehensive set of materials for all shared aspects of the service offering and only provide separate materials for unique aspects of each service to minimize the burden on providers and agencies.

Class C

Providers with Class C Certifications MAY supply per-service FedRAMP Certification materials.

Providers determine what they consider to be separate services, based on maximizing the customer experience for agencies who may only adopt some services and not others.

Providers are encouraged to provide a single comprehensive set of materials for all shared aspects of the service offering and only provide separate materials for unique aspects of each service to minimize the burden on providers and agencies.

Class D

Providers with Class D Certifications MUST supply per-service FedRAMP Certification materials.

Providers determine what they consider to be separate services, based on maximizing the customer experience for agencies who may only adopt some services and not others.

Providers are encouraged to provide a single comprehensive set of materials for all shared aspects of the service offering and only provide separate materials for unique aspects of each service to minimize the burden on providers and agencies.

MAYEvidence required

CDS-CSO-PUB

Public Information

Providers MUST publicly share up-to-date information about the cloud service offering in both human-readable and JSON formats, including at least the following information that is available and applicable:

Generally, this information should be available on a public webpage or publicly shared in a FedRAMP-compatible trust center.

MUSTEvidence required

CDS-CSO-RIS

Responsible Information Sharing

Providers MUST provide sufficient information in FedRAMP Certification Data to support agency authorization decisions but SHOULD NOT include sensitive information that would likely enable a threat actor to gain unauthorized access, cause harm, disrupt operations, or otherwise have a negative adverse impact on the cloud service offering.

This is not a license to exclude accurate risk information, but specifics that would likely lead to compromise should be abstracted. A breach of confidentiality with FedRAMP Certification Data should be anticipated by a secure cloud service provider.

MUSTEvidence required

CDS-CSO-RPS

Responsible Public Package Sharing

Providers MAY responsibly share some or all of the information in a FedRAMP Certification Package publicly or with other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.

MAYEvidence required

CDS-CSO-SVC

Public Service List

Providers MUST publicly share a detailed list of specific services and their security categories that are included in the cloud service offering using clear feature or service names that align with standard public marketing materials; this list MUST be complete enough for a potential customer to determine which services are and are not included in the FedRAMP Minimum Assessment Scope without requesting access to underlying FedRAMP Certification Data.

MUSTEvidence required

CDS-CSO-UTC

Use Trust Centers

Providers MUST use a FedRAMP-compatible trust center to store and share FedRAMP Certification Data with all necessary parties.

Rules for FedRAMP-Compatible Trust Centers are explained in the Certification Data Sharing Rules under the FedRAMP-Compatible Trust Centers section (id: CDS-TRC).

MUSTEvidence required

CDS-TRC-AAI

Agency Access Inventory

Trust centers MUST maintain an inventory and history of federal agency users or systems with access to FedRAMP Certification Data and MUST make this information available to FedRAMP upon request.

MUSTEvidence required

CDS-TRC-ACL

Access Logging

Trust centers MUST log access to FedRAMP Certification Data and store summaries of access for at least six months; such information, as it pertains to specific parties, SHOULD be made available upon request by those parties.

MUSTEvidence required

CDS-TRC-HMR

Human and Machine-Readable Certification Data

Trust centers SHOULD make FedRAMP Certification Data available to view and download in both human-readable and machine-readable formats.

SHOULDEvidence required

CDS-TRC-PAC

Programmatic Access

Trust centers MUST provide documented programmatic access to all FedRAMP Certification Data, including programmatic access to human-readable materials.

MUSTEvidence required

CDS-TRC-SSM

Self-Service Access Management

Trust centers SHOULD include features that encourage all necessary parties to provision and manage access to FedRAMP Certification Data for their users and services directly.

SHOULDEvidence required

CDS-TRC-USH

Uninterrupted Sharing

Trust centers MUST share FedRAMP Certification Data with all necessary parties without interruption.

"Without interruption" means that parties should not have to request manual approval each time they need to access FedRAMP Certification Data or go through a complicated process. The preferred way of ensuring access without interruption is to use on-demand just-in-time access provisioning.

MUSTEvidence required

CDS-UTC-AAD

Agency Access Denial

Providers MUST notify FedRAMP within 5 business days of denying an agency access request for FedRAMP Certification Data.

MUSTEvidence required

CDS-UTC-AGA

Agency Access

Providers SHOULD supply access to the FedRAMP Certification Package with agencies upon request.

SHOULDEvidence required

Cryptographic Module Use · CMU

3 requirements, 0 verifiable by automated check.

CMU-CSO-CAT

Configuration of Agency Tenants

Providers SHOULD configure agency tenants by default to use cryptographic services that use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when such modules are available.

SHOULDEvidence required

CMU-CSO-CMD

Cryptographic Module Documentation

Providers MUST document the cryptographic modules used in each service (or groups of services that use the same modules) where cryptographic services are used to protect federal customer data, including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.

MUSTEvidence required

CMU-CSO-UVM

Using Validated Cryptographic Modules

Class B

Providers with Class B Certifications MAY use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.

Class C

Providers with Class C Certifications SHOULD use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.

Class D

Providers with Class D Certifications MUST use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.

MAYEvidence required

Certification Package Overview · CPO

5 requirements, 0 verifiable by automated check.

CPO-CSF-CPM

Certification Package Maintenance for Rev5

Class B

Providers with Rev5 Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every year.

This maximum timeframe for Rev5 is the absolutely poorest worst case for horrible customer experience and is based on legacy FedRAMP Rev5 allowing providers to leave their packages unmaintained for up to a year. Rev5 providers should maintain their packages far more frequently than this requirement to ensure potential customers have access to up-to-date information, updating it at least after every transformative significant change.

FedRAMP 20x Certifications expect providers to maintain their FedRAMP Certification Packages as changes occur to ensure they are never out of date.

Class C

Providers with Rev5 Class C Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every year.

This maximum timeframe for Rev5 is the absolutely poorest worst case for horrible customer experience and is based on legacy FedRAMP Rev5 allowing providers to leave their packages unmaintained for up to a year. Rev5 providers should maintain their packages far more frequently than this requirement to ensure potential customers have access to up-to-date information, updating it at least after every transformative significant change.

FedRAMP 20x Certifications expect providers to maintain their FedRAMP Certification Packages as changes occur to ensure they are never out of date.

Class D

Providers with Rev5 Class D Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every six months.

This maximum timeframe for Rev5 is the absolutely poorest worst case for horrible customer experience and is based on legacy FedRAMP Rev5 allowing providers to leave their packages unmaintained for up to a year. Rev5 providers should maintain their packages far more frequently than this requirement to ensure potential customers have access to up-to-date information, updating it at least after every transformative significant change.

FedRAMP 20x Certifications expect providers to maintain their FedRAMP Certification Packages as changes occur to ensure they are never out of date.

MUSTEvidence required

CPO-CSO-MTD

Certification Package Overview Metadata

Providers MUST also include the following basic metadata in their Certification Package Overview:

MUSTEvidence required

CPO-CSO-OSA

Overall Summary of Assessment in Certification Package

Class B

Providers seeking Class B Certification MUST also include the overall summary of their FedRAMP independent assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), in their Certification Package Overview.

Class C

Providers seeking Class C Certification MUST also include the overall summary of their FedRAMP independent assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), in their Certification Package Overview.

Class D

Providers seeking Class D Certification MUST also include the overall summary of their FedRAMP independent assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), in their Certification Package Overview.

MUSTEvidence required

CPO-CSO-OVR

Overview of the Cloud Service Offering

Providers MUST supply a Certification Package Overview within their FedRAMP Certification Package, in both human-readable and JSON formats, that includes at least all of the information required by the following rules:

For FedRAMP Rev5, the Certification Package Overview replaces the historically required System Security Plan (not including appendices).

This list of rules may not apply to all FedRAMP Certification Classes or Types - if a rule does not apply then the information is not required.

MUSTEvidence required

CPO-CSX-CPM

Certification Package Maintenance for 20x

Class A

Providers with 20x Class A Certifications SHOULD persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 3 months.

Providers are expected to maintain their FedRAMP Certification Package using automation as changes occur to ensure they are never out of date.

This rule does not require or expect persistent human review of all materials in this cadence.

Class B

Providers with 20x Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every month.

Providers are expected to maintain their FedRAMP Certification Package using automation as changes occur to ensure they are never out of date.

This rule does not require or expect persistent human review of all materials in this cadence.

Class C

Providers with 20x Class C Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 2 weeks.

Providers are expected to maintain their FedRAMP Certification Package using automation as changes occur to ensure they are never out of date.

This rule does not require or expect persistent human review of all materials in this cadence.

Class D

Providers with 20x Class D Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every week.

Providers are expected to maintain their FedRAMP Certification Package using automation as changes occur to ensure they are never out of date.

This rule does not require or expect persistent human review of all materials in this cadence.

SHOULDEvidence required

FedRAMP Certification · FRC

29 requirements, 0 verifiable by automated check.

FRC-APP-AFC

Applying for FedRAMP Certification

Providers MUST complete the FedRAMP Certification Application Form in full to request an initial assessment by FedRAMP.

MUSTEvidence required

FRC-APP-FCP

Fresh FedRAMP Certification Package

Providers MUST supply a fresh initial FedRAMP Certification Package that shows the current status of the cloud service offering as verified and validated by the provider within the previous 7 days.

MUSTEvidence required

FRC-APP-FIA

Fresh Independent Assessment

Class A

Providers seeking Class A Certification MAY supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.

Class B

Providers seeking Class B Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.

Class C

Providers seeking Class C Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.

Class D

Providers seeking Class D Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.

MAYEvidence required

FRC-APP-MLF

Marketplace Listing First

Providers MUST be listed in the FedRAMP Marketplace before applying for FedRAMP Certification, including:

MUSTEvidence required

FRC-APP-NTP

No Third-Party Applicants

Providers MUST NOT use a third party to apply for a FedRAMP Certification on their behalf; this includes independent assessment services.

FedRAMP previously allowed independent assessment services to submit applications on behalf of providers, but this caused confusion about who was responsible for the application and the information in it. Providers should apply directly to ensure clear accountability.

Providers may use third parties to help them prepare their application and assessment materials for submission.

MUST NOTEvidence required

FRC-APP-USA

Updating Stale Assessments

Providers MAY freshen a stale initial independent verification and validation assessment by having a FedRAMP Recognized independent assessment service review any changes between the original assessment and the current status of the cloud service offering in place of a full re-assessment, UNLESS the stale assessment is more than 9 months old.

MAYEvidence required

FRC-APS-ATO

Agency Authorization to Operate

Providers seeking a FedRAMP Rev5 Agency Certification MUST have completed the Authorization to Operate (ATO) process with their agency sponsor for the cloud service offering, concluding with a formal signed ATO letter that the agency has sent over official government channels to FedRAMP.

MUSTEvidence required

FRC-CCL-DCC

Downgrading Certification Class

Providers MUST apply for a new FedRAMP Certification to downgrade their Certification Class.

Downgrade paths include moving from D to C, B, or A; C to B or A; or B to A.

FRC-CCL-DNP (Downgrade Notification Period) applies - please DO NOT downgrade Certification Class with providing advance notification to all necessary parties!

MUSTEvidence required

FRC-CCL-DNP

Downgrade Notification Period

Providers SHOULD notify all necessary parties at least 120 days in advance of an intended downgrade or cancellation of FedRAMP Certification.

Downgrading or canceling FedRAMP Certification will have severe negative consequences for the provider and their agency customers and should only be done after careful consideration and planning... but if it must be done, notify all necessary parties as soon as possible.

SHOULDEvidence required

FRC-CCL-UCC

Upgrading Certification Class

Providers MUST apply for a new FedRAMP Certification to upgrade their Certification Class; all applicable requirements MUST be met in advance.

Upgrade paths include moving from A to B, C, or D; B to C or D; and C to D.

The preferred path is to incrementally update the implementation and assurance commitments within the current Certification Class until the provider has met all requirements for the target Certification Class, then apply for the new Certification Class.

MUSTEvidence required

FRC-CLA-ASF

Approved Alternative Security Frameworks

Providers seeking a FedRAMP Class A Certification MUST have completed a certification or equivalent process, including an independent assessment if applicable, from one of the following alternative security frameworks within the past 12 months:

MUSTEvidence required

FRC-CLA-EAM

External Assessment Materials

Providers seeking a FedRAMP Class A Certification MUST supply the following materials from their alternative security framework assessment to all necessary parties:

MUSTEvidence required

FRC-CLA-IVV

Optional Independent Verification and Validation

Providers seeking a FedRAMP Class A Certification MAY have the FedRAMP Certification Package independently verified and validated by a FedRAMP Recognized assessor before submission to FedRAMP.

MAYEvidence required

FRC-CLA-MFR

Mandatory FedRAMP Rules for Class A

Providers seeking a Class A FedRAMP Certification MUST address all rules in this FedRAMP Class A Certification subset (FRC-CLA) AND the following additional FedRAMP Class A rules; the appropriate artifacts or information mapping for all rules MUST be supplied in the FedRAMP Certification Package.

Some of these specific FedRAMP rules may not have similar counterparts in external frameworks and providers will need to implement new processes to follow these rules.

In general, for each of these FedRAMP requirements, providers should include a sufficiently detailed summary that reviewers will not need to dig into the related security framework materials to understand the related decisions - just saying "see SOC 2 report" is not particularly helpful.

Information about how the provider addresses the included Key Security Indicators are required to receive a class A certification even if the provider intends to pursue a Rev 5 Program Certification path in the future.

MUSTEvidence required

FRC-CLA-OFR

Address Optional FedRAMP Rules for Class A

Providers seeking a Class A FedRAMP Certification MAY address the following additional optional FedRAMP Class A rules (if applicable):

MAYEvidence required

FRC-CLA-RFR

Recommended FedRAMP Rules for Class A

Providers seeking a Class A FedRAMP Certification SHOULD address the following additional recommended FedRAMP Class A rules (if applicable):

SHOULDEvidence required

FRC-CSF-ACP

Assign Control Parameters

Providers MUST assign all organization-defined control parameters, following FedRAMP Rev5 Controls Guidance, and ensure that all control parameter assignments are documented in the Security Decision Record (SDR).

MUSTEvidence required

FRC-CSF-BSL

FedRAMP Rev5 Baselines

Class B

Providers seeking FedRAMP Rev5 Class B Certification MUST include at least the following NIST SP 800-53 Rev. 5 controls in their Security Decision Record:

Class C

Providers seeking FedRAMP Rev5 Class C Certification MUST include at least the following NIST SP 800-53 Rev. 5 controls in their Security Decision Record:

Class D

Providers seeking FedRAMP Rev5 Class D Certification MUST include at least the following NIST SP 800-53 Rev. 5 controls in their Security Decision Record:

MUSTEvidence required

FRC-CSF-FFG

Follow FedRAMP Rev5 Controls Guidance

Providers MUST follow FedRAMP Rev5 Controls Guidance for the implementation and documentation of all applicable controls.

MUSTEvidence required

FRC-CSF-RDY

FedRAMP Ready Conversion

Providers with FedRAMP Rev5 Ready status MUST convert to a FedRAMP Certification by whichever of the follow dates is later: the expiration of their annual assessment or November 17, 2026 (the legacy FedRAMP Ready status will be entirely removed on December 31, 2027).

The simplest conversion in most cases would be to a FedRAMP 20x Class A Certification.

Cloud services that do not wish to convert or do not meet conversion criteria will be renamed Legacy FedRAMP Ready and otherwise retired from FedRAMP Ready.

MUSTEvidence required

FRC-CSO-FCP

FedRAMP Certification Profile

Providers MUST identify a target FedRAMP Certification Profile and apply all relevant FedRAMP Practices to the cloud service offering.

Information resources (including third-party information resources) MAY vary by security category as appropriate to the type of information handled by or impacted by the information resource.

MUSTEvidence required

FRC-CSO-JSN

FedRAMP JSON Schemas

Providers MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule.

FedRAMP JSON schemas are designed to be lightweight and flexible to establish a minimum set of structured information while allowing providers to improve on the format and structure of the information as needed to meet their needs and the needs of their customers.

MUSTEvidence required

FRC-CSO-MRA

Maintain Responsibility and Accountability

Providers MUST maintain responsibility and accountability for the accuracy and completeness of all information in the FedRAMP Certification Package, especially when they engage a third party (such as an independent assessor, advisory service, or external tools) to supply information on their behalf.

MUSTEvidence required

FRC-CSO-PKG

FedRAMP Certification Package

Providers seeking a Certification MUST supply a complete FedRAMP Certification Package to FedRAMP for initial certification; the FedRAMP Certification Package MUST include at least the following information:

MUSTEvidence required

FRC-CSO-POP

Pick One Program Certification Type

Providers MUST NOT seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering; pick one type.

This rule does not prevent a provider from seeking and maintaining a FedRAMP Rev5 Agency Certification and a FedRAMP 20x Program Certification for the same cloud service offering, however, doing so is strongly discouraged due to the increased complexity and risk of confusion for all parties.

MUST NOTEvidence required

FRC-CSX-MAS

Application within MAS

Providers SHOULD apply ALL Key Security Indicators to ALL aspects of their cloud service offering that are within the FedRAMP Minimum Assessment Scope.

SHOULDEvidence required

FRC-CSX-MOT

Metrics Over Time for Key Security Indicators

Class B

Providers seeking 20x Class B Certification SHOULD supply historical metrics for Key Security Indicators.

For initial FedRAMP Certification, providers will need to have mechanisms in place and agree to meet this requirement in the event the cloud service has not been operating with related metrics available for the required period prior to applying for initial certification.

Class C

Providers seeking 20x Class C Certification MUST supply historical metrics including status from persistent validation over at least the past 6 months for all Key Security Indicators.

For initial FedRAMP Certification, providers will need to have mechanisms in place and agree to meet this requirement in the event the cloud service has not been operating with related metrics available for the required period prior to applying for initial certification.

Class D

Providers seeking 20x Class D Certification MUST provide historical metrics including status from persistent validation over at least the past 18 months for all Key Security Indicators.

For initial FedRAMP Certification, providers will need to have mechanisms in place and agree to meet this requirement in the event the cloud service has not been operating with related metrics available for the required period prior to applying for initial certification.

SHOULDEvidence required

FRC-CSX-VVK

Automated Verification and Validation of Key Security Indicators

Class B

Providers seeking 20x Class B Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 1 automated method for each Key Security Indicator.

Class C

Providers seeking 20x Class C Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 2 automated methods for each Key Security Indicator.

Class D

Providers seeking 20x Class D Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 4 automated methods for each Key Security Indicator.

SHOULDEvidence required

FRC-CSX-VVR

Automated Verification and Validation of FedRAMP Rules

Class B

Providers seeking 20x Class B Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.

Different rules will be easy to automate for different providers, depending on the implementation, so FedRAMP generally leaves this implementation up to providers based on what makes the most sense for their own business and approach.

Class C

Providers seeking 20x Class C Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.

Different rules will be easy to automate for different providers, depending on the implementation, so FedRAMP generally leaves this implementation up to providers based on what makes the most sense for their own business and approach.

Class D

Providers seeking 20x Class D Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.

Different rules will be easy to automate for different providers, depending on the implementation, so FedRAMP generally leaves this implementation up to providers based on what makes the most sense for their own business and approach.

SHOULDEvidence required

Incident Evaluation and Communication · IEC

7 requirements, 0 verifiable by automated check.

IEC-CSO-AIR

Automated Incident Reporting

Providers SHOULD use automation to minimize human intervention in the process of reporting FedRAMP Reportable Incidents to all affected parties.

SHOULDEvidence required

IEC-CSO-DPR

Default PAIN Rating

Providers MUST treat FedRAMP Reportable Incidents as if they have a Potential Agency Impact N-rating (PAIN) of 5 UNLESS they promptly estimate the PAIN rating following the rule in IEC-CSO-EFI (Estimate Federal Impact).

MUSTEvidence required

IEC-CSO-EFI

Estimate Federal Impact

Providers SHOULD promptly estimate the likely adverse impact of an incident on agency customers to assign a Potential Agency Impact N-rating; this step is called Incident Rating.

All incidents must be assigned a default PAIN-5 as required by IEC-CSO-DPR (Default PAIN Rating) if this step is not completed.

SHOULDEvidence required

IEC-CSO-EFR

Evaluate FedRAMP Reportability

Providers MUST promptly evaluate incidents to determine if they affect confidentiality or integrity of federal customer data or are likely to affect confidentiality or integrity of federal customer data; such incidents are FedRAMP Reportable Incidents and must be reported following the FedRAMP Incident Evaluation and Communication rules.

MUSTEvidence required

IEC-CSO-FIR

Final Incident Report

Class B

Providers with Class B Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.

Class C

Providers with Class C Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.

Class D

Providers with Class D Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.

MUSTEvidence required

IEC-CSO-IIR

Initial Incident Report

Class B

Providers with Class B Certifications MUST responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:

Class C

Providers with Class C Certifications MUST responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:

Class D

Providers with Class D Certifications MUST responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:

MUSTEvidence required

IEC-CSO-OIR

Ongoing Incident Reports

Class B

Providers with Class B Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:

Class C

Providers with Class C Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:

Class D

Providers with Class D Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:

MUSTEvidence required

Independent Verification and Validation · IVV

13 requirements, 0 verifiable by automated check.

IVV-CSF-ACF

Assessment of Rev5 Controls with Findings

Providers MUST have Rev5 Controls with negative findings from the previous FedRAMP independent assessment included in the next FedRAMP independent assessment.

MUSTEvidence required

IVV-CSF-AIA

Annual Independent Assessments for Rev5

Class B

Providers with Rev5 Class B Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:

Class C

Providers with Rev5 Class C Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:

Class D

Providers with Rev5 Class D Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:

MUSTEvidence required

IVV-CSF-MCA

Mandatory Control Assessment

Providers MUST have all applicable Rev5 Controls included in FedRAMP independent assessments every 3 years but are not required to have all Rev5 Controls included in the same FedRAMP independent assessment.

Traditionally this has been done by reviewing a rotating selection of Rev5 Controls at each annual assessment, however this requirement is a ceiling and not a floor. See IVV-CSF-PCA (Preferred Control Assessment) for FedRAMP's recommended approach to Rev5 control assessments.

MUSTEvidence required

IVV-CSF-PCA

Preferred Control Assessment

Providers SHOULD include all applicable Rev5 Controls in each FedRAMP independent assessment.

SHOULDEvidence required

IVV-CSO-DUS

Document Use of Representative Samples

Providers MUST document and explain the use of representative samples during verification and validation when using representative samples as allowed by IVV-CSO-USR (Use Representative Samples).

MUSTEvidence required

IVV-CSO-FIA

FedRAMP Independent Assessments

Class B

Providers with Class B Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.

The first such completed assessment is typically called an "initial assessment" while following assessments are called "annual assessments."

The specific requirements for independent verification and validation assessments are documented by the FedRAMP Certification Class and Type.

The option for assessment by FedRAMP directly is limited to cloud services that are explicitly prioritized by FedRAMP, in consultation with the FedRAMP Board and the federal Chief Information Officers Council; this is _extremely_ rare.

FedRAMP Recognized independent assessment services are listed on the FedRAMP Marketplace.

Class C

Providers with Class C Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.

The first such completed assessment is typically called an "initial assessment" while following assessments are called "annual assessments."

The specific requirements for independent verification and validation assessments are documented by the FedRAMP Certification Class and Type.

The option for assessment by FedRAMP directly is limited to cloud services that are explicitly prioritized by FedRAMP, in consultation with the FedRAMP Board and the federal Chief Information Officers Council; this is _extremely_ rare.

FedRAMP Recognized independent assessment services are listed on the FedRAMP Marketplace.

Class D

Providers with Class D Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.

The first such completed assessment is typically called an "initial assessment" while following assessments are called "annual assessments."

The specific requirements for independent verification and validation assessments are documented by the FedRAMP Certification Class and Type.

The option for assessment by FedRAMP directly is limited to cloud services that are explicitly prioritized by FedRAMP, in consultation with the FedRAMP Board and the federal Chief Information Officers Council; this is _extremely_ rare.

FedRAMP Recognized independent assessment services are listed on the FedRAMP Marketplace.

MUSTEvidence required

IVV-CSO-ICP

Inclusion in Certification Package

Providers MUST supply the results of FedRAMP independent assessments in their FedRAMP Certification Package without inappropriate modification.

Inappropriate modification in this context means changing the underlying intent/etc. of the content provided by the independent assessment service - the content itself may be modified for presentation, formatting, etc. as needed.

This rule is related to IVV-IAS-VIP (Verify Inclusion in Certification Package).

MUSTEvidence required

IVV-CSO-RAA

Receiving Assessor Advice

Providers MAY ask for and accept advice from their assessor during assessment regarding techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their verification, validation and reporting procedures, UNLESS doing so is likely to compromise the objectivity and integrity of the assessment.

MAYEvidence required

IVV-CSO-SEE

Supply Evidence of Effectiveness

Providers MUST supply evidence to all necessary assessors of the effectiveness of the measures that have been implemented to meet FedRAMP Practices; this evidence is the result of validation.

For example, after verifying that firewalls are configured to block traffic following IVV-CSO-SEI (Supply Evidence of Implementation), the provider would validate that traffic is actually being blocked and supply evidence of that validation to assessors (such as by allowing them to see metrics on the traffic that is blocked vs not).

MUSTEvidence required

IVV-CSO-SEI

Supply Evidence of Implementation

Providers MUST supply evidence to all necessary assessors of the implementation of the measures that have been documented to meet FedRAMP Practices; this evidence is the result of verification.

For example, if the documentation says that firewall rules are used to block traffic then the cloud service provider would verify that firewall rules are in place to block traffic and supply that evidence to assessors (preferably by allowing them to see how firewall configurations are deployed from a source of truth).

MUSTEvidence required

IVV-CSO-STE

Supply Technical Explanations

Providers SHOULD supply all necessary assessors with technical explanations, demonstrations, and other relevant supporting information about the technical capabilities they employ to address FedRAMP rules; this SHOULD be supplied as necessary to ensure the assessor can effectively complete verification and validation.

SHOULDEvidence required

IVV-CSO-USR

Use Representative Samples

Providers MAY use representative samples as appropriate during verification and validation.

Many modern cloud services using effective automation do not need to use representative sampling and are capable of persistently verifying and validating the majority of their security measures automatically.

MAYEvidence required

IVV-CSX-AIA

Annual Independent Assessments for 20x

Class B

Providers with 20x Class B Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.

Class C

Providers with 20x Class C Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.

Class D

Providers with 20x Class D Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.

MUSTEvidence required

Minimum Assessment Scope · MAS

5 requirements, 0 verifiable by automated check.

MAS-CSO-FLO

Information Flows and Security Categories

Providers MUST clearly identify, document, and explain information flows and security categories for ALL information resources or sets of information resources in the cloud service offering.

Information resources (including third-party information resources) MAY vary by security category as appropriate to the type of information handled by or impacted by the information resource.

MUSTEvidence required

MAS-CSO-IIR

Identify Information Resources

Providers MUST identify a set of information resources to assess for FedRAMP Certification that includes all information resources that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering; this set of information resources is the cloud service offering.

Certain categories of cloud computing products and services are specified as entirely outside the scope of FedRAMP by the Director of the Office of Management and Budget. All such products and services are therefore not included in the cloud service offering for FedRAMP. For more, see https://fedramp.gov/scope.

Software produced by cloud service providers that is delivered separately for installation on agency systems and not operated in a shared responsibility model (typically including agents, application clients, mobile applications, etc. that are not fully managed by the cloud service provider) is not a cloud computing product or service and is entirely outside the scope of FedRAMP under the FedRAMP Certification Act. All such software is therefore not included in the cloud service offering for FedRAMP. For more, see https://fedramp.gov/scope.

All aspects of the cloud service offering are determined and maintained by the cloud service provider in accordance with related FedRAMP Certification rules and documented by the cloud service provider in their FedRAMP Certification Package.

MUSTEvidence required

MAS-CSO-MDI

Metadata Inclusion

Providers MUST include metadata (including metadata about federal customer data) in the Minimum Assessment Scope ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES.

MUSTEvidence required

MAS-CSO-SUP

Supplemental Information

Providers MAY include additional materials about other information resources that are not part of the cloud service offering in a FedRAMP Certification Package supplement; these resources will not be FedRAMP Certified and MUST be clearly marked and separated from the cloud service offering.

This is intended to allow inclusion of things like security materials for apps, supplemental marketing collateral, and other information that is not part of the cloud service offering but may be useful to agencies.

MAYEvidence required

MAS-CSO-TPR

Third-Party Information Resources

Providers MUST address the potential impact to federal customer data from third-party information resources used by the cloud service offering, ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES, by documenting the following information about each applicable third-party information resource:

MUSTEvidence required

Marketplace Listing · MKT

5 requirements, 0 verifiable by automated check.

MKT-CSO-MLR

Marketplace Listing Requirements

Providers MUST address at least these FedRAMP rules to apply for a new FedRAMP Marketplace listing OR to request updates to an existing listing:

MUSTEvidence required

MKT-CSO-PML

Provider Marketplace Listing Requests

Providers MUST notify FedRAMP using the FedRAMP Marketplace Providing Listing Request Form to request a listing in the FedRAMP Marketplace.

FedRAMP does not accept applications for a FedRAMP Marketplace Listing via email!

MUSTEvidence required

MKT-IIP-AGU

Agency Use Cases

Providers MUST demonstrate that a cloud service offering is intended for one of the following use cases:

FedRAMP will not list products or services that are outside the explicit statutory scope of FedRAMP; See MKT-FRP-SOF (Scope of FedRAMP).

Services used by private companies to meet other compliance requirements (such as CMMC) that do not also meet one of the above use cases are outside the scope of FedRAMP.

MUSTEvidence required

MKT-IIP-DCP

Demonstrating Continuous Progress

Providers MUST demonstrate continuous progress towards a FedRAMP Certification, documented in their Trust Center or website and updated at least quarterly; progress is measured by the provider against documented goals and milestones.

This is an opportunity for a business to showcase its goals and progress, and should be seen as a marketing and customer experience challenge instead of a compliance challenge.

MUSTEvidence required

MKT-IIP-DLA

Deadline for Assessment

Providers MUST demonstrate that an assessment for a FedRAMP Certification Class B, C, or D has been scheduled within 2 years of initial listing in the Initial Implementation Phase.

If this is not followed:

MUSTEvidence required

Secure Configuration Guide · SCG

9 requirements, 0 verifiable by automated check.

SCG-CSO-AUP

Use Instructions

Providers MUST include instructions in the FedRAMP Certification Package that explain how to obtain and use the Secure Configuration Guide.

These instructions may appear in a variety of ways; it is up to the provider to do so in the most appropriate and effective ways for their specific customer needs.

MUSTEvidence required

SCG-CSO-PUB

Public Secure Configuration Guidance

Providers SHOULD make the Secure Configuration Guide available publicly.

SHOULDEvidence required

SCG-CSO-RSC

Recommended Secure Configuration

Providers MUST create, maintain, and make available recommendations for securely configuring their cloud services (the Secure Configuration Guide) that includes at least the following information:

These rules refer to this guidance as a Secure Configuration Guide but cloud service providers may make this guidance available in various appropriate forms that provide the best customer experience.

This guidance should explain how top-level administrative accounts and privileged accounts are named and referred to in the cloud service offering.

MUSTEvidence required

SCG-CSO-SDF

Secure Defaults

Providers SHOULD set all settings to their recommended secure defaults for top-level administrative accounts and privileged accounts when initially provisioned.

SHOULDEvidence required

SCG-ENH-API

API Capability

Providers SHOULD offer the capability to view and adjust security settings via an API or similar capability.

SHOULDEvidence required

SCG-ENH-CMP

Comparison Capability

Providers SHOULD offer the capability to compare all current settings for top-level administrative accounts and privileged accounts to the recommended secure defaults.

SHOULDEvidence required

SCG-ENH-EXP

Export Capability

Providers SHOULD offer the capability to export all security settings in a machine-readable format.

SHOULDEvidence required

SCG-ENH-MRG

Machine-Readable Guidance

Providers SHOULD also provide the Secure Configuration Guide in a machine-readable format that can be used by customers or third-party tools to compare against current settings.

SHOULDEvidence required

SCG-ENH-VRH

Versioning and Release History

Providers SHOULD provide versioning and a release history for recommended secure default settings for top-level administrative accounts and privileged accounts as they are adjusted over time.

SHOULDEvidence required

Significant Change Notification · SCN

16 requirements, 0 verifiable by automated check.

SCN-ADP-NTF

Notification Requirements

Providers MUST notify all necessary parties within 10 business days after finishing adaptive changes, also including the following information:

Activities that match the adaptive significant change type are a frequent and normal part of iteratively improving a service by deploying new functionality or modifying existing functionality in a way that is typically transparent to customers and does not introduce significant new security risks.

In general, most changes that do not happen regularly will be adaptive changes. This change type deliberately covers a wide range of activities in a way that requires assessment and consideration.

MUSTEvidence required

SCN-CSO-ARI

Additional Relevant Information

Providers MAY include additional relevant information in Significant Change Notifications.

This allows providers to convey whatever additional information they think is relevant without worrying about negative consequences from not following an exact template.

MAYEvidence required

SCN-CSO-EMG

Emergency Changes

Providers MAY execute significant changes (including transformative changes) during an emergency or incident without following the Significant Change Notification rules in advance. In such emergencies, providers MUST follow all relevant procedures, notify all necessary parties, retroactively provide all Significant Change Notification materials, and complete appropriate assessment after the incident.

Procedures for emergency changes should be documented in the FedRAMP Certification Package.

MAYEvidence required

SCN-CSO-EVA

Evaluate Changes

Providers MUST evaluate all potential significant changes to determine the type of significant change and follow the appropriate Significant Change Notification rules.

MUSTEvidence required

SCN-CSO-HIS

Historical Notifications

Providers MUST keep 12 months of historical Significant Change Notifications available with their FedRAMP Certification Data.

MUSTEvidence required

SCN-CSO-HRM

Human and Machine-Readable Notifications

Providers MUST make ALL Significant Change Notifications and related audit records available in human-readable and JSON formats.

MUSTEvidence required

SCN-CSO-INF

Required Information

Providers MUST include at least the following information in Significant Change Notifications:

Structure of the information may vary depending on how the provider tracks this internally.

MUSTEvidence required

SCN-CSO-MAR

Maintain Audit Records

Providers MUST maintain auditable records of the significant change evaluation activities required by SCN-CSO-EVA (Evaluate Changes) and make them available to FedRAMP as requested.

These audit records must be available to FedRAMP on request; these records do not need to be included in the FedRAMP Certification Package by default and do not need to be emailed to FedRAMP continuously.

MUSTEvidence required

SCN-CSO-NOM

Notification Mechanisms

Providers MAY notify necessary parties in a variety of ways as long as the mechanism for notification is clearly documented in the FedRAMP Certification Package and easily accessible.

The sharing mechanism should be designed based on the needs of the provider and their customers and may vary between providers.

The default sharing mechanism for most providers during the SCN beta was to send an email to agency customers and upload a copy of the notification to the provider's secure sharing location.

MAYEvidence required

SCN-RTR-NNR

No Notification Requirements

Providers SHOULD NOT make formal Significant Change Notifications for routine recurring changes; this type of change is exempted from notification requirements.

Activities that match the routine recurring significant change type are performed regularly and routinely by cloud service providers to address flaws or vulnerabilities, address incidents, and generally perform the typical maintenance and service delivery changes expected during day-to-day operations.

These changes leverage mature processes and capabilities to identify, mitigate, and remediate risks as part of the change. They are often entirely automated and may occur without human intervention, even though they have an impact on security of the service.

If the activity does not occur regularly and routinely then it cannot be a significant change of this type (e.g., replacing all physical firewalls to remediate a vulnerability is obviously not regular or routine).

SHOULD NOTEvidence required

SCN-TRF-NAF

Notification After Finishing

Providers MUST notify all necessary parties within 5 business days after finishing transformative changes, including updates to all previously sent information.

MUSTEvidence required

SCN-TRF-NAV

Notification After Verification

Providers MUST notify all necessary parties within 5 business days after completing the verification, assessment, and/or validation of transformative changes, also including the following information:

MUSTEvidence required

SCN-TRF-NFP

Notification of Final Plans

Providers MUST notify all necessary parties of final plans for transformative changes at least 10 business days before starting transformative changes, including updates to all previously sent information.

MUSTEvidence required

SCN-TRF-NIP

Notification of Initial Plans

Providers MUST notify all necessary parties of initial plans for transformative changes at least 30 business days before starting transformative changes, including a summary of any likely security impacts or changes in risk.

MUSTEvidence required

SCN-TRF-TPR

Third-Party Review

Providers SHOULD engage a third-party assessor to review the scope and impact of the planned change before starting transformative changes if human validation is necessary; such reviews SHOULD be limited to security decisions that require human validation.

Activities that match the transformative significant change type are rare for a cloud service offering, adjusted for the size, scale, and complexity of the service. Small cloud service offerings may go years without transformative changes, while hyperscale providers may release multiple transformative changes per year.

SHOULDEvidence required

SCN-TRF-UPD

Update Documentation

Providers MUST publish updated service documentation and other materials to reflect transformative changes within 30 business days after finishing transformative changes.

This requirement is focused on service documentation like user guides, information listed in the marketplace, and other such materials; it does not require updating the system security plan or FedRAMP Certification Package.

MUSTEvidence required

Security Decision Record · SDR

5 requirements, 0 verifiable by automated check.

SDR-CSF-CTF

Rev5 Controls

Providers MUST also include short and simple high-level summaries of at least the following for each applicable Rev5 Control:

MUSTEvidence required

SDR-CSO-FRR

FedRAMP Rules

Providers MUST supply a Security Decision Record, in both human-readable and JSON formats, that includes at least all of the following information for each applicable FedRAMP rule:

MUSTEvidence required

SDR-CSO-MTD

Security Decision Record Metadata

Providers MUST also include the following basic metadata in their Security Decision Record:

MUSTEvidence required

SDR-CSX-KMT

Key Security Indicator Metrics

Class B

Providers with 20x Class B Certifications MUST also include historical metrics in their Security Decision Record, supplying at least the following information for each applicable Key Security Indicator:

Class C

Providers with 20x Class C Certifications MUST also include historical metrics in their Security Decision Record, supplying at least the following information for each applicable Key Security Indicator:

Class D

Providers with 20x Class D Certifications MUST significantly supersede the minimum requirements for lower Classes, with specifics to be set during the 20x Phase 4 Pilot.

MUSTEvidence required

SDR-CSX-KSI

Key Security Indicators

Providers MUST also include short and simple high-level summaries of at least the following for each applicable Key Security Indicator:

MUSTEvidence required

Vulnerability Detection and Response · VDR

18 requirements, 0 verifiable by automated check.

VDR-CSO-ADT

Automate Detection

Providers SHOULD use automated services to improve and streamline vulnerability detection and response.

SHOULDEvidence required

VDR-CSO-AKE

Avoid KEVs

Providers SHOULD NOT deploy or otherwise activate new machine-based information resources with Known Exploited Vulnerabilities.

SHOULD NOTEvidence required

VDR-CSO-DAC

Detect After Changes

Providers SHOULD automatically perform vulnerability detection on representative samples of new or significantly changed information resources.

SHOULDEvidence required

VDR-CSO-DET

Vulnerability Detection

Providers MUST systematically, persistently, and promptly discover and identify vulnerabilities within their cloud service offering using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities; this process is called vulnerability detection. Vulnerability detection includes persistently verifying and validating that information resources and processes are operating as intended and documented for FedRAMP Practices.

FedRAMP's vulnerability detection (and response) rules are intended to set modern expectations for maintaining the security of a cloud service. Historical FedRAMP guidance on vulnerability scanning or continuous monitoring generally focused only on CVE-type vulnerabilities while leaving other types of vulnerabilities and exposures unaddressed.

Providers are encouraged to leverage their existing holistic security review, architecture review, and similar processes to meet these requirements. FedRAMP strongly discourages providers from implementing separate vulnerability detection and response processes for FedRAMP reporting that are operated by independent compliance branches unless these processes are consuming data directly from the areas of the cloud service that actively maintain it.

MUSTEvidence required

VDR-CSO-DFR

Design For Resilience

Providers SHOULD make design and architecture decisions for their cloud service offering that mitigate the risk of vulnerabilities by default AND decrease the risk and complexity of vulnerability detection and response.

SHOULDEvidence required

VDR-CSO-FAV

Failures Are Vulnerabilities

Providers MUST treat problems or failures with their vulnerability detection and response processes as vulnerabilities.

MUSTEvidence required

VDR-CSO-MSP

Maintain Security

Providers SHOULD NOT weaken the security of information resources to facilitate vulnerability scanning, detection, or assessment activities.

SHOULD NOTEvidence required

VDR-CSO-RES

Vulnerability Response

Providers MUST systematically, persistently, and promptly track, evaluate, monitor, mitigate, remediate, assess exploitation of, report, and otherwise manage all detected vulnerabilities within their cloud service offering; this process is called vulnerability response.

If it is not possible to fully mitigate vulnerabilities or remediate vulnerabilities, providers SHOULD instead partially mitigate vulnerabilities promptly, progressively, and persistently.

FedRAMP does not use the terms "mitigation" and "remediation" interchangeably. Mitigation is the process of reducing the risk and impact of a vulnerability through partial mitigation and even full mitigation; remediation is the process of entirely eliminating the vulnerability. A fully mitigated vulnerability will still exist (with negligible risk) until it has been remediated. This separation is based on the plain language definitions of these words.

Please refer to FedRAMP Definitions for strict interpretation in the FedRAMP context.

MUSTEvidence required

VDR-CSO-SIR

Sampling

Providers MAY sample effectively identical information resources, especially machine-based information resources, when performing vulnerability detection UNLESS doing so would decrease the efficiency or effectiveness of vulnerability detection.

MAYEvidence required

VDR-TFR-KEV

Remediate KEVs

Providers SHOULD remediate Known Exploited Vulnerabilities according to the due dates in the CISA Known Exploited Vulnerabilities Catalog (even if the vulnerability has been fully mitigated) as required by CISA Binding Operational Directive (BOD) 26-04 or any successor guidance from CISA.

SHOULDEvidence required

VDR-TFR-MVF

Persistent Machine Verification and Validation for Rev5

Class B

Providers of FedRAMP Rev5 Class B offerings SHOULD verify and validate the status of machine-based information resources at least once every month.

Class C

Providers of FedRAMP Rev5 Class C offerings MUST verify and validate the status of machine-based information resources at least once every month.

Class D

Providers of FedRAMP Rev5 Class D offerings MUST verify and validate the status of machine-based information resources at least once every month.

SHOULDEvidence required

VDR-TFR-MVX

Persistent Machine Verification and Validation for 20x

Class B

Providers of FedRAMP 20x Class B offerings MUST verify and validate the status of machine-based information resources at least once every 7 days.

Class C

Providers of FedRAMP 20x Class C offerings MUST verify and validate the status of machine-based information resources at least once every 3 days.

MUSTEvidence required

VDR-TFR-NMV

Non-Machine Verification and Validation

Providers MUST verify and validate the status of non-machine-based information resources at least once every 3 months.

MUSTEvidence required

VDR-TFR-PCD

Persistently Complete Detection

Class B

Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.

Class C

Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.

Class D

Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.

SHOULDEvidence required

VDR-TFR-PDD

Persistent Drift Detection

Class B

Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every month.

Class C

Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 14 days.

Class D

Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 7 days.

SHOULDEvidence required

VDR-TFR-PSD

Persistent Sample Detection

Class B

Providers with Class B Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 7 days.

Class C

Providers with Class C Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 3 days.

Class D

Providers with Class D Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once per day.

SHOULDEvidence required

VDR-TFR-PVR

Mitigation and Remediation Expectations

Class B

Providers with Class B Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:

Class C

Providers with Class C Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:

Class D

Providers with Class D Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the maximum timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:

SHOULDEvidence required

VDR-TFR-RMN

Remaining Vulnerabilities

Providers SHOULD mitigate or remediate remaining vulnerabilities during routine operations as determined necessary by the provider.

SHOULDEvidence required

Vulnerability Evaluation and Reporting · VER

19 requirements, 0 verifiable by automated check.

VER-EVA-AIA

Assume It's Automatable

Providers MUST assume the exploitation of vulnerabilities can be automated UNLESS they have evidence proving otherwise.

MUSTEvidence required

VER-EVA-EFA

Evaluation Factors

Providers SHOULD consider at least the following factors when considering the context of the cloud service offering to evaluate detected vulnerabilities:

SHOULDEvidence required

VER-EVA-EFP

Evaluate False Positives

Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are false positive vulnerabilities.

SHOULDEvidence required

VER-EVA-EIR

Evaluate Internet-Reachability

Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are internet-reachable vulnerabilities.

FedRAMP focuses on internet-reachable (rather than internet-accessible) to ensure that any service that might receive a payload from the internet is prioritized if that service has a vulnerability that can be triggered by processing the data in the payload.

The simplest way to prevent exploitation of internet-reachable vulnerabilities is to intercept, inspect, filter, sanitize, reject, or otherwise deflect triggering payloads before they are processed by the vulnerable resource; once this prevention is in place the vulnerability should no longer be considered an internet-reachable vulnerability.

A classic example of an internet-reachable vulnerability on systems that are not typically internet-accessible is [SQL injection](https://en.wikipedia.org/wiki/SQL_injection), where an application stack behind a load balancer and firewall with no ability to route traffic to or from the internet can receive a payload indirectly from the internet that triggers the manipulation or compromise of data in a database that can only be accessed by an authorized connection from the application server on a private network.

Another simple example is the infamous Log4Shell (https://en.wikipedia.org/wiki/Log4Shell) vulnerability from 2021, where exploitation was possible via vulnerable internet-reachable resources deep in the application stack that were often not internet-accessible themselves.

MUSTEvidence required

VER-EVA-ELX

Evaluate Exploitability

Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are likely exploitable vulnerabilities.

The simple reality is that most traditional vulnerabilities discovered by scanners or during assessment are not likely to be exploitable; exploitation typically requires an unrealistic set of circumstances that will not occur during normal operation. The likelihood of exploitation will vary depending on so many factors that FedRAMP will not recommend a specific framework for approaching this beyond these rules.

The proof, ultimately, is in the pudding - providers who regularly evaluate vulnerabilities as not likely exploitable without careful consideration are more likely to suffer from an adverse impact where the root cause was an exploited vulnerability that was improperly evaluated. If done recklessly or deliberately, such actions will have a negative impact on a provider's FedRAMP Certification.

MUSTEvidence required

VER-EVA-EPA

Estimate Potential Agency Impact

Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to estimate the potential agency impact of exploitation on government customers AND assign one of the following Potential Agency Impact N-ratings (PAIN):

MUSTEvidence required

VER-EVA-GRV

Group Vulnerabilities

Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to identify logical groupings of affected information resources that may improve the efficiency and effectiveness of vulnerability response by consolidating further activity; FedRAMP Vulnerability Detection and Response rules are then applied to these consolidated groupings of vulnerabilities instead of each individual detected instance.

SHOULDEvidence required

VER-RPT-AVI

Accepted Vulnerability Info

Providers MUST include the following information on accepted vulnerabilities when reporting on vulnerability detection and response activity:

MUSTEvidence required

VER-RPT-HLO

High-Level Overviews

Providers SHOULD include high-level overviews of ALL vulnerability detection and response activities conducted during this period for the cloud service offering; this includes vulnerability disclosure programs, bug bounty programs, penetration testing, assessments, etc.

SHOULDEvidence required

VER-RPT-NID

Responsible Disclosure

Providers MUST NOT irresponsibly disclose specific sensitive information about vulnerabilities that would likely lead to exploitation, but MUST disclose sufficient information for informed risk-based decision-making to all necessary parties.

This requirement will be superseded in the event of formal action related to an investigation or corrective action plan.

MUST NOTEvidence required

VER-RPT-PER

Persistent Reporting

Providers MUST report vulnerability detection and response activity (including persistent verification and validation) to all necessary parties persistently, summarizing ALL activity since the previous report; these reports are FedRAMP Certification Data and are subject to FedRAMP Certification Data Sharing rules.

MUSTEvidence required

VER-RPT-RPD

Responsible Public Disclosure

Providers MAY responsibly disclose vulnerabilities publicly or with other parties if the provider determines doing so will NOT likely lead to exploitation.

MAYEvidence required

VER-RPT-VDT

Vulnerability Details

Providers MUST include the following information (if applicable) on detected vulnerabilities when reporting on vulnerability detection and response activity, UNLESS it is an accepted vulnerability:

MUSTEvidence required

VER-TFR-EVU

Evaluate Vulnerabilities Quickly

Class B

Providers with Class B Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 7 days of detection.

Class C

Providers with Class C Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 5 days of detection.

Class D

Providers with Class D Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 2 days of detection.

SHOULDEvidence required

VER-TFR-IRI

Internet-Reachable Incidents

Class B

Providers with Class B Certifications MAY treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.

Class C

Providers with Class C Certifications SHOULD treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.

Class D

Providers with Class D Certifications SHOULD treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.

MAYEvidence required

VER-TFR-MAV

Mark Accepted Vulnerabilities

Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability.

MUSTEvidence required

VER-TFR-MHR

Monthly Activity Report

Providers MUST report vulnerability detection and response activity to all necessary parties in a consistent format that is human readable at least monthly.

MUSTEvidence required

VER-TFR-MRH

Historical Activity

Class B

Providers with Class B Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every month.

Class C

Providers with Class C Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 14 days.

Class D

Providers with Class D Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 7 days.

SHOULDEvidence required

VER-TFR-NRI

Non-Internet-Reachable Incidents

Class B

Providers with Class B Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.

Class C

Providers with Class C Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.

Class D

Providers with Class D Certifications SHOULD treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.

MAYEvidence required

Stop assembling this by hand.

Zenibit tracks these requirements against your live infrastructure and publishes a trust center agencies can verify themselves. Get in touch.