FedRAMP rules
Every FRR requirement, by ruleset, with its force, its corrective actions, and the class variations the rulebook buries.
FedRAMP Requirements are grouped into rulesets, each with its own effective dates. Force is load-bearing: MUST is an obligation, SHOULD is an expectation you can be asked to justify departing from, and MAY is permission. Where a requirement is worded differently for different impact classes, every wording is shown with the classes it applies to.
Addressing FedRAMP Communication · AFC
8 requirements, 0 verifiable by automated check.
Acknowledge Receipt
Providers SHOULD promptly and automatically acknowledge the receipt of messages received from FedRAMP in their FedRAMP Security Inbox.
Complete Required Actions
Providers MUST complete the required actions in Emergency or Emergency Test designated messages sent by FedRAMP within the timeframe included in the message.
Timeframes may vary by FedRAMP Certification class.
Emergency Message Routing
Providers MUST route Emergency designated messages sent by FedRAMP to a senior security official for their awareness.
Senior security officials are determined by the provider.
Important Message Actions
Providers SHOULD complete the required actions in Important designated messages sent by FedRAMP within the timeframe specified in the message.
Timeframes may vary by FedRAMP Certification class.
Maintain a FedRAMP Security Inbox
Providers MUST establish and maintain an email address to receive messages from FedRAMP; this inbox is a FedRAMP Security Inbox (FSI).
Unless otherwise notified, FedRAMP will use the listed Security Email on the Marketplace for these notifications.
If a provider establishes a new inbox in reaction to this guidance that is different from the Security Email then they must follow the AFC-CSO-NOC (Notification of Changes) rules to notify FedRAMP.
Notification of Changes
Providers MUST immediately notify FedRAMP of any changes to the email address for their FedRAMP Security Inbox.
Receive Email Without Disruption
Providers MUST receive and react to email messages from FedRAMP without disruption and without requiring additional actions from FedRAMP.
This requirement is intended to prevent cloud service providers from requiring FedRAMP to complete a CAPTCHA, log into a customer portal, or otherwise take service-specific actions that might prevent the security team from receiving the message.
Trust @fedramp.gov and @gsa.gov
Providers MUST treat any email originating from an @fedramp.gov or @gsa.gov email address as if it was sent from FedRAMP by default; if such a message is confirmed to originate from someone other than FedRAMP then the FedRAMP Security Inbox rules no longer apply.
Collaborative Continuous Monitoring · CCM
17 requirements, 0 verifiable by automated check.
Anonymized Feedback Summary
Providers MUST supply an anonymized and desensitized summary of the feedback, questions, and answers about each Ongoing Certification Report as an addendum to the Ongoing Certification Report OR in the next Ongoing Certification Report.
This is intended to encourage sharing of information and decrease the burden on the cloud service provider - providing this summary will reduce duplicate questions from agencies and ensure FedRAMP has access to this information. It is generally in the provider's interest to update this addendum frequently throughout the quarter.
Report Availability
Providers MUST supply an Ongoing Certification Report to all necessary parties every 3 months, covering the entire period since the previous summary, in a consistent format that is human readable; this report MUST include high-level summaries of at least the following information:
- Changes to FedRAMP Certification Data
- Planned changes to FedRAMP Certification Data during at least the next 3 months
- Accepted vulnerabilities
- Transformative changes
- Updated recommendations or best practices for security, configuration, usage, or similar aspects of the cloud service offering
- A list of all agencies that are directly using the product
- FedRAMP Reportable Incidents or an attestation that no such incidents occurred
- Lessons learned and changes planned or made as a result of FedRAMP Reportable Incidents (if such occurred)
Feedback Mechanism
Providers MUST supply an asynchronous mechanism for all necessary parties to provide feedback or ask questions about each Ongoing Certification Report.
This could be email by default but providers are encouraged to consider something more interactive as appropriate.
Limit Sensitive Information
Providers MUST NOT irresponsibly disclose sensitive information in an Ongoing Certification Report that would likely have an adverse effect on the cloud service offering.
Next Report Date
Providers MUST supply the target date for their next Ongoing Certification Report with other public FedRAMP Certification Data.
Responsible Public Certification Report Sharing
Providers MAY responsibly supply some or all of the information an Ongoing Certification Report to the public or other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.
Spread Out Reports
Providers SHOULD establish a regular 3 month cycle for Ongoing Certification Reports that is spread out from the beginning, middle, or end of each quarter.
This recommendation is intended to discourage hundreds of cloud service providers from releasing their Ongoing Certification Reports during the first or last week of each quarter because that is the easiest way for a single provider to track this deliverable; the result would overwhelm agencies with many cloud services. Widely used cloud service providers are encouraged to work with their customers to identify ideal timeframes for this cycle.
Additional Content
Providers SHOULD supply additional information in Quarterly Reviews that the provider determines is of interest, use, or otherwise relevant to agencies.
Quarterly Review Meeting
Class B
Providers with Class B Certifications SHOULD host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.
Class C
Providers with Class C Certifications MUST host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.
Class D
Providers with Class D Certifications MUST host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.
No Irresponsible Disclosure
Providers MUST NOT irresponsibly disclose sensitive information in a Quarterly Review that would likely have an adverse effect on the cloud service offering.
Next Review Date
Providers MUST publicly supply the target date for their next Quarterly Review with other public FedRAMP Certification Data.
Meeting Registration Info
Providers MUST supply either a registration link or a downloadable calendar file with meeting information for Quarterly Reviews to all necessary parties.
Restrict Third Parties
Providers SHOULD NOT invite third parties to attend Quarterly Reviews intended for agencies unless they have specific relevance.
This is because agencies are less likely to actively participate in meetings with third parties; the cloud service provider's independent assessor should be considered relevant by default.
Record/Transcribe Reviews
Providers SHOULD record or transcribe Quarterly Reviews and supply them to all necessary parties.
Schedule Around Reports
Providers SHOULD regularly schedule Quarterly Reviews to occur at least 3 business days after releasing an Ongoing Certification Report AND within 10 business days of such release.
Share Content Responsibly
Providers MAY responsibly supply content prepared for a Quarterly Review to the public or other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.
Share Recordings Responsibly
Providers MAY responsibly supply recordings or transcriptions of Quarterly Reviews to the public or other parties ONLY if the provider removes all agency information (comments, questions, names, etc.) AND determines doing so will NOT likely have an adverse effect on the cloud service offering.
Certification Data Sharing · CDS
21 requirements, 0 verifiable by automated check.
Trust Center Migration
Providers MUST notify all necessary parties when migrating to a trust center and MUST provide information in their existing USDA Connect Community Portal secure folders explaining how to use the trust center to obtain FedRAMP Certification Data.
Availability Reporting
Class B
Providers with Class B Certifications MUST maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service MUST be available even if the primary cloud service offering is unavailable.
This service may be separate from the trust center.
Class C
Providers with Class C Certifications MUST maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service MUST be available even if the primary cloud service offering is unavailable.
This service may be separate from the trust center.
Class D
Providers with Class D Certifications MUST maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service MUST be available even if the primary cloud service offering is unavailable.
This service may be separate from the trust center.
Consistency Between Formats
Providers MUST use automation to ensure information remains consistent between human-readable and machine-readable formats when FedRAMP Certification Data is provided in both formats.
Always Include FedRAMP ID
Providers MUST always include the FedRAMP ID of the related cloud service offering in all FedRAMP Certification Data once assigned, including all reports, notifications, and other communication that results from FedRAMP rules.
The FedRAMP ID is supplied by FedRAMP after a cloud service offering is registered to be listed on the FedRAMP Marketplace - providers will need to use a placeholder until the FedRAMP ID is assigned.
Many providers have multiple cloud service offerings or use internal names that don't align to public materials; using the FedRAMP ID ensures we can easily align the communication with a specific cloud service offering.
FedRAMP Certification Reports
Providers MUST include FedRAMP Certification Reports with their FedRAMP Certification Data without inappropriate modifications, and make such reports available within 2 weeks of receiving the materials from FedRAMP.
FedRAMP provides Certification Reports for all cloud service offerings following the Program Certification path as part of the initial and ongoing FedRAMP Certification process, and may provide Certification Reports for cloud service offerings following the Agency Certification path.
Historical FedRAMP Certification Data
Providers MUST supply snapshots of FedRAMP Certification Data aligned to Ongoing Certification Reports to all necessary parties; these snapshots MUST be available for the duration of FedRAMP Certification.
Historical snapshots do not need to be reconstructed for periods before the provider's first Ongoing Certification Report, but should be maintained for all subsequent Ongoing Certification Reports.
Include Relevant Policies
Providers MUST supply all relevant policies and procedures in the FedRAMP Certification Data, including a human-readable and machine-readable reference that explains at least the following about each included policy and procedure:
- Name of policy or procedure
- Name of file, document, web page, etc.
- Brief summary of policy or procedure
- Word count of document
- Current version
- Date of last update
- Related FedRAMP Practices (if applicable)
Per-Service Certification Materials
Class B
Providers with Class B Certifications MAY supply per-service FedRAMP Certification materials.
Providers determine what they consider to be separate services, based on maximizing the customer experience for agencies who may only adopt some services and not others.
Providers are encouraged to provide a single comprehensive set of materials for all shared aspects of the service offering and only provide separate materials for unique aspects of each service to minimize the burden on providers and agencies.
Class C
Providers with Class C Certifications MAY supply per-service FedRAMP Certification materials.
Providers determine what they consider to be separate services, based on maximizing the customer experience for agencies who may only adopt some services and not others.
Providers are encouraged to provide a single comprehensive set of materials for all shared aspects of the service offering and only provide separate materials for unique aspects of each service to minimize the burden on providers and agencies.
Class D
Providers with Class D Certifications MUST supply per-service FedRAMP Certification materials.
Providers determine what they consider to be separate services, based on maximizing the customer experience for agencies who may only adopt some services and not others.
Providers are encouraged to provide a single comprehensive set of materials for all shared aspects of the service offering and only provide separate materials for unique aspects of each service to minimize the burden on providers and agencies.
Public Information
Providers MUST publicly share up-to-date information about the cloud service offering in both human-readable and JSON formats, including at least the following information that is available and applicable:
- FedRAMP ID
- Service Model
- Deployment Model
- Business Category
- UEI Number
- Sales Contact Information
- Security Contact Information
- Product Website Link
- Link to Product Logo
- Overall Service Description
- Detailed list of specific services and their security categories (see CDS-CSO-SVC (Public Service List) (Service List))
- Link to Secure Configuration Guidance
- Overview of documentation supplied by the provider for the cloud service offering
- Link to Trust Center landing page that includes instructions on accessing information in the trust center
- Next Ongoing Certification Report date (see CCM-OCR-NRD (Next Report Date))
- Current FedRAMP Recognized independent assessment service
Generally, this information should be available on a public webpage or publicly shared in a FedRAMP-compatible trust center.
Responsible Information Sharing
Providers MUST provide sufficient information in FedRAMP Certification Data to support agency authorization decisions but SHOULD NOT include sensitive information that would likely enable a threat actor to gain unauthorized access, cause harm, disrupt operations, or otherwise have a negative adverse impact on the cloud service offering.
This is not a license to exclude accurate risk information, but specifics that would likely lead to compromise should be abstracted. A breach of confidentiality with FedRAMP Certification Data should be anticipated by a secure cloud service provider.
Responsible Public Package Sharing
Providers MAY responsibly share some or all of the information in a FedRAMP Certification Package publicly or with other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.
Public Service List
Providers MUST publicly share a detailed list of specific services and their security categories that are included in the cloud service offering using clear feature or service names that align with standard public marketing materials; this list MUST be complete enough for a potential customer to determine which services are and are not included in the FedRAMP Minimum Assessment Scope without requesting access to underlying FedRAMP Certification Data.
Use Trust Centers
Providers MUST use a FedRAMP-compatible trust center to store and share FedRAMP Certification Data with all necessary parties.
Rules for FedRAMP-Compatible Trust Centers are explained in the Certification Data Sharing Rules under the FedRAMP-Compatible Trust Centers section (id: CDS-TRC).
Agency Access Inventory
Trust centers MUST maintain an inventory and history of federal agency users or systems with access to FedRAMP Certification Data and MUST make this information available to FedRAMP upon request.
Access Logging
Trust centers MUST log access to FedRAMP Certification Data and store summaries of access for at least six months; such information, as it pertains to specific parties, SHOULD be made available upon request by those parties.
Human and Machine-Readable Certification Data
Trust centers SHOULD make FedRAMP Certification Data available to view and download in both human-readable and machine-readable formats.
Programmatic Access
Trust centers MUST provide documented programmatic access to all FedRAMP Certification Data, including programmatic access to human-readable materials.
Self-Service Access Management
Trust centers SHOULD include features that encourage all necessary parties to provision and manage access to FedRAMP Certification Data for their users and services directly.
Uninterrupted Sharing
Trust centers MUST share FedRAMP Certification Data with all necessary parties without interruption.
"Without interruption" means that parties should not have to request manual approval each time they need to access FedRAMP Certification Data or go through a complicated process. The preferred way of ensuring access without interruption is to use on-demand just-in-time access provisioning.
Agency Access Denial
Providers MUST notify FedRAMP within 5 business days of denying an agency access request for FedRAMP Certification Data.
Agency Access
Providers SHOULD supply access to the FedRAMP Certification Package with agencies upon request.
Cryptographic Module Use · CMU
3 requirements, 0 verifiable by automated check.
Configuration of Agency Tenants
Providers SHOULD configure agency tenants by default to use cryptographic services that use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when such modules are available.
Cryptographic Module Documentation
Providers MUST document the cryptographic modules used in each service (or groups of services that use the same modules) where cryptographic services are used to protect federal customer data, including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.
Using Validated Cryptographic Modules
Class B
Providers with Class B Certifications MAY use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
Class C
Providers with Class C Certifications SHOULD use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
Class D
Providers with Class D Certifications MUST use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
Certification Package Overview · CPO
5 requirements, 0 verifiable by automated check.
Certification Package Maintenance for Rev5
Class B
Providers with Rev5 Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every year.
This maximum timeframe for Rev5 is the absolutely poorest worst case for horrible customer experience and is based on legacy FedRAMP Rev5 allowing providers to leave their packages unmaintained for up to a year. Rev5 providers should maintain their packages far more frequently than this requirement to ensure potential customers have access to up-to-date information, updating it at least after every transformative significant change.
FedRAMP 20x Certifications expect providers to maintain their FedRAMP Certification Packages as changes occur to ensure they are never out of date.
Class C
Providers with Rev5 Class C Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every year.
This maximum timeframe for Rev5 is the absolutely poorest worst case for horrible customer experience and is based on legacy FedRAMP Rev5 allowing providers to leave their packages unmaintained for up to a year. Rev5 providers should maintain their packages far more frequently than this requirement to ensure potential customers have access to up-to-date information, updating it at least after every transformative significant change.
FedRAMP 20x Certifications expect providers to maintain their FedRAMP Certification Packages as changes occur to ensure they are never out of date.
Class D
Providers with Rev5 Class D Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every six months.
This maximum timeframe for Rev5 is the absolutely poorest worst case for horrible customer experience and is based on legacy FedRAMP Rev5 allowing providers to leave their packages unmaintained for up to a year. Rev5 providers should maintain their packages far more frequently than this requirement to ensure potential customers have access to up-to-date information, updating it at least after every transformative significant change.
FedRAMP 20x Certifications expect providers to maintain their FedRAMP Certification Packages as changes occur to ensure they are never out of date.
Certification Package Overview Metadata
Providers MUST also include the following basic metadata in their Certification Package Overview:
- Name, title, and contact information of official that is responsible and accountable for the FedRAMP Certification Package
- Version
- Date and time of last update
- Source of update
Overall Summary of Assessment in Certification Package
Class B
Providers seeking Class B Certification MUST also include the overall summary of their FedRAMP independent assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), in their Certification Package Overview.
Class C
Providers seeking Class C Certification MUST also include the overall summary of their FedRAMP independent assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), in their Certification Package Overview.
Class D
Providers seeking Class D Certification MUST also include the overall summary of their FedRAMP independent assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), in their Certification Package Overview.
Overview of the Cloud Service Offering
Providers MUST supply a Certification Package Overview within their FedRAMP Certification Package, in both human-readable and JSON formats, that includes at least all of the information required by the following rules:
- Certification Package Overview: CPO-CSO-MTD (Certification Package Overview Metadata)
- Certification Data Sharing: CDS-CSO-PUB (Public Information)
- Certification Data Sharing: CDS-CSO-SVC (Public Service List)
- Certification Data Sharing: CDS-CSO-IRP (Include Relevant Policies)
- Minimum Assessment Scope: MAS-CSO-IIR (Identify Information Resources)
- Minimum Assessment Scope: MAS-CSO-FLO (Information Flows and Security Categories)
- Minimum Assessment Scope: MAS-CSO-TPR (Third-Party Information Resources)
- Using Cryptographic Modules: CMU-CSO-CMD (Cryptographic Module Documentation)
- Independent Verification and Validation: IVV-CSO-ICP (Inclusion in Certification Package)
For FedRAMP Rev5, the Certification Package Overview replaces the historically required System Security Plan (not including appendices).
This list of rules may not apply to all FedRAMP Certification Classes or Types - if a rule does not apply then the information is not required.
Certification Package Maintenance for 20x
Class A
Providers with 20x Class A Certifications SHOULD persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 3 months.
Providers are expected to maintain their FedRAMP Certification Package using automation as changes occur to ensure they are never out of date.
This rule does not require or expect persistent human review of all materials in this cadence.
Class B
Providers with 20x Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every month.
Providers are expected to maintain their FedRAMP Certification Package using automation as changes occur to ensure they are never out of date.
This rule does not require or expect persistent human review of all materials in this cadence.
Class C
Providers with 20x Class C Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 2 weeks.
Providers are expected to maintain their FedRAMP Certification Package using automation as changes occur to ensure they are never out of date.
This rule does not require or expect persistent human review of all materials in this cadence.
Class D
Providers with 20x Class D Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every week.
Providers are expected to maintain their FedRAMP Certification Package using automation as changes occur to ensure they are never out of date.
This rule does not require or expect persistent human review of all materials in this cadence.
FedRAMP Certification · FRC
29 requirements, 0 verifiable by automated check.
Applying for FedRAMP Certification
Providers MUST complete the FedRAMP Certification Application Form in full to request an initial assessment by FedRAMP.
Fresh FedRAMP Certification Package
Providers MUST supply a fresh initial FedRAMP Certification Package that shows the current status of the cloud service offering as verified and validated by the provider within the previous 7 days.
Fresh Independent Assessment
Class A
Providers seeking Class A Certification MAY supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.
Class B
Providers seeking Class B Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.
Class C
Providers seeking Class C Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.
Class D
Providers seeking Class D Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.
Marketplace Listing First
Providers MUST be listed in the FedRAMP Marketplace before applying for FedRAMP Certification, including:
- FedRAMP Marketplace: MKT-CSO-MLR (Marketplace Listing Requirements),
- FedRAMP Marketplace: MKT-CSO-PML (Provider Marketplace Listing Requests)
- FedRAMP Marketplace: MKT-IIP-AGU (Agency Use Cases)
- FedRAMP Marketplace: MKT-IIP-DCP (Demonstrating Continuous Progress)
No Third-Party Applicants
Providers MUST NOT use a third party to apply for a FedRAMP Certification on their behalf; this includes independent assessment services.
FedRAMP previously allowed independent assessment services to submit applications on behalf of providers, but this caused confusion about who was responsible for the application and the information in it. Providers should apply directly to ensure clear accountability.
Providers may use third parties to help them prepare their application and assessment materials for submission.
Updating Stale Assessments
Providers MAY freshen a stale initial independent verification and validation assessment by having a FedRAMP Recognized independent assessment service review any changes between the original assessment and the current status of the cloud service offering in place of a full re-assessment, UNLESS the stale assessment is more than 9 months old.
Agency Authorization to Operate
Providers seeking a FedRAMP Rev5 Agency Certification MUST have completed the Authorization to Operate (ATO) process with their agency sponsor for the cloud service offering, concluding with a formal signed ATO letter that the agency has sent over official government channels to FedRAMP.
Downgrading Certification Class
Providers MUST apply for a new FedRAMP Certification to downgrade their Certification Class.
Downgrade paths include moving from D to C, B, or A; C to B or A; or B to A.
FRC-CCL-DNP (Downgrade Notification Period) applies - please DO NOT downgrade Certification Class with providing advance notification to all necessary parties!
Downgrade Notification Period
Providers SHOULD notify all necessary parties at least 120 days in advance of an intended downgrade or cancellation of FedRAMP Certification.
Downgrading or canceling FedRAMP Certification will have severe negative consequences for the provider and their agency customers and should only be done after careful consideration and planning... but if it must be done, notify all necessary parties as soon as possible.
Upgrading Certification Class
Providers MUST apply for a new FedRAMP Certification to upgrade their Certification Class; all applicable requirements MUST be met in advance.
Upgrade paths include moving from A to B, C, or D; B to C or D; and C to D.
The preferred path is to incrementally update the implementation and assurance commitments within the current Certification Class until the provider has met all requirements for the target Certification Class, then apply for the new Certification Class.
Approved Alternative Security Frameworks
Providers seeking a FedRAMP Class A Certification MUST have completed a certification or equivalent process, including an independent assessment if applicable, from one of the following alternative security frameworks within the past 12 months:
- FedRAMP Rev5 (including FedRAMP Ready) at any historical Impact Level
- SOC 2 Type II
- GovRAMP at any Impact Level
External Assessment Materials
Providers seeking a FedRAMP Class A Certification MUST supply the following materials from their alternative security framework assessment to all necessary parties:
- SOC 2 Type II: Complete report, bridge or gap letter (if applicable), verified audit engagement documentation, estimated schedule for upcoming report, supplemental compliance evidence (if applicable)
- FedRAMP Ready: Readiness Assessment Report, Security Assessment Plan, and any other materials required by FedRAMP.
- GovRAMP: Readiness Assessment Report, Security Assessment Plan, and any other materials required by GovRAMP.
Optional Independent Verification and Validation
Providers seeking a FedRAMP Class A Certification MAY have the FedRAMP Certification Package independently verified and validated by a FedRAMP Recognized assessor before submission to FedRAMP.
Mandatory FedRAMP Rules for Class A
Providers seeking a Class A FedRAMP Certification MUST address all rules in this FedRAMP Class A Certification subset (FRC-CLA) AND the following additional FedRAMP Class A rules; the appropriate artifacts or information mapping for all rules MUST be supplied in the FedRAMP Certification Package.
- FedRAMP Certification: FRC-CSO-PKG (FedRAMP Certification Package)
- FedRAMP Certification: FRC-CSO-JSN (FedRAMP JSON Schemas)
- FedRAMP Certification: FRC-CSO-POP (Pick One Program Certification Type)
- Minimum Assessment Scope: MAS-CSO-IIR (Identify Information Resources)
- Certification Data Sharing: CDS-CSO-PUB (Public Information)
- Certification Data Sharing: CDS-CSO-UTC (Use Trust Centers)
- Certification Data Sharing: CDS-UTC-AAD (Agency Access Denial)
- Addressing FedRAMP Communication: AFC-CSO-INB (Maintain a FedRAMP Security Inbox)
- Addressing FedRAMP Communication: AFC-CSO-RCV (Receive Email Without Disruption)
- Addressing FedRAMP Communication: AFC-CSO-CRA (Complete Required Actions)
- Incident Evaluation and Communication: IEC-CSO-EFR (Evaluate FedRAMP Reportability)
- Incident Evaluation and Communication: IEC-CSO-FIR (Final Incident Report)
- Vulnerability Detection and Response: VDR-CSO-DET (Vulnerability Detection)
- Collaborative Continuous Monitoring: CCM-OCR-AVL (Report Availability)
- Collaborative Continuous Monitoring: CCM-OCR-NRD (Next Report Date)
- Independent Verification and Validation: IVV-CSX-AIA (Annual Independent Assessments for 20x)
- Key Security Indicators: KSI-CMT-LMC (Logging Changes)
- Key Security Indicators: KSI-CNA-RNT (Restricting Network Traffic)
- Key Security Indicators: KSI-CED-RAT (Reviewing All Training)
- Key Security Indicators: KSI-IAM-AAM (Automating Account Management)
- Key Security Indicators: KSI-IAM-APM (Adopting Passwordless Methods)
- Key Security Indicators: KSI-INR-RIR (Reviewing Incident Response Procedures)
- Key Security Indicators: KSI-SVC-SIN (Securing Information)
Some of these specific FedRAMP rules may not have similar counterparts in external frameworks and providers will need to implement new processes to follow these rules.
In general, for each of these FedRAMP requirements, providers should include a sufficiently detailed summary that reviewers will not need to dig into the related security framework materials to understand the related decisions - just saying "see SOC 2 report" is not particularly helpful.
Information about how the provider addresses the included Key Security Indicators are required to receive a class A certification even if the provider intends to pursue a Rev 5 Program Certification path in the future.
Address Optional FedRAMP Rules for Class A
Providers seeking a Class A FedRAMP Certification MAY address the following additional optional FedRAMP Class A rules (if applicable):
- Collaborative Continuous Monitoring: CCM-QTR-MTG (Quarterly Review Meeting)
- Certification Data Sharing: CDS-CSO-PSM (Per-Service Certification Materials)
- Cryptographic Module Use: CMU-CSO-UVM (Using Validated Cryptographic Modules)
- FedRAMP Certification: FRC-APP-FIA (Fresh Independent Assessment)
- Independent Verification and Validation: IVV-CSO-FIA (FedRAMP Independent Assessments)
- Security Decision Record: SDR-CSX-KMT (Key Security Indicator Metrics)
- Vulnerability Evaluation and Reporting: VER-TFR-IRI (Internet-Reachable Incidents)
- Vulnerability Evaluation and Reporting: VER-TFR-MRH (Historical Activity)
- Vulnerability Evaluation and Reporting: VER-TFR-NRI (Non-Internet-Reachable Incidents)
Recommended FedRAMP Rules for Class A
Providers seeking a Class A FedRAMP Certification SHOULD address the following additional recommended FedRAMP Class A rules (if applicable):
- Certification Data Sharing: CDS-CSO-AVR (Availability Reporting)
- Certification Package Overview: CPO-CSF-CPM (Certification Package Maintenance for Rev5)
- Certification Package Overview: CPO-CSX-CPM (Certification Package Maintenance for 20x)
- Incident Evaluation and Communication: IEC-CSO-IIR (Initial Incident Report)
- Incident Evaluation and Communication: IEC-CSO-OIR (Ongoing Incident Reports)
- Vulnerability Detection and Response: VDR-TFR-MVX (Persistent Machine Verification and Validation for 20x)
- Vulnerability Detection and Response: VDR-TFR-PCD (Persistently Complete Detection)
- Vulnerability Detection and Response: VDR-TFR-PDD (Persistent Drift Detection)
- Vulnerability Detection and Response: VDR-TFR-PSD (Persistent Sample Detection)
- Vulnerability Detection and Response: VDR-TFR-PVR (Mitigation and Remediation Expectations)
- Vulnerability Evaluation and Reporting: VER-TFR-EVU (Evaluate Vulnerabilities Quickly)
Assign Control Parameters
Providers MUST assign all organization-defined control parameters, following FedRAMP Rev5 Controls Guidance, and ensure that all control parameter assignments are documented in the Security Decision Record (SDR).
FedRAMP Rev5 Baselines
Class B
Providers seeking FedRAMP Rev5 Class B Certification MUST include at least the following NIST SP 800-53 Rev. 5 controls in their Security Decision Record:
Class C
Providers seeking FedRAMP Rev5 Class C Certification MUST include at least the following NIST SP 800-53 Rev. 5 controls in their Security Decision Record:
Class D
Providers seeking FedRAMP Rev5 Class D Certification MUST include at least the following NIST SP 800-53 Rev. 5 controls in their Security Decision Record:
Follow FedRAMP Rev5 Controls Guidance
Providers MUST follow FedRAMP Rev5 Controls Guidance for the implementation and documentation of all applicable controls.
FedRAMP Ready Conversion
Providers with FedRAMP Rev5 Ready status MUST convert to a FedRAMP Certification by whichever of the follow dates is later: the expiration of their annual assessment or November 17, 2026 (the legacy FedRAMP Ready status will be entirely removed on December 31, 2027).
The simplest conversion in most cases would be to a FedRAMP 20x Class A Certification.
Cloud services that do not wish to convert or do not meet conversion criteria will be renamed Legacy FedRAMP Ready and otherwise retired from FedRAMP Ready.
FedRAMP Certification Profile
Providers MUST identify a target FedRAMP Certification Profile and apply all relevant FedRAMP Practices to the cloud service offering.
Information resources (including third-party information resources) MAY vary by security category as appropriate to the type of information handled by or impacted by the information resource.
FedRAMP JSON Schemas
Providers MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule.
FedRAMP JSON schemas are designed to be lightweight and flexible to establish a minimum set of structured information while allowing providers to improve on the format and structure of the information as needed to meet their needs and the needs of their customers.
Maintain Responsibility and Accountability
Providers MUST maintain responsibility and accountability for the accuracy and completeness of all information in the FedRAMP Certification Package, especially when they engage a third party (such as an independent assessor, advisory service, or external tools) to supply information on their behalf.
FedRAMP Certification Package
Providers seeking a Certification MUST supply a complete FedRAMP Certification Package to FedRAMP for initial certification; the FedRAMP Certification Package MUST include at least the following information:
- Information about the Cloud Service Offering following CPO-CSO-OVR (Overview of the Cloud Service Offering)
- Implementation, Validation, and Assessment information for each relevant FedRAMP requirement/control/ksi as defined in SDR-CSO-FRR (FedRAMP Rules)
- A real or example Ongoing Certification Report following CCM-OCR-AVL (Report Availability)
Pick One Program Certification Type
Providers MUST NOT seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering; pick one type.
This rule does not prevent a provider from seeking and maintaining a FedRAMP Rev5 Agency Certification and a FedRAMP 20x Program Certification for the same cloud service offering, however, doing so is strongly discouraged due to the increased complexity and risk of confusion for all parties.
Application within MAS
Providers SHOULD apply ALL Key Security Indicators to ALL aspects of their cloud service offering that are within the FedRAMP Minimum Assessment Scope.
Metrics Over Time for Key Security Indicators
Class B
Providers seeking 20x Class B Certification SHOULD supply historical metrics for Key Security Indicators.
For initial FedRAMP Certification, providers will need to have mechanisms in place and agree to meet this requirement in the event the cloud service has not been operating with related metrics available for the required period prior to applying for initial certification.
Class C
Providers seeking 20x Class C Certification MUST supply historical metrics including status from persistent validation over at least the past 6 months for all Key Security Indicators.
For initial FedRAMP Certification, providers will need to have mechanisms in place and agree to meet this requirement in the event the cloud service has not been operating with related metrics available for the required period prior to applying for initial certification.
Class D
Providers seeking 20x Class D Certification MUST provide historical metrics including status from persistent validation over at least the past 18 months for all Key Security Indicators.
For initial FedRAMP Certification, providers will need to have mechanisms in place and agree to meet this requirement in the event the cloud service has not been operating with related metrics available for the required period prior to applying for initial certification.
Automated Verification and Validation of Key Security Indicators
Class B
Providers seeking 20x Class B Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 1 automated method for each Key Security Indicator.
Class C
Providers seeking 20x Class C Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 2 automated methods for each Key Security Indicator.
Class D
Providers seeking 20x Class D Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 4 automated methods for each Key Security Indicator.
Automated Verification and Validation of FedRAMP Rules
Class B
Providers seeking 20x Class B Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.
Different rules will be easy to automate for different providers, depending on the implementation, so FedRAMP generally leaves this implementation up to providers based on what makes the most sense for their own business and approach.
Class C
Providers seeking 20x Class C Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.
Different rules will be easy to automate for different providers, depending on the implementation, so FedRAMP generally leaves this implementation up to providers based on what makes the most sense for their own business and approach.
Class D
Providers seeking 20x Class D Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.
Different rules will be easy to automate for different providers, depending on the implementation, so FedRAMP generally leaves this implementation up to providers based on what makes the most sense for their own business and approach.
Incident Evaluation and Communication · IEC
7 requirements, 0 verifiable by automated check.
Automated Incident Reporting
Providers SHOULD use automation to minimize human intervention in the process of reporting FedRAMP Reportable Incidents to all affected parties.
Default PAIN Rating
Providers MUST treat FedRAMP Reportable Incidents as if they have a Potential Agency Impact N-rating (PAIN) of 5 UNLESS they promptly estimate the PAIN rating following the rule in IEC-CSO-EFI (Estimate Federal Impact).
Estimate Federal Impact
Providers SHOULD promptly estimate the likely adverse impact of an incident on agency customers to assign a Potential Agency Impact N-rating; this step is called Incident Rating.
- N1 for a likely minimal customer effect on 1 or more agencies.
- N2 for a likely narrow customer effect on 1 or more agencies.
- N3 for a likely disruptive customer effect on 1 agency.
- N4 for a likely debilitating customer effect on 1 agency or a likely disruptive customer effect on more than 1 agency.
- N5 for a likely debilitating customer effect on more than 1 agency.
All incidents must be assigned a default PAIN-5 as required by IEC-CSO-DPR (Default PAIN Rating) if this step is not completed.
Evaluate FedRAMP Reportability
Providers MUST promptly evaluate incidents to determine if they affect confidentiality or integrity of federal customer data or are likely to affect confidentiality or integrity of federal customer data; such incidents are FedRAMP Reportable Incidents and must be reported following the FedRAMP Incident Evaluation and Communication rules.
Final Incident Report
Class B
Providers with Class B Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.
Class C
Providers with Class C Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.
Class D
Providers with Class D Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.
Initial Incident Report
Class B
Providers with Class B Certifications MUST responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:
- Contact information for the federal incident response coordinator.
- Provider's internally assigned tracking identifier
- Description of the incident
- Timeline of the incident, including start time, time and source of detection, time of completed FedRAMP Reportable Incident evaluation, and other major incident milestones determined by the provider
- Historically and currently estimated Potential Agency Impact N-rating (PAIN) of the incident, including an explanation of the evaluation following the requirements in IEC-CSO-EFI (Estimate Federal Impact) (if applicable)
- Functional impact to federal agency customers (include impact to confidentiality and/or integrity and the impacted federal customer data types)
- Estimated recovery plan, milestones, and timelines
- List of likely affected customer agencies
Class C
Providers with Class C Certifications MUST responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:
- Contact information for the federal incident response coordinator.
- Provider's internally assigned tracking identifier
- Description of the incident
- Timeline of the incident, including start time, time and source of detection, time of completed FedRAMP Reportable Incident evaluation, and other major incident milestones determined by the provider
- Historically and currently estimated Potential Agency Impact N-rating (PAIN) of the incident, including an explanation of the evaluation following the requirements in IEC-CSO-EFI (Estimate Federal Impact) (if applicable)
- Functional impact to federal agency customers (include impact to confidentiality and/or integrity and the impacted federal customer data types)
- Estimated recovery plan, milestones, and timelines
- List of likely affected customer agencies
Class D
Providers with Class D Certifications MUST responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:
- Contact information for the federal incident response coordinator.
- Provider's internally assigned tracking identifier
- Description of the incident
- Timeline of the incident, including start time, time and source of detection, time of completed FedRAMP Reportable Incident evaluation, and other major incident milestones determined by the provider
- Historically and currently estimated Potential Agency Impact N-rating (PAIN) of the incident, including an explanation of the evaluation following the requirements in IEC-CSO-EFI (Estimate Federal Impact) (if applicable)
- Functional impact to federal agency customers (include impact to confidentiality and/or integrity and the impacted federal customer data types)
- Estimated recovery plan, milestones, and timelines
- List of likely affected customer agencies
Ongoing Incident Reports
Class B
Providers with Class B Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:
- Observed incident activity
- Indicators of compromise
- Related Common Vulnerabilities and Exposures (CVE) identifier, if applicable
- Root cause
- Response and recovery activities
Class C
Providers with Class C Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:
- Observed incident activity
- Indicators of compromise
- Related Common Vulnerabilities and Exposures (CVE) identifier, if applicable
- Root cause
- Response and recovery activities
Class D
Providers with Class D Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:
- Observed incident activity
- Indicators of compromise
- Related Common Vulnerabilities and Exposures (CVE) identifier, if applicable
- Root cause
- Response and recovery activities
Independent Verification and Validation · IVV
13 requirements, 0 verifiable by automated check.
Assessment of Rev5 Controls with Findings
Providers MUST have Rev5 Controls with negative findings from the previous FedRAMP independent assessment included in the next FedRAMP independent assessment.
Annual Independent Assessments for Rev5
Class B
Providers with Rev5 Class B Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:
Class C
Providers with Rev5 Class C Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:
Class D
Providers with Rev5 Class D Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:
Mandatory Control Assessment
Providers MUST have all applicable Rev5 Controls included in FedRAMP independent assessments every 3 years but are not required to have all Rev5 Controls included in the same FedRAMP independent assessment.
Traditionally this has been done by reviewing a rotating selection of Rev5 Controls at each annual assessment, however this requirement is a ceiling and not a floor. See IVV-CSF-PCA (Preferred Control Assessment) for FedRAMP's recommended approach to Rev5 control assessments.
Preferred Control Assessment
Providers SHOULD include all applicable Rev5 Controls in each FedRAMP independent assessment.
Document Use of Representative Samples
Providers MUST document and explain the use of representative samples during verification and validation when using representative samples as allowed by IVV-CSO-USR (Use Representative Samples).
FedRAMP Independent Assessments
Class B
Providers with Class B Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.
The first such completed assessment is typically called an "initial assessment" while following assessments are called "annual assessments."
The specific requirements for independent verification and validation assessments are documented by the FedRAMP Certification Class and Type.
The option for assessment by FedRAMP directly is limited to cloud services that are explicitly prioritized by FedRAMP, in consultation with the FedRAMP Board and the federal Chief Information Officers Council; this is _extremely_ rare.
FedRAMP Recognized independent assessment services are listed on the FedRAMP Marketplace.
Class C
Providers with Class C Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.
The first such completed assessment is typically called an "initial assessment" while following assessments are called "annual assessments."
The specific requirements for independent verification and validation assessments are documented by the FedRAMP Certification Class and Type.
The option for assessment by FedRAMP directly is limited to cloud services that are explicitly prioritized by FedRAMP, in consultation with the FedRAMP Board and the federal Chief Information Officers Council; this is _extremely_ rare.
FedRAMP Recognized independent assessment services are listed on the FedRAMP Marketplace.
Class D
Providers with Class D Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.
The first such completed assessment is typically called an "initial assessment" while following assessments are called "annual assessments."
The specific requirements for independent verification and validation assessments are documented by the FedRAMP Certification Class and Type.
The option for assessment by FedRAMP directly is limited to cloud services that are explicitly prioritized by FedRAMP, in consultation with the FedRAMP Board and the federal Chief Information Officers Council; this is _extremely_ rare.
FedRAMP Recognized independent assessment services are listed on the FedRAMP Marketplace.
Inclusion in Certification Package
Providers MUST supply the results of FedRAMP independent assessments in their FedRAMP Certification Package without inappropriate modification.
Inappropriate modification in this context means changing the underlying intent/etc. of the content provided by the independent assessment service - the content itself may be modified for presentation, formatting, etc. as needed.
This rule is related to IVV-IAS-VIP (Verify Inclusion in Certification Package).
Receiving Assessor Advice
Providers MAY ask for and accept advice from their assessor during assessment regarding techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their verification, validation and reporting procedures, UNLESS doing so is likely to compromise the objectivity and integrity of the assessment.
Supply Evidence of Effectiveness
Providers MUST supply evidence to all necessary assessors of the effectiveness of the measures that have been implemented to meet FedRAMP Practices; this evidence is the result of validation.
For example, after verifying that firewalls are configured to block traffic following IVV-CSO-SEI (Supply Evidence of Implementation), the provider would validate that traffic is actually being blocked and supply evidence of that validation to assessors (such as by allowing them to see metrics on the traffic that is blocked vs not).
Supply Evidence of Implementation
Providers MUST supply evidence to all necessary assessors of the implementation of the measures that have been documented to meet FedRAMP Practices; this evidence is the result of verification.
For example, if the documentation says that firewall rules are used to block traffic then the cloud service provider would verify that firewall rules are in place to block traffic and supply that evidence to assessors (preferably by allowing them to see how firewall configurations are deployed from a source of truth).
Supply Technical Explanations
Providers SHOULD supply all necessary assessors with technical explanations, demonstrations, and other relevant supporting information about the technical capabilities they employ to address FedRAMP rules; this SHOULD be supplied as necessary to ensure the assessor can effectively complete verification and validation.
Use Representative Samples
Providers MAY use representative samples as appropriate during verification and validation.
Many modern cloud services using effective automation do not need to use representative sampling and are capable of persistently verifying and validating the majority of their security measures automatically.
Annual Independent Assessments for 20x
Class B
Providers with 20x Class B Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.
Class C
Providers with 20x Class C Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.
Class D
Providers with 20x Class D Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.
Minimum Assessment Scope · MAS
5 requirements, 0 verifiable by automated check.
Information Flows and Security Categories
Providers MUST clearly identify, document, and explain information flows and security categories for ALL information resources or sets of information resources in the cloud service offering.
Information resources (including third-party information resources) MAY vary by security category as appropriate to the type of information handled by or impacted by the information resource.
Identify Information Resources
Providers MUST identify a set of information resources to assess for FedRAMP Certification that includes all information resources that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering; this set of information resources is the cloud service offering.
Certain categories of cloud computing products and services are specified as entirely outside the scope of FedRAMP by the Director of the Office of Management and Budget. All such products and services are therefore not included in the cloud service offering for FedRAMP. For more, see https://fedramp.gov/scope.
Software produced by cloud service providers that is delivered separately for installation on agency systems and not operated in a shared responsibility model (typically including agents, application clients, mobile applications, etc. that are not fully managed by the cloud service provider) is not a cloud computing product or service and is entirely outside the scope of FedRAMP under the FedRAMP Certification Act. All such software is therefore not included in the cloud service offering for FedRAMP. For more, see https://fedramp.gov/scope.
All aspects of the cloud service offering are determined and maintained by the cloud service provider in accordance with related FedRAMP Certification rules and documented by the cloud service provider in their FedRAMP Certification Package.
Metadata Inclusion
Providers MUST include metadata (including metadata about federal customer data) in the Minimum Assessment Scope ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES.
Supplemental Information
Providers MAY include additional materials about other information resources that are not part of the cloud service offering in a FedRAMP Certification Package supplement; these resources will not be FedRAMP Certified and MUST be clearly marked and separated from the cloud service offering.
This is intended to allow inclusion of things like security materials for apps, supplemental marketing collateral, and other information that is not part of the cloud service offering but may be useful to agencies.
Third-Party Information Resources
Providers MUST address the potential impact to federal customer data from third-party information resources used by the cloud service offering, ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES, by documenting the following information about each applicable third-party information resource:
- General usage and configuration
- Explanation or justification for use
- Mitigation measures in place to reduce the potential impact to federal customer data
- Compensating controls in place to reduce the potential impact to federal customer data
Marketplace Listing · MKT
5 requirements, 0 verifiable by automated check.
Marketplace Listing Requirements
Providers MUST address at least these FedRAMP rules to apply for a new FedRAMP Marketplace listing OR to request updates to an existing listing:
- Certification Data Sharing: CDS-CSO-PUB (Public Information)
Provider Marketplace Listing Requests
Providers MUST notify FedRAMP using the FedRAMP Marketplace Providing Listing Request Form to request a listing in the FedRAMP Marketplace.
FedRAMP does not accept applications for a FedRAMP Marketplace Listing via email!
Agency Use Cases
Providers MUST demonstrate that a cloud service offering is intended for one of the following use cases:
- Direct Use: The product will be used directly by agency customers for integration into a federal information system that falls within the scope of 44 USC § 3506 and will receive an agency Authorization to Operate.
- Indirect Use: The product will be included as a third-party information resource in other cloud service offerings that are directly used by agency customers.
FedRAMP will not list products or services that are outside the explicit statutory scope of FedRAMP; See MKT-FRP-SOF (Scope of FedRAMP).
Services used by private companies to meet other compliance requirements (such as CMMC) that do not also meet one of the above use cases are outside the scope of FedRAMP.
Demonstrating Continuous Progress
Providers MUST demonstrate continuous progress towards a FedRAMP Certification, documented in their Trust Center or website and updated at least quarterly; progress is measured by the provider against documented goals and milestones.
This is an opportunity for a business to showcase its goals and progress, and should be seen as a marketing and customer experience challenge instead of a compliance challenge.
Deadline for Assessment
Providers MUST demonstrate that an assessment for a FedRAMP Certification Class B, C, or D has been scheduled within 2 years of initial listing in the Initial Implementation Phase.
If this is not followed:
- If a provider fails to schedule an assessment for a FedRAMP Certification Class B, C, or D within 2 years of initial listing in the Initial Implementation Phase, FedRAMP will remove their listing from the Marketplace until they provide evidence of a scheduled assessment.
Secure Configuration Guide · SCG
9 requirements, 0 verifiable by automated check.
Use Instructions
Providers MUST include instructions in the FedRAMP Certification Package that explain how to obtain and use the Secure Configuration Guide.
These instructions may appear in a variety of ways; it is up to the provider to do so in the most appropriate and effective ways for their specific customer needs.
Public Secure Configuration Guidance
Providers SHOULD make the Secure Configuration Guide available publicly.
Recommended Secure Configuration
Providers MUST create, maintain, and make available recommendations for securely configuring their cloud services (the Secure Configuration Guide) that includes at least the following information:
- Required: Instructions on how to securely access, configure, operate, and decommission top-level administrative accounts that control enterprise access to the entire cloud service offering.
- Required: Explanations of security-related settings that can be operated only by top-level administrative accounts and their security implications.
- Recommended: Explanations of security-related settings that can be operated only by privileged accounts and their security implications.
These rules refer to this guidance as a Secure Configuration Guide but cloud service providers may make this guidance available in various appropriate forms that provide the best customer experience.
This guidance should explain how top-level administrative accounts and privileged accounts are named and referred to in the cloud service offering.
Secure Defaults
Providers SHOULD set all settings to their recommended secure defaults for top-level administrative accounts and privileged accounts when initially provisioned.
API Capability
Providers SHOULD offer the capability to view and adjust security settings via an API or similar capability.
Comparison Capability
Providers SHOULD offer the capability to compare all current settings for top-level administrative accounts and privileged accounts to the recommended secure defaults.
Export Capability
Providers SHOULD offer the capability to export all security settings in a machine-readable format.
Machine-Readable Guidance
Providers SHOULD also provide the Secure Configuration Guide in a machine-readable format that can be used by customers or third-party tools to compare against current settings.
Versioning and Release History
Providers SHOULD provide versioning and a release history for recommended secure default settings for top-level administrative accounts and privileged accounts as they are adjusted over time.
Significant Change Notification · SCN
16 requirements, 0 verifiable by automated check.
Notification Requirements
Providers MUST notify all necessary parties within 10 business days after finishing adaptive changes, also including the following information:
- Summary of any new risks identified and/or vulnerabilities resulting from the change (if applicable)
Activities that match the adaptive significant change type are a frequent and normal part of iteratively improving a service by deploying new functionality or modifying existing functionality in a way that is typically transparent to customers and does not introduce significant new security risks.
In general, most changes that do not happen regularly will be adaptive changes. This change type deliberately covers a wide range of activities in a way that requires assessment and consideration.
Additional Relevant Information
Providers MAY include additional relevant information in Significant Change Notifications.
This allows providers to convey whatever additional information they think is relevant without worrying about negative consequences from not following an exact template.
Emergency Changes
Providers MAY execute significant changes (including transformative changes) during an emergency or incident without following the Significant Change Notification rules in advance. In such emergencies, providers MUST follow all relevant procedures, notify all necessary parties, retroactively provide all Significant Change Notification materials, and complete appropriate assessment after the incident.
Procedures for emergency changes should be documented in the FedRAMP Certification Package.
Evaluate Changes
Providers MUST evaluate all potential significant changes to determine the type of significant change and follow the appropriate Significant Change Notification rules.
- Is it a significant change? --> Continue evaluation and follow the Significant Change Notification rules.
- If it is, is it an FedRAMP Certification class change? --> This requires a new assessment and cannot be done under the Significant Change Notification rules.
- If it is not, is it a routine recurring change? --> Follow the Routine Recurring Change rules (SCN-RTR Routine Recurring Changes).
- If it is not, is it a transformative change? --> Follow the Transformative Change rules (SCN-TRF Transformative Changes).
- If it is not, then it is an adaptive change --> Follow the Adaptive Change rules (SCN-ADP Adaptive Changes).
Historical Notifications
Providers MUST keep 12 months of historical Significant Change Notifications available with their FedRAMP Certification Data.
Human and Machine-Readable Notifications
Providers MUST make ALL Significant Change Notifications and related audit records available in human-readable and JSON formats.
Required Information
Providers MUST include at least the following information in Significant Change Notifications:
- Service Offering FedRAMP ID
- Assessor Name (if applicable)
- Related Vulnerability (if applicable)
- Significant Change type and explanation of categorization
- Short description of change
- Reason for change
- Summary of customer impact, including changes to services and customer configuration responsibilities
- Plan and timeline for the change, including for the verification, assessment, and/or validation of impacted Key Security Indicators or Rev5 Controls
- Copy of the business or security impact analysis
- Name and title of approver
Structure of the information may vary depending on how the provider tracks this internally.
Maintain Audit Records
Providers MUST maintain auditable records of the significant change evaluation activities required by SCN-CSO-EVA (Evaluate Changes) and make them available to FedRAMP as requested.
These audit records must be available to FedRAMP on request; these records do not need to be included in the FedRAMP Certification Package by default and do not need to be emailed to FedRAMP continuously.
Notification Mechanisms
Providers MAY notify necessary parties in a variety of ways as long as the mechanism for notification is clearly documented in the FedRAMP Certification Package and easily accessible.
The sharing mechanism should be designed based on the needs of the provider and their customers and may vary between providers.
The default sharing mechanism for most providers during the SCN beta was to send an email to agency customers and upload a copy of the notification to the provider's secure sharing location.
No Notification Requirements
Providers SHOULD NOT make formal Significant Change Notifications for routine recurring changes; this type of change is exempted from notification requirements.
Activities that match the routine recurring significant change type are performed regularly and routinely by cloud service providers to address flaws or vulnerabilities, address incidents, and generally perform the typical maintenance and service delivery changes expected during day-to-day operations.
These changes leverage mature processes and capabilities to identify, mitigate, and remediate risks as part of the change. They are often entirely automated and may occur without human intervention, even though they have an impact on security of the service.
If the activity does not occur regularly and routinely then it cannot be a significant change of this type (e.g., replacing all physical firewalls to remediate a vulnerability is obviously not regular or routine).
Notification After Finishing
Providers MUST notify all necessary parties within 5 business days after finishing transformative changes, including updates to all previously sent information.
Notification After Verification
Providers MUST notify all necessary parties within 5 business days after completing the verification, assessment, and/or validation of transformative changes, also including the following information:
- Updates to all previously sent information
- Summary of any new risks identified and/or vulnerabilities resulting from the change (if applicable)
- Copy of the security assessment report (if applicable)
Notification of Final Plans
Providers MUST notify all necessary parties of final plans for transformative changes at least 10 business days before starting transformative changes, including updates to all previously sent information.
Notification of Initial Plans
Providers MUST notify all necessary parties of initial plans for transformative changes at least 30 business days before starting transformative changes, including a summary of any likely security impacts or changes in risk.
Third-Party Review
Providers SHOULD engage a third-party assessor to review the scope and impact of the planned change before starting transformative changes if human validation is necessary; such reviews SHOULD be limited to security decisions that require human validation.
Activities that match the transformative significant change type are rare for a cloud service offering, adjusted for the size, scale, and complexity of the service. Small cloud service offerings may go years without transformative changes, while hyperscale providers may release multiple transformative changes per year.
Update Documentation
Providers MUST publish updated service documentation and other materials to reflect transformative changes within 30 business days after finishing transformative changes.
This requirement is focused on service documentation like user guides, information listed in the marketplace, and other such materials; it does not require updating the system security plan or FedRAMP Certification Package.
Security Decision Record · SDR
5 requirements, 0 verifiable by automated check.
Rev5 Controls
Providers MUST also include short and simple high-level summaries of at least the following for each applicable Rev5 Control:
- Any organization-defined parameter values.
- Implementation status, one of Implemented, Partially Implemented, Planned, Alternative Implementation, or Not Applicable.
- The mechanisms or activities that address the control, including inheritance from another cloud service offering if applicable.
- The verification that is in place to ensure the implementation is appropriate for the control.
- The validation that is in place to ensure the implementation is working as intended.
- Independent verification.
- Independent validation.
- Any responses or clarifications to the comments in the independent verification or validation.
- Control-specific artifacts (if applicable).
FedRAMP Rules
Providers MUST supply a Security Decision Record, in both human-readable and JSON formats, that includes at least all of the following information for each applicable FedRAMP rule:
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
- Any responses or clarifications to the comments in the independent verification or validation.
- Rule-specific artifacts (if applicable).
Security Decision Record Metadata
Providers MUST also include the following basic metadata in their Security Decision Record:
- Version
- Date and time of last update
- Source of update
Key Security Indicator Metrics
Class B
Providers with 20x Class B Certifications MUST also include historical metrics in their Security Decision Record, supplying at least the following information for each applicable Key Security Indicator:
- Summary of each metric over the past 30 days
- Summary of metric up to the past year (where available)
Class C
Providers with 20x Class C Certifications MUST also include historical metrics in their Security Decision Record, supplying at least the following information for each applicable Key Security Indicator:
- Summary of each metric over the past 30 days
- Summary of metric up to the past year (where available)
- All daily metric data up to the past year (where available)
Class D
Providers with 20x Class D Certifications MUST significantly supersede the minimum requirements for lower Classes, with specifics to be set during the 20x Phase 4 Pilot.
Key Security Indicators
Providers MUST also include short and simple high-level summaries of at least the following for each applicable Key Security Indicator:
- Explanation of measures (and their objectives) that demonstrate the Key Security Indicator, or an explanation of the reason and resulting risk to customers for not having measures available for that Key Security Indicator.
- Explanation of the cycle for any measures that are implemented persistently (if applicable).
- Verification that the measures demonstrate the Key Security Indicator, or that the reason for not having them is accepted.
- Verification that the automation in place is accurate and sufficient to demonstrate appropriate measures for the Key Security Indicator, or that automation is not necessary for each measure.
- Validation that the measures are accurately produced and are in place and working as intended, or that the reason for not having them is valid.
Vulnerability Detection and Response · VDR
18 requirements, 0 verifiable by automated check.
Automate Detection
Providers SHOULD use automated services to improve and streamline vulnerability detection and response.
Avoid KEVs
Providers SHOULD NOT deploy or otherwise activate new machine-based information resources with Known Exploited Vulnerabilities.
Detect After Changes
Providers SHOULD automatically perform vulnerability detection on representative samples of new or significantly changed information resources.
Vulnerability Detection
Providers MUST systematically, persistently, and promptly discover and identify vulnerabilities within their cloud service offering using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities; this process is called vulnerability detection. Vulnerability detection includes persistently verifying and validating that information resources and processes are operating as intended and documented for FedRAMP Practices.
FedRAMP's vulnerability detection (and response) rules are intended to set modern expectations for maintaining the security of a cloud service. Historical FedRAMP guidance on vulnerability scanning or continuous monitoring generally focused only on CVE-type vulnerabilities while leaving other types of vulnerabilities and exposures unaddressed.
Providers are encouraged to leverage their existing holistic security review, architecture review, and similar processes to meet these requirements. FedRAMP strongly discourages providers from implementing separate vulnerability detection and response processes for FedRAMP reporting that are operated by independent compliance branches unless these processes are consuming data directly from the areas of the cloud service that actively maintain it.
Design For Resilience
Providers SHOULD make design and architecture decisions for their cloud service offering that mitigate the risk of vulnerabilities by default AND decrease the risk and complexity of vulnerability detection and response.
Failures Are Vulnerabilities
Providers MUST treat problems or failures with their vulnerability detection and response processes as vulnerabilities.
Maintain Security
Providers SHOULD NOT weaken the security of information resources to facilitate vulnerability scanning, detection, or assessment activities.
Vulnerability Response
Providers MUST systematically, persistently, and promptly track, evaluate, monitor, mitigate, remediate, assess exploitation of, report, and otherwise manage all detected vulnerabilities within their cloud service offering; this process is called vulnerability response.
If it is not possible to fully mitigate vulnerabilities or remediate vulnerabilities, providers SHOULD instead partially mitigate vulnerabilities promptly, progressively, and persistently.
FedRAMP does not use the terms "mitigation" and "remediation" interchangeably. Mitigation is the process of reducing the risk and impact of a vulnerability through partial mitigation and even full mitigation; remediation is the process of entirely eliminating the vulnerability. A fully mitigated vulnerability will still exist (with negligible risk) until it has been remediated. This separation is based on the plain language definitions of these words.
Please refer to FedRAMP Definitions for strict interpretation in the FedRAMP context.
Sampling
Providers MAY sample effectively identical information resources, especially machine-based information resources, when performing vulnerability detection UNLESS doing so would decrease the efficiency or effectiveness of vulnerability detection.
Remediate KEVs
Providers SHOULD remediate Known Exploited Vulnerabilities according to the due dates in the CISA Known Exploited Vulnerabilities Catalog (even if the vulnerability has been fully mitigated) as required by CISA Binding Operational Directive (BOD) 26-04 or any successor guidance from CISA.
Persistent Machine Verification and Validation for Rev5
Class B
Providers of FedRAMP Rev5 Class B offerings SHOULD verify and validate the status of machine-based information resources at least once every month.
Class C
Providers of FedRAMP Rev5 Class C offerings MUST verify and validate the status of machine-based information resources at least once every month.
Class D
Providers of FedRAMP Rev5 Class D offerings MUST verify and validate the status of machine-based information resources at least once every month.
Persistent Machine Verification and Validation for 20x
Class B
Providers of FedRAMP 20x Class B offerings MUST verify and validate the status of machine-based information resources at least once every 7 days.
Class C
Providers of FedRAMP 20x Class C offerings MUST verify and validate the status of machine-based information resources at least once every 3 days.
Non-Machine Verification and Validation
Providers MUST verify and validate the status of non-machine-based information resources at least once every 3 months.
Persistently Complete Detection
Class B
Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.
Class C
Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.
Class D
Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.
Persistent Drift Detection
Class B
Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every month.
Class C
Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 14 days.
Class D
Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 7 days.
Persistent Sample Detection
Class B
Providers with Class B Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 7 days.
Class C
Providers with Class C Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 3 days.
Class D
Providers with Class D Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once per day.
Mitigation and Remediation Expectations
Class B
Providers with Class B Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
Class C
Providers with Class C Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
Class D
Providers with Class D Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the maximum timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
Remaining Vulnerabilities
Providers SHOULD mitigate or remediate remaining vulnerabilities during routine operations as determined necessary by the provider.
Vulnerability Evaluation and Reporting · VER
19 requirements, 0 verifiable by automated check.
Assume It's Automatable
Providers MUST assume the exploitation of vulnerabilities can be automated UNLESS they have evidence proving otherwise.
Evaluation Factors
Providers SHOULD consider at least the following factors when considering the context of the cloud service offering to evaluate detected vulnerabilities:
- Criticality: How important are the systems or information that might be impacted by the vulnerability?
- Reachability: How might a threat actor reach the vulnerability and how likely is that?
- Exploitability: How easy is it for a threat actor to exploit the vulnerability and how likely is that?
- Detectability: How easy is it for a threat actor to become aware of the vulnerability and how likely is that?
- Prevalence: How much of the cloud service offering is affected by the vulnerability?
- Privilege: How much privileged authority or access is granted or can be gained from exploiting the vulnerability?
- Proximate Vulnerabilities: How does this vulnerability interact with previously detected vulnerabilities, especially partially or fully mitigated vulnerabilities?
- Known Threats: How might already known threats leverage the vulnerability and how likely is that?
Evaluate False Positives
Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are false positive vulnerabilities.
Evaluate Internet-Reachability
Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are internet-reachable vulnerabilities.
FedRAMP focuses on internet-reachable (rather than internet-accessible) to ensure that any service that might receive a payload from the internet is prioritized if that service has a vulnerability that can be triggered by processing the data in the payload.
The simplest way to prevent exploitation of internet-reachable vulnerabilities is to intercept, inspect, filter, sanitize, reject, or otherwise deflect triggering payloads before they are processed by the vulnerable resource; once this prevention is in place the vulnerability should no longer be considered an internet-reachable vulnerability.
A classic example of an internet-reachable vulnerability on systems that are not typically internet-accessible is [SQL injection](https://en.wikipedia.org/wiki/SQL_injection), where an application stack behind a load balancer and firewall with no ability to route traffic to or from the internet can receive a payload indirectly from the internet that triggers the manipulation or compromise of data in a database that can only be accessed by an authorized connection from the application server on a private network.
Another simple example is the infamous Log4Shell (https://en.wikipedia.org/wiki/Log4Shell) vulnerability from 2021, where exploitation was possible via vulnerable internet-reachable resources deep in the application stack that were often not internet-accessible themselves.
Evaluate Exploitability
Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are likely exploitable vulnerabilities.
The simple reality is that most traditional vulnerabilities discovered by scanners or during assessment are not likely to be exploitable; exploitation typically requires an unrealistic set of circumstances that will not occur during normal operation. The likelihood of exploitation will vary depending on so many factors that FedRAMP will not recommend a specific framework for approaching this beyond these rules.
The proof, ultimately, is in the pudding - providers who regularly evaluate vulnerabilities as not likely exploitable without careful consideration are more likely to suffer from an adverse impact where the root cause was an exploited vulnerability that was improperly evaluated. If done recklessly or deliberately, such actions will have a negative impact on a provider's FedRAMP Certification.
Estimate Potential Agency Impact
Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to estimate the potential agency impact of exploitation on government customers AND assign one of the following Potential Agency Impact N-ratings (PAIN):
- N1: Exploitation could be expected to have minimal customer effects on one or more agencies that use the cloud service offering.
- N2: Exploitation could be expected to have narrow customer effects on one or more agencies that use the cloud service offering.
- N3: Exploitation could be expected to have a disruptive customer effect on one agency that uses the cloud service offering.
- N4: Exploitation could be expected to have a debilitating customer effect on one agency that uses the cloud service offering OR a disruptive customer effect on more than one federal agency that uses the cloud service offering.
- N5: Exploitation could be expected to have a debilitating customer effect on more than one agency that uses the cloud service offering.
Group Vulnerabilities
Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to identify logical groupings of affected information resources that may improve the efficiency and effectiveness of vulnerability response by consolidating further activity; FedRAMP Vulnerability Detection and Response rules are then applied to these consolidated groupings of vulnerabilities instead of each individual detected instance.
Accepted Vulnerability Info
Providers MUST include the following information on accepted vulnerabilities when reporting on vulnerability detection and response activity:
- Provider's internally assigned tracking identifier
- Time and source of the detection
- Time of completed evaluation
- Is it an internet-reachable vulnerability or not?
- Is it a likely exploitable vulnerability or not?
- Currently estimated Potential Agency Impact N-rating
- Explanation of why this is an accepted vulnerability
- Any supplementary information the provider determines will responsibly help federal agencies assess or mitigate the risk to their federal customer data within the cloud service offering resulting from the accepted vulnerability
High-Level Overviews
Providers SHOULD include high-level overviews of ALL vulnerability detection and response activities conducted during this period for the cloud service offering; this includes vulnerability disclosure programs, bug bounty programs, penetration testing, assessments, etc.
Responsible Disclosure
Providers MUST NOT irresponsibly disclose specific sensitive information about vulnerabilities that would likely lead to exploitation, but MUST disclose sufficient information for informed risk-based decision-making to all necessary parties.
This requirement will be superseded in the event of formal action related to an investigation or corrective action plan.
Persistent Reporting
Providers MUST report vulnerability detection and response activity (including persistent verification and validation) to all necessary parties persistently, summarizing ALL activity since the previous report; these reports are FedRAMP Certification Data and are subject to FedRAMP Certification Data Sharing rules.
Responsible Public Disclosure
Providers MAY responsibly disclose vulnerabilities publicly or with other parties if the provider determines doing so will NOT likely lead to exploitation.
Vulnerability Details
Providers MUST include the following information (if applicable) on detected vulnerabilities when reporting on vulnerability detection and response activity, UNLESS it is an accepted vulnerability:
- Provider's internally assigned tracking identifier
- Time and source of the detection
- Time of completed evaluation
- Is it an internet-reachable vulnerability or not?
- Is it a likely exploitable vulnerability or not?
- Historically and currently estimated Potential Agency Impact N-rating of exploitation
- Time and Potential Agency Impact N-rating of each completed and evaluated reduction in Potential Agency Impact N-rating
- Estimated time and target Potential Agency Impact N-rating of next reduction in Potential Agency Impact N-rating
- Is it currently or is it likely to become an overdue vulnerability or not? If so, explain.
- Any supplementary information the provider responsibly determines will help federal agencies assess or mitigate the risk to their federal customer data within the cloud service offering resulting from the vulnerability
- Final disposition of the vulnerability
Evaluate Vulnerabilities Quickly
Class B
Providers with Class B Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 7 days of detection.
Class C
Providers with Class C Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 5 days of detection.
Class D
Providers with Class D Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 2 days of detection.
Internet-Reachable Incidents
Class B
Providers with Class B Certifications MAY treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.
Class C
Providers with Class C Certifications SHOULD treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.
Class D
Providers with Class D Certifications SHOULD treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.
Mark Accepted Vulnerabilities
Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability.
Monthly Activity Report
Providers MUST report vulnerability detection and response activity to all necessary parties in a consistent format that is human readable at least monthly.
Historical Activity
Class B
Providers with Class B Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every month.
Class C
Providers with Class C Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 14 days.
Class D
Providers with Class D Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 7 days.
Non-Internet-Reachable Incidents
Class B
Providers with Class B Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.
Class C
Providers with Class C Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.
Class D
Providers with Class D Certifications SHOULD treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.
Stop assembling this by hand.
Zenibit tracks these requirements against your live infrastructure and publishes a trust center agencies can verify themselves. Get in touch.