FedRAMP Rev 5
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
FedRAMP: 3PAO Assessment and FedRAMP Marketplace
Third Party Assessment Organizations (3PAOs) are independent assessors accredited by the FedRAMP PMO + A2LA (American Association for Laboratory Accreditation). 3PAO accreditation requires: (a) ISO/IEC 17020:2012 compliance for inspection bodies; (b) FedRAMP-specific training + experience; (c) FedRAMP PMO + A2LA review + accreditation. 3PAOs conduct: initial assessment for FedRAMP authorization + annual ConMon assessments + assessment for significant changes + 3-year full re-assessment. Output: SAR + supporting evidence + recommendations. FEDRAMP MARKETPLACE is the public-facing FedRAMP authorization listing at marketplace.fedramp.gov - lists CSPs by authorization status (In Process + JAB Authorized + Agency Authorized + Ready) + baseline + agency sponsorship + 3PAO + FedRAMP impact level. CSPs achieve 'FedRAMP Ready' status (3PAO Readiness Assessment Report indicating likelihood of auth
- 3PAO engagement records
- ISO/IEC 17020 evidence
- FedRAMP Marketplace listing + ongoing maintenance
- 3PAO not FedRAMP-accredited
- Marketplace listing stale or inaccurate
- Authorization status not updated through significant changes
FedRAMP: Authorization Boundary, SSP, SAR, POA&M and System Documentation
The FedRAMP AUTHORIZATION BOUNDARY is the precise definition of the cloud system + all of its components subject to FedRAMP authorization. Documentation requirements: (a) SYSTEM SECURITY PLAN (SSP) - documents the cloud system + boundary + control implementation per NIST 800-53 Rev 5 baseline; (b) SECURITY ASSESSMENT REPORT (SAR) - prepared by an accredited 3PAO documenting the results of the security assessment; (c) PLAN OF ACTION AND MILESTONES (POA&M) - tracks open weaknesses + remediation plans + milestones; (d) BOUNDARY DIAGRAM with data-flow diagrams + asset inventory + interconnection inventory; (e) CONTINUOUS MONITORING PLAN (ConMon Plan); (f) INCIDENT RESPONSE PLAN (IRP); (g) CONFIGURATION MANAGEMENT PLAN (CMP); (h) CONTINGENCY PLAN; (i) PRIVACY IMPACT ASSESSMENT (PIA); (j) eAUTHENTICATION RISK ASSESSMENT; (k) others per FedRAMP PMO templates. The SSP is the central authorizatio
- FedRAMP authorization package + version control
- Boundary diagram + asset inventory + interconnection inventory
- Annual SSP review + update + 3PAO re-assessment
- Authorization boundary ambiguous or shifting
- SSP / SAR / POA&M out-of-date
- Boundary diagram missing data-flow or interconnections
FedRAMP Rev 5 supply chain risk management aligns with Executive Order 14028 + NIST SP 800-218 Secure Software Development Framework (SSDF). REQUIREMENTS: (a) SUPPLY CHAIN RISK MANAGEMENT POLICY + PLAN (NIST 800-53 Rev 5 SR family) + integration into the SSP; (b) SOFTWARE BILL OF MATERIALS (SBOM) for critical software + components per OMB M-22-18 + the FedRAMP 2024 Pre-market SBOM guidance + the NTIA SBOM Minimum Elements; (c) Software Provider Assurance via NIST SSDF attestation + supply-chain risk-management practices documented in the SSP; (d) Vulnerability Exploitability eXchange (VEX) documents for SBOM components; (e) Component-level monitoring for known vulnerabilities (CISA KEV Catalog) + sector-specific threat intelligence; (f) FOREIGN COMPONENT RESTRICTIONS - certain components from countries of concern restricted per the Countering CCP Software Act + Section 889 of the FY2019
- Supply chain risk management policy + plan
- SBOM repository + VEX documents
- CISA KEV monitoring + remediation
- Section 889 + countries-of-concern screening
- Supply chain risk management absent or minimal
- SBOM not maintained or VEX missing
- Section 889 + countries-of-concern screening not implemented
FedRAMP: Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters
FedRAMP defines four baselines based on FIPS 199 system impact level: (a) LI-SAAS (Low Impact SaaS) - low-impact SaaS with no sensitive data + 156 controls + accelerated authorization path; (b) LOW (Low Impact) - 156 controls; (c) MODERATE (Moderate Impact) - 323 controls + applies to most federal cloud workloads handling Controlled Unclassified Information (CUI); (d) HIGH (High Impact) - 417 controls + applies to mission-critical + national-security-related cloud workloads. The baselines derive from NIST SP 800-53 Rev 5 + FedRAMP-specific parameter values (e.g. password lengths + cryptographic algorithm strengths + audit-retention periods). Baseline selection is the CSP's responsibility based on the agencies it will serve + the data classification it will process. FedRAMP Moderate is the most common baseline + applies to most federal cloud services.
- Baseline selection rationale documented
- FedRAMP parameter compliance evidence
- Cross-reference to FedRAMP Moderate + High control sets
- Baseline selection without rationale
- FedRAMP parameter values not configured (e.g. password length too short, audit retention too short)
- CSP attempting to operate at Low when Moderate or High is required by the agencies it serves
FedRAMP Rev 5 PII handling + privacy controls operationalise: (a) the PRIVACY ACT OF 1974 (5 USC 552a) + the E-Government Act of 2002; (b) NIST SP 800-53 Rev 5 PT family (PT-1 to PT-7 - PII processing transparency + minimisation + retention + dispute + breach response + opt-out); (c) FIPS 199 / 200 + NIST 800-122 for protecting PII; (d) the System of Records Notice (SORN) for federal record systems containing PII; (e) the Privacy Impact Assessment (PIA) requirement under E-Gov Act Section 208. FEDRAMP PRIVACY-SPECIFIC REQUIREMENTS: (a) PIA + SORN preparation as part of the authorization package; (b) PII minimisation + retention per agency policy; (c) PII breach notification per agency + US-CERT + OMB M-17-12 (Breach Response Guidance); (d) GAO + Inspector General audit-readiness for PII handling; (e) AGENCY-SPECIFIC PII rules (HIPAA for HHS + IRS + Census etc.) flow through to FedRAMP-au
- PIA + SORN documentation
- PT family controls implementation
- Breach response procedure
- Agency-specific PII rules cross-reference
- PII minimisation not enforced
- Breach response slow or incomplete
- Agency-specific PII rules not flowed-through to CSP operations
FedRAMP: Continuous Monitoring (ConMon) and Significant Change Requests
Continuous Monitoring (ConMon) is the post-authorization monitoring + reporting regime. Required activities: (a) MONTHLY vulnerability scanning + reporting via FedRAMP secure reporting portal; (b) MONTHLY POA&M update; (c) ANNUAL SECURITY ASSESSMENT by a 3PAO covering subset of NIST 800-53 controls (full assessment every 3 years on re-authorization); (d) QUARTERLY operating-system + database + web-application vulnerability scans; (e) HIGH-IMPACT VULNERABILITY remediation within 30 days; MODERATE within 90 days; LOW within 180 days (FedRAMP timelines per Rev 5); (f) annual penetration testing including authenticated + insider threat + external + internal + social engineering testing per FedRAMP PMO requirements; (g) annual review of the SSP + ConMon Plan + IRP + Contingency Plan + other authorization-package documents. SIGNIFICANT CHANGE REQUEST (SCR) workflow: CSPs must submit an SCR for
- Monthly vuln scan reports
- Annual 3PAO assessment evidence
- POA&M updates within SLA
- SCR submission + PMO approval records
- Monthly vuln scanning gap
- Annual assessment slips beyond 12 months
- 30/90/180-day remediation SLA missed
- SCR not submitted for significant changes
FedRAMP incident-reporting regime: CSPs must report incidents to: (a) the FedRAMP PMO; (b) agency customer points-of-contact; (c) US-CERT (CISA) per the FISMA incident-reporting requirements. INCIDENT TYPES requiring reporting: confirmed incidents affecting CSP system + customer agency data + Personally Identifiable Information (PII) + Controlled Unclassified Information (CUI) + cryptographic-system compromise + significant ConMon-detected anomalies. INCIDENT REPORTING TIMELINES per FedRAMP guidance + the 2024 OMB M-24-15: initial notification within 1 hour of confirmation for high-severity incidents (vs the prior 4-hour requirement); status updates + final reports per FedRAMP PMO + agency expectations + the CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act of 2022) Final Rule (effective 2026) which extends to FedRAMP-authorized CSPs serving critical infrastructure agencie
- IR procedure aligned with FedRAMP + US-CERT + agency reporting
- 1-hour notification capability test
- CIRCIA coverage assessment
- Annual IRP review + tabletop testing
- IR procedure missing FedRAMP-specific reporting paths
- Notification slow beyond 1-hour SLA
- CIRCIA coverage not assessed
- IRP not annually reviewed or tested
FedRAMP: Coordination with FISMA, NIST RMF, NIST 800-53 Rev 5 and Status
FedRAMP Rev 5 is operationalised against NIST SP 800-53 Revision 5 (published September 2020) which contains 1,189 controls + control enhancements across 20 families (AC + AT + AU + CA + CM + CP + IA + IR + MA + MP + PE + PL + PM + PS + PT + RA + SA + SC + SI + SR). FedRAMP-SPECIFIC OVERLAY PARAMETERS in the FedRAMP Rev 5 Baselines mandate specific values for selected parameters (e.g. password length minimum + cryptographic algorithm strength + audit retention period + access review frequency). The FedRAMP MODERATE BASELINE (323 controls verified in the graph as 'FedRAMP Moderate' framework) covers most federal cloud workloads + the FedRAMP HIGH BASELINE (417 controls verified in the graph as 'FedRAMP High' framework) covers mission-critical workloads. The substantive control content is in those baseline-specific frameworks; this Program-level reference covers the authorization process +
- NIST 800-53 Rev 5 baseline compliance file
- FedRAMP overlay parameter compliance
- Cross-reference to FedRAMP Moderate + High framework codes
- Tracking of NIST 800-53 Rev 6 + FedRAMP Rev 6 pipeline
- NIST 800-53 Rev 5 + FedRAMP overlay parameters confused
- FedRAMP Moderate / High distinction unclear
- NIST 800-53 Rev 6 + FedRAMP Rev 6 transition not anticipated
This corpus node tracks FedRAMP at the PROGRAM-LEVEL reference covering authorization paths + PMO + ConMon + 3PAO + Marketplace + M-24-15 modernization + StateRAMP / GovRAMP coordination. SUBSTANTIVE CONTROL CONTENT is in the separate FedRAMP Moderate (323 controls verified) + FedRAMP High (417 controls verified) framework nodes in the graph - each verified against NIST 800-53 Rev 5 OSCAL. Status: REFERENCED - the FedRAMP Rev 5 Program-level reference is publicly known + grounded against the FedRAMP PMO publications + OMB M-24-15 + FedRAMP Baseline documents (publicly available on fedramp.gov). Future evolution: M-24-15 implementation through 2025-2026; FedRAMP 2.0 automation + continuous assurance; permanent authorization + reciprocity; integration with StateRAMP + GovRAMP + CMMC; transition to NIST 800-53 Rev 6 anticipated 2026-2027 + FedRAMP Rev 6 12-24 months later; coordination with
- Tracking of M-24-15 milestones
- FedRAMP Moderate / High baseline implementation status
- NIST 800-53 Rev 6 + FedRAMP Rev 6 readiness
- Compliance program tied to pre-M-24-15 timelines + processes
- FedRAMP Moderate / High baseline implementation gaps
- Rev 6 transition not anticipated
FedRAMP: OMB M-24-15 Modernization, FedRAMP 2.0 and Coordination with StateRAMP / GovRAMP
OMB Memorandum M-24-15 'Modernizing the Federal Risk and Authorization Management Program (FedRAMP)' issued July 2024 launches FedRAMP 2.0 modernization. KEY PROVISIONS: (a) streamlined authorization process - reduce 12+ month JAB authorization to less than 12 months for most CSPs through automation + reciprocity + Trusted Internet Connections-3 (TIC 3.0) coordination; (b) AUTOMATION + CONTINUOUS ASSURANCE - move from point-in-time assessments to continuous monitoring with automated assurance evidence; (c) PERMANENT FedRAMP authorization (subject to ongoing ConMon) replacing the prior expiration-and-renewal model; (d) SHARED ARTEFACTS + REPOSITORIES across agencies + StateRAMP + GovRAMP reducing duplicate effort; (e) FedRAMP BOARD restructure including chartered membership + governance + transparency improvements; (f) integration with the Cybersecurity Executive Orders (EO 14028 + EO 141
- Tracking of M-24-15 implementation milestones
- Continuous assurance + automation readiness
- StateRAMP / GovRAMP reciprocity engagement
- No tracking of M-24-15 modernization affecting authorization timeline + scope
- Continuous assurance + automation not adopted
- Shared-artefact reciprocity not leveraged
STATERAMP + GovRAMP are FedRAMP-aligned authorization programs for state + local + tribal governments. STATERAMP (https://stateramp.org/) - non-profit organization + administers state-government cloud authorization mirroring FedRAMP processes + uses FedRAMP-compatible baselines (Low + Moderate + High) + adopts 3PAO assessment. GOVRAMP (https://www.govramp.org/) - similar program targeting cross-jurisdictional government cloud authorization. RECIPROCITY: CSPs with FedRAMP Moderate or High authorization are typically eligible for StateRAMP / GovRAMP fast-track + the M-24-15 modernization emphasises reciprocity. CROSS-AUTHORIZATION PATHWAYS: CSPs may pursue FedRAMP first + then leverage to StateRAMP / GovRAMP + vice versa. The Cybersecurity Maturity Model Certification (CMMC) for DOD contractors is separate but coordinates with FedRAMP through the DOD JAB review of FedRAMP-authorized CSPs s
- StateRAMP / GovRAMP authorization status if applicable
- Reciprocity engagement records
- CMMC alignment where DOD contractor
- State / local government cloud use without StateRAMP / GovRAMP authorization
- Reciprocity not pursued
- CMMC requirements not coordinated with FedRAMP
FedRAMP: Program, Authorization Paths and PMO Governance
FedRAMP was established in 2011 by OMB Memorandum M-11-30 + implementing FISMA for cloud services used by US federal agencies. The FedRAMP Program Management Office (PMO) is housed within the General Services Administration (GSA). Two authorization paths exist: (a) JAB AUTHORIZATION - the Joint Authorization Board comprises DOD + DHS + GSA + reviews CSPs against the highest risk + most-utilised cloud services + issues a Provisional Authority to Operate (P-ATO); (b) AGENCY AUTHORIZATION - any federal agency may sponsor a CSP through the FedRAMP authorization process + issue an agency Authority to Operate (ATO) recognised across the federal government once accepted via the FedRAMP Marketplace. Both paths require: completion of the FedRAMP Authorization Package (SSP + SAR + POA&M + ConMon Plan + Inventory + Boundary Diagram + Configuration Management + Incident Response + others); 3PAO asse
- FedRAMP authorization path determination
- PMO + JAB / Agency engagement records
- Marketplace listing
- Federal cloud use without FedRAMP authorization
- Authorization path not formally selected
- PMO engagement informal without records
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FedRAMP Rev 5 framework page.