Skip to content

Evidence request lists

NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

System Protection and Communications

3.13.1
Boundary Protection Assessment

Assess implementation of boundary protections to monitor and control communications at external system boundaries.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for 3.13.1 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing 3.13.1 scope across data, control, and management planes for the cloud service offering
  • Trusted Internet Connection (TIC) alignment evidence including managed interface inventory
  • Web application firewall and DDoS protection configuration screenshots
  • Deny by default egress filtering rules with documented exceptions
Where this commonly fails
  • Managed interface inventory missing recently added SaaS interconnection
  • Egress filtering set to permit by default with broad exception
  • Web application firewall in detect only mode for production
FEDRAMP-CM-1
Configuration Management Policy

Develop, document, and disseminate configuration management policy per FedRAMP parameters.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for FEDRAMP-CM-1 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing FEDRAMP-CM-1 scope across data, control, and management planes for the cloud service offering
  • Approved policy document with annual review attestations from CISO or AO
  • Procedures dissemination evidence to system owners and 3PAO with version control log
  • FedRAMP control parameter table showing organization-defined values aligned to baseline
Where this commonly fails
  • Policy exists but not disseminated to all in scope roles per FedRAMP parameter
  • Annual review attestation missing for two consecutive cycles
  • FedRAMP parameter values left at NIST defaults instead of FedRAMP overlay
FEDRAMP-CM-2
Baseline Configuration

Develop, document, and maintain a current baseline configuration of the information system. FedRAMP requires CIS benchmark or equivalent.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for FEDRAMP-CM-2 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing FEDRAMP-CM-2 scope across data, control, and management planes for the cloud service offering
  • Hardened baseline configuration documents per CIS benchmark or DISA STIG with FedRAMP deviations
  • Infrastructure as code repository commits showing baseline enforcement via Terraform or CloudFormation
  • Baseline drift detection reports with remediation tickets
Where this commonly fails
  • Baseline drift undetected because compliance scanning omits new resource types
  • Configuration exceptions registered but never reviewed for sunset
  • Production hosts diverge from infrastructure as code baseline without change record
FEDRAMP-CM-6
Configuration Settings

Establish and document configuration settings using security configuration checklists. FedRAMP defines specific security configuration requirements.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for FEDRAMP-CM-6 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing FEDRAMP-CM-6 scope across data, control, and management planes for the cloud service offering
  • Configuration settings library aligned to CIS or USGCB with FedRAMP parameter overlays
  • Compliance scan results showing settings enforcement across production fleet
  • Configuration exception register with risk acceptance signed by AO
Where this commonly fails
  • Baseline drift undetected because compliance scanning omits new resource types
  • Configuration exceptions registered but never reviewed for sunset
  • Production hosts diverge from infrastructure as code baseline without change record
FEDRAMP-CP-9
System Backup

Conduct backups of system-level, user-level, and system documentation information per FedRAMP-defined frequencies.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for FEDRAMP-CP-9 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing FEDRAMP-CP-9 scope across data, control, and management planes for the cloud service offering
  • Backup schedule documentation meeting FedRAMP daily incremental and weekly full minimums
  • Backup integrity test results with documented restore validation per quarter
  • Geographically separated backup storage attestation with encryption at rest evidence
Where this commonly fails
  • Restore tests run on schedule but only against non production environment
  • Backup encryption keys colocated with backup storage region
  • Documentation backup omitted, only data restore tested
FEDRAMP-SC-1
System and Communications Protection Policy

Develop, document, and disseminate system and communications protection policy per FedRAMP parameters.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for FEDRAMP-SC-1 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing FEDRAMP-SC-1 scope across data, control, and management planes for the cloud service offering
  • Approved policy document with annual review attestations from CISO or AO
  • Procedures dissemination evidence to system owners and 3PAO with version control log
  • FedRAMP control parameter table showing organization-defined values aligned to baseline
Where this commonly fails
  • Policy exists but not disseminated to all in scope roles per FedRAMP parameter
  • Annual review attestation missing for two consecutive cycles
  • FedRAMP parameter values left at NIST defaults instead of FedRAMP overlay
FEDRAMP-SC-12
Cryptographic Key Establishment and Management

Establish and manage cryptographic keys using NIST-approved key management technology and processes.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for FEDRAMP-SC-12 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing FEDRAMP-SC-12 scope across data, control, and management planes for the cloud service offering
  • Approved policy document with annual review attestations from CISO or AO
  • Procedures dissemination evidence to system owners and 3PAO with version control log
  • FedRAMP control parameter table showing organization-defined values aligned to baseline
Where this commonly fails
  • Non FIPS validated cryptographic library in scope for sensitive data
  • Key rotation cadence undocumented for envelope encryption keys
  • TLS 1.0 or 1.1 still permitted on internal east west traffic
FEDRAMP-SC-13
Cryptographic Protection

Implement FIPS 140-2/140-3 validated cryptography to protect the confidentiality and integrity of information.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for FEDRAMP-SC-13 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing FEDRAMP-SC-13 scope across data, control, and management planes for the cloud service offering
  • Approved policy document with annual review attestations from CISO or AO
  • Procedures dissemination evidence to system owners and 3PAO with version control log
  • FedRAMP control parameter table showing organization-defined values aligned to baseline
Where this commonly fails
  • Non FIPS validated cryptographic library in scope for sensitive data
  • Key rotation cadence undocumented for envelope encryption keys
  • TLS 1.0 or 1.1 still permitted on internal east west traffic
FEDRAMP-SC-28
Protection of Information at Rest

Protect the confidentiality and integrity of information at rest. FedRAMP requires FIPS-validated encryption for all CUI/sensitive data at rest.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for FEDRAMP-SC-28 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing FEDRAMP-SC-28 scope across data, control, and management planes for the cloud service offering
  • Encryption at rest configuration evidence for object storage, block volumes, and databases using FIPS validated modules
  • Tenant data isolation attestation including envelope encryption design
  • Key custody segregation showing customer managed key option where applicable
Where this commonly fails
  • Managed interface inventory missing recently added SaaS interconnection
  • Egress filtering set to permit by default with broad exception
  • Web application firewall in detect only mode for production
FEDRAMP-SC-7
Boundary Protection

Monitor and control communications at the external managed interfaces of the system and at key internal managed interfaces within the system.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for FEDRAMP-SC-7 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing FEDRAMP-SC-7 scope across data, control, and management planes for the cloud service offering
  • Trusted Internet Connection (TIC) alignment evidence including managed interface inventory
  • Web application firewall and DDoS protection configuration screenshots
  • Deny by default egress filtering rules with documented exceptions
Where this commonly fails
  • Managed interface inventory missing recently added SaaS interconnection
  • Egress filtering set to permit by default with broad exception
  • Web application firewall in detect only mode for production
FEDRAMP-SC-8
Transmission Confidentiality and Integrity

Protect the confidentiality and integrity of transmitted information. FedRAMP requires FIPS-validated encryption for all data in transit.

Artefacts an auditor will ask for
  • FedRAMP SSP control implementation narrative for FEDRAMP-SC-8 including FedRAMP parameter values and inheritance from leveraged authorizations
  • Authorization boundary diagram showing FEDRAMP-SC-8 scope across data, control, and management planes for the cloud service offering
  • TLS 1.2 minimum enforcement evidence with cipher suite hardening configuration
  • Internal east west encryption attestation for service mesh or VPC traffic
  • Certificate inventory with renewal automation and pinning policy
Where this commonly fails
  • Managed interface inventory missing recently added SaaS interconnection
  • Egress filtering set to permit by default with broad exception
  • Web application firewall in detect only mode for production
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements framework page.