FedRAMP Moderate
What is FedRAMP Moderate?
FedRAMP Moderate baseline. Federal cloud service authorization built on NIST SP 800-53 Rev 5 with FedRAMP-specific parameters.. It comprises 238 controls organised across 1 domains, and applies in the United States.
How FedRAMP Moderate maps to other frameworks
All 238 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 1 domains FedRAMP Moderate groups its controls into
Frameworks that share controls with FedRAMP Moderate
Each of these has at least one control mapped to a control in FedRAMP Moderate. The number is how many FedRAMP Moderate controls are shared, counted from the mapping graph.
Implementation guides for frameworks that overlap FedRAMP Moderate
Training on frameworks that overlap FedRAMP Moderate
There is no course on FedRAMP Moderate itself. These cover frameworks that share controls with it, so the material carries across even though the standard named is different.
Where FedRAMP Moderate overlaps with the standards you already hold
What FedRAMP Moderate means in your sector
What FedRAMP Moderate means for your job
Questions people ask about FedRAMP Moderate
What is FedRAMP Moderate?
How many controls does FedRAMP Moderate have?
Where does FedRAMP Moderate apply?
What frameworks does FedRAMP Moderate map to?
How do I get started with FedRAMP Moderate compliance?
Query FedRAMP Moderate programmatically
FedRAMP Moderate, its 238 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
FedRAMP Moderate API reference and MCP config →What FedRAMP Moderate requires, control by control
Each page carries the requirement text for one FedRAMP Moderate control and what an assessor expects to see as evidence.
- AC-1 Policy and Procedures
- AC-11 Device Lock
- AC-12 Session Termination
- AC-14 Permitted Actions Without Identification or Authentication
- AC-17 Remote Access
- AC-18 Wireless Access
- AC-19 Access Control for Mobile Devices
- AC-2 Account Management
- AC-20 Use of External Systems
- AC-21 Information Sharing
How much of another standard FedRAMP Moderate already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ACSC Essential Eight to FedRAMP Moderate crosswalk
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) to FedRAMP Moderate crosswalk
- FedRAMP Moderate to APEC Cross-Border Privacy Rules (CBPR) System crosswalk
- APRA CPS 230 Operational Risk Management to FedRAMP Moderate crosswalk
- APRA CPS 234 to FedRAMP Moderate crosswalk
- ASD Strategies to Mitigate Cyber Security Incidents to FedRAMP Moderate crosswalk
- Australia Consumer Data Right - Banking (CDR) to FedRAMP Moderate crosswalk
- Australia My Health Records Act 2012 to FedRAMP Moderate crosswalk
How ready are you for FedRAMP Moderate?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.