FedRAMP Rev 5
What is FedRAMP Rev 5?
FedRAMP is the US Federal Risk and Authorization Management Program established in 2011 by OMB Memorandum M-11-30 + implementing the Federal Information Security Management Act (FISMA) for cloud services used by US federal agencies. FedRAMP Rev 5 is the current version operating against NIST SP 800-53 Revision 5 + the FedRAMP Rev 5 Baselines (Low + Moderate + High + LI-SaaS) with FedRAMP-specific overlay parameters. It comprises 12 controls organised across 7 domains, and applies in the United States.
How FedRAMP Rev 5 maps to other frameworks
All 12 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 7 domains FedRAMP Rev 5 groups its controls into
Where FedRAMP Rev 5 overlaps with the standards you already hold
What FedRAMP Rev 5 means in your sector
What FedRAMP Rev 5 means for your job
Questions people ask about FedRAMP Rev 5
What is FedRAMP Rev 5?
How many controls does FedRAMP Rev 5 have?
Where does FedRAMP Rev 5 apply?
What frameworks does FedRAMP Rev 5 map to?
How do I get started with FedRAMP Rev 5 compliance?
Query FedRAMP Rev 5 programmatically
FedRAMP Rev 5, its 12 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
FedRAMP Rev 5 API reference and MCP config →What FedRAMP Rev 5 requires, control by control
Each page carries the requirement text for one FedRAMP Rev 5 control and what an assessor expects to see as evidence.
- FEDRAMP-BASELINES FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters
- FEDRAMP-BOUNDARY Authorization Boundary, SSP, SAR, POA&M documentation
- FEDRAMP-CONMON Continuous Monitoring (ConMon) and Significant Change Requests
- FEDRAMP-INCIDENTREPORTING FedRAMP incident reporting to PMO and US-CERT
- FEDRAMP-PII-PRIVACY FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act)
- FEDRAMP-SUPPLYCHAIN-SBOM FedRAMP supply chain risk management + SBOM (per EO 14028 + NIST 800-218 SSDF)
How ready are you for FedRAMP Rev 5?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.