Controls
We take security, compliance, and privacy seriously. Explore our certifications, reports, and policies in one place.
⌘KAFC-CSO-CRA
PassAFC-CSO-INB
PassAFC-CSO-NOC
PassAFC-CSO-RCV
PassCCM-OCR-AVL
PassCCM-OCR-NRD
PassCCM-QTR-MTG-A
PassProviders with Class A Certifications MAY host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.
CDS-CSO-AVR-A
PassProviders with Class A Certifications SHOULD maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service SHOULD be available even if the primary cloud service offering is unavailable.
CDS-CSO-IRP
PassCDS-CSO-PSM-A
PassProviders with Class A Certifications MAY supply per-service FedRAMP Certification materials.
CDS-CSO-PUB
PassCDS-CSO-SVC
PassCDS-CSO-UTC
PassCDS-UTC-AAD
PassCMU-CSO-CMD
PartialCMU-CSO-UVM-A
PassProviders with Class A Certifications MAY use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
CPO-CSO-MTD
PassCPO-CSO-OSA
PassProviders seeking Class [ A | B | C | D ] Certification [ MAY | MUST ] also include [ an | the ] overall summary of their FedRAMP independent [ assessment | assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), ] in their Certification Package Overview.
CPO-CSO-OVR
PassCPO-CSX-CPM-A
PassProviders with 20x Class A Certifications SHOULD persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 3 months.
FRC-APP-AFC
PassProviders MUST complete the FedRAMP Certification Application Form in full to request an initial assessment by FedRAMP.
FRC-APP-FCP
PassProviders MUST supply a fresh initial FedRAMP Certification Package that shows the current status of the cloud service offering as verified and validated by the provider within the previous 7 days.
FRC-APP-FIA-A
PassProviders seeking Class A Certification MAY supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.
FRC-APP-MLF
PassProviders MUST be listed in the FedRAMP Marketplace before applying for FedRAMP Certification, including:
• FedRAMP Marketplace: MKT-CSO-MLR (Marketplace Listing Requirements),
• FedRAMP Marketplace: MKT-CSO-PML (Provider Marketplace Listing Requests)
• FedRAMP Marketplace: MKT-IIP-AGU (Agency Use Cases)
• FedRAMP Marketplace: MKT-IIP-DCP (Demonstrating Continuous Progress)
FRC-APP-NTP
PassProviders MUST NOT use a third party to apply for a FedRAMP Certification on their behalf; this includes independent assessment services.
• FedRAMP previously allowed independent assessment services to submit applications on behalf of providers, but this caused confusion about who was responsible for the application and the information in it. Providers should apply directly to ensure clear accountability.
• Providers may use third parties to help them prepare their application and assessment materials for submission.
FRC-APP-USA
PassProviders MAY freshen a stale initial independent verification and validation assessment by having a FedRAMP Recognized independent assessment service review any changes between the original assessment and the current status of the cloud service offering in place of a full re-assessment, UNLESS the stale assessment is more than 9 months old.
FRC-CCL-DCC
PassProviders MUST apply for a new FedRAMP Certification to downgrade their Certification Class.
• Downgrade paths include moving from D to C, B, or A; C to B or A; or B to A.
• FRC-CCL-DNP (Downgrade Notification Period) applies - please DO NOT downgrade Certification Class with providing advance notification to all necessary parties!
FRC-CCL-DNP
PassProviders SHOULD notify all necessary parties at least 120 days in advance of an intended downgrade or cancellation of FedRAMP Certification.
FRC-CCL-UCC
PassProviders MUST apply for a new FedRAMP Certification to upgrade their Certification Class; all applicable requirements MUST be met in advance.
• Upgrade paths include moving from A to B, C, or D; B to C or D; and C to D.
• The preferred path is to incrementally update the implementation and assurance commitments within the current Certification Class until the provider has met all requirements for the target Certification Class, then apply for the new Certification Class.
FRC-CLA-ASF
PassProviders seeking a FedRAMP Class A Certification MUST have completed a certification or equivalent process, including an independent assessment if applicable, from one of the following alternative security frameworks within the past 12 months:
• FedRAMP Rev5 (including FedRAMP Ready) at any historical Impact Level
• SOC 2 Type II
• GovRAMP at any Impact Level
FRC-CLA-EAM
PassProviders seeking a FedRAMP Class A Certification MUST supply the following materials from their alternative security framework assessment to all necessary parties:
• SOC 2 Type II: Complete report, bridge or gap letter (if applicable), verified audit engagement documentation, estimated schedule for upcoming report, supplemental compliance evidence (if applicable)
• FedRAMP Ready: Readiness Assessment Report, Security Assessment Plan, and any other materials required by FedRAMP.
• GovRAMP: Readiness Assessment Report, Security Assessment Plan, and any other materials required by GovRAMP.
FRC-CLA-IVV
PassProviders seeking a FedRAMP Class A Certification MAY have the FedRAMP Certification Package independently verified and validated by a FedRAMP Recognized assessor before submission to FedRAMP.
FRC-CLA-MFR
PassProviders seeking a Class A FedRAMP Certification MUST address all rules in this FedRAMP Class A Certification subset (FRC-CLA) AND the following additional FedRAMP Class A rules; the appropriate artifacts or information mapping for all rules MUST be supplied in the FedRAMP Certification Package.
• FedRAMP Certification: FRC-CSO-PKG (FedRAMP Certification Package)
• FedRAMP Certification: FRC-CSO-JSN (FedRAMP JSON Schemas)
• FedRAMP Certification: FRC-CSO-POP (Pick One Program Certification Type)
• Minimum Assessment Scope: MAS-CSO-IIR (Identify Information Resources)
• Certification Data Sharing: CDS-CSO-PUB (Public Information)
• Certification Data Sharing: CDS-CSO-UTC (Use Trust Centers)
• Certification Data Sharing: CDS-UTC-AAD (Agency Access Denial)
• Certification Data Sharing: CDS-CSO-AVR (Availability Reporting)
• Addressing FedRAMP Communication: AFC-CSO-INB (Maintain a FedRAMP Security Inbox)
• Addressing FedRAMP Communication: AFC-CSO-RCV (Receive Email Without Disruption)
• Addressing FedRAMP Communication: AFC-CSO-CRA (Complete Required Actions)
• Incident Evaluation and Communication: IEC-CSO-EFR (Evaluate FedRAMP Reportability)
• Incident Evaluation and Communication: IEC-CSO-FIR (Final Incident Report)
• Vulnerability Detection and Response: VDR-CSO-DET (Vulnerability Detection)
• Collaborative Continuous Monitoring: CCM-OCR-AVL (Report Availability)
• Collaborative Continuous Monitoring: CCM-OCR-NRD (Next Report Date)
• Independent Verification and Validation: IVV-CSX-AIA (Annual Independent Assessments for 20x)
• Independent Verification and Validation: IVV-CSF-AIA (Annual Independent Assessments for Rev5)
• Key Security Indicators: KSI-CMT-LMC (Logging Changes)
• Key Security Indicators: KSI-CNA-RNT (Restricting Network Traffic)
• Key Security Indicators: KSI-CED-RAT (Reviewing All Training)
• Key Security Indicators: KSI-IAM-AAM (Automating Account Management)
• Key Security Indicators: KSI-IAM-APM (Adopting Passwordless Methods)
• Key Security Indicators: KSI-INR-RIR (Reviewing Incident Response Procedures)
• Key Security Indicators: KSI-SVC-SIN (Securing Information)
FRC-CLA-OFR
PassProviders seeking a Class A FedRAMP Certification MAY address the following additional optional FedRAMP Class A rules (if applicable):
• Collaborative Continuous Monitoring: CCM-QTR-MTG (Quarterly Review Meeting)
• Certification Data Sharing: CDS-CSO-PSM (Per-Service Certification Materials)
• Cryptographic Module Use: CMU-CSO-UVM (Using Validated Cryptographic Modules)
• FedRAMP Certification: FRC-APP-FIA (Fresh Independent Assessment)
• Independent Verification and Validation: IVV-CSO-FIA (FedRAMP Independent Assessments)
• Security Decision Record: SDR-CSX-KMT (Key Security Indicator Metrics)
• Vulnerability Evaluation and Reporting: VER-TFR-IRI (Internet-Reachable Incidents)
• Vulnerability Evaluation and Reporting: VER-TFR-MRH (Historical Activity)
• Vulnerability Evaluation and Reporting: VER-TFR-NRI (Non-Internet-Reachable Incidents)
FRC-CLA-RFR
PassProviders seeking a Class A FedRAMP Certification SHOULD address the following additional recommended FedRAMP Class A rules (if applicable):
• Certification Data Sharing: CDS-CSO-AVR (Availability Reporting)
• Certification Package Overview: CPO-CSF-CPM (Certification Package Maintenance for Rev5)
• Certification Package Overview: CPO-CSX-CPM (Certification Package Maintenance for 20x)
• Incident Evaluation and Communication: IEC-CSO-IIR (Initial Incident Report)
• Incident Evaluation and Communication: IEC-CSO-OIR (Ongoing Incident Reports)
• Vulnerability Detection and Response: VDR-TFR-MVX (Persistent Machine Verification and Validation for 20x)
• Vulnerability Detection and Response: VDR-TFR-PCD (Persistently Complete Detection)
• Vulnerability Detection and Response: VDR-TFR-PDD (Persistent Drift Detection)
• Vulnerability Detection and Response: VDR-TFR-PSD (Persistent Sample Detection)
• Vulnerability Detection and Response: VDR-TFR-PVR (Mitigation and Remediation Expectations)
• Vulnerability Evaluation and Reporting: VER-TFR-EVU (Evaluate Vulnerabilities Quickly)
FRC-CSO-FCP
PassProviders MUST identify a target FedRAMP Certification Profile and apply all relevant FedRAMP Practices to the cloud service offering.
FRC-CSO-JSN
PassProviders MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule.
FRC-CSO-MRA
PassProviders MUST maintain responsibility and accountability for the accuracy and completeness of all information in the FedRAMP Certification Package, especially when they engage a third party (such as an independent assessor, advisory service, or external tools) to supply information on their behalf.
FRC-CSO-PKG
PassProviders seeking a Certification MUST supply a complete FedRAMP Certification Package to FedRAMP for initial certification; the FedRAMP Certification Package MUST include at least the following information:
• A Certification Package Overview
• A Security Decision Record
• A real or example Ongoing Certification Report following CCM-OCR-AVL (Report Availability)
FRC-CSO-POP
PassProviders MUST NOT seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering; pick one type.
FRC-CSX-MOT-A
PassProviders seeking 20x Class A Certification MAY supply historical metrics for Key Security Indicators.
FRC-CSX-VVK-A
PassProviders seeking 20x Class A Certification MAY implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators.
FRC-CSX-VVR-A
PassProviders seeking 20x Class A Certification MAY implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.
IEC-CSO-DPR
PassIEC-CSO-EFI
PassIEC-CSO-EFR
PassIEC-CSO-FIR-A
PassProviders with Class A Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.
IEC-CSO-IIR-A
PassProviders with Class A Certifications SHOULD responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:
• Contact information for the federal incident response coordinator
• Provider's internally assigned tracking identifier
• Description of the incident
• Timeline of the incident, including start time, time and source of detection, time of completed FedRAMP Reportable Incident evaluation, and other major incident milestones determined by the provider
• Historically and currently estimated Potential Agency Impact N-rating (PAIN) of the incident, including an explanation of the evaluation following the requirements in IEC-CSO-EFI (Estimate Federal Impact) (if applicable)
• Functional impact to federal agency customers (include impact to confidentiality and/or integrity and the impacted federal customer data types)
• Estimated recovery plan, milestones, and timelines
• List of likely affected customer agencies
IEC-CSO-OIR-A
PassProviders with Class A Certifications SHOULD responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:
• Observed incident activity
• Indicators of compromise
• Related Common Vulnerabilities and Exposures (CVE) identifier (if applicable)
• Root cause
• Response and recovery activities
IVV-CSO-FIA-A
PassProviders with Class A Certifications MAY persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.
IVV-CSO-ICP
PassIVV-CSX-AIA-A
PassProviders with 20x Class A Certifications MUST meet the expectations of their underlying alternative security framework as part of their persistent independent verification and validation assessment.
KSI-CED-RAT
PassThe effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.
KSI-CMT-LMC
PassModifications to the cloud service offering are logged and monitored.
KSI-CNA-RNT
PassMachine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.
KSI-IAM-AAM
PassThe lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.
KSI-IAM-APM
PartialSecure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.
KSI-INR-RIR
PassThe effectiveness of documented incident response procedures is persistently reviewed.
KSI-SVC-SIN
PartialInformation is encrypted or otherwise secured from unwanted access or modification.
MAS-CSO-FLO
PassMAS-CSO-IIR
PassMAS-CSO-TPR
PassMKT-CSO-MLR
PassProviders MUST address at least these FedRAMP rules to apply for a new FedRAMP Marketplace listing OR to request updates to an existing listing:
• Certification Data Sharing: CDS-CSO-PUB (Public Information)
MKT-CSO-PML
PassProviders MUST notify FedRAMP using the FedRAMP Marketplace Providing Listing Request Form to request a listing in the FedRAMP Marketplace.
MKT-IIP-AGU
PassProviders MUST demonstrate that a cloud service offering is intended for one of the following use cases:
• Direct Use: The product will be used directly by agency customers for integration into a federal information system that falls within the scope of 44 USC § 3506 and will receive an agency Authorization to Operate.
• Indirect Use: The product will be included as a third-party information resource in other cloud service offerings that are directly used by agency customers.
MKT-IIP-DCP
PassProviders MUST demonstrate continuous progress towards a FedRAMP Certification, documented in their Trust Center or website and updated at least quarterly; progress is measured by the provider against documented goals and milestones.
MKT-IIP-DLA
PassProviders MUST demonstrate that an assessment for a FedRAMP Certification Class B, C, or D has been scheduled within 2 years of initial listing in the Initial Implementation Phase.
SDR-CSO-FRR
PassSDR-CSX-KMT-A
PassProviders with 20x Class A Certifications MAY also include historical metrics in their Security Decision Record.
VDR-CSO-DET
PassVDR-TFR-MVX-A
PassProviders of FedRAMP 20x Class A offerings SHOULD verify and validate the status of machine-based information resources at least once every month.
VDR-TFR-PCD-A
PassProviders with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.
VDR-TFR-PDD-A
PassProviders with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 3 months.
VDR-TFR-PSD-A
PassProviders with Class A Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 14 days.
VDR-TFR-PVR-A
PartialProviders with Class A Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating, internet reachability, and likely exploitability.
Potential Agency Impact N-rating (PAIN) Timeframes:
PAIN-5 — LEV+IRV 4d · LEV+NIRV 8d · NLEV 32d
PAIN-4 — LEV+IRV 8d · LEV+NIRV 32d · NLEV 64d
PAIN-3 — LEV+IRV 32d · LEV+NIRV 64d · NLEV 192d
PAIN-2 — LEV+IRV 96d · LEV+NIRV 160d · NLEV 192d
VER-EVA-EPA
PassVER-TFR-EVU-A
PartialProviders with Class A Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 14 days of detection.
VER-TFR-IRI-A
PartialProviders with Class A Certifications MAY treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.
VER-TFR-MRH-A
PassProviders with Class A Certifications MAY make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information MAY be updated persistently, at least once every month.
VER-TFR-NRI-A
PassProviders with Class A Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.