Harness Gov

Controls

We take security, compliance, and privacy seriously. Explore our certifications, reports, and policies in one place.
⌘K

AFC-CSO-CRA

Pass

AFC-CSO-INB

Pass

AFC-CSO-NOC

Pass

AFC-CSO-RCV

Pass

CCM-OCR-AVL

Pass

CCM-OCR-NRD

Pass

CCM-QTR-MTG-A

Pass
Providers with Class A Certifications MAY host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.

CDS-CSO-AVR-A

Pass
Providers with Class A Certifications SHOULD maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service SHOULD be available even if the primary cloud service offering is unavailable.

CDS-CSO-IRP

Pass

CDS-CSO-PSM-A

Pass
Providers with Class A Certifications MAY supply per-service FedRAMP Certification materials.

CDS-CSO-PUB

Pass

CDS-CSO-SVC

Pass

CDS-CSO-UTC

Pass

CDS-UTC-AAD

Pass

CMU-CSO-CMD

Partial

CMU-CSO-UVM-A

Pass
Providers with Class A Certifications MAY use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.

CPO-CSO-MTD

Pass

CPO-CSO-OSA

Pass
Providers seeking Class [ A | B | C | D ] Certification [ MAY | MUST ] also include [ an | the ] overall summary of their FedRAMP independent [ assessment | assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), ] in their Certification Package Overview.

CPO-CSO-OVR

Pass

CPO-CSX-CPM-A

Pass
Providers with 20x Class A Certifications SHOULD persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 3 months.

FRC-APP-AFC

Pass
Providers MUST complete the FedRAMP Certification Application Form in full to request an initial assessment by FedRAMP.

FRC-APP-FCP

Pass
Providers MUST supply a fresh initial FedRAMP Certification Package that shows the current status of the cloud service offering as verified and validated by the provider within the previous 7 days.

FRC-APP-FIA-A

Pass
Providers seeking Class A Certification MAY supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.

FRC-APP-MLF

Pass
Providers MUST be listed in the FedRAMP Marketplace before applying for FedRAMP Certification, including: • FedRAMP Marketplace: MKT-CSO-MLR (Marketplace Listing Requirements), • FedRAMP Marketplace: MKT-CSO-PML (Provider Marketplace Listing Requests) • FedRAMP Marketplace: MKT-IIP-AGU (Agency Use Cases) • FedRAMP Marketplace: MKT-IIP-DCP (Demonstrating Continuous Progress)

FRC-APP-NTP

Pass
Providers MUST NOT use a third party to apply for a FedRAMP Certification on their behalf; this includes independent assessment services. • FedRAMP previously allowed independent assessment services to submit applications on behalf of providers, but this caused confusion about who was responsible for the application and the information in it. Providers should apply directly to ensure clear accountability. • Providers may use third parties to help them prepare their application and assessment materials for submission.

FRC-APP-USA

Pass
Providers MAY freshen a stale initial independent verification and validation assessment by having a FedRAMP Recognized independent assessment service review any changes between the original assessment and the current status of the cloud service offering in place of a full re-assessment, UNLESS the stale assessment is more than 9 months old.

FRC-CCL-DCC

Pass
Providers MUST apply for a new FedRAMP Certification to downgrade their Certification Class. • Downgrade paths include moving from D to C, B, or A; C to B or A; or B to A. • FRC-CCL-DNP (Downgrade Notification Period) applies - please DO NOT downgrade Certification Class with providing advance notification to all necessary parties!

FRC-CCL-DNP

Pass
Providers SHOULD notify all necessary parties at least 120 days in advance of an intended downgrade or cancellation of FedRAMP Certification.

FRC-CCL-UCC

Pass
Providers MUST apply for a new FedRAMP Certification to upgrade their Certification Class; all applicable requirements MUST be met in advance. • Upgrade paths include moving from A to B, C, or D; B to C or D; and C to D. • The preferred path is to incrementally update the implementation and assurance commitments within the current Certification Class until the provider has met all requirements for the target Certification Class, then apply for the new Certification Class.

FRC-CLA-ASF

Pass
Providers seeking a FedRAMP Class A Certification MUST have completed a certification or equivalent process, including an independent assessment if applicable, from one of the following alternative security frameworks within the past 12 months: • FedRAMP Rev5 (including FedRAMP Ready) at any historical Impact Level • SOC 2 Type II • GovRAMP at any Impact Level

FRC-CLA-EAM

Pass
Providers seeking a FedRAMP Class A Certification MUST supply the following materials from their alternative security framework assessment to all necessary parties: • SOC 2 Type II: Complete report, bridge or gap letter (if applicable), verified audit engagement documentation, estimated schedule for upcoming report, supplemental compliance evidence (if applicable) • FedRAMP Ready: Readiness Assessment Report, Security Assessment Plan, and any other materials required by FedRAMP. • GovRAMP: Readiness Assessment Report, Security Assessment Plan, and any other materials required by GovRAMP.

FRC-CLA-IVV

Pass
Providers seeking a FedRAMP Class A Certification MAY have the FedRAMP Certification Package independently verified and validated by a FedRAMP Recognized assessor before submission to FedRAMP.

FRC-CLA-MFR

Pass
Providers seeking a Class A FedRAMP Certification MUST address all rules in this FedRAMP Class A Certification subset (FRC-CLA) AND the following additional FedRAMP Class A rules; the appropriate artifacts or information mapping for all rules MUST be supplied in the FedRAMP Certification Package. • FedRAMP Certification: FRC-CSO-PKG (FedRAMP Certification Package) • FedRAMP Certification: FRC-CSO-JSN (FedRAMP JSON Schemas) • FedRAMP Certification: FRC-CSO-POP (Pick One Program Certification Type) • Minimum Assessment Scope: MAS-CSO-IIR (Identify Information Resources) • Certification Data Sharing: CDS-CSO-PUB (Public Information) • Certification Data Sharing: CDS-CSO-UTC (Use Trust Centers) • Certification Data Sharing: CDS-UTC-AAD (Agency Access Denial) • Certification Data Sharing: CDS-CSO-AVR (Availability Reporting) • Addressing FedRAMP Communication: AFC-CSO-INB (Maintain a FedRAMP Security Inbox) • Addressing FedRAMP Communication: AFC-CSO-RCV (Receive Email Without Disruption) • Addressing FedRAMP Communication: AFC-CSO-CRA (Complete Required Actions) • Incident Evaluation and Communication: IEC-CSO-EFR (Evaluate FedRAMP Reportability) • Incident Evaluation and Communication: IEC-CSO-FIR (Final Incident Report) • Vulnerability Detection and Response: VDR-CSO-DET (Vulnerability Detection) • Collaborative Continuous Monitoring: CCM-OCR-AVL (Report Availability) • Collaborative Continuous Monitoring: CCM-OCR-NRD (Next Report Date) • Independent Verification and Validation: IVV-CSX-AIA (Annual Independent Assessments for 20x) • Independent Verification and Validation: IVV-CSF-AIA (Annual Independent Assessments for Rev5) • Key Security Indicators: KSI-CMT-LMC (Logging Changes) • Key Security Indicators: KSI-CNA-RNT (Restricting Network Traffic) • Key Security Indicators: KSI-CED-RAT (Reviewing All Training) • Key Security Indicators: KSI-IAM-AAM (Automating Account Management) • Key Security Indicators: KSI-IAM-APM (Adopting Passwordless Methods) • Key Security Indicators: KSI-INR-RIR (Reviewing Incident Response Procedures) • Key Security Indicators: KSI-SVC-SIN (Securing Information)

FRC-CLA-OFR

Pass
Providers seeking a Class A FedRAMP Certification MAY address the following additional optional FedRAMP Class A rules (if applicable): • Collaborative Continuous Monitoring: CCM-QTR-MTG (Quarterly Review Meeting) • Certification Data Sharing: CDS-CSO-PSM (Per-Service Certification Materials) • Cryptographic Module Use: CMU-CSO-UVM (Using Validated Cryptographic Modules) • FedRAMP Certification: FRC-APP-FIA (Fresh Independent Assessment) • Independent Verification and Validation: IVV-CSO-FIA (FedRAMP Independent Assessments) • Security Decision Record: SDR-CSX-KMT (Key Security Indicator Metrics) • Vulnerability Evaluation and Reporting: VER-TFR-IRI (Internet-Reachable Incidents) • Vulnerability Evaluation and Reporting: VER-TFR-MRH (Historical Activity) • Vulnerability Evaluation and Reporting: VER-TFR-NRI (Non-Internet-Reachable Incidents)

FRC-CLA-RFR

Pass
Providers seeking a Class A FedRAMP Certification SHOULD address the following additional recommended FedRAMP Class A rules (if applicable): • Certification Data Sharing: CDS-CSO-AVR (Availability Reporting) • Certification Package Overview: CPO-CSF-CPM (Certification Package Maintenance for Rev5) • Certification Package Overview: CPO-CSX-CPM (Certification Package Maintenance for 20x) • Incident Evaluation and Communication: IEC-CSO-IIR (Initial Incident Report) • Incident Evaluation and Communication: IEC-CSO-OIR (Ongoing Incident Reports) • Vulnerability Detection and Response: VDR-TFR-MVX (Persistent Machine Verification and Validation for 20x) • Vulnerability Detection and Response: VDR-TFR-PCD (Persistently Complete Detection) • Vulnerability Detection and Response: VDR-TFR-PDD (Persistent Drift Detection) • Vulnerability Detection and Response: VDR-TFR-PSD (Persistent Sample Detection) • Vulnerability Detection and Response: VDR-TFR-PVR (Mitigation and Remediation Expectations) • Vulnerability Evaluation and Reporting: VER-TFR-EVU (Evaluate Vulnerabilities Quickly)

FRC-CSO-FCP

Pass
Providers MUST identify a target FedRAMP Certification Profile and apply all relevant FedRAMP Practices to the cloud service offering.

FRC-CSO-JSN

Pass
Providers MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule.

FRC-CSO-MRA

Pass
Providers MUST maintain responsibility and accountability for the accuracy and completeness of all information in the FedRAMP Certification Package, especially when they engage a third party (such as an independent assessor, advisory service, or external tools) to supply information on their behalf.

FRC-CSO-PKG

Pass
Providers seeking a Certification MUST supply a complete FedRAMP Certification Package to FedRAMP for initial certification; the FedRAMP Certification Package MUST include at least the following information: • A Certification Package Overview • A Security Decision Record • A real or example Ongoing Certification Report following CCM-OCR-AVL (Report Availability)

FRC-CSO-POP

Pass
Providers MUST NOT seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering; pick one type.

FRC-CSX-MOT-A

Pass
Providers seeking 20x Class A Certification MAY supply historical metrics for Key Security Indicators.

FRC-CSX-VVK-A

Pass
Providers seeking 20x Class A Certification MAY implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators.

FRC-CSX-VVR-A

Pass
Providers seeking 20x Class A Certification MAY implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.

IEC-CSO-DPR

Pass

IEC-CSO-EFI

Pass

IEC-CSO-EFR

Pass

IEC-CSO-FIR-A

Pass
Providers with Class A Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.

IEC-CSO-IIR-A

Pass
Providers with Class A Certifications SHOULD responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item: • Contact information for the federal incident response coordinator • Provider's internally assigned tracking identifier • Description of the incident • Timeline of the incident, including start time, time and source of detection, time of completed FedRAMP Reportable Incident evaluation, and other major incident milestones determined by the provider • Historically and currently estimated Potential Agency Impact N-rating (PAIN) of the incident, including an explanation of the evaluation following the requirements in IEC-CSO-EFI (Estimate Federal Impact) (if applicable) • Functional impact to federal agency customers (include impact to confidentiality and/or integrity and the impacted federal customer data types) • Estimated recovery plan, milestones, and timelines • List of likely affected customer agencies

IEC-CSO-OIR-A

Pass
Providers with Class A Certifications SHOULD responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item: • Observed incident activity • Indicators of compromise • Related Common Vulnerabilities and Exposures (CVE) identifier (if applicable) • Root cause • Response and recovery activities

IVV-CSO-FIA-A

Pass
Providers with Class A Certifications MAY persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.

IVV-CSO-ICP

Pass

IVV-CSX-AIA-A

Pass
Providers with 20x Class A Certifications MUST meet the expectations of their underlying alternative security framework as part of their persistent independent verification and validation assessment.

KSI-CED-RAT

Pass
The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.

KSI-CMT-LMC

Pass
Modifications to the cloud service offering are logged and monitored.

KSI-CNA-RNT

Pass
Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.

KSI-IAM-AAM

Pass
The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.

KSI-IAM-APM

Partial
Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.

KSI-INR-RIR

Pass
The effectiveness of documented incident response procedures is persistently reviewed.

KSI-SVC-SIN

Partial
Information is encrypted or otherwise secured from unwanted access or modification.

MAS-CSO-FLO

Pass

MAS-CSO-IIR

Pass

MAS-CSO-TPR

Pass

MKT-CSO-MLR

Pass
Providers MUST address at least these FedRAMP rules to apply for a new FedRAMP Marketplace listing OR to request updates to an existing listing: • Certification Data Sharing: CDS-CSO-PUB (Public Information)

MKT-CSO-PML

Pass
Providers MUST notify FedRAMP using the FedRAMP Marketplace Providing Listing Request Form to request a listing in the FedRAMP Marketplace.

MKT-IIP-AGU

Pass
Providers MUST demonstrate that a cloud service offering is intended for one of the following use cases: • Direct Use: The product will be used directly by agency customers for integration into a federal information system that falls within the scope of 44 USC § 3506 and will receive an agency Authorization to Operate. • Indirect Use: The product will be included as a third-party information resource in other cloud service offerings that are directly used by agency customers.

MKT-IIP-DCP

Pass
Providers MUST demonstrate continuous progress towards a FedRAMP Certification, documented in their Trust Center or website and updated at least quarterly; progress is measured by the provider against documented goals and milestones.

MKT-IIP-DLA

Pass
Providers MUST demonstrate that an assessment for a FedRAMP Certification Class B, C, or D has been scheduled within 2 years of initial listing in the Initial Implementation Phase.

SDR-CSO-FRR

Pass

SDR-CSX-KMT-A

Pass
Providers with 20x Class A Certifications MAY also include historical metrics in their Security Decision Record.

VDR-CSO-DET

Pass

VDR-TFR-MVX-A

Pass
Providers of FedRAMP 20x Class A offerings SHOULD verify and validate the status of machine-based information resources at least once every month.

VDR-TFR-PCD-A

Pass
Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.

VDR-TFR-PDD-A

Pass
Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 3 months.

VDR-TFR-PSD-A

Pass
Providers with Class A Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 14 days.

VDR-TFR-PVR-A

Partial
Providers with Class A Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating, internet reachability, and likely exploitability. Potential Agency Impact N-rating (PAIN) Timeframes: PAIN-5 — LEV+IRV 4d · LEV+NIRV 8d · NLEV 32d PAIN-4 — LEV+IRV 8d · LEV+NIRV 32d · NLEV 64d PAIN-3 — LEV+IRV 32d · LEV+NIRV 64d · NLEV 192d PAIN-2 — LEV+IRV 96d · LEV+NIRV 160d · NLEV 192d

VER-EVA-EPA

Pass

VER-TFR-EVU-A

Partial
Providers with Class A Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 14 days of detection.

VER-TFR-IRI-A

Partial
Providers with Class A Certifications MAY treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.

VER-TFR-MRH-A

Pass
Providers with Class A Certifications MAY make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information MAY be updated persistently, at least once every month.

VER-TFR-NRI-A

Pass
Providers with Class A Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.