Understanding the Transition from Rev. 4 to Rev. 5
The FedRAMP Joint Authorization Board (JAB) updated the FedRAMP security controls baseline to align with National Institutes of Standards and Technology (NIST) Special Publication (SP) 800-53 (SP 800-53), Security and Privacy Controls for Federal Information Systems and Organizations, Revision 5 (Rev. 5). The FedRAMP Program Management Office (PMO) updated the FedRAMP documentation and templates to reflect the changes in NIST SP 800-53, Rev. 5, and developed guidance to assist Cloud Service Providers (CSPs) in transitioning to Rev. 5.
Please refer to the FAQ page for additional information.
Rev. 5 documents can be found on the Documents and Templates page.
On the Automation GitHub, the FedRAMP Open Security Controls Assessment Language (OSCAL) versions of the Rev. 5 baselines for High, Moderate, Low, and Tailored for Low Impact-Software as a Service (LI-SaaS), including XML, JSON, and YAML versions can be found.
In the table below, the archived Rev. 4 documents are crosswalked with their d Rev. 5 version to make it easy for stakeholders to locate the documents they need. New Rev. 5 documents are also listed, as well as retiring documents. This mapping illustrates the consolidation of some previous FedRAMP Rev. 4 documents into fewer Rev. 5 documents to reduce the burden on stakeholders.