All Items (39)

  • 2023-04-06

    3PAO Obligations and Performance Guide

    Provides guidance for 3PAOs on the quality, independence, personnel, and FedRAMP knowledge standards required to become a FedRAMP recognized 3PAO and how to maintain recognition

    3PAO
  • 2024-10-17

    3PAO Readiness Assessment Report Guide

    Provides 3PAOs with guidance on how best to utilize the FedRAMP Readiness Assessment Report (RAR) Template

    3PAOReadiness Assessment Report
  • 2025-11-18

    Agency Authorization Playbook

    Compilation of best practices, tips, and step-by-step guidance for agencies seeking FedRAMP authorization

    PlaybookAgency Authorization
  • 2024-03-04

    Annual Assessment Controls Selection Worksheet

    Provides a matrix to assist CSPs, 3PAOs, and federal agencies in assessing and tracking controls for their annual assessment

    FedRAMP Security PackageContinuous MonitoringAnnual Assessment
  • 2022-09-01

    Branding Guidance

    Provides guidelines on the use of the FedRAMP name, logo, and marks on all FedRAMP-related marketing and collateral materials

    Program Documents
  • 2024-11-19

    Continuous Monitoring Monthly Executive Summary Template

    Provides FedRAMP and agency authorizing officials (AOs) with an executive summary of a CSP's monthly continuous monitoring submission

    Continuous Monitoring
  • 2025-11-18

    Continuous Monitoring Playbook

    Provides an overview of FedRAMP Rev 5 continuous monitoring (ConMon) requirements and activities, along with guidance and best practices

    Program DocumentsContinuous MonitoringPlaybook
  • 2025-11-18

    CSP Authorization Playbook

    Provides an overview of all of the partners involved in a FedRAMP authorization, things to consider when determining your authorization strategy, the types of authorizations, and important considerations for your offering when working with FedRAMP

    PlaybookAgency Authorization
  • 2019-06-20

    FedRAMP ATO Letter Template

    An optional template for agencies to use when granting authorizations for CSOs

    FedRAMP Security Package
  • 2021-07-13

    FedRAMP Authorization Boundary Guidance

    Provides CSPs guidance for developing the authorization boundary for their offering(s)

    Program Documents
  • 2024-12-04

    FedRAMP Continuous Monitoring Deliverables Template

    Used to identify the schedule and location for monthly and annual continuous monitoring deliverables

    FedRAMP Security PackageAgency AuthorizationContinuous Monitoring
  • 2024-05-31

    FedRAMP High Readiness Assessment Report (RAR) Template

    Used to evaluate a CSO's organizational processes and security capabilities at the High impact level

    Readiness Assessment Report
  • 2023-10-13

    FedRAMP High, Moderate, Low, LI-SaaS Baseline System Security Plan (SSP)

    Provides the framework to describe a CSO; the service offering's components and features; and its security posture

    FedRAMP Security PackageBaselinesSystem Security Plan
  • 2023-06-30

    FedRAMP Initial Authorization Package Checklist

    Details the documents required for a complete FedRAMP initial authorization package

    FedRAMP Security Package
  • 2024-05-31

    FedRAMP Moderate Readiness Assessment Report (RAR) Template

    Used to evaluate a CSO's organizational processes and security capabilities at the Moderate impact level

    Readiness Assessment Report
  • 2024-04-30

    FedRAMP Package Access Request Form

    Used by federal agencies to gain access to a FedRAMP Authorized packages

    Authorization ReuseAgency Authorization
  • 2025-12-05

    FedRAMP Plan of Action and Milestones (POA&M) Template

    Provides a structured framework for aggregating system vulnerabilities and deficiencies through security assessment and continuous monitoring efforts

    FedRAMP Security PackageContinuous Monitoring
  • 2025-01-16

    FedRAMP Policy for Cryptographic Module Selection v1.1.0

    Outlines requirements and recommendations for CSPs, 3PAOs, designated leads, and package reviewers regarding the selection and use of cryptographic modules to protect federal information

    Program DocumentsCryptography
  • 2025-12-08

    FedRAMP SAR Appendix B - High Security Requirements Traceability Matrix Template

    Provides a standard risk and controls template for assessing High baseline controls and helps to drive consistency in 3PAO annual assessment testing

    FedRAMP Security Package
  • 2025-12-08

    FedRAMP SAR Appendix B - Low Security Requirements Traceability Matrix Template

    Provides a standard risk and controls template for assessing Low baseline controls and helps to drive consistency in 3PAO annual assessment testing

    FedRAMP Security Package
  • 2025-12-08

    FedRAMP SAR Appendix B - Moderate Security Requirements Traceability Matrix Template

    Provides a standard risk and controls template for assessing Moderate baseline controls and helps to drive consistency in 3PAO annual assessment testing

    FedRAMP Security Package
  • 2023-06-30

    FedRAMP Security Assessment Plan (SAP) Template

    Designed for 3PAOs to plan CSP security assessment testing associated with initial authorization assessments, annual assessments, and SCRs

    FedRAMP Security Package
  • 2024-12-06

    FedRAMP Security Assessment Report (SAR) Template

    Provides a framework for 3PAOs to evaluate a cloud system’s implementation of and compliance with system-specific, baseline security controls required by FedRAMP

    FedRAMP Security Package
  • 2025-12-05

    FedRAMP Security Controls Baseline

    Provides the catalog of FedRAMP High, Moderate, Low, and LI-SaaS baseline security controls along with additional guidance and requirements

    Program DocumentsBaselines
  • 2024-08-08

    FedRAMP Vulnerability Deviation Request Form

    Provides a standardized method to document deviation requests and is used to document risk adjustments, false positives, and operational requirements

    Continuous MonitoringVulnerability Management
  • 2022-06-30

    Penetration Test Guidance

    Provides guidelines for organizations on how to plan and conduct penetration testing

    FedRAMP Security PackageAnnual AssessmentContinuous Monitoring
  • 2022-07-26

    Reusing Authorizations for Cloud Products Quick Guide

    Outlines steps and guidance to help agencies quickly and efficiently reuse authorized cloud offerings within the FedRAMP Marketplace

    Authorization ReuseAgency Authorization
  • 2024-03-29

    SAR Appendix A - FedRAMP Risk Exposure Table (RET) Template

    The FedRAMP Risk Exposure Table Template is designed to capture all security weaknesses and deficiencies identified during security assessment testing.

    FedRAMP Security Package
  • 2025-12-08

    SSP Appendix A - High FedRAMP Security Controls

    Provides the FedRAMP High baseline security control requirements for High impact CSOs

    Baselines
  • 2025-12-08

    SSP Appendix A - LI-SaaS FedRAMP Security Controls

    Provides the FedRAMP baseline security control requirements for LI-SaaS impact cloud systems

    BaselinesLI-SaaSFedRAMP Tailored
  • 2025-12-08

    SSP Appendix A - Low FedRAMP Security Controls

    Provides the FedRAMP Low baseline security control requirements for Low impact cloud systems

    Baselines
  • 2025-12-08

    SSP Appendix A - Moderate FedRAMP Security Controls

    Provides the FedRAMP Moderate baseline security control requirements for Moderate impact CSOs

    Baselines
  • 2023-06-30

    SSP Appendix F - Rules of Behavior (RoB) Template

    Describes the security controls associated with user responsibilities and specific expectations of behavior for following security policies, standards, and procedures

    FedRAMP Security PackageSystem Security Plan
  • 2024-12-06

    SSP Appendix G - Information System Contingency Plan (ISCP) Template

    Supports the ISCP requirements for FedRAMP

    FedRAMP Security PackageSystem Security Plan
  • 2023-07-13

    SSP Appendix J - CIS and CRM Workbook

    Delineates the control responsibilities of CSPs and agencies and provides a summary of all required controls and enhancements across a CSO

    FedRAMP Security PackageSystem Security Plan
  • 2024-12-06

    SSP Appendix M - Integrated Inventory Workbook Template

    Consolidates all of the inventory information previously required in five FedRAMP templates that included the SSP, ISCP, SAP, SAR, and POA&M

    FedRAMP Security PackageSystem Security Plan
  • 2023-06-30

    SSP Appendix Q - Cryptographic Modules Table

    Documents the encryption status of all areas/flows of data associated with a CSO

    FedRAMP Security PackageSystem Security Plan
  • 2020-12-11

    Timeliness and Accuracy of Testing Requirements

    Describes the timeliness and accuracy of testing requirements for CSPs seeking a FedRAMP authorization

    FedRAMP Security PackageAnnual AssessmentContinuous Monitoring
  • 2021-03-16

    Vulnerability Scanning Requirements for Containers

    Addresses FedRAMP compliance pertaining to the processes, architecture, and security considerations specific to vulnerability scanning for CSOs using container technology

    Program Documents