United States federal government

FedRAMP Rev 5

65 controls. 117 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

65 controls 117 frameworks share controls with it United States federal government verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
FedRAMP-3PAO3PAO Assessment, FedRAMP Marketplace and Accreditation0
FedRAMP-BaselinesFedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters28
FedRAMP-BoundaryAuthorization Boundary, SSP, SAR, POA&M documentation102
FedRAMP-ConMonContinuous Monitoring (ConMon) and Significant Change Requests72
FedRAMP-IncidentReportingFedRAMP incident reporting to PMO and US-CERT42
FedRAMP-NIST-800-53-Rev5Coordination with NIST SP 800-53 Rev 5 + FedRAMP High + FedRAMP Moderate frameworks0
FedRAMP-OMB-M-24-15OMB Memorandum M-24-15 (July 2024) - FedRAMP modernization0
FedRAMP-PII-PrivacyFedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act)37
FedRAMP-ProgramFedRAMP Program establishment, PMO and authorization paths0
FedRAMP-StateRAMP-GovRAMPCoordination with StateRAMP, GovRAMP and state + local + tribal government cloud authorization0
FedRAMP-StatusFedRAMP Rev 5 - corpus status, baseline references, M-24-15 modernization pipeline0
FedRAMP-SupplyChain-SBOMFedRAMP supply chain risk management + SBOM (per EO 14028 + NIST 800-218 SSDF)37
AAuthorization process0
A.1A.1 CSP Information Form and FedRAMP ID0
A.10A.10 Secure repository and package access0
A.11A.11 Independence of the assessor0
A.2A.2 Impact level categorization0
A.3A.3 Deployment model, service model and system stack0
A.4A.4 FedRAMP Ready and the readiness assessment0
A.5A.5 Agency partnership, authorization planning and the In Process request0
A.6A.6 Kickoff meeting0
A.7A.7 Full security assessment0
A.8A.8 Agency ATO and the FedRAMP review to Authorized0
A.9A.9 Reuse: every agency issues its own authorization0
CContinuous monitoring0
C.1C.1 Monthly continuous monitoring deliverables0
C.10C.10 ConMon performance management and escalation0
C.2C.2 Vulnerability scanning requirements0
C.3C.3 Scan types, POA&M entries and image scanning0
C.4C.4 Container requirements0
C.5C.5 Sampling for vulnerability scanning0
C.6C.6 Annual assessment0
C.7C.7 Significant changes: types and process0
C.8C.8 Incident communications0
C.9C.9 Collaborative continuous monitoring0
FRFedRAMP Rev 5: the program, its parties and its status0
GProgram governance and scope under OMB M-24-150
G.1G.1 Scope of FedRAMP0
G.10G.10 Agency duties on oversight, metrics and cost0
G.2G.2 Presumption of adequacy and its limits0
G.3G.3 Authorization paths0
G.4G.4 Threat-based assessment of security postures0
G.5G.5 Marketplace designations, contract conditions, prioritization and temporary authorizations0
G.6G.6 Automation, machine-readable artifacts and OSCAL0
G.7G.7 Acceptance of external security frameworks and certifications0
G.8G.8 Continuous monitoring framework principles0
G.9G.9 Agency duties on authorization and reuse0
KCryptographic module selection and use0
K.1K.1 FRR1 to FRR4: documenting cryptographic module use0
K.2K.2 FRR5 to FRR8: assessment alignment, transition plans, monitoring visibility and public claims0
K.3K.3 FRR9 and FRR10: vulnerabilities in non-inherited modules0
K.4K.4 FRR11 to FRR14: expectations of module providers0
K.5K.5 FRR15 to FRR17: assessor duties0
K.6K.6 FRR18 to FRR21: designated leads and package reviewers0
PAuthorization package0
P.1P.1 Package inventory, templates and the initial checklist0
P.2P.2 System security plan quality0
P.3P.3 Authorization boundary and data flow diagrams0
P.4P.4 SSP appendices0
P.5P.5 Documenting controls in SSP Appendix A0
P.6P.6 Security assessment plan0
P.7P.7 Security assessment report0
P.8P.8 Plan of action and milestones0
TRev 5 transition and program status0
T.1T.1 Rev 5 baseline transition plan0

Tell me when FedRAMP Rev 5 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for FedRAMP Rev 5, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition