Q: What must a complete FedRAMP 20x Class A package include?
A: A complete FedRAMP 20x Class A package includes:
- External Assessment Materials
- Certification Package Overview (CPO)
- Security Decision Record (SDR)
- Sample schemas (referenced by applicable rules)
- Initial Incident Report (IEC-CSO-IIR) SHOULD
- Ongoing Incident Report (IEC-CSO-OIR) SHOULD
- Final Incident Report (IEC-CSO-FIR) MUST
- Historical VER Activity (VER-TFR-MRH) MAY - if Rule is included in SDR
- Ongoing Certification Report (CCM-OCR-AVL) MUST
- Assessment Summary (in SDR) and Overall Summary of Assessment (CPO) - if optional IV&V
Tips for a Smooth Process
Completeness
- Human and machine-readable files present
- ALL MUST and SHOULD rules included in SDR (even if not met)
- MAY are extra credit, but if included will be FULLY reviewed
Accuracy
- Use the JSON Schema Validator: https://www.fedramp.gov/schemas/validator/
- If a rule/KSI is not fully implemented, mark as Partially Implemented - please and thanks
Review Experience
- Easy to access and use Trust Center
- Simple to find artifacts (direct links from SDR best!)