Q: Is “see the SOC 2 report” an acceptable response to FedRAMP rule?
A: Usually, no. FedRAMP states that the Class A package should contain enough detail for a reviewer to understand the security decision without having to dig through the external-framework materials. Map the SOC 2 evidence to the relevant FedRAMP rule, explain your implementation, and link directly to the supporting artifact.
Source: fedramp