Q: Do we need to address every Class A KSI?
A: Yes. Class A applicants must address the listed Class A requirements, including the required Key Security Indicators such as logging changes, network traffic restriction, training review, automated account management, passwordless methods, incident-response procedure review, and securing information. This applies even if the CSP has plans to pursue a Rev. 5 Program Certification path in the future.
Source: fedramp