Q: Can FedRAMP sign our NDA before reviewing our Certification Package?
A: No. GSA federal personnel do not execute vendor-specific nondisclosure agreements in order to access security information submitted to FedRAMP for review. Federal employees accessing this information in their official capacity are subject to federal statutory and regulatory restrictions governing the disclosure and use of proprietary and nonpublic information, including 18 U.S.C. § 1905 (Disclosure of confidential information generally) and 5 C.F.R. § 2635.703 (Use of nonpublic information), as well as applicable protections for trade secrets under 18 U.S.C. § 1832 (Theft of trade secrets). In other words, all FedRAMP staff are restricted by existing government law and policy from taking any inappropriate action with provided Certification information and do not need to be covered by a company-specific NDA. No company should expect FedRAMP staff to agree to terms and conditions or an NDA to perform review; if a company is unwilling or unable to share information without an NDA in place then FedRAMP will be unable to review the information required for certification.
Source: fedramp
Q: How can we protect sensitive information if FedRAMP cannot sign our NDA?
A: From the outset, your cloud architecture, and by extension, the information contained in your FedRAMP 20x package, should not be reliant on security via obscurity. Design the package and Trust Center for secure, role-appropriate sharing rather than relying on an NDA. The package should contain sufficient information for authorization decisions while excluding details that could enable unauthorized access, harm, or operational disruption. Since 20x doesn't require hosting on connect.gov, you have more control than ever over how your information is presented and secured. Therefore, you should be able to provide the information needed to evaluate the service without including secrets or exploit-enabling details such as passwords, API keys, credentials, or sensitive technical details that could materially increase risk. CSPs may also limit public sharing when disclosure could adversely affect the cloud service offering, while still meeting their obligation to share Certification Data with necessary parties through the Trust Center.