Q: How recent must the submitted package be?
A: The initial package must reflect the current CSO and must have been verified and validated by the provider within the preceding seven days. Submissions using stale screenshots, expired exports, outdated implementation descriptions, or old evidence will be rejected.
Source: fedramp
Q: What is the SDR, and does it replace the SSP?
A: The Security Decision Record is the persistently maintained, verified, and validated record of security decisions for the CSO. It replaces the traditional System Security Plan approach for 20x and documents how applicable FedRAMP practices are addressed, including rationale, customer risk, findings, and supporting artifacts.
Source: fedramp
Q: What must be included for every applicable rule in the SDR?
A: For each applicable FedRAMP rule, provide in both human-readable and JSON formats:
- How the rule is followed, or why it is not followed, and the customer risk resulting from that security decision
- Verification that the implementation meets all expected KSI standards or a senior/management level explanation on the reason it is not fully implemented
- Validation that it is implemented and operating as intended or senior/management level assurance
- Independent verification
- Independent validation
- Responses or clarifications addressing independent-review comments
- Rule-specific artifacts where applicable.
Source: fedramp
Q: Should we omit a rule if we have not implemented it yet?
A: No. Do not omit applicable requirements. The SDR must either explain how the rule is followed, or explain why it is not followed yet and the resulting customer risk. For an incomplete implementation, state the current status plainly, identify the gap, describe the risk, name the accountable owner, and provide a credible remediation plan and timeline. If a control is labeled MUST or SHOULD you are required to address it in your SDR.
Source: fedramp
Q: Can we mark a requirement “Implemented” if evidence is still being finalized?
A: No. The status must be supported by verification and validation that demonstrate the implementation is appropriate, in place, and functioning as intended. If the evidence does not support full implementation, accurately represent the partial state and describe the remediation plan.
Source: fedramp