Just getting started or still building your package? Watch the September 20x Community Update to hear directly from other CSPs who went through the 20x Class A Certification process!
Certification Package Composition
All files should be accessible to FedRAMP from the Trust Center without signing an NDA or agreeing to terms of service or conditions.
All FedRAMP schemas referenced by rules (like SDR or OCR) should be presented in both machine-readable and human-readable versions. Even if the activity has not occurred yet (like an incident or OCR), samples/examples should be provided.
- Alternative Security Framework materials (like SOC 2 Type II Report, Bridge Letter, RAR, etc)
- Certification Package Overview (CPO)
- Security Decision Record (SDR)
- References Artifacts
- Sample schemas (referenced by applicable rules)
- Initial Incident Report (IEC-CSO-IIR) SHOULD
- Ongoing Incident Report (IEC-CSO-OIR) SHOULD
- Final Incident Report (IEC-CSO-FIR) MUST
- Historical VER Activity (VER-TFR-MRH) MAY - if Rule is included in SDR
- Ongoing Certification Report (CCM-OCR-AVL) MUST
- Anything that adds additional context or value - FedRAMP sets the minimum but provides you the CSP with the freedom to exceed!
If an optional Independent Verification and Validation was performed by a FedRAMP-recognized Independent Assessment Service specifically for this Class A Certification:
- Assessment Summary (under each Rule/KSI in SDR)
- Overall Summary of Assessment (CPO)
Security Decision Record (SDR) Completeness
The SDR contains information about the implementation status of FedRAMP Practices (Rules + Key Security Indicators) in relation to your cloud service implementation.
- Ensure ALL rules applicable to Class A are in scope, both MUST and SHOULD are required to be addressed even if Not Implemented or Partially Implemented. See Force of the Rule.
- See Class A Ruleset Reference for applicability.
- Bonus: take credit for the hard work you have already done and think about including any MAY rules that could already apply!
- Each Rule and Key Security Indicator (KSI) should have an Alternative Security Framework mapping, an associated artifact, or even both.
- A mapping should be direct like page 2, section 3, table 1 or CC8.1 NOT "See SOC report".
- An artifact could be a link to a webpage, an email address, a policy document, etc. It should be directly linked or easy to find.
- Each Rule and KSI should have an implementation status (Implemented, Partially Implemented, or Not Implemented). This should be accurate and if Partially or Not Implemented, a clear explanation of why including any future plans with timeframes for implementation.
- If an optional IV&V was performed, the Independent Assessor's Assessment Summary should be included for each Rule and KSI.
Pro-tips
- Be clear and concise. The goal is to be able to make a risk-based decision, not be confused.
- A 20x Class A is not intended to be a heavy lift. If it feels too hard, you may be overthinking!
- Use the JSON Schema Validator.
- Before requests are placed in the Review Queue, the Trust Center and package materials are verified. Speedy Trust Center access + package completeness = accelerated Review Queue entry.
- The easier it is to find information and access artifacts (like via links) the faster your review will be.
- FedRAMP reviews everything included, so if something doesn't add value, it is just slowing down the process. No extra points are awarded for file size.