Certification Package Composition
All files should be accessible to FedRAMP from the Trust Center without signing an NDA or agreeing to terms of service or conditions. GSA federal personnel do not execute vendor-specific nondisclosure agreements in order to access security information submitted to FedRAMP for review.
All FedRAMP schemas referenced by rules (like SDR or OCR) should be presented in both machine-readable and human-readable versions. Even if the activity has not occurred yet (like an incident or OCR), samples/examples should be provided.
- Certification Package Overview (CPO) - FRC-CSO-PKG
- Security Decision Record (SDR) - SDR-CSO-FRR
- Secure Configuration Guide (SCG) - SCG-CSO-RSC
- Referenced Artifacts and Evidence
- Sample schemas (referenced by applicable rules)
| Schema Name | Rule | Class B Force | Class C Force |
| Ongoing Certification Report | CCM-OCR-AVL | MUST | MUST |
| Initial Incident Report | IEC-CSO-IIR | MUST | MUST |
| Ongoing Incident Report | IEC-CSO-OIR | MUST | MUST |
| Final Incident Report | IEC-CSO-FIR | MUST | MUST |
| Significant Change Notification | SCN-CSO-INF | MUST | MUST |
| Accepted Vulnerability Info | VER-RPT-AVI | MUST | MUST |
| Historical VER Activity | VER-TFR-MRH | SHOULD | SHOULD |
| Vulnerability Detail Report | VER-RPT-VDT | MUST | MUST |
- Assessment Summary (under each Rule/KSI in SDR) - IVV-IAS-SUM
- Overall Summary of Assessment (included in CPO) - IVV-IAS-OSA
- Anything that adds additional context or value - FedRAMP sets the minimum but provides you the CSP with the freedom to exceed!
Security Decision Record (SDR) Completeness
The SDR contains information about the implementation status of FedRAMP Practices (Rules + Key Security Indicators) in relation to your cloud service implementation.
- Ensure ALL rules applicable to Class B or C are in scope, both MUST and SHOULD are required to be addressed even if Not Implemented or Partially Implemented. See Force of the Rule.
- Each Rule and KSI should have an implementation status (Implemented, Partially Implemented, or Not Implemented). This should be accurate and if Partially or Not Implemented, a clear explanation of why including any future plans with timeframes for implementation.
- Independent Assessor's Assessment Summary should be included for each Rule and KSI.
- Historical KSI Metrics (Class B SHOULD, CLASS C MUST) - FRC-CSX-MOT
- Automated Verification & Validation of Rules (SHOULD) - FRC-CSX-VVR
Pro-tips
- Be clear and concise. The goal is to be able to make a risk-based decision, not be confused.
- Use the JSON Schema Validator.
- Before requests are placed in the Review Queue, the Trust Center and package materials are verified. Speedy Trust Center access + package completeness = accelerated Review Queue entry.
- The easier it is to find information and access artifacts (like via links) the faster your review will be.
- FedRAMP reviews everything included, so if something doesn't add value, it is just slowing down the process. No extra points are awarded for file size!