Class A
- Must Class A providers include automated validations in the SDR?
- Can we include historical KSI metrics in Class A?
- Do we need to address every Class A KSI?
- What automation is recommended for Class A vulnerability monitoring?
- Is “see the SOC 2 report” an acceptable response to FedRAMP rule?
- Which external frameworks are accepted for Class A?
FedRAMP
Cloud Service Providers
- Cloud Service Providers
- NDAs
- Can our assessor, consultant, or advisory firm submit the application for us?
- Can we submit a FedRAMP 20x package before our Marketplace listing is ready?
- Can I get a Class A 20x Certification, then go to Class B Rev 5 Certification?
- Can cloud service providers use non-FedRAMP services within their certified cloud service offering?
Independent Assessors
Getting FedRAMP Certified
- Getting FedRAMP Certified
- Which materials must be machine-readable?
- Is a human-readable document alone enough?
- How should we test JSON before submission?
- Why was my Marketplace Listing submission rejected, and what do I need to do before resubmitting?
- What happens if a cloud service provider’s Marketplace status was incorrectly converted?
Rev5
- What milestone must be reached by 11 June 2027 for a new authorization effort to proceed under Rev. 5?
- Will uplifts still be accepted after 11 Jun 2027?
- What happens if a cloud service offering (CSO) loses its agency customers?
- Are cloud service providers allowed to change parameter definitions at any time?
- How should cloud service providers transition from the traditional POA&M process to the new VDR/VER process?
- Q: Will FedRAMP provide guidance on the sunsetting of FIPS 140-2? What do I do if our planned 140-3 Module is not yet approved.