sushegaad/claude-skills-governance-risk-and-compliance

fedramp

Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

Voir la source
Document Skill original

Rendu depuis le dépôt source en conservant titres, exemples, code, tableaux, liens et images.

FedRAMP Certification Skill

Last verified: 2026-08-15

A comprehensive guide for helping users navigate FedRAMP authorization — from initial readiness through ATO and ongoing continuous monitoring.

Quick Reference: What Does the User Need?

Identify the user's goal and jump to the appropriate section:

User GoalGo To
"Are we ready for FedRAMP?" / gap assessmentReadiness & Gap Assessment
Writing SSP, POA&M, SAR, SAP, or other docsATO Documentation
"Which controls apply to us?" / control mappingNIST 800-53 Control Mapping
Cloud architecture / AWS/Azure/GCP configArchitecture Guidance
Already authorized, ongoing complianceContinuous Monitoring

Current FedRAMP State (as of August 2026 — CR26)

⚠️ CR26 (FedRAMP Consolidated Rules for 2026): FedRAMP has restructured its authorization framework. FIPS 199-based baseline labels (Low/Moderate/High/LI-SaaS) are replaced with Certification Classes A–D (per notice NTC-0004; CR26 rules valid through December 31, 2028). Class labels change the names of the baselines, not their requirements. CSPs already authorized under the old labels retain their authorization through a transition period in which old and new labels are linked.
  • Baseline: NIST SP 800-53 Rev 5 (fully in effect)
  • Control counts (Rev 5): Low ≈ 156, Moderate = 323, High = 421 (legacy references; CR26 class-based counts being published by PMO)
  • CR26 Certification Classes (official mapping, NTC-0004): A = new pilot/transitional baseline (entry via external frameworks such as SOC 2 Type II through Program Certification; holders have a 2-year window to obtain B/C/D), B = current LI-SaaS + Low baselines, C = current Moderate baseline (majority of federal deployments, incl. CUI), D = current High baseline.
  • FedRAMP 20x: Now the primary authorization pathway — continuous authorization built on Key Security Indicators (KSIs), machine-readable evidence, modular API-driven submissions, and automated validation. Traditional SSP/SAP/SAR templates remain for legacy paths.
  • CR26 status: finalized June 25, 2026; optional early adoption since July 4, 2026; mandatory January 1, 2027.
  • Legacy FedRAMP Ready: the Ready designation was retired/relabeled Legacy FedRAMP Ready on July 28, 2026 — no new submissions. Rev5 Ready holders must convert by the later of their annual-assessment expiration or November 17, 2026; the status disappears entirely December 31, 2027.
  • Certification Class pipelines: Class A open since August 3, 2026; Classes B/C open August 31, 2026; Class D pilot expected late 2026 with a formal option in early 2027.
  • Rev5 wind-down: new Rev5 applications are not accepted after June 11, 2027; Rev5 sunsets December 31, 2028.
  • JAB P-ATO: Fully suspended; FedRAMP PMO is the sole authorization body.
  • OSCAL mandate (RFC-0024): machine-readable packages required for new authorizations from September 30, 2026, and for all packages by September 30, 2027.
  • Security Inbox: All authorized CSPs must maintain a dedicated Security Inbox (no CAPTCHAs or barriers) for urgent vulnerability directives — effective January 5, 2026.
  • Key templates updated: SSP, SAR, SAP, POA&M, CIS/CRM, IIW, ISCP — all updated to align with Rev 5 (Dec 2024 releases).

1. Readiness & Gap Assessment

Approach

  1. Clarify scope — Ask the user: What is the CSO (Cloud Service Offering)? IaaS/PaaS/SaaS? Target Certification Class under CR26?
  2. Identify authorization path — FedRAMP 20x (primary, preferred) vs. legacy Agency Authorization package (still available for complex systems during CR26 transition)
  3. Run through the readiness checklist — See references/readiness-checklist.md
  4. Surface gaps — Map current state to required controls; flag missing documentation, unimplemented controls, and architectural deficiencies
  5. Prioritize — Group gaps by: (a) blockers for readiness review, (b) items addressable before 3PAO assessment, (c) POA&M candidates
FedRAMP Ready retired July 28, 2026 (now "Legacy FedRAMP Ready"). Advise CSPs by pipeline instead: Class A (open since August 3, 2026) for external-framework entry, Classes B/C from August 31, 2026 for full certification; legacy Rev5 Ready holders must convert by the later of annual-assessment expiration or November 17, 2026.

Key Readiness Questions to Ask the User

  • Are you targeting FedRAMP 20x (preferred) or a legacy authorization package?
  • What cloud platform (AWS GovCloud, Azure Government, GCP, on-prem hybrid)?
  • Are you leveraging any existing FedRAMP-authorized IaaS/PaaS (e.g., AWS GovCloud FedRAMP High)?
  • Do you have FIPS 140-2/3 validated encryption in place?
  • Is your authorization boundary defined and documented?
  • Do you have a vulnerability scanning program (OS, DB, web app, container)?
  • Are security policies and procedures documented?
  • Do you have an Incident Response Plan (IRP) and Contingency Plan (CP) that have been tested?
  • Are your authorization package artifacts in OSCAL format (mandatory by September 30, 2026)?

Output Format

  • Produce a gap table: Control Family | Current State | Gap | Priority | Owner
  • Summarize top 5–10 high-priority gaps as prose
  • Note the target Certification Class and whether FedRAMP 20x is feasible

2. ATO Documentation

The core FedRAMP authorization package consists of:

Authorization Package
├── System Security Plan (SSP) + Appendices A–Q
├── Security Assessment Plan (SAP) + Appendices A–D  [3PAO-prepared]
├── Security Assessment Report (SAR) + Appendices A–F  [3PAO-prepared]
└── Plan of Action & Milestones (POA&M)  [SSP Appendix O]
Important: CSPs must use official FedRAMP PMO templates. OSCAL-format submissions are mandatory by September 30, 2026. Templates: https://www.fedramp.gov/documents-templates/

Document Guidance

For detailed guidance on each document type, read the appropriate reference file:

  • SSPreferences/ssp-guide.md
  • POA&Mreferences/poam-guide.md
  • SAP / SARreferences/sap-sar-guide.md
  • Supporting appendicesreferences/appendices-guide.md

General Writing Principles for All ATO Docs

  1. Describe only what is implemented — Do not document planned or aspirational controls; these trigger findings and must go in POA&M instead
  2. Be specific — Reference exact tools, filenames, section numbers, policy names; vague language causes findings
  3. Mind the verbs — Each control requirement uses specific verbs (track, document, enforce, test). Address each verb explicitly
  4. Shared responsibility — For any customer-configurable or shared control, create a clear "Customer Responsibility" section
  5. Keep it consistent — Architecture diagrams, data flows, inventory, and control statements must all be internally consistent

3. NIST 800-53 Control Mapping

Control Families (Rev 5)

IDFamilyNotes
ACAccess ControlIAM, RBAC, least privilege, remote access
ATAwareness & TrainingSecurity + privacy training (new in Rev 5)
AUAudit & AccountabilityLog retention, SIEM, audit review
CAAssessment, Authorization & MonitoringConMon, 3PAO, ATO
CMConfiguration ManagementBaselines, change control, CMDB
CPContingency PlanningBCP/DR, tested annually
IAIdentification & AuthenticationMFA, PIV, FIPS 140-2/3 crypto
IRIncident ResponseIRP, tested annually, reporting SLAs
MAMaintenanceRemote maintenance controls
MPMedia ProtectionData at rest, media sanitization
PEPhysical & EnvironmentalDatacenters; often inherited from IaaS
PLPlanningSSP, rules of behavior
PMProgram ManagementEnterprise-level security program
PSPersonnel SecurityScreening, termination procedures
PTPII Processing & TransparencyNew family in Rev 5 — privacy controls
RARisk AssessmentVulnerability scanning, MITRE ATT&CK scoring
SASystem & Services AcquisitionSDLC, supply chain
SCSystem & Communications ProtectionEncryption in transit, network segmentation
SISystem & Information IntegrityPatching, malware, integrity monitoring
SRSupply Chain Risk ManagementNew family in Rev 5 — SCRM

CR26 Certification Class Mapping

Under CR26, the FedRAMP PMO is aligning control baselines to Certification Classes. When users describe their system, map to a class:

  • Class A (Pilot/Transitional): New baseline introduced under 20x — entry into the federal market via external frameworks (initially SOC 2 Type II) through Program Certification; Class A holders have a 2-year window to obtain a Class B, C, or D certification through full assessment
  • Class B (replaces LI-SaaS + Low): Systems handling non-sensitive federal information where a breach would cause limited harm
  • Class C (replaces Moderate): Most common — the majority of federal cloud deployments, including systems handling CUI
  • Class D (replaces High): Federal information where compromise has severe or catastrophic effect (e.g., law enforcement, financial, health data)
Legacy references: Many existing FedRAMP documents still reference Low/Moderate/High/LI-SaaS. These map to LI-SaaS/Low → Class B, Moderate → Class C, High → Class D (Class A is new — it has no legacy equivalent). During the CR26 transition, old and new labels are linked. Advise CSPs to check fedramp.gov for the latest.

Mapping Workflow

  1. Ask: What types of federal data will the system process/store/transmit?
  2. Determine target Certification Class (A, B, C, or D) under CR26
  3. Select NIST 800-53 Rev 5 baseline using the class mapping (B ↔ Low, C ↔ Moderate, D ↔ High)
  4. Cross-reference with FedRAMP parameter requirements (FedRAMP often sets stricter parameters than base NIST)
  5. For inherited controls, identify which are fully/partially inherited from leveraged FedRAMP IaaS/PaaS and document in CIS/CRM workbook

Rev 4 → Rev 5 Key Changes to Highlight

  • New control families: PT (Privacy), SR (Supply Chain)
  • Password controls revised: No more forced rotation schedules; requires compromised-password lists and password strength meters (NIST 800-63b alignment)
  • Privacy integrated: AT-3 now mandates privacy training; many families have privacy-specific enhancements
  • Threat-based methodology: MITRE ATT&CK framework informs control prioritization

4. Architecture Guidance

Authorization Boundary

The boundary defines what is IN scope for FedRAMP. This is one of the most common sources of findings and delays.

Key principles:

  • Everything that processes, stores, or transmits federal data must be inside the boundary
  • External services connected to in-scope systems must be FedRAMP-authorized OR documented with compensating controls
  • Boundary must be depicted in a clear network/data flow diagram (required in SSP)

Cloud Platform Considerations

AWS GovCloud (US)

  • AWS GovCloud is FedRAMP High authorized — most PE and some SC controls are fully inherited
  • Use AWS Config, CloudTrail, GuardDuty, Security Hub to satisfy AU, RA, SI controls
  • Ensure use of GovCloud region endpoints (not standard commercial) to stay in boundary
  • FIPS endpoints available for IA controls

Azure Government

  • Azure Government is FedRAMP High authorized
  • Azure Policy + Defender for Cloud maps well to CM, RA, SI
  • Use Azure Blueprints / Policy Initiatives aligned to FedRAMP Moderate/High

Google Cloud (FedRAMP-authorized regions)

  • Assured Workloads for FedRAMP compliance
  • Chronicle SIEM for AU controls

Architecture Patterns That Support FedRAMP

  • Zero Trust — aligns directly with AC, IA, SC control families
  • Immutable infrastructure — simplifies CM (configuration drift is a common finding)
  • Centralized logging — SIEM/log aggregation addresses AU family comprehensively
  • Automated vulnerability scanning — Required; must cover OS, DB, web app, and containers (if used)
  • OSCAL-native tooling — Invest now; OSCAL submission is mandatory September 30, 2026

Common Architecture Findings

  • Undocumented external connections leaving the boundary
  • FIPS-non-compliant encryption algorithms in transit or at rest
  • Overly broad IAM roles / lack of least privilege
  • Missing MFA on privileged accounts
  • Vulnerability scans not covering all boundary components
  • Logging gaps (not all components sending logs to centralized SIEM)
  • Authorization packages not in OSCAL format ahead of September 2026 mandate

5. Continuous Monitoring

Once authorized, CSPs must maintain compliance through ConMon activities:

Monthly Requirements

  • Vulnerability scan results submitted to agency AOs
  • POA&M updates (open findings, remediation progress)
  • Inventory updates (new/removed assets)
  • ConMon Monthly Executive Summary (template updated Nov 2024)

Annual Requirements

  • Full security assessment by 3PAO using Annual Assessment Controls Selection Worksheet
  • Updated SSP and appendices
  • Tested IRP and CP
  • SAR and updated POA&M

POA&M Management

  • All open findings must have: risk level, owner, milestone dates, remediation plan
  • Vendor Dependencies (VDs): when a finding depends on a third-party fix — document and track
  • Deviation Requests (DRs): false positives and risk adjustments require AO approval
  • SLA for remediation (FedRAMP ConMon Performance Management Guide): High = 30 days, Moderate = 90 days, Low = 180 days from identification. Where Critical is distinguished from High (e.g., scanner ratings), treat it as High-or-stricter (≤30 days, prioritized immediately)

Output Formatting Guide

Match output format to request type:

Request TypePreferred Format
Gap assessmentTable + prose summary
SSP control narrativeProse paragraphs (one per control/enhancement)
POA&M entryStructured table row with all required fields
Architecture reviewBullet findings + recommended remediations
Control mapping questionTable: Control ID \Requirement \How to Implement
Readiness overviewExecutive summary prose + priority action list

When generating document content, always note: "Use official FedRAMP templates from fedramp.gov — this content should be inserted into the appropriate template section."


Reference Files

Load these when more depth is needed:

  • references/readiness-checklist.md — Full readiness checklist (75+ items)
  • references/ssp-guide.md — SSP section-by-section writing guide
  • references/poam-guide.md — POA&M structure, field definitions, SLA table
  • references/sap-sar-guide.md — SAP/SAR overview and review tips for CSPs
  • references/appendices-guide.md — Guide to all SSP appendices (A–Q)
  • references/control-families.md — Deep-dive on each of the 20 control families

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
du même dépôt

Autres Skills

Tous les Skills
sushegaad
Communauté

dpdpa

Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: "Section 6 consent", "Section 7 legitimate uses", "Section 9 children's data", "Section 10 SDF", "Section 16 cross-border", "Rule 6 breach notification", "Rule 13 SDF obligations", "Data Protection Board complaint", "verifiable parental consent India", "DPDPA compliance roadmap", or "India privacy law global company".

installations
1
GitHub Stars
876
Mis à jour
30 août
sushegaad
Communauté

eu-cra

Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the EU. Use this skill for gap analysis, product classification (Default / Class I / Class II), conformity assessment route selection, CE marking, SBOM requirements, vulnerability and incident reporting to ENISA/CSIRTs, support period obligations, and manufacturer/importer/distributor duties. Trigger for EU CRA, Cyber Resilience Act, PDE compliance, Annex I requirements, SBOM EU, CE marking cybersecurity, or connected product security EU.

installations
1
GitHub Stars
876
Mis à jour
30 août
sushegaad
Communauté

gdpr-compliance

Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing Agreements (DPAs), and consent notices, (3) answering GDPR compliance questions with authoritative article citations, and (4) reviewing data flows and PII handling practices. Use this skill whenever the user mentions GDPR, data protection, privacy compliance, lawful basis, data subject rights, DPA, privacy notices, consent management, data breaches, DPIAs, controller/ processor relationships, cross-border data transfers, or any EU/UK data privacy topic. Also trigger for questions like "is this GDPR compliant?", "how do I handle personal data?", "what does a privacy policy need?", or any request involving PII, personal data, or data retention in a regulatory context.

installations
1
GitHub Stars
876
Mis à jour
30 août
sushegaad
Communauté

ism

Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control selection, gap analysis, system authorisation, IRAP assessment preparation, security documentation, and ASD compliance. Triggers on: ISM controls, ASD compliance, IRAP assessment, PROTECTED system scoping, Essential Eight vs ISM, system authorisation, NC/OS/ PROTECTED/SECRET/TOP SECRET classification markings, security objectives, ISM guidelines or chapters, control applicability markings, cybersecurity documentation for Australian government, the June 2026 ISM update, ISM AI application controls (ISM-2112/2113/2114), and any question about the ASD Information Security Manual framework or Australian government cybersecurity obligations.

installations
1
GitHub Stars
876
Mis à jour
30 août