Expert guidance for FedRAMP certification and compliance. Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document types: SSP, SAP, SAR, POA&M, CIS/CRM workbooks. Also trigger for questions about FedRAMP impact levels (Low, Moderate, High, LI-SaaS), FedRAMP 20x, OSCAL, 3PAO assessments, continuous monitoring (ConMon), gap assessments, system boundary definition, FedRAMP readiness, or architecture reviews for federal cloud. When in doubt, use this skill — it covers the full FedRAMP lifecycle from readiness through continuous monitoring.
A comprehensive guide for helping users navigate FedRAMP authorization — from initial readiness through ATO and ongoing continuous monitoring.
Identify the user's goal and jump to the appropriate section:
| User Goal | Go To |
|---|---|
| "Are we ready for FedRAMP?" / gap assessment | → Readiness & Gap Assessment |
| Writing SSP, POA&M, SAR, SAP, or other docs | → ATO Documentation |
| "Which controls apply to us?" / control mapping | → NIST 800-53 Control Mapping |
| Cloud architecture / AWS/Azure/GCP config |
| → Architecture Guidance |
| Already authorized, ongoing compliance | → Continuous Monitoring |
references/readiness-checklist.mdThe core FedRAMP authorization package consists of:
Authorization Package
├── System Security Plan (SSP) + Appendices A–Q
├── Security Assessment Plan (SAP) + Appendices A–D [3PAO-prepared]
├── Security Assessment Report (SAR) + Appendices A–F [3PAO-prepared]
└── Plan of Action & Milestones (POA&M) [SSP Appendix O]
Important: CSPs must use official FedRAMP PMO templates. Reviewers are trained on standardized formats; non-standard submissions risk rejection or delays. Templates: https://www.fedramp.gov/rev5/documents-templates/
For detailed guidance on each document type, read the appropriate reference file:
references/ssp-guide.mdreferences/poam-guide.mdreferences/sap-sar-guide.mdreferences/appendices-guide.md| ID | Family | Notes |
|---|---|---|
| AC | Access Control | IAM, RBAC, least privilege, remote access |
| AT | Awareness & Training | Security + privacy training (new in Rev 5) |
| AU | Audit & Accountability | Log retention, SIEM, audit review |
| CA | Assessment, Authorization & Monitoring | ConMon, 3PAO, ATO |
| CM | Configuration Management | Baselines, change control, CMDB |
| CP | Contingency Planning | BCP/DR, tested annually |
| IA | Identification & Authentication | MFA, PIV, FIPS 140-2/3 crypto |
| IR | Incident Response | IRP, tested annually, reporting SLAs |
| MA | Maintenance | Remote maintenance controls |
| MP | Media Protection | Data at rest, media sanitization |
| PE | Physical & Environmental | Datacenters; often inherited from IaaS |
| PL | Planning | SSP, rules of behavior |
| PM | Program Management | Enterprise-level security program |
| PS | Personnel Security | Screening, termination procedures |
| PT | PII Processing & Transparency | New family in Rev 5 — privacy controls |
| RA | Risk Assessment | Vulnerability scanning, MITRE ATT&CK scoring |
| SA | System & Services Acquisition | SDLC, supply chain |
| SC | System & Communications Protection | Encryption in transit, network segmentation |
| SI | System & Information Integrity | Patching, malware, integrity monitoring |
| SR | Supply Chain Risk Management | New family in Rev 5 — SCRM |
When the user describes their system, recommend the impact level:
The boundary defines what is IN scope for FedRAMP. This is one of the most common sources of findings and delays.
Key principles:
AWS GovCloud (US)
Azure Government
Google Cloud (FedRAMP-authorized regions)
Once authorized, CSPs must maintain compliance through ConMon activities:
Match output format to request type:
| Request Type | Preferred Format |
|---|---|
| Gap assessment | Table + prose summary |
| SSP control narrative | Prose paragraphs (one per control/enhancement) |
| POA&M entry | Structured table row with all required fields |
| Architecture review | Bullet findings + recommended remediations |
| Control mapping question | Table: Control ID | Requirement | How to Implement |
| Readiness overview | Executive summary prose + priority action list |
When generating document content, always note: "Use official FedRAMP templates from fedramp.gov — this content should be inserted into the appropriate template section."
Load these when more depth is needed:
references/readiness-checklist.md — Full readiness checklist (75+ items)references/ssp-guide.md — SSP section-by-section writing guidereferences/poam-guide.md — POA&M structure, field definitions, SLA tablereferences/sap-sar-guide.md — SAP/SAR overview and review tips for CSPsreferences/appendices-guide.md — Guide to all SSP appendices (A–Q)references/control-families.md — Deep-dive on each of the 20 control families