What problem does it solve? Achieving a FedRAMP Authority to Operate requires navigating FIPS 199 categorization, NIST 800-53 Rev 5 control implementation, 3PAO assessment, and continuous monitoring — a process where unprovable control claims and imprecise authorization boundaries cause assessment failures and lost credibility. ## Core Features & Use Cases - Dual Pathway Guidance: Supports both the traditional Rev5 path (narrative SSP, agency sponsorship, 3PAO control-by-control assessment) and the FedRAMP 20x path (Key Security Indicators, automated machine-readable validation, no sponsor required). - Compliance Artifact Generation: Produces FIPS 199 categorizations, authorization boundary definitions, assessable SSP control implementation statements, POA&M entries, and ATO packages with OSCAL machine-readable formatting against the 2026/2027 deadlines. - Continuous Monitoring Design: Establishes monthly ConMon cadences, significant-change governance, POA&M management, and annual assessment planning to keep the ATO valid. - Use Case: A SaaS company pursuing FedRAMP Moderate uses this Skill to categorize its system under FIPS 199, draw the authorization boundary, write testable implementation statements for each 800-53 control, and build an honest POA&M before the 3PAO assessment. ## Quick Start Ask the agent to perform a FIPS 199 categorization for your system and recommend whether the Rev5 or FedRAMP 20x authorization pathway fits your timeline and sponsorship situation.