What problem does it solve? Navigating FedRAMP authorization is complex: CSPs must choose the right certification class, write hundreds of pages of ATO documentation (SSP, SAP, SAR, POA&M), map NIST SP 800-53 Rev 5 controls, and maintain continuous monitoring compliance. This Skill provides structured expert guidance across the entire FedRAMP lifecycle under the CR26 rules. ## Core Features & Use Cases - Readiness & Gap Assessment: Run structured gap assessments using a 75+ item readiness checklist, producing prioritized gap tables mapped to control families. - ATO Documentation Guidance: Section-by-section writing guidance for the SSP and all appendices A–Q, plus POA&M field definitions, SLA tables, and SAP/SAR review tips. - Control Mapping & Architecture: Map systems to CR26 Certification Classes A–D, review cloud architectures (AWS GovCloud, Azure Government, GCP) against FedRAMP requirements, and identify common findings. - Use Case: A SaaS company targeting FedRAMP Moderate (Class C) asks which controls apply and how to write their SSP Section 10 control narratives — the Skill maps the baseline, flags Rev 5 changes (PT and SR families), and provides per-control writing guidance. ## Quick Start Ask the assistant to perform a FedRAMP readiness gap assessment for your cloud service offering, including your target certification class and cloud platform.