fedramp

Guides FedRAMP authorization, ATO documentation, NIST 800-53 control mapping, and continuous monitoring.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill fedramp-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: fedramp
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/fedramp
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill fedramp-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Navigating FedRAMP authorization is complex: CSPs must choose the right certification class, write hundreds of pages of ATO documentation (SSP, SAP, SAR, POA&M), map NIST SP 800-53 Rev 5 controls, and maintain continuous monitoring compliance. This Skill provides structured expert guidance across the entire FedRAMP lifecycle under the CR26 rules. ## Core Features & Use Cases - Readiness & Gap Assessment: Run structured gap assessments using a 75+ item readiness checklist, producing prioritized gap tables mapped to control families. - ATO Documentation Guidance: Section-by-section writing guidance for the SSP and all appendices A–Q, plus POA&M field definitions, SLA tables, and SAP/SAR review tips. - Control Mapping & Architecture: Map systems to CR26 Certification Classes A–D, review cloud architectures (AWS GovCloud, Azure Government, GCP) against FedRAMP requirements, and identify common findings. - Use Case: A SaaS company targeting FedRAMP Moderate (Class C) asks which controls apply and how to write their SSP Section 10 control narratives — the Skill maps the baseline, flags Rev 5 changes (PT and SR families), and provides per-control writing guidance. ## Quick Start Ask the assistant to perform a FedRAMP readiness gap assessment for your cloud service offering, including your target certification class and cloud platform.

Frequently Asked Questions about fedramp

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for FedRAMP authorization?

Start with a readiness gap assessment: define your authorization boundary, determine your target Certification Class (A–D under CR26), and work through a readiness checklist covering policies, MFA, encryption, vulnerability scanning, and logging. Then select FedRAMP 20x or a legacy agency authorization path.

What documents are required for a FedRAMP ATO package?

The core package includes the System Security Plan (SSP) with appendices A–Q, the 3PAO-prepared Security Assessment Plan (SAP) and Security Assessment Report (SAR), and the POA&M. All must use official FedRAMP PMO templates, with OSCAL format mandatory by September 30, 2026.

How do FedRAMP Certification Classes map to Low, Moderate, and High baselines?

Under CR26 (notice NTC-0004), Class B replaces LI-SaaS and Low, Class C replaces Moderate, and Class D replaces High. Class A is a new pilot/transitional baseline entered via external frameworks like SOC 2 Type II, with a 2-year window to obtain B, C, or D.

What are the FedRAMP POA&M remediation SLAs?

Per the FedRAMP Continuous Monitoring Performance Management Guide: High findings must be remediated within 30 days, Moderate within 90 days, and Low within 180 days of identification. Critical findings, where distinguished from High, should be treated as 30 days or stricter.

Does FedRAMP require FIPS-validated encryption?

Yes. All federal data must be encrypted at rest and in transit using FIPS 140-2 or 140-3 validated cryptographic modules, with TLS 1.2 minimum (1.3 preferred) in transit. Every module must be listed in the SSP's Cryptographic Modules Table appendix with its CMVP certificate number.

When should I not pursue FedRAMP Ready?

FedRAMP Ready retires July 28, 2026, and no new designations are being issued. CSPs currently pursuing Ready should pivot immediately to FedRAMP 20x, now the primary authorization pathway, or begin a full agency authorization package.