Skip to main content

FedRAMP 20x Agency Onboarding: Connect Your Package to the Customer System

Identify the certified offering, share usable package references, and connect provider capabilities to customer configuration and operating responsibilities. The agency documents and authorizes its own information system and retains its risk decision. A handoff record is an implementation aid; the agency decides the outcome.

Written by Boundera Team|October 10, 2026|3 min read

Main question

How should a 20x provider hand off package information for an agency customer's system authorization?

FedRAMP 20x agency onboarding works best when the handoff connects your package to the customer's actual use of the service. Give the agency a clear way to identify the certified offering, understand the capabilities it will rely on, and configure the responsibilities it owns.

The provider package is reusable evidence. The agency still makes its own system authorization and risk decision. A useful handoff helps the customer describe that use without copying your entire package into its system documentation.

Start with the agency system and the certified offering

FedRAMP's agency-use guidance distinguishes certification of the cloud offering from authorization of the agency information system. It says the agency authorizing official accepts risk for the agency's specific use, including its information, configuration, integrations and agency-operated controls. It directs agencies to authorize the system using the offering as an external service rather than create a standalone ATO for the offering itself. FedRAMP Using a Certified Cloud Service

The same guidance tells agencies to confirm they are using the certified version and review the package, including certification type and class, inherited controls, provider responsibilities, secure configuration guidance and ongoing data.

For the provider's handoff, begin with the exact offering and services the customer intends to use. Ask the customer to identify its intended integration and configuration so the discussion stays tied to a concrete deployment.

Map capabilities to customer actions

The official agency SSP guidance says to account for every selected control, describe agency implementation in detail and reference the provider package for capabilities the agency uses or relies on. It calls for one SSP for the agency information system rather than a separate agency SSP for each cloud service. FedRAMP Agency System Security Plan

A provider-side handoff record can help organize that discussion. The following fields are editorial suggestions for that discussion:

Handoff topicUseful provider contributionCustomer decision to clarify
Service scopeOffering identity, service names and relevant package referencesWhich services the agency plans to use
IdentitySupported configuration guidance and capability evidenceHow the agency configures accounts, groups and its identity integration
LoggingEvent and export capability documentationWhat the agency collects, reviews and responds to
Shared operationsApplicable provider procedures and contact routesWho owns customer-side activities and escalations

Use the secure configuration guide article for the customer-settings part of this handoff. Avoid rewriting the configuration workflow into a second, potentially conflicting checklist.

Share references that remain usable

As an implementation practice, supply stable references to the relevant package material and note the version used in the onboarding discussion. Have the customer's intended readers exercise access before depending on those references in their documentation.

Follow the package-sharing review approach when preparing material for the recipient. Keep the risk explanation useful and direct the customer to the appropriate access route for supporting evidence.

For each open question, record which party will answer it and whether it concerns provider evidence or an agency implementation choice. This can keep a request for a customer-specific setting from becoming an unnecessary rewrite of the provider package.

Connect onboarding to ongoing operation

FedRAMP's agency-use guidance says agencies should monitor ongoing certification reports, vulnerability information, quarterly reviews and other certification data at intervals appropriate to their system's risk. Its SSP guidance also calls for updates when use, configuration, dependencies or relevant provider capabilities change. FedRAMP agency-use guidance

Before completing the handoff, identify the recipients for ongoing information and agree how implementation questions will reach the right owner. Our collaborative monitoring guide explains the broader division of responsibilities.

Treat onboarding completion as a record of what was explained, shared and left open. The agency retains its authorization decision; a well-organized handoff supports that decision without promising its outcome.

Frequently asked questions

Should the agency copy the provider package into its SSP?

Official guidance says the SSP should describe the agency's implementation and reference provider package evidence for capabilities it uses or relies on, rather than copy the full provider implementation.

Does the agency issue a standalone ATO for the cloud offering?

FedRAMP's agency-use guidance directs agencies to authorize the federal information system that uses the offering as an external service, rather than create a standalone offering ATO.

Is the handoff table an official required artifact?

No. It is an editorial tool for organizing provider references and customer decisions during onboarding.

Next step

If you want to turn this guidance into an execution plan, the product side handles control mapping, SSP drafting, and evidence collection.

Related articles