FedRAMP 20x Secure Configuration Guide: Beyond the Responsibility Matrix
Explain the lifecycle of top-level administrative accounts and the security implications of their restricted settings. Put instructions for obtaining and using the guide in the Certification Package. Keep public availability, secure defaults and enhanced capabilities labeled with their SHOULD strength.
In this article
Main question
What should a Class B or C FedRAMP 20x Secure Configuration Guide explain to customer administrators?
A responsibility matrix can identify a customer-owned task without telling the administrator how to perform it. A useful FedRAMP 20x Secure Configuration Guide closes that gap: it connects a setting, the account that controls it, and the security effect of the customer's choice.
This guide focuses on the current Class B and Class C provider rules. FedRAMP's June 2026 transition notice described the Secure Configuration Guide as replacing the Control Implementation Summary / Customer Responsibility Matrix. For the actual contents and requirement strength, use the current Secure Configuration Guide rules.
Start with the customer's administrative tasks
SCG-CSO-RSC requires providers to create, maintain, and make available secure configuration recommendations. Its required content covers instructions for securely accessing, configuring, operating, and decommissioning top-level administrative accounts that control enterprise access to the whole offering. It also requires explanations of security settings only those accounts can operate, including their security implications. Explanations for settings restricted to other privileged accounts are recommended.
Build your content inventory around the product's actual account names and administrative screens. A suggested entry might include the setting name, account role, secure recommendation, steps to apply it, and the effect of changing it. Those fields are an editorial format, not a FedRAMP-prescribed template.
For example, a customer-facing entry for an administrative session setting could explain who can change it, what behavior changes, and how the administrator confirms the result. Use a value supported by your product's security design. Do not invent a universal FedRAMP setting value where the rule asks you to explain your offering.
Make the instructions usable from the package
SCG-CSO-AUP requires instructions in the Certification Package explaining how to obtain and use the guide. The rule allows providers to choose an appropriate presentation for their customers. SCG-CSO-RSC likewise permits appropriate forms of guidance rather than requiring one specific document layout.
Test the path a customer actually follows: start at the package instructions, open the guide, locate the named administrative account, and follow one configuration task. Record broken links, outdated screen labels, or prerequisites the guide assumes without explaining. This is a suggested usability check for your release process.
Public availability has a different requirement strength: SCG-CSO-PUB says providers SHOULD make the guide public. Do not turn that recommendation into a blanket MUST, and do not confuse it with the separate obligation to supply package instructions for obtaining and using the guide.
Separate secure defaults from enhanced capabilities
SCG-CSO-SDF says settings for top-level administrative and privileged accounts SHOULD start at the recommended secure defaults when initially provisioned. The enhanced-capability rules also use SHOULD:
- SCG-ENH-CMP: compare current account settings with recommended secure defaults.
- SCG-ENH-EXP: export all security settings in a machine-readable format.
- SCG-ENH-API: view and adjust security settings through an API or similar capability.
- SCG-ENH-MRG: supply machine-readable guidance usable for comparisons.
- SCG-ENH-VRH: provide versioning and release history for recommended secure defaults as they change.
Use those distinctions when planning engineering work. A guide, a settings export, and a comparison feature serve related but different customer needs. Describe the capabilities your service actually supplies instead of promising that publishing instructions creates the rest.
Review the guide when the product changes
Assign a content owner for each administrative area and include guidance review in relevant release work. A suggested review should check renamed settings, new privileged roles, changed defaults, and instructions for decommissioning access. Preserve enough internal context to explain why a recommendation changed.
The current 20x SCG page shows March 1, 2026 for obtaining and maintaining certification and July 1, 2026 as the grace-period end. These dates differ from the January 2027 maintenance dates on some other rule sets. Check the applicable SCG rules directly when setting your plan.
The reader should leave the guide able to perform a task and understand its consequence. Keep the responsibility mapping as useful context, then supply the operational instructions that an administrator needs at the point of configuration.
Frequently asked questions
Must the guide use a particular document template?
The SCG rules allow appropriate forms of guidance and flexible presentation of the instructions for obtaining and using it. The required information still needs to be supplied.
Must the Secure Configuration Guide be public?
SCG-CSO-PUB uses SHOULD for public availability. SCG-CSO-AUP separately uses MUST for Certification Package instructions explaining how to obtain and use the guide.
Are machine-readable exports and comparison features mandatory under the SCG enhanced-capability rules?
The cited enhanced-capability rules use SHOULD. Preserve that distinction while evaluating exports, comparison, API access, machine-readable guidance and version history.
Next step
If you want to turn this guidance into an execution plan, the product side handles control mapping, SSP drafting, and evidence collection.
Related articles
FedRAMP 20x: Do You Need a Separate Government Deployment?
Compare shared and dedicated deployment designs for Class B/C using the shared-infrastructure policy, actual assessment scope and agency needs.
FedRAMP 20x: Handle Denied Agency Package Access Requests
Handle denied agency package-access requests for Class B/C providers using a compatible trust center, preserving the five-business-day notification trigger.
FedRAMP 20x: Reconcile Agency Access Records in Your Trust Center
Reconcile Class B/C trust-center permission history and access activity, with the right six-month summary retention and request-specific retrieval.