SCG-CSO-AUPMUSTAll frameworksImplementation guide coming soonUse Instructions
Secure Configuration Guide (SCG) · General Provider Responsibilities
Applies to: Providers
- Who this applies to
- Providers
- Service class
- All service classes
- Force
- MUST
- Timeframe
- No fixed timeframe
Reviewed implementation guidance for SCG-CSO-AUP is not published yet. The official source below remains complete and authoritative.
Expected evidence artifacts
- URL or explanation of how to request these materials.
- Explanation of how the provider decides whether or not to share these materials or other related policies.
Official FedRAMP source
Verbatim from FedRAMP/rules
Providers MUST include instructions in the FedRAMP Certification Package that explain how to obtain and use the Secure Configuration Guide.
Defined terms in this requirement
Notes
- These instructions may appear in a variety of ways; it is up to the provider to do so in the most appropriate and effective ways for their specific customer needs.
Change history
2026-06-24Official launch of the FedRAMP Consolidated Rules for 2026.
Content provenance
Official requirement text is sourced from FedRAMP/rules . Boundera implementation guidance has not been fully reviewed for this item.