Skip to main content
Pricing
Sign inRequest demo
SCG-CSO-AUPMUSTAll frameworksImplementation guide coming soon

Use Instructions

Secure Configuration Guide (SCG) · General Provider Responsibilities

Applies to: Providers
Who this applies to
Providers
Service class
All service classes
Force
MUST
Timeframe
No fixed timeframe

Reviewed implementation guidance for SCG-CSO-AUP is not published yet. The official source below remains complete and authoritative.

Expected evidence artifacts

  • URL or explanation of how to request these materials.
  • Explanation of how the provider decides whether or not to share these materials or other related policies.

Official FedRAMP source

Verbatim from FedRAMP/rules

Providers MUST include instructions in the FedRAMP Certification Package that explain how to obtain and use the Secure Configuration Guide.

Defined terms in this requirement

Operationalize this rule

Boundera turns FedRAMP 20x requirements like SCG-CSO-AUP into assigned evidence, remediation work, and validation workflows.

See it on your cloud

Notes

  • These instructions may appear in a variety of ways; it is up to the provider to do so in the most appropriate and effective ways for their specific customer needs.

Change history

  • 2026-06-24Official launch of the FedRAMP Consolidated Rules for 2026.

Content provenance

Official requirement text is sourced from FedRAMP/rules . Boundera implementation guidance has not been fully reviewed for this item.