FedRAMP 20x for cloud service providers
Know what is required. Build it. Prove it.
Search every KSI and the 168 rules addressed to providers. See the requirement, implementation guidance, and evidence context without sorting through obligations owned by agencies, assessors, or FedRAMP. Not sure where you stand? Take the free FedRAMP 20x gap assessment to find your certification class and KSI readiness first.
Based on FedRAMP/rules 2026.07.06.01, updated 2026-07-06
CSP implementation explorer
Showing 35 of 284 CSP resources
KSICMT
KSI-CMT-LMCLogging Changes
All service classesImplementation guidance
KSICMT
KSI-CMT-RMVRedeploying vs Modifying
All service classesImplementation guidance
KSICMT
KSI-CMT-RVPReviewing Change Procedures
All service classesImplementation guidance
KSICMT
KSI-CMT-VTDValidating Throughout Deployment
All service classesImplementation guidance
KSICNA
KSI-CNA-DFPDefining Functionality and Privileges
All service classesImplementation guidance
KSICNA
KSI-CNA-EISEnforcing Intended State
Classes B, CImplementation guidance
KSICNA
KSI-CNA-IBPImplementing Best Practices
All service classesImplementation guidance
KSICNA
KSI-CNA-MATMinimizing Attack Surface
All service classesImplementation guidance
KSICNA
KSI-CNA-OFAOptimizing for Availability
All service classesImplementation guidance
KSICNA
KSI-CNA-RNTRestricting Network Traffic
All service classesImplementation guidance
KSICNA
KSI-CNA-RVPReviewing Protections
All service classesImplementation guidance
KSICNA
KSI-CNA-ULNUsing Logical Networking
All service classesImplementation guidance
KSIIAM
KSI-IAM-AAMAutomating Account Management
All service classesImplementation guidance
KSIIAM
KSI-IAM-APMAdopting Passwordless Methods
All service classesImplementation guidance
KSIIAM
KSI-IAM-ELPEnsuring Least Privilege
All service classesImplementation guidance
KSIIAM
KSI-IAM-JITAuthorizing Just-in-Time
All service classesImplementation guidance
KSIIAM
KSI-IAM-SNUSecuring Non-User Authentication
All service classesImplementation guidance
KSIIAM
KSI-IAM-SUSResponding to Suspicious Activity
All service classesImplementation guidance
KSIMLA
KSI-MLA-ALAAuthorizing Log Access
Classes B, CImplementation guidance
KSIMLA
KSI-MLA-EVCEvaluating Configurations
All service classesImplementation guidance Automated check
KSIMLA
KSI-MLA-LETLogging Event Types
All service classesImplementation guidance
KSIMLA
KSI-MLA-OSMOperating SIEM Capability
All service classesImplementation guidance
KSIMLA
KSI-MLA-RVLReviewing Logs
All service classesImplementation guidance
KSIPIY
KSI-PIY-GIVGenerating Inventories
All service classesImplementation guidance
KSIRPL
KSI-RPL-ABOAligning Backups with Objectives
All service classesImplementation guidance
KSIRPL
KSI-RPL-TRCTesting Recovery Capabilities
All service classesImplementation guidance
KSISCR
KSI-SCR-MITMitigating Supply Chain Risk
All service classesImplementation guidance
KSISCR
KSI-SCR-MONMonitoring Supply Chain Risk
All service classesImplementation guidance
KSISVC
KSI-SVC-ACMAutomating Configuration Management
All service classesImplementation guidance
KSISVC
KSI-SVC-ASMAutomating Secret Management
All service classesImplementation guidance
KSISVC
KSI-SVC-EISEvaluating and Improving Security
All service classesImplementation guidance
KSISVC
KSI-SVC-PRRPreventing Residual Risk
Classes B, CImplementation guidance
KSISVC
KSI-SVC-SINSecuring Information
All service classesImplementation guidance
KSISVC
KSI-SVC-VCMValidating Communications
Classes B, CImplementation guidance
KSISVC
KSI-SVC-VRIValidating Resource Integrity
All service classesImplementation guidance