Skip to main content
WhyHow It WorksFeaturesPricingBlog
Sign inRequest demo

FedRAMP 20x for cloud service providers

Know what is required. Build it. Prove it.

Search every KSI and the 148 rules addressed to providers. See the requirement, implementation guidance, and evidence context without sorting through obligations owned by agencies, assessors, or FedRAMP.

Based on FedRAMP/rules 2026.06.04.01-preview, updated 2026-06-04

CSP implementation explorer

Showing 148 of 254 CSP resources

Provider ruleCCMMUST
CCM-OCR-AFS

Anonymized Feedback Summary

All service classesOfficial source
Provider ruleCCMMUST
CCM-OCR-AVL

Report Availability

All service classesOfficial source
Provider ruleCCMMUST
CCM-OCR-FBM

Feedback Mechanism

All service classesOfficial source
Provider ruleCCMMUST NOT
CCM-OCR-LSI

Limit Sensitive Information

All service classesOfficial source
Provider ruleCCMMUST
CCM-OCR-NRD

Next Report Date

All service classesOfficial source
Provider ruleCCMMAY
CCM-OCR-RPS

Responsible Public Certification Report Sharing

All service classesOfficial source
Provider ruleCCMSHOULD
CCM-OCR-SOR

Spread Out Reports

All service classesOfficial source
Provider ruleCCMSHOULD
CCM-QTR-ACT

Additional Content

All service classesOfficial source
Provider ruleCCM
CCM-QTR-MTG

Quarterly Review Meeting

Classes A, B, C, DOfficial source
Provider ruleCCMMUST NOT
CCM-QTR-NID

No Irresponsible Disclosure

All service classesOfficial source
Provider ruleCCMMUST
CCM-QTR-NRD

Next Review Date

All service classesOfficial source
Provider ruleCCMMUST
CCM-QTR-REG

Meeting Registration Info

All service classesOfficial source
Provider ruleCCMSHOULD NOT
CCM-QTR-RTP

Restrict Third Parties

All service classesOfficial source
Provider ruleCCMSHOULD
CCM-QTR-RTR

Record/Transcribe Reviews

All service classesOfficial source
Provider ruleCCMSHOULD
CCM-QTR-SAR

Schedule Around Reports

All service classesOfficial source
Provider ruleCCMMAY
CCM-QTR-SCR

Share Content Responsibly

All service classesOfficial source
Provider ruleCCMMAY
CCM-QTR-SRR

Share Recordings Responsibly

All service classesOfficial source
Provider ruleCDS
CDS-CSO-AVR

Availability Reporting

Classes A, B, C, DOfficial source
Provider ruleCDSMUST
CDS-CSO-CBF

Consistency Between Formats

All service classesOfficial source
Provider ruleCDSMUST
CDS-CSO-HAD

Historical FedRAMP Certification Data

All service classesOfficial source
Provider ruleCDS
CDS-CSO-PSM

Per-Service Certification Materials

Classes A, B, C, DOfficial source
Provider ruleCDSMUST
CDS-CSO-PUB

Public Information

All service classesOfficial source
Provider ruleCDSMUST
CDS-CSO-RIS

Responsible Information Sharing

All service classesOfficial source
Provider ruleCDSMAY
CDS-CSO-RPS

Responsible Public Package Sharing

All service classesOfficial source
Provider ruleCDSMUST
CDS-CSO-SVC

Service List

All service classesOfficial source
Provider ruleCDSMUST
CDS-CSO-UTC

Use Trust Centers

All service classesOfficial source
Provider ruleCDSMUST
CDS-TRC-AAI

Agency Access Inventory

All service classesOfficial source
Provider ruleCDSMUST
CDS-TRC-ACL

Access Logging

All service classesOfficial source
Provider ruleCDSSHOULD
CDS-TRC-HMR

Human and Machine-Readable Certification Data

All service classesOfficial source
Provider ruleCDSMUST
CDS-TRC-PAC

Programmatic Access

All service classesOfficial source
Provider ruleCDSSHOULD
CDS-TRC-SSM

Self-Service Access Management

All service classesOfficial source
Provider ruleCDSMUST
CDS-TRC-USH

Uninterrupted Sharing

All service classesOfficial source
Provider ruleCDSMUST
CDS-UTC-AAD

Agency Access Denial

All service classesOfficial source
Provider ruleCDSSHOULD
CDS-UTC-AGA

Agency Access

All service classesOfficial source
Provider ruleFRAMAY
FRA-CSO-RAA

Receiving Assessor Advice

All service classesOfficial source
Provider ruleFRASHOULD
FRA-CSO-STE

Supply Technical Evidence

All service classesOfficial source
Provider ruleFSISHOULD
FSI-CSO-ACK

Acknowledge Receipt

All service classesOfficial source
Provider ruleFSIMUST
FSI-CSO-CRA

Complete Required Actions

All service classesOfficial source
Provider ruleFSIMUST
FSI-CSO-EMR

Emergency Message Routing

All service classesOfficial source
Provider ruleFSISHOULD
FSI-CSO-IMA

Important Message Actions

All service classesOfficial source
Provider ruleFSIMUST
FSI-CSO-INB

Maintain a FedRAMP Security Inbox

All service classesOfficial source
Provider ruleFSIMUST
FSI-CSO-NOC

Notification of Changes

All service classesOfficial source
Provider ruleFSIMUST
FSI-CSO-RCV

Receive Email Without Disruption

All service classesOfficial source
Provider ruleFSIMUST
FSI-CSO-TFG

Trust @fedramp.gov and @gsa.gov

All service classesOfficial source
Provider ruleICPSHOULD
ICP-CSO-AIR

Automated Incident Reporting

All service classesOfficial source
Provider ruleICPMUST
ICP-CSO-DPR

Default PAIN Rating

All service classesOfficial source
Provider ruleICPSHOULD
ICP-CSO-EFI

Estimate Federal Impact

All service classesOfficial source
Provider ruleICPMUST
ICP-CSO-EFR

Evaluate FedRAMP Reportability

All service classesOfficial source
Provider ruleICP
ICP-CSO-FIR

Final Incident Report

Classes A, B, C, DOfficial source
Provider ruleICP
ICP-CSO-IIR

Initial Incident Report

Classes A, B, C, DOfficial source
Provider ruleICP
ICP-CSO-OIR

Ongoing Incident Reports

Classes A, B, C, DOfficial source
Provider ruleIFRMUST
IFR-APP-AFC

Applying for FedRAMP Certification

All service classesOfficial source
Provider ruleIFRMUST
IFR-APP-FCP

Fresh FedRAMP Certification Package

All service classesOfficial source
Provider ruleIFRMUST
IFR-APP-FIA

Fresh Independent Assessment

All service classesOfficial source
Provider ruleIFRMUST
IFR-APP-MLF

Marketplace Listing First

All service classesOfficial source
Provider ruleIFRMUST
IFR-APS-ATO

Agency Authorization to Operate

All service classesOfficial source
Provider ruleIFRMUST
IFR-CLA-AFR

Address FedRAMP Rules

All service classesOfficial source
Provider ruleIFRMUST
IFR-CLA-ASF

Approved Alternative Security Frameworks

All service classesOfficial source
Provider ruleIFRMUST
IFR-CLA-EAM

External Assessment Materials

All service classesOfficial source
Provider ruleIFRMAY
IFR-CLA-IVV

Optional Independent Verification and Validation

All service classesOfficial source
Provider ruleIFRMUST
IFR-CLA-KSM

Key Security Indicator Mapping

All service classesOfficial source
Provider ruleIFR
IFR-CSO-PKG

FedRAMP Certification Package

Classes A, B, C, DOfficial source
Provider ruleIFRMUST NOT
IFR-CSO-POP

Pick One Program Certification Type

All service classesOfficial source
Provider ruleIFRSHOULD
IFR-CSX-MAS

Application within MAS

All service classesOfficial source
Provider ruleIFRMUST
IFR-CSX-SUM

Initial Implementation Summaries

All service classesOfficial source
Provider ruleMASMUST
MAS-CSO-FLO

Information Flows and Security Categories

All service classesOfficial source
Provider ruleMASMUST
MAS-CSO-IIR

Identify Information Resources

All service classesOfficial source
Provider ruleMASMUST
MAS-CSO-MDI

Metadata Inclusion

All service classesOfficial source
Provider ruleMASMAY
MAS-CSO-SUP

Supplemental Information

All service classesOfficial source
Provider ruleMASMUST
MAS-CSO-TPR

Third-Party Information Resources

All service classesOfficial source
Provider ruleMKTMUST
MKT-CSO-AGU

Agency Use Cases

All service classesOfficial source
Provider ruleMKTMUST
MKT-CSO-LRQ

Listing Requests for Providers

All service classesOfficial source
Provider ruleMKTMUST
MKT-PRE-DCP

Demonstrating Continuous Progress

All service classesOfficial source
Provider ruleMKTMUST
MKT-PRE-DLA

Deadline for Assessment

All service classesOfficial source
Provider ruleMKTMUST
MKT-PRE-REQ

Preparation Phase Requirements

All service classesOfficial source
Provider ruleOFRMUST
OFR-AFR-CCM

Collaborative Continuous Monitoring

All service classesOfficial source
Provider ruleOFRMUST
OFR-AFR-CDS

FedRAMP Certification Data Sharing

All service classesOfficial source
Provider ruleOFRMUST
OFR-AFR-FSI

FedRAMP Security Inbox

All service classesOfficial source
Provider ruleOFRMUST
OFR-AFR-ICP

Incident Communications Procedures

All service classesOfficial source
Provider ruleOFRMUST
OFR-AFR-MAS

Minimum Assessment Scope

All service classesOfficial source
Provider ruleOFRMUST
OFR-AFR-SCG

Secure Configuration Guide

All service classesOfficial source
Provider ruleOFRMUST
OFR-AFR-SCN

Significant Change Notifications

All service classesOfficial source
Provider ruleOFRMUST
OFR-AFR-UCM

Using Cryptographic Modules

All service classesOfficial source
Provider ruleOFRMUST
OFR-AFR-VDR

Vulnerability Detection and Response

All service classesImplementation guidance
Provider ruleOFR
OFR-CSO-IVV

Independent Verification and Validation

Classes A, B, C, DOfficial source
Provider ruleSCGMUST
SCG-CSO-AUP

Use Instructions

All service classesOfficial source
Provider ruleSCGSHOULD
SCG-CSO-PUB

Public Secure Configuration Guidance

All service classesOfficial source
Provider ruleSCGMUST
SCG-CSO-RSC

Recommended Secure Configuration

All service classesOfficial source
Provider ruleSCGSHOULD
SCG-CSO-SDF

Secure Defaults

All service classesOfficial source
Provider ruleSCGSHOULD
SCG-ENH-API

API Capability

All service classesOfficial source
Provider ruleSCGSHOULD
SCG-ENH-CMP

Comparison Capability

All service classesOfficial source
Provider ruleSCGSHOULD
SCG-ENH-EXP

Export Capability

All service classesOfficial source
Provider ruleSCGSHOULD
SCG-ENH-MRG

Machine-Readable Guidance

All service classesOfficial source
Provider ruleSCGSHOULD
SCG-ENH-VRH

Versioning and Release History

All service classesOfficial source
Provider ruleSCNMUST
SCN-ADP-NTF

Notification Requirements

All service classesOfficial source
Provider ruleSCNMAY
SCN-CSO-ARI

Additional Relevant Information

All service classesOfficial source
Provider ruleSCNMAY
SCN-CSO-EMG

Emergency Changes

All service classesOfficial source
Provider ruleSCNMUST
SCN-CSO-EVA

Evaluate Changes

All service classesOfficial source
Provider ruleSCNMUST
SCN-CSO-HIS

Historical Notifications

All service classesOfficial source
Provider ruleSCNMUST
SCN-CSO-HRM

Human and Machine-Readable Notifications

All service classesOfficial source
Provider ruleSCNMUST
SCN-CSO-INF

Required Information

All service classesOfficial source
Provider ruleSCNMUST
SCN-CSO-MAR

Maintain Audit Records

All service classesOfficial source
Provider ruleSCNMAY
SCN-CSO-NOM

Notification Mechanisms

All service classesOfficial source
Provider ruleSCNSHOULD NOT
SCN-RTR-NNR

No Notification Requirements

All service classesOfficial source
Provider ruleSCNMUST
SCN-TRF-NAF

Notification After Finishing

All service classesOfficial source
Provider ruleSCNMUST
SCN-TRF-NAV

Notification After Verification

All service classesOfficial source
Provider ruleSCNMUST
SCN-TRF-NFP

Notification of Final Plans

All service classesOfficial source
Provider ruleSCNMUST
SCN-TRF-NIP

Notification of Initial Plans

All service classesOfficial source
Provider ruleSCNSHOULD
SCN-TRF-TPR

Third-Party Review

All service classesOfficial source
Provider ruleSCNMUST
SCN-TRF-UPD

Update Documentation

All service classesOfficial source
Provider ruleUCMSHOULD
UCM-CSO-CAT

Configuration of Agency Tenants

All service classesOfficial source
Provider ruleUCMMUST
UCM-CSO-CMD

Cryptographic Module Documentation

All service classesOfficial source
Provider ruleUCM
UCM-CSO-UVM

Using Validated Cryptographic Modules

Classes A, B, C, DOfficial source
Provider ruleVDRSHOULD
VDR-BST-ADT

Automate Detection

All service classesOfficial source
Provider ruleVDRSHOULD NOT
VDR-BST-AKE

Avoid KEVs

All service classesOfficial source
Provider ruleVDRSHOULD
VDR-BST-DAC

Detect After Changes

All service classesOfficial source
Provider ruleVDRSHOULD
VDR-BST-DFR

Design For Resilience

All service classesOfficial source
Provider ruleVDRSHOULD NOT
VDR-BST-MSP

Maintain Security

All service classesOfficial source
Provider ruleVDRMAY
VDR-BST-SIR

Sampling

All service classesOfficial source
Provider ruleVDRMUST
VDR-CSO-DET

Vulnerability Detection

All service classesOfficial source
Provider ruleVDRMUST
VDR-CSO-FAV

Failures Are Vulnerabilities

All service classesOfficial source
Provider ruleVDRMUST
VDR-CSO-RES

Vulnerability Response

All service classesOfficial source
Provider ruleVDRSHOULD
VDR-EVA-EFA

Evaluation Factors

All service classesOfficial source
Provider ruleVDRSHOULD
VDR-EVA-EFP

Evaluate False Positives

All service classesOfficial source
Provider ruleVDRMUST
VDR-EVA-EIR

Evaluate Internet-Reachability

All service classesOfficial source
Provider ruleVDRMUST
VDR-EVA-ELX

Evaluate Exploitability

All service classesOfficial source
Provider ruleVDRMUST
VDR-EVA-EPA

Estimate Potential Adverse Impact

All service classesOfficial source
Provider ruleVDRSHOULD
VDR-EVA-GRV

Group Vulnerabilities

All service classesOfficial source
Provider ruleVDRMUST
VDR-RPT-AVI

Accepted Vulnerability Info

All service classesOfficial source
Provider ruleVDRSHOULD
VDR-RPT-HLO

High-Level Overviews

All service classesOfficial source
Provider ruleVDRMUST NOT
VDR-RPT-NID

Responsible Disclosure

All service classesOfficial source
Provider ruleVDRMUST
VDR-RPT-PER

Persistent Reporting

All service classesOfficial source
Provider ruleVDRMAY
VDR-RPT-RPD

Responsible Public Disclosure

All service classesOfficial source
Provider ruleVDRMUST
VDR-RPT-VDT

Vulnerability Details

All service classesOfficial source
Provider ruleVDR
VDR-TFR-EVU

Evaluate Vulnerabilities Quickly

Classes A, B, C, DOfficial source
Provider ruleVDR
VDR-TFR-IRI

Internet-Reachable Incidents

Classes A, B, C, DOfficial source
Provider ruleVDRSHOULD
VDR-TFR-KEV

Remediate KEVs

All service classesOfficial source
Provider ruleVDRMUST
VDR-TFR-MAV

Mark Accepted Vulnerabilities

All service classesOfficial source
Provider ruleVDRMUST
VDR-TFR-MHR

Monthly Activity Report

All service classesOfficial source
Provider ruleVDR
VDR-TFR-MRH

Historical Activity

Classes A, B, C, DOfficial source
Provider ruleVDR
VDR-TFR-MVX

Persistent Machine Verification and Validation for 20x

Classes A, B, COfficial source
Provider ruleVDRMUST
VDR-TFR-NMV

Non-Machine Verification and Validation

All service classesOfficial source
Provider ruleVDR
VDR-TFR-NRI

Non-Internet-Reachable Incidents

Classes A, B, C, DOfficial source
Provider ruleVDR
VDR-TFR-PCD

Persistently Complete Detection

Classes A, B, C, DOfficial source
Provider ruleVDR
VDR-TFR-PDD

Persistent Drift Detection

Classes A, B, C, DOfficial source
Provider ruleVDR
VDR-TFR-PSD

Persistent Sample Detection

Classes A, B, C, DOfficial source
Provider ruleVDR
VDR-TFR-PVR

Mitigation and Remediation Expectations

Classes A, B, C, DOfficial source
Provider ruleVDRSHOULD
VDR-TFR-RMN

Remaining Vulnerabilities

All service classesOfficial source