Resources
FedRAMP 20x examples, templates, and planning resources for teams moving toward certification.
Explore certification-data examples, readiness checklists, playbooks, and planning tools. Each worked data example pairs human-readable HTML with machine-readable JSON.
All resources
The FedRAMP 20x Executive Playbook
A field guide to building a machine-readable FedRAMP 20x program: how to automate evidence and continuous validation without faking the attestation. Covers treating every check as a first-class object, deriving control status from live state, and keeping humans on the attestations machines can't make.
Control Implementation Matrix Template
Excel-based matrix for tracking implementation status of all NIST 800-53 controls. Includes responsibility assignments and evidence links.
FedRAMP 20x Historical VER Activity Example
See how recent active and accepted vulnerability records can be assembled into an automation-friendly historical VER snapshot.
FedRAMP 20x Ongoing Certification Report (OCR) Example
See how an OCR can summarize a reporting period's changes, planned work, accepted vulnerabilities, incidents, recommendations, and feedback mechanism.
Evidence Collection Guide by Control Family
Comprehensive guide showing what evidence is needed for each NIST 800-53 control family. Includes automated evidence sources.
FedRAMP 20x Incident Reports (IIR, OIR, FIR) Example
Follow fictional incident information from Initial through Ongoing and Final reports, including timelines, PAIN ratings, impact, activity, recovery, and root cause.
FedRAMP 20x Significant Change Notification (SCN) Examples
Follow a synthetic transformative-change lifecycle and contrast it with a rough adaptive notification that demonstrates a completeness failure.
FedRAMP 20x Accepted Vulnerability Information Example
Examine how accepted vulnerability records can pair technical evaluation fields with explicit rationale and accountable senior-official acceptance.
FedRAMP 20x Vulnerability Detail Report Example
Study three synthetic vulnerability records showing detection, internet reachability, likely exploitability, completed evaluation, and current rating fields.
FedRAMP 20x Security Decision Record (SDR) Example
Explore a substantial SDR example containing FedRAMP rule records, KSI summaries, validation statements, evidence references, tests, and historical metrics.
FedRAMP 20x Certification Package Overview (CPO) Example
See how a FedRAMP 20x Certification Package Overview can organize offering metadata, documentation links, service scope, contacts, and third-party resources.
FedRAMP Budget & Timeline Calculator
Interactive spreadsheet to estimate FedRAMP authorization costs and timeline based on your baseline level and current readiness.
FedRAMP Readiness Assessment Checklist
Self-assessment checklist to determine if your organization is ready to begin FedRAMP authorization. Covers technical, operational, and business readiness.