Skip to main content
Pricing
Sign inRequest demo

FedRAMP 20x Incident Reports (IIR, OIR, FIR) Example

Follow fictional incident information from Initial through Ongoing and Final reports, including timelines, PAIN ratings, impact, activity, recovery, and root cause.

0 downloads|ZIP (HTML + JSON)|5.0 KB

What's inside

  • Understand how IIR, OIR, and FIR content evolves
  • See how PAIN information and timelines are carried forward
  • Compare a nested report index with individual schema documents
  • Prototype incident communication and update workflows

Best fit

  • Incident response and communication teams
  • Security operations engineers
  • Agency and assessor incident reviewers

Related topics

#FedRAMP 20x#FedRAMP Incident Report#Final Incident Report (FIR)#Incident Communication#Initial Incident Report (IIR)#Ongoing Incident Report (OIR)#PAIN Rating

Unlock this resource

Enter your work email to download FedRAMP 20x Incident Reports (IIR, OIR, FIR) Example.

From initial report to final report

This pair contains four synthetic incident-report records. Three describe one fictional credential-stuffing scenario as it moves through an Initial Incident Report, an Ongoing Incident Report, and a Final Incident Report. The fourth is an Initial Incident Report for a separate fictional anomalous-egress scenario.

The IIR demonstrates early information such as the federal incident coordinator, provider tracking ID, incident description, detection timeline, Potential Agency Impact N-rating (PAIN), functional impact, and recovery plan. The OIR adds observed activity and indicators of compromise as the investigation develops. The FIR supplies final resolution information, root cause, and response and recovery activities. Reading the sequence shows which fields should persist, which estimates can change, and how later reports should update earlier uncertainty instead of silently replacing it.

Structure and practical use

The outer reports envelope is an index, not a standalone FedRAMP report schema. Each nested report states its document schema and report type. Validation and storage workflows should preserve the filed report, its filing time, and the relationship among updates sharing a provider tracking identifier.

Use JSON to prototype ingestion, correlation, deadline tracking, and reviewer alerts. Use HTML to test whether a person can distinguish known facts from estimates, locate changed PAIN information, and understand current recovery status. Current FedRAMP terminology is Incident Evaluation and Communication; these examples do not replace official reporting procedures, federal notification channels, or agency-specific requirements.

Synthetic example and current status

The incidents, accounts, telemetry, indicators, federal contacts, timelines, impacts, PAIN ratings, root causes, and response actions in these 2026-07-27 files are fictional. No listed incident occurred in Boundera production and none describes actual agency or customer data. Refer to the official FedRAMP Marketplace record for current status.

Frequently asked questions

What are IIR, OIR, and FIR?

They are Initial, Ongoing, and Final Incident Reports used at different stages of incident communication.

What does PAIN mean?

PAIN is the Potential Agency Impact N-rating used to communicate likely adverse impact on agency customers.

Did these incidents happen to Boundera?

No. Every incident and related detail in the download is synthetic.

Put this resource to work

Turn this resource into a live FedRAMP workflow.

Boundera connects the evidence, gaps, POA&Ms, and continuous monitoring work behind the document.

Request demo

Related resources