{"id":"fedramp","name":"fedramp","summary":"CR26(FedRAMP統合規則2026)に基づくFedRAMP認証およびコンプライアンスに関する専門家のガイダンス。","body":"# FedRAMP Certification Skill\n\n> **Last verified:** 2026-08-15\n\nA comprehensive guide for helping users navigate FedRAMP authorization — from initial\nreadiness through ATO and ongoing continuous monitoring.\n\n## Quick Reference: What Does the User Need?\n\nIdentify the user's goal and jump to the appropriate section:\n\n| User Goal | Go To |\n|---|---|\n| \"Are we ready for FedRAMP?\" / gap assessment | → [Readiness & Gap Assessment](#1-readiness--gap-assessment) |\n| Writing SSP, POA&M, SAR, SAP, or other docs | → [ATO Documentation](#2-ato-documentation) |\n| \"Which controls apply to us?\" / control mapping | → [NIST 800-53 Control Mapping](#3-nist-800-53-control-mapping) |\n| Cloud architecture / AWS/Azure/GCP config | → [Architecture Guidance](#4-architecture-guidance) |\n| Already authorized, ongoing compliance | → [Continuous Monitoring](#5-continuous-monitoring) |\n\n---\n\n## Current FedRAMP State (as of August 2026 — CR26)\n\n> ⚠️ **CR26 (FedRAMP Consolidated Rules for 2026)**: FedRAMP has restructured its authorization framework. FIPS 199-based baseline labels (Low/Moderate/High/LI-SaaS) are replaced with **Certification Classes A–D** (per notice NTC-0004; CR26 rules valid through December 31, 2028). Class labels change the *names* of the baselines, not their requirements. CSPs already authorized under the old labels retain their authorization through a transition period in which old and new labels are linked.\n\n- **Baseline**: NIST SP 800-53 **Rev 5** (fully in effect)\n- **Control counts** (Rev 5): Low ≈ 156, Moderate = 323, High = 421 (legacy references; CR26 class-based counts being published by PMO)\n- **CR26 Certification Classes** (official mapping, NTC-0004): **A** = new pilot/transitional baseline (entry via external frameworks such as SOC 2 Type II through Program Certification; holders have a 2-year window to obtain B/C/D), **B** = current **LI-SaaS + Low** baselines, **C** = current **Moderate** baseline (majority of federal deployments, incl. CUI), **D** = current **High** baseline.\n- **FedRAMP 20x**: Now the **primary authorization pathway** — continuous authorization built on **Key Security Indicators (KSIs)**, machine-readable evidence, modular API-driven submissions, and automated validation. Traditional SSP/SAP/SAR templates remain for legacy paths.\n- **CR26 status**: finalized **June 25, 2026**; optional early adoption since **July 4, 2026**; **mandatory January 1, 2027**.\n- **Legacy FedRAMP Ready**: the Ready designation was retired/relabeled **Legacy FedRAMP Ready on July 28, 2026** — no new submissions. Rev5 Ready holders must convert by the later of their annual-assessment expiration or **November 17, 2026**; the status disappears entirely **December 31, 2027**.\n- **Certification Class pipelines**: **Class A open since August 3, 2026**; Classes **B/C open August 31, 2026**; Class D pilot expected late 2026 with a formal option in early 2027.\n- **Rev5 wind-down**: new Rev5 applications are not accepted after **June 11, 2027**; Rev5 sunsets **December 31, 2028**.\n- **JAB P-ATO**: Fully suspended; FedRAMP PMO is the sole authorization body.\n- **OSCAL mandate (RFC-0024)**: machine-readable packages required for **new authorizations from September 30, 2026**, and for **all packages by September 30, 2027**.\n- **Security Inbox**: All authorized CSPs must maintain a dedicated Security Inbox (no CAPTCHAs or barriers) for urgent vulnerability directives — effective January 5, 2026.\n- **Key templates updated**: SSP, SAR, SAP, POA&M, CIS/CRM, IIW, ISCP — all updated to align with Rev 5 (Dec 2024 releases).\n\n---\n\n## 1. Readiness & Gap Assessment\n\n### Approach\n1. **Clarify scope** — Ask the user: What is the CSO (Cloud Service Offering)? IaaS/PaaS/SaaS? Target Certification Class under CR26?\n2. **Identify authorization path** — FedRAMP 20x (primary, preferred) vs. legacy Agency Authorization package (still available for complex systems during CR26 transition)\n3. **Run through the readiness checklist** — See `references/readiness-checklist.md`\n4. **Surface gaps** — Map current state to required controls; flag missing documentation, unimplemented controls, and architectural deficiencies\n5. **Prioritize** — Group gaps by: (a) blockers for readiness review, (b) items addressable before 3PAO assessment, (c) POA&M candidates\n\n> **FedRAMP Ready retired July 28, 2026** (now \"Legacy FedRAMP Ready\"). Advise CSPs by pipeline instead: Class A (open since August 3, 2026) for external-framework entry, Classes B/C from August 31, 2026 for full certification; legacy Rev5 Ready holders must convert by the later of annual-assessment expiration or November 17, 2026.\n\n### Key Readiness Questions to Ask the User\n- Are you targeting FedRAMP 20x (preferred) or a legacy authorization package?\n- What cloud platform (AWS GovCloud, Azure Government, GCP, on-prem hybrid)?\n- Are you leveraging any existing FedRAMP-authorized IaaS/PaaS (e.g., AWS GovCloud FedRAMP High)?\n- Do you have FIPS 140-2/3 validated encryption in place?\n- Is your authorization boundary defined and documented?\n- Do you have a vulnerability scanning program (OS, DB, web app, container)?\n- Are security policies and procedures documented?\n- Do you have an Incident Response Plan (IRP) and Contingency Plan (CP) that have been tested?\n- Are your authorization package artifacts in OSCAL format (mandatory by September 30, 2026)?\n\n### Output Format\n- Produce a **gap table**: Control Family | Current State | Gap | Priority | Owner\n- Summarize top 5–10 high-priority gaps as prose\n- Note the target Certification Class and whether FedRAMP 20x is feasible\n\n---\n\n## 2. ATO Documentation\n\nThe core FedRAMP authorization package consists of:\n\n```\nAuthorization Package\n├── System Security Plan (SSP) + Appendices A–Q\n├── Security Assessment Plan (SAP) + Appendices A–D  [3PAO-prepared]\n├── Security Assessment Report (SAR) + Appendices A–F  [3PAO-prepared]\n└── Plan of Action & Milestones (POA&M)  [SSP Appendix O]\n```\n\n> **Important**: CSPs must use official FedRAMP PMO templates. OSCAL-format submissions are mandatory by September 30, 2026.\n> Templates: https://www.fedramp.gov/documents-templates/\n\n### Document Guidance\n\nFor detailed guidance on each document type, read the appropriate reference file:\n\n- **SSP** → `references/ssp-guide.md`\n- **POA&M** → `references/poam-guide.md`\n- **SAP / SAR** → `references/sap-sar-guide.md`\n- **Supporting appendices** → `references/appendices-guide.md`\n\n### General Writing Principles for All ATO Docs\n1. **Describe only what is implemented** — Do not document planned or aspirational controls; these trigger findings and must go in POA&M instead\n2. **Be specific** — Reference exact tools, filenames, section numbers, policy names; vague language causes findings\n3. **Mind the verbs** — Each control requirement uses specific verbs (track, document, enforce, test). Address each verb explicitly\n4. **Shared responsibility** — For any customer-configurable or shared control, create a clear \"Customer Responsibility\" section\n5. **Keep it consistent** — Architecture diagrams, data flows, inventory, and control statements must all be internally consistent\n\n---\n\n## 3. NIST 800-53 Control Mapping\n\n### Control Families (Rev 5)\n\n| ID | Family | Notes |\n|---|---|---|\n| AC | Access Control | IAM, RBAC, least privilege, remote access |\n| AT | Awareness & Training | Security + **privacy** training (new in Rev 5) |\n| AU | Audit & Accountability | Log retention, SIEM, audit review |\n| CA | Assessment, Authorization & Monitoring | ConMon, 3PAO, ATO |\n| CM | Configuration Management | Baselines, change control, CMDB |\n| CP | Contingency Planning | BCP/DR, tested annually |\n| IA | Identification & Authentication | MFA, PIV, FIPS 140-2/3 crypto |\n| IR | Incident Response | IRP, tested annually, reporting SLAs |\n| MA | Maintenance | Remote maintenance controls |\n| MP | Media Protection | Data at rest, media sanitization |\n| PE | Physical & Environmental | Datacenters; often inherited from IaaS |\n| PL | Planning | SSP, rules of behavior |\n| PM | Program Management | Enterprise-level security program |\n| PS | Personnel Security | Screening, termination procedures |\n| PT | PII Processing & Transparency | **New family in Rev 5** — privacy controls |\n| RA | Risk Assessment | Vulnerability scanning, MITRE ATT&CK scoring |\n| SA | System & Services Acquisition | SDLC, supply chain |\n| SC | System & Communications Protection | Encryption in transit, network segmentation |\n| SI | System & Information Integrity | Patching, malware, integrity monitoring |\n| SR | Supply Chain Risk Management | **New family in Rev 5** — SCRM |\n\n### CR26 Certification Class Mapping\n\nUnder CR26, the FedRAMP PMO is aligning control baselines to Certification Classes. When users describe their system, map to a class:\n\n- **Class A** (Pilot/Transitional): New baseline introduced under 20x — entry into the federal market via external frameworks (initially SOC 2 Type II) through Program Certification; Class A holders have a **2-year window** to obtain a Class B, C, or D certification through full assessment\n- **Class B** (replaces LI-SaaS + Low): Systems handling non-sensitive federal information where a breach would cause limited harm\n- **Class C** (replaces Moderate): Most common — the majority of federal cloud deployments, including systems handling CUI\n- **Class D** (replaces High): Federal information where compromise has severe or catastrophic effect (e.g., law enforcement, financial, health data)\n\n> **Legacy references**: Many existing FedRAMP documents still reference Low/Moderate/High/LI-SaaS. These map to **LI-SaaS/Low → Class B, Moderate → Class C, High → Class D** (Class A is new — it has no legacy equivalent). During the CR26 transition, old and new labels are linked. Advise CSPs to check fedramp.gov for the latest.\n\n### Mapping Workflow\n1. Ask: What types of federal data will the system process/store/transmit?\n2. Determine target Certification Class (A, B, C, or D) under CR26\n3. Select NIST 800-53 Rev 5 baseline using the class mapping (B ↔ Low, C ↔ Moderate, D ↔ High)\n4. Cross-reference with FedRAMP parameter requirements (FedRAMP often sets stricter parameters than base NIST)\n5. For inherited controls, identify which are fully/partially inherited from leveraged FedRAMP IaaS/PaaS and document in CIS/CRM workbook\n\n### Rev 4 → Rev 5 Key Changes to Highlight\n- **New control families**: PT (Privacy), SR (Supply Chain)\n- **Password controls revised**: No more forced rotation schedules; requires compromised-password lists and password strength meters (NIST 800-63b alignment)\n- **Privacy integrated**: AT-3 now mandates privacy training; many families have privacy-specific enhancements\n- **Threat-based methodology**: MITRE ATT&CK framework informs control prioritization\n\n---\n\n## 4. Architecture Guidance\n\n### Authorization Boundary\nThe boundary defines what is IN scope for FedRAMP. This is one of the most common sources of findings and delays.\n\nKey principles:\n- **Everything that processes, stores, or transmits federal data** must be inside the boundary\n- External services connected to in-scope systems must be FedRAMP-authorized OR documented with compensating controls\n- Boundary must be depicted in a clear **network/data flow diagram** (required in SSP)\n\n### Cloud Platform Considerations\n\n**AWS GovCloud (US)**\n- AWS GovCloud is FedRAMP High authorized — most PE and some SC controls are fully inherited\n- Use AWS Config, CloudTrail, GuardDuty, Security Hub to satisfy AU, RA, SI controls\n- Ensure use of GovCloud region endpoints (not standard commercial) to stay in boundary\n- FIPS endpoints available for IA controls\n\n**Azure Government**\n- Azure Government is FedRAMP High authorized\n- Azure Policy + Defender for Cloud maps well to CM, RA, SI\n- Use Azure Blueprints / Policy Initiatives aligned to FedRAMP Moderate/High\n\n**Google Cloud (FedRAMP-authorized regions)**\n- Assured Workloads for FedRAMP compliance\n- Chronicle SIEM for AU controls\n\n### Architecture Patterns That Support FedRAMP\n- **Zero Trust** — aligns directly with AC, IA, SC control families\n- **Immutable infrastructure** — simplifies CM (configuration drift is a common finding)\n- **Centralized logging** — SIEM/log aggregation addresses AU family comprehensively\n- **Automated vulnerability scanning** — Required; must cover OS, DB, web app, and containers (if used)\n- **OSCAL-native tooling** — Invest now; OSCAL submission is mandatory September 30, 2026\n\n### Common Architecture Findings\n- Undocumented external connections leaving the boundary\n- FIPS-non-compliant encryption algorithms in transit or at rest\n- Overly broad IAM roles / lack of least privilege\n- Missing MFA on privileged accounts\n- Vulnerability scans not covering all boundary components\n- Logging gaps (not all components sending logs to centralized SIEM)\n- Authorization packages not in OSCAL format ahead of September 2026 mandate\n\n---\n\n## 5. Continuous Monitoring\n\nOnce authorized, CSPs must maintain compliance through ConMon activities:\n\n### Monthly Requirements\n- Vulnerability scan results submitted to agency AOs\n- POA&M updates (open findings, remediation progress)\n- Inventory updates (new/removed assets)\n- ConMon Monthly Executive Summary (template updated Nov 2024)\n\n### Annual Requirements\n- Full security assessment by 3PAO using Annual Assessment Controls Selection Worksheet\n- Updated SSP and appendices\n- Tested IRP and CP\n- SAR and updated POA&M\n\n### POA&M Management\n- All open findings must have: risk level, owner, milestone dates, remediation plan\n- Vendor Dependencies (VDs): when a finding depends on a third-party fix — document and track\n- Deviation Requests (DRs): false positives and risk adjustments require AO approval\n- SLA for remediation (FedRAMP ConMon Performance Management Guide): **High = 30 days**, **Moderate = 90 days**, **Low = 180 days** from identification. Where Critical is distinguished from High (e.g., scanner ratings), treat it as High-or-stricter (≤30 days, prioritized immediately)\n\n---\n\n## Output Formatting Guide\n\nMatch output format to request type:\n\n| Request Type | Preferred Format |\n|---|---|\n| Gap assessment | Table + prose summary |\n| SSP control narrative | Prose paragraphs (one per control/enhancement) |\n| POA&M entry | Structured table row with all required fields |\n| Architecture review | Bullet findings + recommended remediations |\n| Control mapping question | Table: Control ID \\| Requirement \\| How to Implement |\n| Readiness overview | Executive summary prose + priority action list |\n\nWhen generating document content, always note: *\"Use official FedRAMP templates from fedramp.gov — this content should be inserted into the appropriate template section.\"*\n\n---\n\n## Reference Files\n\nLoad these when more depth is needed:\n\n- `references/readiness-checklist.md` — Full readiness checklist (75+ items)\n- `references/ssp-guide.md` — SSP section-by-section writing guide\n- `references/poam-guide.md` — POA&M structure, field definitions, SLA table\n- `references/sap-sar-guide.md` — SAP/SAR overview and review tips for CSPs\n- `references/appendices-guide.md` — Guide to all SSP appendices (A–Q)\n- `references/control-families.md` — Deep-dive on each of the 20 control families\n\n---\n\n> *This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.*","author":"@Sushegaad","ownerProfile":null,"authorContacts":null,"sourceUrl":"https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/fedramp/skills/fedramp","license":"MIT","category":"writing","lang":"en","tokens":3686,"stars":0,"calls30d":1,"claimed":false,"visibility":"public","origin":"crawler","version":"0.1.0","createdAt":"2026-08-22","updatedAt":"2026-08-22","files":[{"path":"references/appendices-guide.md","size":11067,"sha256":"1cde00c6002fc5793d9215a51a45b91cb5940659acfa49ab1de27994507bf823"},{"path":"references/control-families.md","size":16534,"sha256":"c2182344aca8e5858e8ecc9901107e5d9cabad724def465e58f276f882eb00be"},{"path":"references/poam-guide.md","size":4030,"sha256":"e0563ee6928d7f2812d5aacda4796c74222b705a6a70921fff4eb176ec0ce2f6"},{"path":"references/readiness-checklist.md","size":6280,"sha256":"f0925a4eb4a416b0c5ab87c0df7968e61662cd76526c4959de671099a11f0529"},{"path":"references/sap-sar-guide.md","size":4363,"sha256":"60ed2b54c989a914646873f46ffe4c677d81e72af89d6288edda6148aff222fa"},{"path":"references/ssp-guide.md","size":5632,"sha256":"4760da1b25d7433ef87e4b3ea43e9db9baec7d05f1b4b773397448cd52bf88cb"}],"requires":{"mcp":[],"tools":[]},"safety":{"flags":[],"scannedAt":"2026-08-22","hasScripts":false,"networkEndpoints":["www.fedramp.gov"]}}