← ClaudeAtlas

fedramplisted

Expert guidance for FedRAMP certification and compliance. Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document types: SSP, SAP, SAR, POA&M, CIS/CRM workbooks. Also trigger for questions about FedRAMP impact levels (Low, Moderate, High, LI-SaaS), FedRAMP 20x, OSCAL, 3PAO assessments, continuous monitoring (ConMon), gap assessments, system boundary definition, FedRAMP readiness, or architecture reviews for federal cloud. When in doubt, use this skill — it covers the full FedRAMP lifecycle from readiness through continuous monitoring.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance · ★ 2 · Data & Documents · score 75
Install: claude install-skill Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
# FedRAMP Certification Skill A comprehensive guide for helping users navigate FedRAMP authorization — from initial readiness through ATO and ongoing continuous monitoring. ## Quick Reference: What Does the User Need? Identify the user's goal and jump to the appropriate section: | User Goal | Go To | |---|---| | "Are we ready for FedRAMP?" / gap assessment | → [Readiness & Gap Assessment](#1-readiness--gap-assessment) | | Writing SSP, POA&M, SAR, SAP, or other docs | → [ATO Documentation](#2-ato-documentation) | | "Which controls apply to us?" / control mapping | → [NIST 800-53 Control Mapping](#3-nist-800-53-control-mapping) | | Cloud architecture / AWS/Azure/GCP config | → [Architecture Guidance](#4-architecture-guidance) | | Already authorized, ongoing compliance | → [Continuous Monitoring](#5-continuous-monitoring) | --- ## Current FedRAMP State (as of 2025–2026) - **Baseline**: NIST SP 800-53 **Rev 5** (approved May 2023, fully in effect) - **Control counts** (Rev 5): Low = ~156, Moderate = 323, High = 410 - **OSCAL mandate**: RFC-0024 requires all CSPs to transition to machine-readable OSCAL packages by **September 2026** - **Security Inbox**: As of January 5, 2026, all authorized CSPs must maintain a dedicated Security Inbox for urgent vulnerability directives (no CAPTCHAs or barriers) - **FedRAMP 20x**: A modernization initiative in progress; introduces continuous authorization and modular/API-driven submissions. Traditional SSP/SAP/SAR templates remain require