The FedRAMP Compliance Checklist: What You Need Before, During, and After Authorization
A FedRAMP compliance checklist organizes preparation, but the label can mislead. A checklist implies self-assessment: complete the items, check the boxes, move on. Federal Risk and Authorization Management Program (FedRAMP) certification does not work that way. Independent evaluation remains part of the process, with requirements that vary between Rev5 and 20x and by Certification Class.
Federal revenue depends on clearing FedRAMP. On the Rev5 path, a Third-Party Assessment Organization (3PAO) independently tests the system and documents its findings and recommendations. The applicable government authority then makes the certification or authorization decision.
Key Takeaways
- Independent assessment. A 3PAO tests and reports findings on the Rev5 path, while the applicable government authority makes the certification or authorization decision; 20x Classes B and C require independent KSI validation. Class A follows its own certification pathway.
- Parallel authorization paths. New Rev5 applications close June 11, 2027; the Consolidated Rules for 2026, released June 24, 2026, become mandatory January 1, 2027.
- Documentation differs by path. System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M) templates are legacy documentation assets; 20x uses the Certification Package Overview and JSON artifacts.
- Monitoring continues after certification. Rev5 vulnerabilities retain 30/90/180-day remediation deadlines. Under the current rules, providers use VDR/VER, agencies maintain POA&Ms under VER-AGM-MAP, and 20x uses an Accepted Weaknesses list.
Five Stages Span FedRAMP Scoping Through Continuous Monitoring
This working sequence spans the full authorization lifecycle. The steps apply to any provider pursuing FedRAMP certification, though the specific artifacts and cadence shift between Rev5 and 20x.
- Scope and categorize. Identify every system, service, and data flow that creates, collects, processes, stores, or maintains federal information, and document third-party information resources inside the boundary, treating unresolved risk. Categorize under FIPS 199 by the high-water mark, then elect a Certification Class and apply the corresponding Rev5 baseline where applicable.
- Document. Build the package for your path. Rev5 centers on the System Security Plan (SSP), now a legacy template asset; 20x uses the Certification Package Overview plus machine-readable JSON. POA&M upkeep has moved to agencies under VER-AGM-MAP.
- Implement and validate controls. Run a gap analysis with all technical controls implemented and operational, then validate encryption, MFA, Domain Name System (DNS) security, and least-privilege access in the live environment.
- Assess. Rev5 requires 3PAO testing under a Security Assessment Plan (SAP) and Security Assessment Report (SAR); for 20x Classes B and C, address KSI requirements through persistent automated validation and required historical KSI metrics. Receive FedRAMP Certification, after which each purchasing agency completes its own agency Authority to Operate (ATO) process.
- Monitor. Operate Continuous Monitoring (ConMon) from day one at your path's cadence.
The first stage does more than open the sequence. How third-party services sit inside the authorization boundary and which Certification Class the system elects determine whether preparation can begin, and they set the scope and cost of everything that follows.
Two Requirements Determine Whether FedRAMP Compliance Work Can Begin
These two decisions define eligibility and sit outside the preparation timeline. Getting both right keeps the process moving on the correct scope.
Third-Party Services Must Be Addressed Within the FedRAMP Boundary
Every third-party service that processes or stores federal data must be accounted for within the Cloud Service Provider's (CSP's) FedRAMP authorization boundary: the defined set of systems, services, and data flows the government evaluates. The current Minimum Assessment Scope (MAS) requires providers to identify the information resources in the cloud service offering, document applicable third-party information resources, and describe their potential impact on federal customer data.
On the Rev5 path, the 3PAO Readiness Assessment Report (RAR) Guide requires the RAR to describe system components and services within the authorization boundary, connections to external systems, and data flows for sensitive federal data. 3PAOs may only submit after validating the boundary and data flows, confirming federal mandates are implemented, and finding no major technical gaps between implemented controls and FedRAMP requirements.
The available treatments when a third-party service is unauthorized include:
- Remove the service from the federal data path entirely
- Replace it with a FedRAMP-authorized equivalent
- Absorb it into the provider's own boundary, feasible only where the provider controls the service
- Mitigate unresolved risk according to the requirements of the applicable path
The MAS permits an unauthorized third-party information resource when the provider identifies and documents it, explains relevant inheritance and information flows, and addresses unresolved risk according to the applicable path. Documented mitigation is therefore available alongside removal, replacement, or absorption.
If your product depends on a monitoring tool, ticketing system, or analytics engine that touches government data, documenting and treating its risk early can prevent added preparation time and preserve your investment.
The Correct FedRAMP Compliance Level Determines Scope and Cost
Notice NTC-0004 (February 25, 2026) announced that new baseline labels would align to Certification Classes A through D and that FedRAMP would retire the term "levels" and numbers for these labels. A later notice (NTC-0008) specified that labels would be transitioned from impact levels to Certification Classes. Low, Moderate, and High remain valid FIPS 199 security categories, assigned by the high-water mark. The class you elect now sets the control requirements and assessment cost.
Class A is a new pilot baseline with no legacy equivalent; its pipeline opened August 3, 2026. The current Rev5 class baselines require at least 155 National Institute of Standards and Technology (NIST) 800-53 Rev5 controls for Class B, 322 for Class C, and 409 for Class D. Classes B, C, and D map from the legacy Low, Moderate, and High baselines, respectively.
Safeguarding requirements for CUI in nonfederal systems now trace to NIST SP 800-171 Rev3, final since May 14, 2024. For defense contractors, however, DFARS 252.204-7012 still requires NIST SP 800-171 Rev2, not Rev3: the clause was never amended to point to Rev3, and DoD Class Deviation 2024-O0013 (May 2, 2024) expressly holds contractors to Rev2. Handling CUI and determining the FIPS 199 categorization are separate analyses, so CUI alone does not require a Moderate categorization.
Scope changes after certification follow significant change notification procedures instead of an automatic restart: adaptive changes require notice within 10 business days after completion, and major changes require notice 30 business days before.
The selected scope determines which evidence and operational controls assessors evaluate.
FedRAMP Preparation Requires Evidence and Operational Controls
Preparation depends on the evidence assessors require and the patterns that lead to remediation. Start with a gap analysis. Readiness attestation requires a 3PAO to validate the authorization boundary and data flows, confirm federal mandates are implemented, and determine that no major technical gaps exist between implemented controls and FedRAMP requirements.
A structured FedRAMP readiness assessment therefore belongs before the formal engagement.
SSP Documentation Drives Rev5 Assessment
For Rev5 packages, FedRAMP documentation centers on the System Security Plan, which describes every implemented security control and how the system protects federal data. The 3PAO uses the SSP to evaluate every provider claim, comparing narratives against diagrams and documented policy against observed implementation—documentation inconsistencies drive many remediation findings.
Every SSP, SAP, SAR, and POA&M template became a legacy asset on June 24, 2026, "intended only for reference during the transition." FedRAMP accepts new Rev5 applications through June 11, 2027. 20x submissions instead use the Certification Package Overview, which replaces the Rev5 base SSP, alongside machine-readable JSON validated against FedRAMP schemas. Structured data still demands consistency between package claims and the live environment: schema validation catches formatting errors, while package review identifies contradictions between stated and observed controls.
Technical Controls Require Validation Through Live Assessment
Beyond documentation, the FedRAMP audit is a live evaluation. On the Rev5 readiness and full-assessment path, 3PAOs observe controls in real time, run authenticated scans, and conduct penetration testing. Preparation typically concentrates on these areas:
- FIPS-validated cryptography. All Moderate and above federal data and metadata must be encrypted at rest and in transit using FIPS 140-validated cryptography. Under the 2026 rules, Class D providers must use modules with active Cryptographic Module Validation Program (CMVP) validations, Class C providers should, and applicable classes must document the modules in use.
- MFA for administrative access. 3PAO guidance calls for validating MFA through testing and observation, such as watching an administrator authenticate.
- DNSSEC on external domains. 3PAOs verify that external authoritative DNS servers reply with valid DNSSEC responses.
- Audit log retention (Rev5-specific). Control AU-11 governs audit-record retention; 20x uses a different evidence model.
- Identity and access control maturity. 3PAOs assess the system's technical, management, and operational capabilities against federal mandates and FedRAMP requirements.
Documentation and technical controls must stay aligned throughout the assessment and be backed by organizational maturity.
Continuous Monitoring Readiness Begins Before Certification
The assessor evaluates the maturity of the provider's ConMon process during the assessment itself, so monitoring capability built before certification serves both a scoring criterion and the ongoing operating model. Scanning infrastructure must be operational, aligned with documented policy, and cover the required inventory unless a government-authority-approved sampling approach applies. On Rev5, providers run VDR/VER for vulnerability detection, response, evaluation, and reporting; agencies own POA&M upkeep under VER-AGM-MAP. For 20x, VDR requires continuous automated identification, analysis, prioritization, and remediation of vulnerabilities and related exposures.
Incident response is held to the same standard. Under the FedRAMP Continuous Monitoring Playbook, Version 1.0 (November 17, 2025), the assessor confirms the plan is documented, tested, and staffed by trained personnel, and that it aligns with FedRAMP notification timelines starting with one-hour incident reporting.
The Rev5 assessment covers readiness across documentation, technical controls, and monitoring. The 20x path holds providers to comparable operational maturity through a different mechanism.
FedRAMP 20x Runs on Continuous KSI Validation
The 20x path replaces prescriptive control lists with automated Key Security Indicator (KSI) evaluation, and the assessment cadence depends on the Certification Class. FedRAMP must independently assess every KSI for Class B providers annually.
For Class C providers, the independent assessment occurs initially, and persistent automated KSI validation continues after that. Class A follows a different certification pathway. Providers on 20x publish machine-readable evidence continuously rather than assembling a static package once, which shifts preparation toward automation and telemetry rather than document production.
FedRAMP's live counter showed 534 FedRAMP Certified services on September 1, 2026, including 30 with 20x certifications. The program's terminology has changed: the designation is now FedRAMP certification, agencies still complete their own ATO process, and Marketplace impact-level labels have been updated to Certification Classes. Transition guidance links old and new baseline labels through mandatory adoption on January 1, 2027.
Four Challenges Delay FedRAMP Compliance
Four patterns can delay efforts on both paths.
- Documentation complexity. FedRAMP no longer issues Word and Excel templates for new certifications; packages must include machine-readable authorization data, and when a FedRAMP rule includes a JSON schema, providers must supply JSON documents that validate against that schema. Teams benefit from treating documentation as an engineering artifact that stays synchronized with the environment it describes.
- Assessor selection. The 3PAO owns the RAR and is fully responsible for its content, assessing through interviews, observation, demonstration, and examination. Assessor availability affects scheduling, so engage one early enough to plan the fieldwork.
- Planning too late. Governance shifted with the launch of the FedRAMP Board, which replaced the Joint Authorization Board, and the process phases changed.
- Under-automation. The 20x KSIs assume automation: automated enforcement of the intended operational state, automated secret rotation, and automated configuration management. Persistent validation requires more automation than the manual evidence collection used in a Rev5 assessment.
Each of these patterns traces back to work the provider is doing at the infrastructure layer.
An Already-Authorized Boundary Reduces the Infrastructure Scope
Independent FedRAMP certification requires documentation across hundreds of controls, live validation of cryptography and access management, and operational monitoring before the assessment. Most remediation findings originate in the infrastructure layer, so removing that layer from the authorization scope changes the equation entirely.
A pre-authorized boundary is a cloud environment that already carries an active FedRAMP authorization and inherits controls from the provider building on top of it. When a provider deploys inside such a boundary, the infrastructure-layer controls, such as physical security, host hardening, network segmentation, hypervisor configuration, and the associated evidence, are already assessed and monitored. The provider's scope contracts to the application layer and includes only the controls the provider can implement.
Control inheritance is not automatic. The provider must document what is inherited, what is shared, and what remains fully owned, and the 3PAO tests those boundaries during assessment. Where the model works cleanly, it removes the largest recurring source of findings from the provider's package and shortens the path to certification without changing the standard the assessor applies.
Maintaining Authorization Requires Permanent Continuous Monitoring
Certification does not end the compliance obligation. Whether a provider authorizes independently or deploys inside a pre-authorized boundary, continuous monitoring becomes a permanent operating requirement from the day the certification is granted.
Certification then locks in a permanent ConMon obligation with recurring deliverables, strict remediation SLAs, and an escalation process. On Rev5, each vulnerability carries a hard remediation deadline from its date of discovery:
The Playbook still references monthly vulnerability scanning for Rev5, while the new vulnerability detection and response rules use variable, class-dependent and organization-defined scan frequencies. On 20x, VER requires a monthly VDR activity report, with both VDR and VER mandatory from December 7, 2026.
Collaborative Continuous Monitoring adds a quarterly Ongoing Certification Report. Mandatory adoption of the Consolidated Rules for 2026 begins January 1, 2027. The final default grace period for the Consolidated Rules expires February 1, 2028, by which point noncompliant offerings lose their FedRAMP certification; individual requirements carry earlier deadlines, such as the Significant Change Notification and Cryptographic Module Use rules on June 1, 2027.
Start FedRAMP Preparation Before Q4 Federal Buying Peaks
FedRAMP authorization has failure modes at every phase, and each delay directly costs federal revenue. Federal contract activity concentrates in Q4 (July to September) of the fiscal year, so a certification that slips past that window means pipelines stall while assessment and remediation continue—translating into engineering time lost, product roadmap delays, and federal contracts that close without you. Starting preparation early and pursuing a General Services Administration (GSA) Schedule or relevant cloud contract vehicle in parallel keeps go-to-market work moving while the authorization runs its course.
Knox Systems delivers a FedRAMP-as-a-Service platform built on a pre-authorized boundary that reduces the infrastructure portion of a provider's authorization scope, supports inherited NIST 800-53 Rev5 controls, and sustains ongoing continuous monitoring. Knox currently supports FedRAMP Moderate, FedRAMP High, and Defense Information Systems Agency (DISA) Impact Level 4 (IL-4). IL-5 authorization is in process, with an estimated completion date of December 2026.
Schedule a demo to review your authorization timeline, infrastructure scope, and continuous monitoring requirements.
Frequently Asked Questions
How Much Does Traditional FedRAMP Authorization Cost and How Long Does It Take?
Estimates put the all-in cost at upwards of $3.5 million, covering 3PAO fees, remediation engineering, documentation, and dedicated compliance staff. Timelines typically run 12 to 36 months, or up to three years, from initial scoping through the authorization decision. Most of that cost and schedule is consumed by remediating infrastructure-layer controls, which is why deploying inside a pre-authorized boundary that removes that layer from scope compresses both figures so sharply.
Does FedRAMP Certification Expire or Require Reauthorization?
FedRAMP certification does not lapse on a fixed expiration date, but it is not permanent either. Maintaining it depends on uninterrupted continuous monitoring: monthly deliverables, remediation within the required deadlines, and recurring assessment of a defined control subset. On the 20x path, Class B providers face annual independent KSI assessment. Failure to sustain these obligations can trigger a corrective action plan and, if unresolved, suspension or revocation, rather than a simple lapse at a scheduled date.
Can a Single FedRAMP Certification Be Reused Across Multiple Agencies?
Reuse is central to the program's design. Once a cloud service offering is FedRAMP certified, the program publishes its security package for other agencies to review. Each agency still completes its own authorization decision, but it can leverage the existing assessment instead of commissioning a fresh one, which is far faster than a first authorization. This reuse model is why the initial certification is the heavy lift and subsequent agency authorizations are comparatively lightweight.
Do Companies Need a Federal Agency Sponsor to Begin FedRAMP?
Historically, a provider needed a federal agency willing to sponsor its authorization and issue the initial ATO. That agency sponsorship model paired the provider with a partner agency that reviewed the security package and accepted the residual risk. Under the current program, the applicable government authority makes the certification decision, but the buying relationship still matters: agencies remain the purchasers, and early engagement helps align authorization scope with the contract requirements a provider actually needs to meet.