Skip to content

Official FedRAMP Package Map

This map keeps the templates folder honest. Local Markdown and MDX files are review material; official package work should still use the current FedRAMP templates and any agency-specific instructions.

Core Authorization Package

ArtifactOfficial RoleLocal SourceCompletion Test
System Security PlanMain system description, boundary, architecture, control implementation, roles, and responsibilities.03-system-security-plan-working-outline.mdx, 04-control-implementation-matrix.mdxSSP draft has no unowned controls or placeholder boundary claims.
FIPS 199 CategorizationDetermines Low, Moderate, or High baseline using confidentiality, integrity, and availability.02-fips-199-and-boundary.mdxAO or sponsor accepts the impact rationale.
Boundary DiagramShows authorization boundary, users, systems, external connections, and trust boundaries.02-fips-199-and-boundary.mdxDiagram matches inventory and data-flow documentation.
Data Flow DiagramShows federal data movement, storage, processing, logging, and external sharing.02-fips-199-and-boundary.mdx, 09-access-audit-and-data-protection-plan.mdxEvery sensitive data flow has owner, control, and logging decision.
Control Implementation SummaryShows implementation status, inherited controls, shared controls, gaps, and evidence.04-control-implementation-matrix.mdxEvery row has status, owner, evidence, and POA&M link when needed.
Plan of Action and MilestonesTracks weaknesses, deficiencies, vulnerabilities, milestones, due dates, and status.06-poam-and-risk-register.mdxEvery known gap is tracked with owner and due date.
Security Assessment PlanDefines 3PAO assessment scope, methods, sampling, schedule, and rules of engagement.04-control-implementation-matrix.mdx, 05-evidence-and-conmon-plan.mdx3PAO can trace scope to boundary and controls.
Security Assessment ReportDocuments assessment results, findings, risk exposure, and recommendations.3PAO outputFindings are reconciled into POA&M.
Risk Exposure TableCaptures assessment weaknesses and deficiencies.3PAO output, 06-poam-and-risk-register.mdxFindings tie to POA&M items and risk owner decisions.

Continuous Monitoring Package

ArtifactOfficial RoleLocal SourceCompletion Test
Monthly Executive SummaryGives AO monthly posture, findings, POA&M movement, and significant changes.05-evidence-and-conmon-plan.mdxMonthly package is generated from current evidence.
Vulnerability Scan PackageProvides OS, web app, database, container, dependency, and infrastructure scan results.05-evidence-and-conmon-plan.mdx, 10-ato-tooling-overview.mdxScans cover 100% of current inventory or approved exceptions.
Inventory UpdateShows current components, software, services, external systems, and ownership.02-fips-199-and-boundary.mdx, 15-evidence-automation-map.mdxInventory is updated monthly and after change.
POA&M UpdateShows new, open, remediated, delayed, and risk-accepted items.06-poam-and-risk-register.mdxNo overdue item lacks escalation or risk decision.
Significant Change RecordDocuments major changes, affected controls, customer impact, and validation plan.14-operational-procedure-library.mdxChange record exists before production impact.
Annual Assessment EvidenceSupports annual review and ongoing authorization.All template docsEvidence index proves control behavior over time.

Supporting Plans and Policies

ArtifactNIST FamiliesLocal SourceCompletion Test
Access Control PolicyAC, IA09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdxRole matrix, access review, and privileged MFA are defined.
Audit and Accountability PolicyAU09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdxAudit schema, retention, review, and alerting are defined.
Configuration Management PlanCM08-secure-sdlc-and-supply-chain-plan.mdx, 13-policy-library.mdxBaseline, change control, drift detection, and inventory are defined.
Contingency PlanCP07-incident-contingency-and-dr-plan.mdx, 13-policy-library.mdxBackup, restore, RTO, RPO, and exercise cadence are defined.
Incident Response PlanIR07-incident-contingency-and-dr-plan.mdx, 13-policy-library.mdxRoles, severity, containment, reporting, and after-action review are defined.
Risk Assessment PlanRA06-poam-and-risk-register.mdx, 13-policy-library.mdxScan scope, risk scoring, remediation windows, and acceptance are defined.
Secure SDLC PlanSA, SR, SI08-secure-sdlc-and-supply-chain-plan.mdx, 13-policy-library.mdxCI/CD gates, SBOM, signing, provenance, and review evidence are defined.
Privacy and Data Protection PlanPT, MP, SC09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdxData inventory, minimization, retention, deletion, and crypto are defined.
Rules of BehaviorPL, AC, AT13-policy-library.mdxUsers and administrators have documented acceptable-use rules.

Transfer Rules

  • Download official templates fresh before package drafting begins.
  • Keep local templates files as the editable source until the agency-specific format is known.
  • Transfer only reviewed statements into official templates.
  • Mark unimplemented controls as planned or partial and add POA&M items.
  • Keep screenshots as fallback evidence; prefer API exports, signed artifacts, logs, SARIF, JSON, OSCAL, SPDX, CycloneDX, and in-toto attestations.

Sources

SourceUse
FedRAMP Rev 5 documents and templatesCurrent official template entry point.
FedRAMP SSP guidanceSSP expectations and package narrative guidance.
FedRAMP POA&M guidancePOA&M purpose, risk tracking, and template requirement.
FedRAMP continuous monitoring overviewMonthly inventory, POA&M, and ongoing authorization context.
FedRAMP Continuous Monitoring PlaybookRev 5 ConMon expectations and scanning guidance.