Resources
Official sources and reference material. When accuracy matters, always defer to these over any summary — including this site.
Official FedRAMP resources
- FedRAMP.gov — the official program website.
- FedRAMP Marketplace — searchable list of authorized cloud services, their impact levels, and accredited 3PAOs.
- Documents & templates — official SSP, SAP, SAR, and POA&M templates and guidance.
Underlying standards (NIST)
- FIPS 199 — Standards for Security Categorization.
- NIST SP 800-53 Rev. 5 — Security and Privacy Controls.
- NIST SP 800-37 Rev. 2 — Risk Management Framework.
Design & this site
- U.S. Web Design System — the design system this site is built with.
- USWDS developer guide — install and compile documentation.
Glossary
| Term | Meaning |
|---|---|
| ATO | Authorization to Operate — the signed decision accepting a system's risk. |
| AO | Authorizing Official — the agency official who signs the ATO. |
| CSP | Cloud Service Provider — the operator of the service being authorized. |
| 3PAO | Third-Party Assessment Organization — the accredited independent assessor. |
| SSP | System Security Plan — documents how each control is implemented. |
| RAR | Readiness Assessment Report — early attestation of likely authorization. |
| SAP / SAR | Security Assessment Plan / Report — the assessment's methodology and findings. |
| POA&M | Plan of Action & Milestones — the tracked remediation plan for open findings. |
| ConMon | Continuous Monitoring — ongoing activities that keep an authorization valid. |
| PMO | Program Management Office — runs FedRAMP day to day, within GSA. |
| LI-SaaS | Low-Impact SaaS — a tailored baseline for low-risk software services. |