Skip to main content

Resources

Official sources and reference material. When accuracy matters, always defer to these over any summary — including this site.

Official FedRAMP resources

Underlying standards (NIST)

Design & this site

Glossary

Key FedRAMP terms and acronyms
TermMeaning
ATOAuthorization to Operate — the signed decision accepting a system's risk.
AOAuthorizing Official — the agency official who signs the ATO.
CSPCloud Service Provider — the operator of the service being authorized.
3PAOThird-Party Assessment Organization — the accredited independent assessor.
SSPSystem Security Plan — documents how each control is implemented.
RARReadiness Assessment Report — early attestation of likely authorization.
SAP / SARSecurity Assessment Plan / Report — the assessment's methodology and findings.
POA&MPlan of Action & Milestones — the tracked remediation plan for open findings.
ConMonContinuous Monitoring — ongoing activities that keep an authorization valid.
PMOProgram Management Office — runs FedRAMP day to day, within GSA.
LI-SaaSLow-Impact SaaS — a tailored baseline for low-risk software services.