Source profileQuality 91/100

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/plugins/fedramp/skills/fedramp/SKILL.md

fedramp

Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document types: SSP, SAP, SAR, POA&M, CIS/CRM workbooks. Also trigger for questions about FedRAMP Certification Classes (A, B, C, D — new baseline labels: A = pilot/transitional, B = LI-SaaS/Lo

Source repository stars
855
Declared platforms
0
Static risk flags
1
Last source update
2026-08-23
Source checked
2026-08-25

Decision brief

What it does: where it fits

Last verified: 2026-08-15

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill "plugins/fedramp/skills/fedramp"
    Safe inspection promptEditorial

    Inspect the Agent Skill "fedramp" from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/blob/134b6564c6c0094cde032466874c37de43a6d1b8/plugins/fedramp/skills/fedramp/SKILL.md at commit 134b6564c6c0094cde032466874c37de43a6d1b8. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      1. Readiness & Gap Assessment

      1. Clarify scope — Ask the user: What is the CSO (Cloud Service Offering)? IaaS/PaaS/SaaS? Target Certification Class under CR26? 2. Identify authorization path — FedRAMP 20x (primary, preferred) vs. legacy Agency Authorization package (still available for complex systems during…

      Clarify scope — Ask the user: What is the CSO (Cloud Service Offering)? IaaS/PaaS/SaaS? Target Certification Class under CR26?Identify authorization path — FedRAMP 20x (primary, preferred) vs. legacy Agency Authorization package (still available for complex systems during CR26 transition)Run through the readiness checklist — See references/readiness-checklist.md
    2. 02

      Mapping Workflow

      1. Ask: What types of federal data will the system process/store/transmit? 2. Determine target Certification Class (A, B, C, or D) under CR26 3. Select NIST 800-53 Rev 5 baseline using the class mapping (B ↔ Low, C ↔ Moderate, D ↔ High) 4. Cross-reference with FedRAMP parameter…

      Ask: What types of federal data will the system process/store/transmit?Determine target Certification Class (A, B, C, or D) under CR26Select NIST 800-53 Rev 5 baseline using the class mapping (B ↔ Low, C ↔ Moderate, D ↔ High)
    3. 03

      Quick Reference: What Does the User Need?

      Identify the user's goal and jump to the appropriate section:

      Identify the user's goal and jump to the appropriate section:
    4. 04

      Current FedRAMP State (as of August 2026 — CR26)

      ⚠️ CR26 (FedRAMP Consolidated Rules for 2026): FedRAMP has restructured its authorization framework. FIPS 199-based baseline labels (Low/Moderate/High/LI-SaaS) are replaced with Certification Classes A–D (per notice NTC-0004; CR26 rules valid through December 31, 2028). Class la…

      Baseline: NIST SP 800-53 Rev 5 (fully in effect)Control counts (Rev 5): Low ≈ 156, Moderate = 323, High = 421 (legacy references; CR26 class-based counts being published by PMO)CR26 Certification Classes (official mapping, NTC-0004): A = new pilot/transitional baseline (entry via external frameworks such as SOC 2 Type II through Program Certification; holders have a 2-year window to obtain B/C…
    5. 05

      Approach

      1. Clarify scope — Ask the user: What is the CSO (Cloud Service Offering)? IaaS/PaaS/SaaS? Target Certification Class under CR26? 2. Identify authorization path — FedRAMP 20x (primary, preferred) vs. legacy Agency Authorization package (still available for complex systems during…

      Clarify scope — Ask the user: What is the CSO (Cloud Service Offering)? IaaS/PaaS/SaaS? Target Certification Class under CR26?Identify authorization path — FedRAMP 20x (primary, preferred) vs. legacy Agency Authorization package (still available for complex systems during CR26 transition)Run through the readiness checklist — See references/readiness-checklist.md

    Permission review

    Static risk signals and limitations

    Reads files

    low · line 87

    The documentation asks the agent to read local files, directories, or repositories.

    For detailed guidance on each document type, read the appropriate reference file:

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score91/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars855SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
    Skill path
    plugins/fedramp/skills/fedramp/SKILL.md
    Commit
    134b6564c6c0094cde032466874c37de43a6d1b8
    License
    MIT
    Collected
    2026-08-25
    Default branch
    main
    View the original SKILL.md

    FedRAMP Certification Skill

    Last verified: 2026-08-15

    A comprehensive guide for helping users navigate FedRAMP authorization — from initial readiness through ATO and ongoing continuous monitoring.

    Quick Reference: What Does the User Need?

    Identify the user's goal and jump to the appropriate section:

    User GoalGo To
    "Are we ready for FedRAMP?" / gap assessmentReadiness & Gap Assessment
    Writing SSP, POA&M, SAR, SAP, or other docsATO Documentation
    "Which controls apply to us?" / control mappingNIST 800-53 Control Mapping
    Cloud architecture / AWS/Azure/GCP configArchitecture Guidance
    Already authorized, ongoing complianceContinuous Monitoring

    Current FedRAMP State (as of August 2026 — CR26)

    ⚠️ CR26 (FedRAMP Consolidated Rules for 2026): FedRAMP has restructured its authorization framework. FIPS 199-based baseline labels (Low/Moderate/High/LI-SaaS) are replaced with Certification Classes A–D (per notice NTC-0004; CR26 rules valid through December 31, 2028). Class labels change the names of the baselines, not their requirements. CSPs already authorized under the old labels retain their authorization through a transition period in which old and new labels are linked.

    • Baseline: NIST SP 800-53 Rev 5 (fully in effect)
    • Control counts (Rev 5): Low ≈ 156, Moderate = 323, High = 421 (legacy references; CR26 class-based counts being published by PMO)
    • CR26 Certification Classes (official mapping, NTC-0004): A = new pilot/transitional baseline (entry via external frameworks such as SOC 2 Type II through Program Certification; holders have a 2-year window to obtain B/C/D), B = current LI-SaaS + Low baselines, C = current Moderate baseline (majority of federal deployments, incl. CUI), D = current High baseline.
    • FedRAMP 20x: Now the primary authorization pathway — continuous authorization built on Key Security Indicators (KSIs), machine-readable evidence, modular API-driven submissions, and automated validation. Traditional SSP/SAP/SAR templates remain for legacy paths.
    • CR26 status: finalized June 25, 2026; optional early adoption since July 4, 2026; mandatory January 1, 2027.
    • Legacy FedRAMP Ready: the Ready designation was retired/relabeled Legacy FedRAMP Ready on July 28, 2026 — no new submissions. Rev5 Ready holders must convert by the later of their annual-assessment expiration or November 17, 2026; the status disappears entirely December 31, 2027.
    • Certification Class pipelines: Class A open since August 3, 2026; Classes B/C open August 31, 2026; Class D pilot expected late 2026 with a formal option in early 2027.
    • Rev5 wind-down: new Rev5 applications are not accepted after June 11, 2027; Rev5 sunsets December 31, 2028.
    • JAB P-ATO: Fully suspended; FedRAMP PMO is the sole authorization body.
    • OSCAL mandate (RFC-0024): machine-readable packages required for new authorizations from September 30, 2026, and for all packages by September 30, 2027.
    • Security Inbox: All authorized CSPs must maintain a dedicated Security Inbox (no CAPTCHAs or barriers) for urgent vulnerability directives — effective January 5, 2026.
    • Key templates updated: SSP, SAR, SAP, POA&M, CIS/CRM, IIW, ISCP — all updated to align with Rev 5 (Dec 2024 releases).

    1. Readiness & Gap Assessment

    Approach

    1. Clarify scope — Ask the user: What is the CSO (Cloud Service Offering)? IaaS/PaaS/SaaS? Target Certification Class under CR26?
    2. Identify authorization path — FedRAMP 20x (primary, preferred) vs. legacy Agency Authorization package (still available for complex systems during CR26 transition)
    3. Run through the readiness checklist — See references/readiness-checklist.md
    4. Surface gaps — Map current state to required controls; flag missing documentation, unimplemented controls, and architectural deficiencies
    5. Prioritize — Group gaps by: (a) blockers for readiness review, (b) items addressable before 3PAO assessment, (c) POA&M candidates

    FedRAMP Ready retired July 28, 2026 (now "Legacy FedRAMP Ready"). Advise CSPs by pipeline instead: Class A (open since August 3, 2026) for external-framework entry, Classes B/C from August 31, 2026 for full certification; legacy Rev5 Ready holders must convert by the later of annual-assessment expiration or November 17, 2026.

    Key Readiness Questions to Ask the User

    • Are you targeting FedRAMP 20x (preferred) or a legacy authorization package?
    • What cloud platform (AWS GovCloud, Azure Government, GCP, on-prem hybrid)?
    • Are you leveraging any existing FedRAMP-authorized IaaS/PaaS (e.g., AWS GovCloud FedRAMP High)?
    • Do you have FIPS 140-2/3 validated encryption in place?
    • Is your authorization boundary defined and documented?
    • Do you have a vulnerability scanning program (OS, DB, web app, container)?
    • Are security policies and procedures documented?
    • Do you have an Incident Response Plan (IRP) and Contingency Plan (CP) that have been tested?
    • Are your authorization package artifacts in OSCAL format (mandatory by September 30, 2026)?

    Output Format

    • Produce a gap table: Control Family | Current State | Gap | Priority | Owner
    • Summarize top 5–10 high-priority gaps as prose
    • Note the target Certification Class and whether FedRAMP 20x is feasible

    2. ATO Documentation

    The core FedRAMP authorization package consists of:

    Authorization Package
    ├── System Security Plan (SSP) + Appendices A–Q
    ├── Security Assessment Plan (SAP) + Appendices A–D  [3PAO-prepared]
    ├── Security Assessment Report (SAR) + Appendices A–F  [3PAO-prepared]
    └── Plan of Action & Milestones (POA&M)  [SSP Appendix O]
    

    Important: CSPs must use official FedRAMP PMO templates. OSCAL-format submissions are mandatory by September 30, 2026. Templates: https://www.fedramp.gov/documents-templates/

    Document Guidance

    For detailed guidance on each document type, read the appropriate reference file:

    • SSPreferences/ssp-guide.md
    • POA&Mreferences/poam-guide.md
    • SAP / SARreferences/sap-sar-guide.md
    • Supporting appendicesreferences/appendices-guide.md

    General Writing Principles for All ATO Docs

    1. Describe only what is implemented — Do not document planned or aspirational controls; these trigger findings and must go in POA&M instead
    2. Be specific — Reference exact tools, filenames, section numbers, policy names; vague language causes findings
    3. Mind the verbs — Each control requirement uses specific verbs (track, document, enforce, test). Address each verb explicitly
    4. Shared responsibility — For any customer-configurable or shared control, create a clear "Customer Responsibility" section
    5. Keep it consistent — Architecture diagrams, data flows, inventory, and control statements must all be internally consistent

    3. NIST 800-53 Control Mapping

    Control Families (Rev 5)

    IDFamilyNotes
    ACAccess ControlIAM, RBAC, least privilege, remote access
    ATAwareness & TrainingSecurity + privacy training (new in Rev 5)
    AUAudit & AccountabilityLog retention, SIEM, audit review
    CAAssessment, Authorization & MonitoringConMon, 3PAO, ATO
    CMConfiguration ManagementBaselines, change control, CMDB
    CPContingency PlanningBCP/DR, tested annually
    IAIdentification & AuthenticationMFA, PIV, FIPS 140-2/3 crypto
    IRIncident ResponseIRP, tested annually, reporting SLAs
    MAMaintenanceRemote maintenance controls
    MPMedia ProtectionData at rest, media sanitization
    PEPhysical & EnvironmentalDatacenters; often inherited from IaaS
    PLPlanningSSP, rules of behavior
    PMProgram ManagementEnterprise-level security program
    PSPersonnel SecurityScreening, termination procedures
    PTPII Processing & TransparencyNew family in Rev 5 — privacy controls
    RARisk AssessmentVulnerability scanning, MITRE ATT&CK scoring
    SASystem & Services AcquisitionSDLC, supply chain
    SCSystem & Communications ProtectionEncryption in transit, network segmentation
    SISystem & Information IntegrityPatching, malware, integrity monitoring
    SRSupply Chain Risk ManagementNew family in Rev 5 — SCRM

    CR26 Certification Class Mapping

    Under CR26, the FedRAMP PMO is aligning control baselines to Certification Classes. When users describe their system, map to a class:

    • Class A (Pilot/Transitional): New baseline introduced under 20x — entry into the federal market via external frameworks (initially SOC 2 Type II) through Program Certification; Class A holders have a 2-year window to obtain a Class B, C, or D certification through full assessment
    • Class B (replaces LI-SaaS + Low): Systems handling non-sensitive federal information where a breach would cause limited harm
    • Class C (replaces Moderate): Most common — the majority of federal cloud deployments, including systems handling CUI
    • Class D (replaces High): Federal information where compromise has severe or catastrophic effect (e.g., law enforcement, financial, health data)

    Legacy references: Many existing FedRAMP documents still reference Low/Moderate/High/LI-SaaS. These map to LI-SaaS/Low → Class B, Moderate → Class C, High → Class D (Class A is new — it has no legacy equivalent). During the CR26 transition, old and new labels are linked. Advise CSPs to check fedramp.gov for the latest.

    Mapping Workflow

    1. Ask: What types of federal data will the system process/store/transmit?
    2. Determine target Certification Class (A, B, C, or D) under CR26
    3. Select NIST 800-53 Rev 5 baseline using the class mapping (B ↔ Low, C ↔ Moderate, D ↔ High)
    4. Cross-reference with FedRAMP parameter requirements (FedRAMP often sets stricter parameters than base NIST)
    5. For inherited controls, identify which are fully/partially inherited from leveraged FedRAMP IaaS/PaaS and document in CIS/CRM workbook

    Rev 4 → Rev 5 Key Changes to Highlight

    • New control families: PT (Privacy), SR (Supply Chain)
    • Password controls revised: No more forced rotation schedules; requires compromised-password lists and password strength meters (NIST 800-63b alignment)
    • Privacy integrated: AT-3 now mandates privacy training; many families have privacy-specific enhancements
    • Threat-based methodology: MITRE ATT&CK framework informs control prioritization

    4. Architecture Guidance

    Authorization Boundary

    The boundary defines what is IN scope for FedRAMP. This is one of the most common sources of findings and delays.

    Key principles:

    • Everything that processes, stores, or transmits federal data must be inside the boundary
    • External services connected to in-scope systems must be FedRAMP-authorized OR documented with compensating controls
    • Boundary must be depicted in a clear network/data flow diagram (required in SSP)

    Cloud Platform Considerations

    AWS GovCloud (US)

    • AWS GovCloud is FedRAMP High authorized — most PE and some SC controls are fully inherited
    • Use AWS Config, CloudTrail, GuardDuty, Security Hub to satisfy AU, RA, SI controls
    • Ensure use of GovCloud region endpoints (not standard commercial) to stay in boundary
    • FIPS endpoints available for IA controls

    Azure Government

    • Azure Government is FedRAMP High authorized
    • Azure Policy + Defender for Cloud maps well to CM, RA, SI
    • Use Azure Blueprints / Policy Initiatives aligned to FedRAMP Moderate/High

    Google Cloud (FedRAMP-authorized regions)

    • Assured Workloads for FedRAMP compliance
    • Chronicle SIEM for AU controls

    Architecture Patterns That Support FedRAMP

    • Zero Trust — aligns directly with AC, IA, SC control families
    • Immutable infrastructure — simplifies CM (configuration drift is a common finding)
    • Centralized logging — SIEM/log aggregation addresses AU family comprehensively
    • Automated vulnerability scanning — Required; must cover OS, DB, web app, and containers (if used)
    • OSCAL-native tooling — Invest now; OSCAL submission is mandatory September 30, 2026

    Common Architecture Findings

    • Undocumented external connections leaving the boundary
    • FIPS-non-compliant encryption algorithms in transit or at rest
    • Overly broad IAM roles / lack of least privilege
    • Missing MFA on privileged accounts
    • Vulnerability scans not covering all boundary components
    • Logging gaps (not all components sending logs to centralized SIEM)
    • Authorization packages not in OSCAL format ahead of September 2026 mandate

    5. Continuous Monitoring

    Once authorized, CSPs must maintain compliance through ConMon activities:

    Monthly Requirements

    • Vulnerability scan results submitted to agency AOs
    • POA&M updates (open findings, remediation progress)
    • Inventory updates (new/removed assets)
    • ConMon Monthly Executive Summary (template updated Nov 2024)

    Annual Requirements

    • Full security assessment by 3PAO using Annual Assessment Controls Selection Worksheet
    • Updated SSP and appendices
    • Tested IRP and CP
    • SAR and updated POA&M

    POA&M Management

    • All open findings must have: risk level, owner, milestone dates, remediation plan
    • Vendor Dependencies (VDs): when a finding depends on a third-party fix — document and track
    • Deviation Requests (DRs): false positives and risk adjustments require AO approval
    • SLA for remediation (FedRAMP ConMon Performance Management Guide): High = 30 days, Moderate = 90 days, Low = 180 days from identification. Where Critical is distinguished from High (e.g., scanner ratings), treat it as High-or-stricter (≤30 days, prioritized immediately)

    Output Formatting Guide

    Match output format to request type:

    Request TypePreferred Format
    Gap assessmentTable + prose summary
    SSP control narrativeProse paragraphs (one per control/enhancement)
    POA&M entryStructured table row with all required fields
    Architecture reviewBullet findings + recommended remediations
    Control mapping questionTable: Control ID | Requirement | How to Implement
    Readiness overviewExecutive summary prose + priority action list

    When generating document content, always note: "Use official FedRAMP templates from fedramp.gov — this content should be inserted into the appropriate template section."


    Reference Files

    Load these when more depth is needed:

    • references/readiness-checklist.md — Full readiness checklist (75+ items)
    • references/ssp-guide.md — SSP section-by-section writing guide
    • references/poam-guide.md — POA&M structure, field definitions, SLA table
    • references/sap-sar-guide.md — SAP/SAR overview and review tips for CSPs
    • references/appendices-guide.md — Guide to all SSP appendices (A–Q)
    • references/control-families.md — Deep-dive on each of the 20 control families

    This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

    Frequently asked questions

    What to verify before installation and use

    What does the fedramp source document cover?

    Last verified: 2026-08-15

    How do I install fedramp?

    The source record exposes this install command: npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill "plugins/fedramp/skills/fedramp". Inspect the command and pinned source before running it.

    Which permission-related actions were detected?

    Static rules flagged read-files in the source; the page lists the matching lines and excerpts.

    Alternatives

    Compare before choosing

    Computed 9615

    getcargohq/cargo-skills

    cargo-gtm

    Do business-to-business go-to-market work on Cargo — research accounts and buying committees, enrich and verify B2B contact records from licensed data providers, score and qualify leads, draft permission-based outreach for the user's own sequencer, sync to CRM, and monitor buying signals. Consent basis, suppression lists, and volume limits gate every step that touches a person (`references/acceptable-use.md`); bulk unsolicited messaging, purchased or scraped lists, and consumer targeting are ref

    Computed 9435

    tenequm/skills

    web3-protocol-gtm

    Go-to-market strategy for web3 builders - protocols, products, services, and solo founders. Use when planning growth for a crypto protocol, building developer community, crafting CT narrative, planning ecosystem partnerships, preparing grant applications, launching tokens, pricing crypto-native products, or growing as a solo founder in web3.

    Computed 9340

    OpenCoven/coven

    heygen-video

    Generate HeyGen presenter videos via the v3 Video Agent pipeline — handles Frame Check (aspect ratio correction), prompt engineering, avatar resolution, and voice selection. Required for any HeyGen video generation. Replaces deprecated endpoints with v3. Use when: (1) generating any HeyGen video (via API or otherwise), (2) sending a personalized video message (outreach, update, announcement, pitch, knowledge), (3) creating a HeyGen presenter-led explainer, tutorial, or product demo with a human

    Computed 9240

    OpenCoven/coven

    heygen-skills

    Create HeyGen avatar videos via the v3 Video Agent pipeline — handles avatar resolution, aspect ratio correction, prompt engineering, and voice selection automatically. Required for any HeyGen API usage (api.heygen.com). Replaces deprecated v1/v2 endpoints with the optimized v3 pipeline. Use when: (1) calling any HeyGen API endpoint (api.heygen.com), (2) creating a HeyGen avatar or digital twin from a photo, (3) making a personalized video message (outreach, pitch, update, announcement, knowledg