This Request for Comment (or set of RFCs) related to the FedRAMP Marketplace and authorization designations will attempt to address many gaps in the current process. Goals for this RFC include:
- Adding a "Preparation" step aligned with the NIST RMF Step 1 that will allow any cloud service provider to publicly attest that they are carrying out the essential activities to prepare their cloud service offering for a FedRAMP authorization.
- Replacing "FedRAMP Ready" with a CSP + 3PAO attested "Independently Assessed" state.
- Adding a "Remediation" status
- Replacing final status with "Continuous Monitoring" and "Persistent Validation" instead of "authorized"
- Renaming "In Process" to "Agency Authorization In Process" for Rev5
Plus supporting requirements for these various states and a few other interesting things.
This Request for Comment (or set of RFCs) related to the FedRAMP Marketplace and authorization designations will attempt to address many gaps in the current process. Goals for this RFC include:
Plus supporting requirements for these various states and a few other interesting things.