Skip to main content

Legacy FedRAMP

The FedRAMP PMO no longer uses traditional SSP, Assessment Plans, Assessment Reports, or POA&Ms. This information remains for reference as it serves as an example for modeling of similar tools. For information related to the use of OSCAL for the revised FedRAMP Rules, see https://patterns.rufrisk.com/shelves/fedramp-cr26.

---


Federal Risk and Authorization Management Program (FedRAMP) a United States Federal compliance program based on the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF).

This work is based on the efforts of the OSCAL Foundation's FedRAMP Technical Working Group. Please visit https://oscalfoundationlists.org/g/tfg-fedramp to join the working group.

All content is considered to be in the public domain and free for all to use without constraint unless otherwise marked. [A specific open source license will be identified by the OSCAL foundation and specified here in the near future.]