Editor’s Note: FedRAMP Initial Review Results Template Version 1.0 is available here.
From: FedRAMP

To better address the growing number of Cloud Service Provider (CSP) applicants, the FedRAMP PMO has revamped its process for reviewing and approving Authorization Packages. This new Review and Approve (R&A) Process is designed to be more efficient, structured, and scalable with an emphasis on training and improving the quality of submitted Authorization Package documentation through greater transparency of FedRAMP processes and evaluation criteria.

A CSP pursuing the Joint Authorization Board (JAB), Agency, or CSP Supplied Authorization Paths will follow the R&A process outlined in the Detailed R&A Process Flow Diagram and standard operating procedure. A simplified R&A process flow graphic is depicted above and a summary of the process is described below. The four phases of the R&A process are: Prepare and Apply, Accept for Review, Initial and Detailed Reviews, and Approve. Each phase is designed to enable a CSP to move more efficiently and accurately through the FedRAMP Authorization process.
The Four Phases
- Prepare and Apply

The R&A process begins when a CSP decides to pursue a FedRAMP Authorization. During this period, the CSP does preliminary research on the FedRAMP process to gain a better understanding of the detail and rigor necessary to successfully obtain an Authorization to Operate (ATO). The CSP then decides an authorization path to pursue (JAB, Agency, or CSP Supplied) or may decide a specific path to pursue at a later time*.
Next, the applicant must complete FedRAMP’s Online Training and submit a certificate of course completion to the FedRAMP PMO. The CSP must then submit a FedRAMP Application to begin the R&A process with the FedRAMP PMO. After the application is submitted, the PMO will conduct an intake interview with the applicant to confirm participation in the R&A process and to answer any questions. During this phase, the applicant should be assembling their Authorization Package using FedRAMP-provided templates.
*Note: If a CSP is undecided as to what path to take, they can submit their SSP and attachments for an Initial Review. Once the documents are approved, the CSP will be listed as FedRAMP Ready. A CSP can wait for a maximum of one year to make a decision as to what path to take and submit the remaining documentation to pass an Initial Review.
- Accept for Review

When the CSP has completed their Authorization Package, they will be directed to submit their documentation to FedRAMP by uploading their package to the OMB MAX Secure Repository. The FedRAMP PMO will then validate that a complete Authorization Package has been correctly submitted.
Based upon the package documentation and the results of the intake interview, the PMO will determine whether the CSP is ready for review. If accepted, the CSP will move onto the Initial Review. If not accepted, the applicant will be advised to revise its documentation and resubmit.
- Initial and Detailed Reviews

All Authorization Packages undergo a FedRAMP Initial Review. The Initial Review includes quality checks for completeness, showstoppers (missing, incomplete, or weak critical security controls), and readability (clear, concise, and consistent documentation). To be designated as FedRAMP Ready, a CSP’s SSP and attachments must pass an Initial Review. To successfully complete the Initial Review phase, a CSP must pass a review of these documents.
- System Security Plan (SSP)
- Security Assessment Plan (SAP)
- Plan of Action and Milestones Template (POA&M)
- Security Assessment Report (SAR)
After passing an Initial Review of all required documentation, the Authorization Package will become FedRAMP Compliant (in PMO Review) for Agency authorizations, CSP Supplied packages will be moved to a queue for the FedRAMP Director’s approval to become FedRAMP Compliant, and JAB packages will designated as FedRAMP In-Process after a FedRAMP ISSO and kick-off meeting is held.
Here’s where things get more in-depth:
For those CSPs that are opting to pursue a JAB P-ATO, the Authorization Package must undergo a FedRAMP Detailed Review. Prior to undergoing a rigorous Detailed Review, the CSP will be assigned a FedRAMP ISSO and a kick off meeting will be held. At this time, the CSP will be designated as FedRAMP In-Process. The Detailed Review determines whether a cloud system is in compliance with Information Technology (IT) security requirements defined by the Federal Information Security Management Act (FISMA), the National Institute of Standards and Technology (NIST) Special Publications (SP) 800-53 Revision 4, and FedRAMP. This determination is made by performing a Detailed Review of the:
- System Security Plan (SSP)
- Security Assessment Plan (SAP)
- Plan of Action and Milestones Template (POA&M)
- Security Assessment Report (SAR)
- Approve

Once all documentation for the JAB P-ATO path is completed and approved by the JAB, the JAB will grant a P-ATO. For CSP Supplied and Agency packages, the CSP Authorization Package will be reviewed by the FedRAMP Director for approval. Once a CSP is granted authorization for its selected path, the CSP will be listed as FedRAMP Compliant on fedramp.gov. Success!
Leave a Reply