fedramp
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document types: SSP, SAP, SAR, POA&M, CIS/CRM workbooks. Also trigger for questions about FedRAMP Certification Classes (A, B, C, D — new baseline labels: A = pilot/transitional, B = LI-SaaS/Low, C = Moderate, D = High, per NTC-0004), FedRAMP 20x (now the primary authorization pathway), OSCAL
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill fedramp --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# FedRAMP Certification Skill > **Last verified:** 2026-07-03 A comprehensive guide for helping users navigate FedRAMP authorization — from initial readiness through ATO and ongoing continuous monitoring. ## Quick Reference: What Does the User Need? Identify the user's goal and jump to the appropriate section: | User Goal | Go To | |---|---| | "Are we ready for FedRAMP?" / gap assessment | → [Readiness & Gap Assessment](#1-readiness--gap-assessment) | | Writing SSP, POA&M, SAR, SAP, or other docs | → [ATO Documentation](#2-ato-documentation) | | "Which controls apply to us?" / control mapping | → [NIST 800-53 Control Mapping](#3-nist-800-53-control-mapping) | | Cloud architecture / AWS/Azure/GCP config | → [Architecture Guidance](#4-architecture-guidance) | | Already authorized, ongoing compliance | → [Continuous Monitoring](#5-continuous-monitoring) | --- ## Current FedRAMP State (as of July 2026 — CR26) > ⚠️ **CR26 (FedRAMP Consolidated Rules for 2026)**: FedRAMP has restructured its authorization framework. FIPS 199-based baseline labels (Low/Moderate/High/LI-SaaS) are replaced with **Certification Classes A–D** (per notice NTC-0004; CR26 rules valid through December 31, 2028).
- Quick Reference: What Does the User Need?
- Current FedRAMP State (as of July 2026 — CR26)
- 1. Readiness & Gap Assessment
- Approach
- Key Readiness Questions to Ask the User
- Output Format
- 2. ATO Documentation
- Document Guidance
- General Writing Principles for All ATO Docs
- 3. NIST 800-53 Control Mapping
- Control Families (Rev 5)
- CR26 Certification Class Mapping
- Mapping Workflow
- Rev 4 → Rev 5 Key Changes to Highlight
What does the fedramp skill do?
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document types: SSP, SAP, SAR, POA&M, CIS/CRM workbooks. Also trigger for questions about FedRAMP Certification Classes (A, B, C, D — new baseline labels: A = pilot/transitional, B = LI-SaaS/Low, C = Moderate, D = High, per NTC-0004), FedRAMP 20x (now the primary authorization pathway), OSCAL
How do I install it?
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill fedramp --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
