FedRAMP High
FedRAMP High baseline, based on NIST SP 800-53 Revision 5, includes all 421 security controls with FedRAMP-specific tailoring and implementation guidance.
FedRAMP High is a compliance framework from United States with 18 domains and 410 controls that map to 280 other frameworks. The largest domains are AC - Access Control (50 controls), CP - Contingency Planning (35 controls), SC - System and Communications Protection (35 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
AC - Access Control
| Code | Title |
|---|---|
| AC-1 | Policy and Procedures |
| AC-10 | Concurrent Session Control |
| AC-11 | Device Lock |
| AC-11(1) | Device Lock | Pattern-hiding Displays (AC-11(1)) |
| AC-12 | Session Termination |
| AC-14 | Permitted Actions Without Identification or Authentication |
| AC-17 | Remote Access |
| AC-17(1) | Monitoring and Control |
| AC-17(2) | Protection of Confidentiality and Integrity Using Encryption |
| AC-17(3) | Managed Access Control Points |
| AC-17(4) | Privileged Commands and Access |
| AC-18 | Wireless Access |
| AC-18(1) | Authentication and Encryption |
| AC-18(3) | Wireless Access | Disable Wireless Networking (AC-18(3)) |
| AC-18(4) | Restrict Configurations by Users |
| AC-18(5) | Antennas and Transmission Power Levels |
| AC-19 | Access Control for Mobile Devices |
| AC-19(5) | Full Device or Container-Based Encryption |
| AC-2 | Account Management |
| AC-2(1) | Automated System Account Management |
| AC-2(11) | Usage Conditions |
| AC-2(12) | Account Monitoring for Atypical Usage |
| AC-2(13) | Disable Accounts for High-Risk Individuals |
| AC-2(2) | Automated Temporary and Emergency Account Management |
| AC-2(3) | Disable Accounts |
| AC-2(4) | Automated Audit Actions |
| AC-2(5) | Inactivity Logout |
| AC-2(7) | Privileged User Accounts |
| AC-2(9) | Restrictions on Use of Shared and Group Accounts |
| AC-20 | Use of External Systems |
| AC-20(1) | Limits on Authorized Use |
| AC-20(2) | Portable Storage Devices Restricted Use |
| AC-21 | Information Sharing |
| AC-22 | Publicly Accessible Content |
| AC-3 | Access Enforcement |
| AC-4 | Information Flow Enforcement |
| AC-4(21) | Physical or Logical Separation of Information Flows |
| AC-4(4) | Flow Control of Encrypted Information |
| AC-5 | Separation of Duties |
| AC-6 | Least Privilege |
| AC-6(1) | Authorize Access to Security Functions |
| AC-6(10) | Prohibit Non-Privileged Users from Executing Privileged Functions |
| AC-6(2) | Non-Privileged Access for Nonsecurity Functions |
| AC-6(3) | Network Access to Privileged Commands |
| AC-6(5) | Privileged Accounts |
| AC-6(7) | Review of User Privileges |
| AC-6(8) | Privilege Levels for Code Execution |
| AC-6(9) | Log Use of Privileged Functions |
| AC-7 | Unsuccessful Logon Attempts |
| AC-8 | System Use Notification |
AT - Awareness and Training
AU - Audit and Accountability
| Code | Title |
|---|---|
| AU-1 | Policy and Procedures |
| AU-10 | Non-Repudiation |
| AU-11 | Audit Record Retention |
| AU-12 | Audit Record Generation |
| AU-12(1) | System-wide and Time-correlated Audit Trail |
| AU-12(3) | Changes by Authorized Individuals |
| AU-2 | Event Logging |
| AU-3 | Content of Audit Records |
| AU-3(1) | Additional Audit Information |
| AU-4 | Audit Log Storage Capacity |
| AU-5 | Response to Audit Logging Process Failures |
| AU-5(1) | Storage Capacity Warning |
| AU-5(2) | Real-Time Alerts |
| AU-6 | Audit Record Review, Analysis, and Reporting |
| AU-6(1) | Automated Process Integration |
| AU-6(3) | Correlate Audit Record Repositories |
| AU-6(4) | Central Review and Analysis |
| AU-6(5) | Integrated Analysis of Audit Records |
| AU-6(6) | Correlation with Physical Monitoring |
| AU-6(7) | Permitted Actions |
| AU-7 | Audit Record Reduction and Report Generation |
| AU-7(1) | Automatic Processing |
| AU-8 | Time Stamps |
| AU-9 | Protection of Audit Information |
| AU-9(2) | Store on Separate Physical Systems or Components |
| AU-9(3) | Cryptographic Protection |
| AU-9(4) | Access by Subset of Privileged Users |
CA - Assessment, Authorization, and Monitoring
| Code | Title |
|---|---|
| CA-1 | Policy and Procedures |
| CA-2 | Control Assessments |
| CA-2(1) | Independent Assessors |
| CA-2(2) | Specialized Assessments |
| CA-2(3) | Control Assessments | Leveraging Results from External Organizations (CA-2(3)) |
| CA-3 | Information Exchange |
| CA-3(6) | Information Exchange | Transfer Authorizations |
| CA-5 | Plan of Action and Milestones |
| CA-6 | Authorization |
| CA-7 | Continuous Monitoring |
| CA-7(1) | Independent Assessment |
| CA-7(4) | Continuous Monitoring | Risk Monitoring (CA-7(4)) |
| CA-8 | Penetration Testing |
| CA-8(1) | Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1)) |
| CA-8(2) | Penetration Testing | Red Team Exercises (CA-8(2)) |
| CA-9 | Internal System Connections |
CM - Configuration Management
| Code | Title |
|---|---|
| CM-1 | Policy and Procedures |
| CM-10 | Software Usage Restrictions |
| CM-11 | User-Installed Software |
| CM-12 | Information Location (CM-12) |
| CM-12(1) | Information Location | Automated Tools to Support Information Location (CM-12(1)) |
| CM-14 | Signed Components |
| CM-2 | Baseline Configuration |
| CM-2(2) | Automation Support for Accuracy and Currency |
| CM-2(3) | Retention of Previous Configurations |
| CM-2(7) | Configure Systems and Components for High-Risk Areas |
| CM-3 | Configuration Change Control |
| CM-3(1) | Automated Documentation, Notification, and Prohibition |
| CM-3(2) | Testing, Validation, and Documentation of Changes |
| CM-3(4) | Security and Privacy Representatives |
| CM-3(6) | Cryptography Management |
| CM-4 | Impact Analyses |
| CM-4(1) | Separate Test Environments |
| CM-4(2) | Impact Analyses | Verification of Controls (CM-4(2)) |
| CM-5 | Access Restrictions for Change |
| CM-5(1) | Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) |
| CM-5(5) | Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5)) |
| CM-6 | Configuration Settings |
| CM-6(1) | Automated Management, Application, and Verification |
| CM-6(2) | Respond to Unauthorized Changes |
| CM-7 | Least Functionality |
| CM-7(1) | Periodic Review |
| CM-7(2) | Prevent Program Execution |
| CM-7(5) | Authorized Software Allow-by-Exception |
| CM-8 | System Component Inventory |
| CM-8(1) | Updates During Installation and Removal |
| CM-8(2) | Automated Maintenance |
| CM-8(3) | Automated Unauthorized Component Detection |
| CM-8(4) | Accountability Information |
| CM-9 | Configuration Management Plan |
CP - Contingency Planning
| Code | Title |
|---|---|
| CP-1 | Policy and Procedures |
| CP-10 | System Recovery and Reconstitution |
| CP-10(2) | System Recovery and Reconstitution | Transaction Recovery (CP-10(2)) |
| CP-10(4) | Restore Within Time Period |
| CP-2 | Contingency Plan |
| CP-2(1) | Coordinate with Related Plans |
| CP-2(2) | Capacity Planning |
| CP-2(3) | Resume Mission and Business Functions |
| CP-2(5) | Continue Mission and Business Functions |
| CP-2(8) | Contingency Plan | Identify Critical Assets (CP-2(8)) |
| CP-3 | Contingency Training |
| CP-3(1) | Simulated Events |
| CP-4 | Contingency Plan Testing |
| CP-4(1) | Coordinate with Related Plans |
| CP-4(2) | Alternate Processing Site |
| CP-6 | Alternate Storage Site |
| CP-6(1) | Alternate Storage Site | Separation from Primary Site (CP-6(1)) |
| CP-6(2) | Recovery Time and Recovery Point Objectives |
| CP-6(3) | Alternate Storage Site | Accessibility (CP-6(3)) |
| CP-7 | Alternate Processing Site |
| CP-7(1) | Alternate Processing Site | Separation from Primary Site (CP-7(1)) |
| CP-7(2) | Alternate Processing Site | Accessibility (CP-7(2)) |
| CP-7(3) | Alternate Processing Site | Priority of Service (CP-7(3)) |
| CP-7(4) | Preparation for Use |
| CP-8 | Telecommunications Services |
| CP-8(1) | Telecommunications Services | Priority of Service Provisions (CP-8(1)) |
| CP-8(2) | Telecommunications Services | Single Points of Failure (CP-8(2)) |
| CP-8(3) | Separation of Primary and Alternate Providers |
| CP-8(4) | Provider Contingency Plan |
| CP-9 | System Backup |
| CP-9(1) | Testing for Reliability and Integrity |
| CP-9(2) | Test Restoration Using Sampling |
| CP-9(3) | Separate Storage for Critical Information |
| CP-9(5) | Transfer to Alternate Storage Site |
| CP-9(8) | System Backup | Cryptographic Protection (CP-9(8)) |
IA - Identification and Authentication
| Code | Title |
|---|---|
| IA-1 | Policy and Procedures |
| IA-11 | Re-Authentication |
| IA-12 | Identity Proofing (IA-12) |
| IA-12(2) | Identity Proofing | Identity Evidence (IA-12(2)) |
| IA-12(3) | Identity Proofing | Identity Evidence Validation and Verification (IA-12(3)) |
| IA-12(4) | In-Person Validation and Verification |
| IA-12(5) | Identity Proofing | Address Confirmation (IA-12(5)) |
| IA-2 | Identification and Authentication (Organizational Users) |
| IA-2(1) | MFA to Privileged Accounts |
| IA-2(12) | Acceptance of PIV Credentials |
| IA-2(2) | MFA to Non-Privileged Accounts |
| IA-2(5) | Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5)) |
| IA-2(6) | Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6)) |
| IA-2(8) | Access to Accounts Replay Resistant |
| IA-3 | Device Identification and Authentication |
| IA-4 | Identifier Management |
| IA-4(4) | Identifier Management | Identify User Status (IA-4(4)) |
| IA-5 | Authenticator Management |
| IA-5(1) | Password-Based Authentication |
| IA-5(13) | Authenticator Management | Expiration of Cached Authenticators |
| IA-5(2) | Public Key-Based Authentication |
| IA-5(6) | Protection of Authenticators |
| IA-5(7) | Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7)) |
| IA-5(8) | Multiple System Accounts |
| IA-6 | Authentication Feedback |
| IA-7 | Cryptographic Module Authentication |
| IA-8 | Identification and Authentication (Non-Organizational Users) |
| IA-8(1) | Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) |
| IA-8(2) | Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2)) |
| IA-8(4) | Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4)) |
IR - Incident Response
| Code | Title |
|---|---|
| IR-1 | Policy and Procedures |
| IR-2 | Incident Response Training |
| IR-2(1) | Simulated Events |
| IR-2(2) | Automated Training Environments |
| IR-3 | Incident Response Testing |
| IR-3(2) | Incident Response Testing | Coordination with Related Plans (IR-3(2)) |
| IR-4 | Incident Handling |
| IR-4(1) | Automated Incident Handling Processes |
| IR-4(11) | Incident Handling | Integrated Incident Response Team |
| IR-4(2) | Incident Handling | Dynamic Reconfiguration |
| IR-4(4) | Information Correlation |
| IR-4(6) | Insider Threats |
| IR-5 | Incident Monitoring |
| IR-5(1) | Automated Tracking, Data Collection, and Analysis |
| IR-6 | Incident Reporting |
| IR-6(1) | Automated Reporting |
| IR-6(3) | Incident Reporting | Supply Chain Coordination (IR-6(3)) |
| IR-7 | Incident Response Assistance |
| IR-7(1) | Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) |
| IR-8 | Incident Response Plan |
| IR-9 | Information Spillage Response (IR-9) |
| IR-9(2) | Information Spillage Response | Training (IR-9(2)) |
| IR-9(3) | Information Spillage Response | Post-spill Operations (IR-9(3)) |
| IR-9(4) | Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4)) |
MA - Maintenance
| Code | Title |
|---|---|
| MA-1 | Policy and Procedures |
| MA-2 | Controlled Maintenance |
| MA-2(2) | Automated Maintenance Activities |
| MA-3 | Maintenance Tools (MA-3) |
| MA-3(1) | Maintenance Tools | Inspect Tools (MA-3(1)) |
| MA-3(2) | Maintenance Tools | Inspect Media (MA-3(2)) |
| MA-3(3) | Maintenance Tools | Prevent Unauthorized Removal (MA-3(3)) |
| MA-4 | Nonlocal Maintenance |
| MA-4(3) | Comparable Security and Sanitization |
| MA-5 | Maintenance Personnel |
| MA-5(1) | Maintenance Personnel | Individuals Without Appropriate Access (MA-5(1)) |
| MA-6 | Timely Maintenance (MA-6) |
MP - Media Protection
| Code | Title |
|---|---|
| MP-1 | Policy and Procedures |
| MP-2 | Media Access |
| MP-3 | Media Marking |
| MP-4 | Media Storage |
| MP-5 | Media Transport |
| MP-6 | Media Sanitization |
| MP-6(1) | Review, Approve, Track, Document, Verify |
| MP-6(2) | Equipment Testing |
| MP-6(3) | Nondestructive Techniques |
| MP-7 | Media Use |
PE - Physical and Environmental Protection
| Code | Title |
|---|---|
| PE-1 | Policy and Procedures |
| PE-10 | Emergency Shutoff (PE-10) |
| PE-11 | Emergency Power (PE-11) |
| PE-11(1) | Alternate Power Supply Minimal Operational Capability |
| PE-12 | Emergency Lighting |
| PE-13 | Fire Protection |
| PE-13(1) | Fire Protection | Detection Systems: Automatic Activation and Notification (PE-13(1)) |
| PE-13(2) | Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2)) |
| PE-14 | Environmental Controls |
| PE-14(2) | Environmental Controls | Monitoring with Alarms and Notifications |
| PE-15 | Water Damage Protection (PE-15) |
| PE-15(1) | Automation Support |
| PE-16 | Delivery and Removal |
| PE-17 | Alternate Work Site |
| PE-18 | Location of System Components |
| PE-2 | Physical Access Authorizations |
| PE-3 | Physical Access Control |
| PE-3(1) | System Access |
| PE-4 | Access Control for Transmission (PE-4) |
| PE-5 | Access Control for Output Devices (PE-5) |
| PE-6 | Monitoring Physical Access |
| PE-6(1) | Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment (PE-6(1)) |
| PE-6(4) | Monitoring Physical Access to Systems |
| PE-8 | Visitor Access Records |
| PE-8(1) | Automated Records Maintenance and Review |
| PE-9 | Power Equipment and Cabling (PE-9) |
PL - Planning
| Code | Title |
|---|---|
| PL-1 | Policy and Procedures |
| PL-10 | Baseline Selection. Select a control baseline for the system |
| PL-11 | Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions |
| PL-2 | System Security and Privacy Plans |
| PL-4 | Rules of Behavior |
| PL-4(1) | Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1)) |
| PL-8 | Security and Privacy Architectures |
PS - Personnel Security
| Code | Title |
|---|---|
| PS-1 | Policy and Procedures |
| PS-2 | Position Risk Designation |
| PS-3 | Personnel Screening |
| PS-3(3) | Personnel Screening | Information Requiring Special Protective Measures (PS-3(3)) |
| PS-4 | Personnel Termination |
| PS-4(2) | Automated Actions |
| PS-5 | Personnel Transfer |
| PS-6 | Access Agreements |
| PS-7 | External Personnel Security |
| PS-8 | Personnel Sanctions |
| PS-9 | Position Descriptions (PS-9) |
RA - Risk Assessment
| Code | Title |
|---|---|
| RA-1 | Policy and Procedures |
| RA-2 | Security Categorization |
| RA-3 | Risk Assessment |
| RA-3(1) | Risk Assessment | Supply Chain Risk Assessment (RA-3(1)) |
| RA-5 | Vulnerability Monitoring and Scanning |
| RA-5(11) | Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11)) |
| RA-5(2) | Update Vulnerabilities to be Scanned |
| RA-5(3) | Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) |
| RA-5(4) | Discoverable Information |
| RA-5(5) | Privileged Access |
| RA-5(8) | Vulnerability Monitoring and Scanning | Review Historic Audit Logs |
| RA-7 | Risk Response |
| RA-9 | Criticality Analysis (RA-9) |
SA - System and Services Acquisition
| Code | Title |
|---|---|
| SA-1 | Policy and Procedures |
| SA-10 | Developer Configuration Management |
| SA-11 | Developer Testing and Evaluation |
| SA-11(1) | Developer Testing and Evaluation | Static Code Analysis (SA-11(1)) |
| SA-11(2) | Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2)) |
| SA-15 | Development Process, Standards, and Tools (SA-15) |
| SA-15(3) | Development Process, Standards, and Tools | Criticality Analysis (SA-15(3)) |
| SA-16 | Developer-Provided Training |
| SA-17 | Developer Security and Privacy Architecture and Design |
| SA-2 | Allocation of Resources |
| SA-21 | Developer Screening |
| SA-22 | Unsupported System Components (SA-22) |
| SA-3 | System Development Life Cycle |
| SA-4 | Acquisition Process |
| SA-4(1) | Acquisition Process | Functional Properties of Controls (SA-4(1)) |
| SA-4(10) | Use of Approved PIV Products |
| SA-4(2) | Acquisition Process | Design and Implementation Information for Controls (SA-4(2)) |
| SA-4(5) | System, Component, and Service Configurations |
| SA-4(9) | Acquisition Process | Functions, Ports, Protocols, and Services in Use (SA-4(9)) |
| SA-5 | System Documentation |
| SA-8 | Security and Privacy Engineering Principles |
| SA-9 | External System Services |
| SA-9(1) | External System Services | Risk Assessments and Organizational Approvals (SA-9(1)) |
| SA-9(2) | Identification of Functions, Ports, Protocols, and Services |
| SA-9(5) | External System Services | Processing, Storage, and Service Location (SA-9(5)) |
SC - System and Communications Protection
| Code | Title |
|---|---|
| SC-1 | Policy and Procedures |
| SC-10 | Network Disconnect |
| SC-12 | Cryptographic Key Establishment and Management |
| SC-12(1) | Availability |
| SC-13 | Cryptographic Protection |
| SC-15 | Collaborative Computing Devices and Applications |
| SC-17 | Public Key Infrastructure Certificates |
| SC-18 | Mobile Code |
| SC-2 | Separation of System and User Functionality |
| SC-20 | Secure Name/Address Resolution Service (Authoritative) |
| SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) |
| SC-22 | Architecture and Provisioning for Name/Address Resolution Service |
| SC-23 | Session Authenticity |
| SC-24 | Fail in Known State |
| SC-28 | Protection of Information at Rest |
| SC-28(1) | Cryptographic Protection |
| SC-3 | Security Function Isolation |
| SC-39 | Process Isolation |
| SC-4 | Information in Shared System Resources |
| SC-45 | System Time Synchronization (SC-45) |
| SC-45(1) | System Time Synchronization | Synchronization with Authoritative Time Source (SC-45(1)) |
| SC-5 | Denial-of-Service Protection |
| SC-7 | Boundary Protection |
| SC-7(10) | Prevent Exfiltration |
| SC-7(12) | Boundary Protection | Host-based Protection (SC-7(12)) |
| SC-7(18) | Boundary Protection | Fail Secure (SC-7(18)) |
| SC-7(20) | Dynamic Isolation and Segregation |
| SC-7(21) | Isolation of System Components |
| SC-7(3) | Access Points |
| SC-7(4) | External Telecommunications Services |
| SC-7(5) | Deny by Default Allow by Exception |
| SC-7(7) | Split Tunneling for Remote Devices |
| SC-7(8) | Route Traffic to Authenticated Proxy Servers |
| SC-8 | Transmission Confidentiality and Integrity |
| SC-8(1) | Cryptographic Protection |
SI - System and Information Integrity
| Code | Title |
|---|---|
| SI-1 | Policy and Procedures |
| SI-10 | Information Input Validation |
| SI-11 | Error Handling |
| SI-12 | Information Management and Retention |
| SI-16 | Memory Protection |
| SI-2 | Flaw Remediation |
| SI-2(2) | Automated Flaw Remediation Status |
| SI-2(3) | Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) |
| SI-3 | Malicious Code Protection |
| SI-4 | System Monitoring |
| SI-4(1) | System Monitoring | System-wide Intrusion Detection System (SI-4(1)) |
| SI-4(10) | Visibility of Encrypted Communications |
| SI-4(11) | Analyze Communications Traffic Anomalies |
| SI-4(12) | Automated Organization-Generated Alerts |
| SI-4(14) | Wireless Intrusion Detection |
| SI-4(16) | System Monitoring | Correlate Monitoring Information (SI-4(16)) |
| SI-4(18) | System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) |
| SI-4(19) | Risk for Individuals |
| SI-4(2) | Automated Tools and Mechanisms for Real-Time Analysis |
| SI-4(20) | Privileged Users |
| SI-4(22) | Unauthorized Network Services |
| SI-4(23) | System Monitoring | Host-based Devices (SI-4(23)) |
| SI-4(4) | Inbound and Outbound Communications Traffic |
| SI-4(5) | System-Generated Alerts |
| SI-5 | Security Alerts, Advisories, and Directives |
| SI-5(1) | Automated Alerts and Advisories |
| SI-6 | Security and Privacy Function Verification (SI-6) |
| SI-7 | Software, Firmware, and Information Integrity |
| SI-7(1) | Integrity Checks |
| SI-7(15) | Software, Firmware, and Information Integrity | Code Authentication |
| SI-7(2) | Automated Notifications of Integrity Violations |
| SI-7(5) | Automated Response to Integrity Violations |
| SI-7(7) | Integration of Detection and Response |
| SI-8 | Spam Protection |
| SI-8(2) | Spam Protection | Automatic Updates (SI-8(2)) |
SR - Supply Chain Risk Management
| Code | Title |
|---|---|
| SR-1 | Policy and Procedures (SR-1) |
| SR-10 | Inspection of Systems or Components (SR-10) |
| SR-11 | Component Authenticity (SR-11) |
| SR-11(1) | Component Authenticity | Anti-counterfeit Training (SR-11(1)) |
| SR-11(2) | Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2)) |
| SR-12 | Component Disposal (SR-12) |
| SR-2 | Supply Chain Risk Management Plan (SR-2) |
| SR-2(1) | Supply Chain Risk Management Plan | Establish SCRM Team (SR-2(1)) |
| SR-3 | Supply Chain Controls and Processes (SR-3) |
| SR-5 | Acquisition Strategies, Tools, and Methods (SR-5) |
| SR-6 | Supplier Assessments and Reviews (SR-6) |
| SR-8 | Notification Agreements (SR-8) |
| SR-9 | Tamper Resistance and Detection (SR-9) |
| SR-9(1) | Multiple Stages of SDLC (SR-9(1)) |
Your Compliance Coverage
If you comply with FedRAMP High, you already cover:
Maps to 280 other frameworks
Coverage is not the same as your position
This page shows what FedRAMP High overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is FedRAMP High and who does it apply to?
FedRAMP High is a compliance framework from United States with 18 domains and 410 controls. FedRAMP High baseline, based on NIST SP 800-53 Revision 5, includes all 421 security controls with FedRAMP-specific tailoring and implementation guidance. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does FedRAMP High actually require?
FedRAMP High has 410 controls organised across 18 domains. The largest domains are AC - Access Control (50 controls), CP - Contingency Planning (35 controls), SC - System and Communications Protection (35 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of FedRAMP High do I already cover?
FedRAMP High maps to 280 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 HIGH (90% coverage), NIST SP 800-53 Rev 5 (79% coverage), ISO 27002:2022 (78% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement FedRAMP High?
Start your FedRAMP High compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FedRAMP High requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 410 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required