← Back to blog

FedRAMP Moderate Controls: Rev. 5 Guide for IT Teams

August 13, 2026
FedRAMP Moderate Controls: Rev. 5 Guide for IT Teams

FedRAMP Moderate controls are the Rev. 5 security control baseline, estimated at roughly 320–325 controls, required for cloud systems that process Controlled Unclassified Information (CUI), sensitive HR data, and federal financial records. The Agency Authorizing Official (AO) makes the final risk-acceptance decision, even when a FedRAMP package already exists. Official Rev. 5 templates, OSCAL profiles, and the baseline spreadsheet live on FedRAMP.gov, which also hosts the FedRAMP Marketplace of authorized services.

Quick-start checklist:

  • Download the Rev. 5 SSP template and baseline spreadsheet from FedRAMP.gov
  • Map your Customer Responsibility Matrix (CRM) against the platform's Customer Implementation Summary (CIS)
  • Identify inherited, shared, and customer-owned controls before writing a single SSP narrative
  • Engage a Third Party Assessment Organization (3PAO) early, ideally before the SSP is finalized
  • Request access to existing platform packages through the FedRAMP Marketplace to accelerate inheritance mapping

Key Takeaways

The FedRAMP Moderate Rev. 5 baseline requires roughly 320–325 controls, and the authorization outcome depends on the accuracy of CRM mapping, the quality of evidence, and sustained continuous monitoring, not just control count.

PointDetails
Rev. 5 control countThe Moderate baseline carries roughly 320–325 controls including enhancements; use the official baseline spreadsheet as the master reference.
CRM mapping is the critical pathMis-mapped inherited and shared controls are the most common deficiency; build the CRM before drafting SSP narratives.
Inheritance compresses timelinesPlatform inheritance can cover roughly 60% of Moderate controls, potentially reducing agency ATO timelines from months to weeks.
OSCAL templates are mandatoryRev. 4 artifacts are not acceptable for new authorizations; start with Rev. 5 OSCAL templates from FedRAMP.gov to avoid PMO rework.
Primereadysub for defined-scope supportRutledge & Associates delivers owned CRM, OSCAL SSP, and continuous monitoring packages for government teams and prime contractors.

Table of Contents

What are FedRAMP controls and how does the program organize baselines?

FedRAMP provides the government-wide, standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. Every control in a FedRAMP baseline originates from NIST SP 800-53 Revision 5, the primary control catalog published by the National Institute of Standards and Technology. FedRAMP does not simply adopt NIST controls verbatim. It tailors them: selecting a subset, adding enhancements, and assigning prescriptive parameter values that are stricter than the open NIST language.

A FedRAMP control has three layers:

  • Base control: The core NIST SP 800-53 requirement (e.g., AC-2, Account Management)
  • Enhancement: An additional, numbered sub-requirement that strengthens the base (e.g., AC-2(1), Automated System Account Management)
  • FedRAMP-assigned parameter: A specific value FedRAMP sets where NIST leaves the parameter open (e.g., "within 24 hours" for account disabling after termination)

The program organizes its requirements into three impact-level baselines: Low, Moderate, and High. Impact level is determined by the potential harm a security breach would cause to agency operations, assets, or individuals. Low covers publicly available data with minimal harm potential. Moderate covers the majority of federal cloud workloads, specifically systems where a breach could cause serious adverse effects. High applies to systems where compromise could cause severe or catastrophic harm, such as law enforcement or emergency services data.

For most cloud service providers (CSPs) entering the federal market, Moderate is the relevant baseline. It covers CUI, sensitive HR records, financial data, and most agency operational systems that do not rise to the High threshold.


How many controls does the FedRAMP Moderate baseline include in Rev. 5?

Industry guidance estimates the Rev. 5 FedRAMP Moderate baseline at roughly 320–325 controls, counting both base controls and selected enhancements. The official FedRAMP Rev. 5 security controls spreadsheet enumerates every required control and enhancement and identifies FedRAMP's assigned parameters for each one. That spreadsheet is the authoritative source, and practitioners should treat it as the ground truth rather than any secondary summary.

Rev. 5 introduced several changes that matter specifically for Moderate implementations:

  • New PT (Personally Identifiable Information Processing and Transparency) family: Privacy controls are now a distinct family in Rev. 5, adding requirements that did not exist as a named family in Rev. 4.
  • OSCAL-formatted templates: FedRAMP released updated OSCAL profiles and Rev. 5 templates alongside the baseline, replacing the older Word and Excel SSP formats for new submissions.
  • Program Management (PM) family removed from the baseline: PM controls shifted to organizational-level requirements rather than system-level baseline controls.

The number of controls that include enhancements is significant. Many Moderate controls carry two, three, or more enhancements, each requiring its own implementation narrative and evidence. This is why the raw control count understates the actual documentation burden.

Pro Tip: Never start an SSP using a Rev. 4 template. Rev. 4 artifacts are no longer acceptable for new authorizations. Confirm your SSP, SAP, SAR, and POA&M templates carry the Rev. 5 header and OSCAL structure before writing a single narrative. Catching this at the start saves weeks of rework during PMO review.


Which control families carry the most weight in the Moderate baseline?

FedRAMP organizes controls into 20 families, each identified by a two-letter code. For Moderate systems, several families carry a disproportionate share of the implementation burden and assessor scrutiny.

  • AC (Access Control): The largest family in Moderate. Key controls include AC-2 (Account Management), AC-3 (Access Enforcement), and AC-17 (Remote Access). FedRAMP requires multi-factor authentication (MFA) and least-privilege enforcement with specific parameter values for account review frequency.
  • AU (Audit and Accountability): Covers log generation, retention, and review. FedRAMP sets specific log retention periods that are stricter than general NIST guidance. AU-2 (Event Logging) and AU-12 (Audit Record Generation) are commonly cited in deficiency findings.
  • CM (Configuration Management): Requires a documented baseline configuration and deviation tracking. CM-6 (Configuration Settings) and CM-7 (Least Functionality) demand evidence of hardened configurations, often tied to DISA STIGs or CIS Benchmarks.
  • IR (Incident Response): IR-6 (Incident Reporting) sets a specific reporting window to US-CERT and the agency AO. FedRAMP's parameter is more prescriptive than the base NIST language.
  • CA (Security Assessment and Authorization): Covers the authorization process itself, including CA-2 (Control Assessments) and CA-7 (Continuous Monitoring). These controls govern how the 3PAO conducts its assessment and how the CSP maintains evidence post-authorization.
  • SI (System and Information Integrity): SI-2 (Flaw Remediation) and SI-3 (Malware Protection) are high-scrutiny controls. FedRAMP assigns specific scan cadences and remediation timelines for critical and high vulnerabilities.
  • SC (System and Communications Protection): Covers encryption in transit and at rest, network segmentation, and boundary protection. SC-8 (Transmission Confidentiality and Integrity) and SC-28 (Protection of Information at Rest) are frequently tested.
  • PT (PII Processing and Transparency): New in Rev. 5. Requires documented privacy notices, consent mechanisms, and data minimization practices for any system processing PII.
  • SA (System and Services Acquisition): Covers supply chain risk management and developer security requirements. SA-9 (External System Services) is particularly relevant for CSPs using third-party subservices.
  • PL (Planning): PL-2 (System Security Plan) is the anchor document for the entire authorization package.
  • RA (Risk Assessment): RA-5 (Vulnerability Monitoring and Scanning) drives the continuous monitoring scanning cadence and ties directly to POA&M management.

The three families with the highest combined control weight in Moderate are Access Control, System and Communications Protection, and Configuration Management. These three account for a substantial share of assessor findings and are where most CSPs spend the most remediation effort before assessment.


How does FedRAMP authorization work for Moderate systems?

FedRAMP authorization follows NIST SP 800-37's Risk Management Framework and establishes a presumption-of-adequacy for agency reuse of existing FedRAMP packages, provided continuous monitoring remains active. The AO's risk-acceptance decision is the final gate, even when a package is already FedRAMP-authorized at the Moderate level.

The typical authorization process for a Moderate system follows this sequence:

  1. Categorize the system using FIPS 199 and FIPS 200 to confirm Moderate impact level across confidentiality, integrity, and availability.
  2. Select and tailor controls from the Rev. 5 Moderate baseline spreadsheet, document any tailoring decisions, and identify the system boundary.
  3. Implement controls and document in the System Security Plan (SSP), mapping each control to its implementation narrative, responsible party, and evidence reference.
  4. Achieve FedRAMP Ready (optional but valuable): A 3PAO attests to readiness through a FedRAMP Ready designation, valid for one year, which signals capability to agency partners before a formal ATO.
  5. Engage a 3PAO to develop the Security Assessment Plan (SAP) and conduct independent testing against Rev. 5 assessment procedures.
  6. 3PAO produces the Security Assessment Report (SAR), documenting findings, risk ratings, and recommendations.
  7. CSP develops or updates the POA&M to address SAR findings with remediation timelines.
  8. Submit the authorization package (SSP, SAP, SAR, POA&M, CIS, CRM) to the FedRAMP PMO or directly to the sponsoring agency AO.
  9. Agency AO reviews the package, applies the presumption-of-adequacy principle for any inherited controls, and issues an Agency Authority to Operate (ATO) or requests additional remediation.
  10. Continuous monitoring begins, with the CSP delivering monthly scan results, POA&M updates, and annual independent assessments to maintain the authorization.

Two authorization paths exist for Moderate systems. The agency-led path is the most common: a federal agency sponsors the CSP, reviews the package, and the agency AO issues the ATO. The FedRAMP PMO reviews the package for completeness and program compliance before it enters the FedRAMP Marketplace. The JAB (Joint Authorization Board) path, historically used for broad reuse across agencies, has been restructured under recent FedRAMP policy updates; practitioners should confirm current PMO guidance on this path before planning for it.


What documentation does FedRAMP Moderate require?

The authorization package for a Moderate system is a structured set of artifacts, each with a defined purpose, owner, and update cadence. Using the wrong template version or missing required evidence in any artifact is one of the most common causes of PMO review delays.

ArtifactPurposePrimary OwnerUpdate Cadence
System Security Plan (SSP)Documents control implementations, system boundary, and architectureCSPUpdated with any significant change; reviewed annually
Security Assessment Plan (SAP)Defines scope, methodology, and test procedures for the 3PAO assessment3PAO (with CSP input)Per assessment event
Security Assessment Report (SAR)Documents 3PAO findings, risk ratings, and residual risk3PAOPer assessment event; annual for continuous monitoring
Plan of Action & Milestones (POA&M)Tracks open findings, remediation owners, and target datesCSPMonthly updates required
Customer Implementation Summary (CIS)Describes how the CSP implements each control for customer referenceCSPUpdated with SSP changes
Customer Responsibility Matrix (CRM)Maps each control to its ownership type (inherited, shared, customer-owned)CSPUpdated with SSP changes
Continuous Monitoring PackageMonthly scan results, log review evidence, incident reportsCSPMonthly delivery to AO and PMO

Beyond the core artifacts, FedRAMP expects OSCAL-formatted versions of the SSP, SAP, and SAR for new Rev. 5 submissions. FedRAMP's Rev. 5 release included OSCAL profiles and updated templates specifically to reduce manual submission effort and lower the risk of template-related deficiencies during PMO review. Teams that automate OSCAL exports from their GRC platform avoid the manual re-entry errors that frequently trigger PMO comment cycles.

Common submission pitfalls to avoid:

  • Incorrect control mapping: Narratives that describe a control implementation but reference the wrong control ID or enhancement number
  • Missing test procedures: SAPs that do not map test cases to specific Rev. 5 assessment procedures
  • Stale architecture diagrams: SSP diagrams that do not match the actual deployed boundary, which assessors verify during testing
  • Incomplete CRM: Controls listed as "inherited" without a reference to the platform's CIS artifact or the specific package from which they are inherited

For teams evaluating compliance automation tooling to support NIST SP 800-53 control mapping and OSCAL exports, selecting a platform that natively supports Rev. 5 control families, including the PT family, prevents significant rework later in the process.


What documentation does FedRAMP Moderate require? — overview diagram

How does control ownership work, and what is the Customer Responsibility Matrix?

Control ownership is the single most consequential mapping decision in a FedRAMP Moderate authorization. Every control in the baseline falls into one of three categories:

  • Inherited: The platform or underlying infrastructure provider fully implements the control. The CSP references the platform's CIS and does not need to implement or evidence the control independently.
  • Shared: Both the platform and the CSP contribute to the control's implementation. Each party documents its portion, and the CSP's SSP narrative must clearly delineate the boundary.
  • Customer-owned: The CSP implements the control entirely within its own system boundary, with no reliance on the platform.

Accurate CRM and CIS mapping dramatically reduces assessor questions and PMO rework. Mis-mapped controls, particularly controls listed as "inherited" without a valid CIS reference, are the most common source of deficiency findings in Moderate package reviews.

A practical mapping workflow:

  1. Identify the platform: Confirm which FedRAMP-authorized platform (IaaS, PaaS) the system runs on and download the platform's CIS from the FedRAMP Marketplace.
  2. Map each Moderate control against the CIS to determine ownership type.
  3. Document inherited controls in the SSP with a direct reference to the platform package name, authorization date, and the specific CIS section.
  4. Write shared-control narratives that explicitly describe the CSP's portion and reference the platform's portion.
  5. Collect evidence for customer-owned and shared controls: configuration screenshots, scan results, policy documents, and test results.

5 Moderate controls, enabling agencies to inherit evidence and, in some cases, achieve system-level ATOs in weeks rather than months. That figure illustrates why platform selection is a compliance decision, not just an infrastructure one.

Pro Tip: Structure the CRM as a living spreadsheet with columns for control ID, ownership type, CIS reference, SSP section, evidence artifact, and last-verified date. Assessors frequently request this mapping during kickoff. Having it pre-built and cross-referenced to the SSP reduces the back-and-forth that extends assessment timelines.

Hands typing at laptop with compliance spreadsheet blurred

For teams navigating IT partner selection for public sector programs, the CRM structure and evidence ownership model should be a primary evaluation criterion when choosing a platform or subcontractor.


What does continuous monitoring require after authorization?

Authorization is not a one-time event. Maintaining a FedRAMP Moderate authorization requires a sustained, documented continuous monitoring program that the CSP delivers to both the agency AO and the FedRAMP PMO on a defined schedule.

Required ongoing activities include:

  • Monthly vulnerability scanning: Infrastructure, operating system, and web application scans with results delivered in the FedRAMP-required format. Critical and high findings carry specific remediation timelines.
  • Monthly POA&M updates: Open findings must be tracked with updated remediation status, responsible owners, and revised target dates.
  • Incident reporting: Security incidents must be reported to US-CERT and the agency AO within FedRAMP's prescribed timeframes.
  • Annual independent assessment: A 3PAO conducts a full or partial reassessment annually, producing an updated SAR and confirming that controls remain effective.
  • Significant change notifications: Any major architecture change, new external service, or change to the authorization boundary requires notification to the AO and, in many cases, a supplemental assessment.

FedRAMP's continuous monitoring expectations include monthly vulnerability scanning, annual assessments, and ongoing POA&M updates to remain in good standing. Agencies that detect deficient packages, unresolved high findings, or missed reporting cycles may re-evaluate the presumption-of-adequacy and require additional remediation before continuing to rely on the package.

OSCAL-formatted continuous monitoring deliverables reduce the manual effort of monthly reporting. Teams using a GRC automation platform that exports scan results and POA&M data in OSCAL format can cut monthly reporting preparation from days to hours. The DevOps and CI/CD pipeline integration that supports automated evidence collection is particularly valuable here, since manual evidence gathering is the primary labor cost in sustained continuous monitoring.


What is the typical timeline and cost for FedRAMP Moderate authorization?

Preparing for FedRAMP Moderate typically takes months to years depending on the provider's starting posture. A CSP starting from scratch, with no existing FedRAMP package and no pre-authorized platform, should plan for 12–24 months from initial gap assessment to ATO issuance. A CSP building on a pre-authorized platform and inheriting a substantial portion of controls can compress that timeline significantly.

Major cost drivers include:

  • Remediation work: Closing gaps identified in the initial gap assessment, including infrastructure hardening, MFA implementation, and logging configuration
  • Documentation effort: Writing SSP narratives for all customer-owned and shared controls, which is labor-intensive even with templates
  • 3PAO assessment fees: Independent assessment costs vary by system complexity and scope; larger boundaries with more services cost more
  • Continuous monitoring tooling: Vulnerability scanners, SIEM platforms, and GRC tools that produce FedRAMP-formatted outputs
  • Personnel time: Internal security, engineering, and compliance staff hours across the full authorization lifecycle
  • Platform changes: Architectural modifications required to meet FedRAMP's boundary and encryption requirements

The FedRAMP Ready designation, available through a 3PAO attestation and valid for one year, is a cost-effective intermediate milestone. It demonstrates readiness to agency partners before the full assessment investment and can accelerate agency sponsorship.

When inheritance is maximized, the timeline compresses substantially. Budget planning should also account for sustained continuous monitoring costs, which typically run annually at a fraction of the initial authorization cost but are non-negotiable for maintaining the ATO.

For teams aligning procurement timelines with authorization schedules, the proposal compliance process guide offers practical guidance on sequencing authorization milestones with contract award timelines.


How does FedRAMP High differ from FedRAMP Moderate?

FedRAMP High applies to systems where a security breach could cause severe or catastrophic harm to agency operations, national security, or public safety. Law enforcement databases, emergency response systems, and systems processing classified-adjacent data are typical High use cases. Moderate covers the majority of federal cloud workloads where a breach would cause serious but not catastrophic harm.

Key differences between Moderate and High:

  • Control count: High carries a meaningfully larger control set than Moderate, with additional base controls and more enhancements required across most families. The delta reflects the additional safeguards High-impact data demands.
  • Parameter stringency: FedRAMP assigns stricter parameter values in High for controls like AU-11 (Audit Record Retention), IR-6 (Incident Reporting), and SI-2 (Flaw Remediation). Remediation timelines for critical vulnerabilities are shorter.
  • Assessment rigor: High assessments require more extensive testing, including penetration testing with broader scope and more detailed evidence requirements for each control.
  • Use cases: An agency may require a High authorization even when a Moderate package exists if the specific data processed by that agency's use case exceeds the Moderate impact threshold.
  • Ongoing monitoring: High systems carry more frequent reporting obligations and tighter timelines for POA&M remediation.
  • Availability of authorized services: The FedRAMP Marketplace lists significantly fewer High-authorized services than Moderate-authorized ones, reflecting the higher implementation burden.

A CSP with a Moderate authorization cannot automatically serve High-impact use cases. Agencies must evaluate whether the data and operations in their specific deployment exceed the Moderate threshold, and if so, require the CSP to pursue a High authorization or accept residual risk explicitly in the ATO documentation.


Where can you find authoritative FedRAMP resources and authorized services?

The primary sources for FedRAMP Moderate implementation are:

  • Fedramp: The official program site. Download Rev. 5 SSP, SAP, SAR, and POA&M templates, access OSCAL profiles, and find policy documents. The FedRAMP Marketplace, accessible from the main site, lists all authorized CSPs and their authorization status, impact level, and package access request process.
  • NIST SP 800-53 Rev. 5: The source control catalog. Useful for understanding the full context of a control's intent when writing SSP narratives, particularly for controls where FedRAMP's parameter narrows but does not fully replace the NIST guidance.
  • FedRAMP Marketplace: Search for authorized platforms and request access to existing packages. Platform packages include the CIS, which is the starting point for CRM mapping.
  • FedRAMP Rev. 5 baselines release archive: Documents the Rev. 5 release, OSCAL profiles, and template changes. Useful for teams transitioning from Rev. 4 artifacts.
  • M-24-15 Section IV authorization process guidance: The policy basis for the Risk Management Framework alignment and presumption-of-adequacy principle.

Using official OSCAL and SSP templates from the start prevents the rework that occurs when PMO reviewers identify template version mismatches. Teams that download templates directly from FedRAMP.gov and validate the version header before writing any narrative avoid one of the most common and easily preventable delays in the review process.


What practitioners have learned from FedRAMP Moderate authorization projects

The most consistent pattern across FedRAMP Moderate authorization projects is that teams underestimate the granularity of evidence required, not the number of controls. Writing an SSP narrative that describes a control implementation is straightforward. Producing the specific, dated, artifact-referenced evidence that a 3PAO can test against is where most timelines slip.

Three pitfalls appear repeatedly:

Mis-mapped CRM entries. Controls listed as "inherited" without a valid CIS reference, or shared controls where the CSP's portion is described vaguely, generate the most assessor questions. The fix is to build the CRM before writing SSP narratives, not after. Every inherited control should have a CIS section number and the platform package name in the CRM before the SSP narrative is drafted.

Outdated Rev. 4 artifacts. Teams that begin with a Rev. 4 SSP template and attempt to update it for Rev. 5 controls frequently miss the PT family entirely and carry over PM controls that no longer belong in the system-level baseline. Starting with the official Rev. 5 OSCAL template is faster than retrofitting.

Underestimating evidence granularity. A scan result is not evidence of SI-2 compliance unless it is dated, scoped to the authorization boundary, and cross-referenced to the POA&M for any findings. A policy document is not evidence of AC-2 compliance unless it is accompanied by a configuration screenshot showing the policy is enforced in the system. Pre-validating the evidence package with the 3PAO before the formal assessment starts, using a readiness review or pre-assessment walkthrough, catches these gaps before they become SAR findings.

The concrete fixes that shorten timelines: enforce CIS-driven evidence references in the CRM from day one, automate vulnerability scans and OSCAL exports so monthly reporting does not require manual compilation, and schedule a 3PAO pre-assessment review before submitting the package to the PMO. These three practices, consistently applied, are what separate a 12-month authorization from an 18-month one.


Primereadysub delivers defined-scope FedRAMP Moderate authorization support

For government IT teams and prime contractors that need a partner to own the compliance work, not just advise on it, Primereadysub (Rutledge & Associates, LLC) delivers defined-scope FedRAMP Moderate authorization packages: CRM and CIS mapping, OSCAL-formatted SSP development, compliance automation setup, and continuous monitoring program design. As an SDVOSB, woman-owned, and SBA-certified firm with direct experience on compliance-heavy public-sector programs in Maryland, New York, and Florida, the team takes ownership of clearly scoped work packages rather than providing staff augmentation.

The practical difference: instead of adding headcount to your team and managing the work yourself, you get a deliverable, a timeline, and an accountable partner. That model works particularly well for prime contractors that need a high-value, low-oversight subcontractor to carry the authorization documentation and evidence work while the prime manages the agency relationship.

To discuss a readiness assessment or get help mapping your CRM and OSCAL artifacts, contact Primereadysub directly.


Sources

The following primary sources support the claims in this article and are the recommended starting points for downloading templates, baselines, and policy documents:

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.