FedRAMP CMMC anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

FedRAMP and CMMC Anchors

FedRAMP

Operating bodies

  • OMB โ€” policy.
  • GSA FedRAMP PMO โ€” program management.
  • JAB โ€” Joint Authorization Board (DoD, DHS, GSA).
  • DHS โ€” continuous monitoring.

Reference documents

  • FedRAMP baselines (Low, Moderate, High) โ€” NIST 800-53 tailored.
  • FedRAMP Marketplace โ€” authorized services list.
  • 3PAO accreditation program.

Cloud providers (illustrative)

AWS (GovCloud), Azure (Government), Google Cloud (Government), Oracle (Government), Salesforce, ServiceNow, and many others FedRAMP-authorized.

CMMC

Operating bodies

  • DoD CIO โ€” policy.
  • DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) โ€” DoD assessor for Level 3.
  • CyberAB โ€” Accreditation Body administering CMMC ecosystem.
  • C3PAO โ€” Certified Third Party Assessor Organizations for Level 2.

Reference documents

  • CMMC 2.0 model.
  • NIST SP 800-171 Rev. 3 โ€” base controls for Level 2.
  • NIST SP 800-172 โ€” additional controls for Level 3.
  • DFARS 252.204-7012 / 7019 / 7020 / 7021 โ€” DoD acquisition clauses.

Reference resources

  • fedramp.gov
  • cyberab.org โ€” CMMC Accreditation Body.
  • NIST publications portal for 800-53, 800-171, 800-172.

Adjacent

  • StateRAMP โ€” US state-level analog to FedRAMP.
  • NIST CSF โ€” related framework.
  • ISO 27001 โ€” international counterpart.

See also