FedRAMP and CMMC Anchors
FedRAMP
Operating bodies
- OMB โ policy.
- GSA FedRAMP PMO โ program management.
- JAB โ Joint Authorization Board (DoD, DHS, GSA).
- DHS โ continuous monitoring.
Reference documents
- FedRAMP baselines (Low, Moderate, High) โ NIST 800-53 tailored.
- FedRAMP Marketplace โ authorized services list.
- 3PAO accreditation program.
Cloud providers (illustrative)
AWS (GovCloud), Azure (Government), Google Cloud (Government), Oracle (Government), Salesforce, ServiceNow, and many others FedRAMP-authorized.
CMMC
Operating bodies
- DoD CIO โ policy.
- DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) โ DoD assessor for Level 3.
- CyberAB โ Accreditation Body administering CMMC ecosystem.
- C3PAO โ Certified Third Party Assessor Organizations for Level 2.
Reference documents
- CMMC 2.0 model.
- NIST SP 800-171 Rev. 3 โ base controls for Level 2.
- NIST SP 800-172 โ additional controls for Level 3.
- DFARS 252.204-7012 / 7019 / 7020 / 7021 โ DoD acquisition clauses.
Reference resources
- fedramp.gov
- cyberab.org โ CMMC Accreditation Body.
- NIST publications portal for 800-53, 800-171, 800-172.
Adjacent
- StateRAMP โ US state-level analog to FedRAMP.
- NIST CSF โ related framework.
- ISO 27001 โ international counterpart.