Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

MITAuto-check passedLegal & Compliance

Install Fedramp

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill fedramp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance fedramp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/fedramp/skills/fedramp .claude/skills/fedramp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fedramp
GitHub stars
946
Used in
1 other repo
Token cost
~4.4k tokens
SKILL.md length
2,058 words
Files
7 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

  • Works in 5 steps: Readiness & Gap Assessment → ATO Documentation → NIST 800-53 Control Mapping → …
  • A user asks about FedRAMP authorization
  • SKILL.md covers Quick Reference: What Does the…, Current FedRAMP State (as of…, 1. Readiness & Gap Assessment and 2. ATO Documentation, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Fedramp is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document types: SSP, SAP, SAR, POA&M, CIS/CRM workbooks. Also trigger for questions about FedRAMP Certification Classes (A, B, C, D — new baseline labels: A = pilot/transitional, B = LI-SaaS/Low, C = Moderate, D…

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/appendices-guide.md`, `references/control-families.md` and `references/poam-guide.md`).

It sits in Legal & Compliance, covering Software architecture, Cloud security and Authorization and RBAC. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • A user asks about FedRAMP authorization
  • ATO (Authority to Operate)
  • Cloud security for federal government
  • NIST SP 800-53 controls

Example prompts

  • “/fedramp”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Readiness & Gap Assessment
  2. ATO Documentation
  3. NIST 800-53 Control Mapping
  4. Architecture Guidance
  5. Continuous Monitoring

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • fedramp.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fedramp loads about 4.4k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 237 tokens; SKILL.md has 2,058 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~237
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 2,058 words, ~4,390 tokens.

Download SKILL.mdSave it as .claude/skills/fedramp/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
fedramp
description
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document types: SSP, SAP, SAR, POA&M, CIS/CRM workbooks. Also trigger for questions about FedRAMP Certification Classes (A, B, C, D — new baseline labels: A = pilot/transitional, B = LI-SaaS/Low, C = Moderate, D = High, per NTC-0004), FedRAMP 20x (now the primary authorization pathway), OSCAL mandate (September 2026), 3PAO assessments, continuous monitoring (ConMon), gap assessments, system boundary definition, or architecture reviews for federal cloud. FedRAMP Ready retired July 28, 2026 (Legacy FedRAMP Ready). When in doubt, use this skill — it covers the full FedRAMP lifecycle from readiness through continuous monitoring.

FedRAMP Certification Skill

Last verified: 2026-10-03

A comprehensive guide for helping users navigate FedRAMP authorization — from initial readiness through ATO and ongoing continuous monitoring.

Quick Reference: What Does the User Need?

Identify the user's goal and jump to the appropriate section:

User GoalGo To
"Are we ready for FedRAMP?" / gap assessment→ Readiness & Gap Assessment
Writing SSP, POA&M, SAR, SAP, or other docs→ ATO Documentation
"Which controls apply to us?" / control mapping→ NIST 800-53 Control Mapping
Cloud architecture / AWS/Azure/GCP config→ Architecture Guidance
Already authorized, ongoing compliance→ Continuous Monitoring

Current FedRAMP State (as of August 2026 — CR26)

⚠️ CR26 (FedRAMP Consolidated Rules for 2026): FedRAMP has restructured its authorization framework. FIPS 199-based baseline labels (Low/Moderate/High/LI-SaaS) are replaced with Certification Classes A–D (per notice NTC-0004; CR26 rules valid through December 31, 2028). Class labels change the names of the baselines, not their requirements. CSPs already authorized under the old labels retain their authorization through a transition period in which old and new labels are linked.

  • Baseline: NIST SP 800-53 Rev 5 (fully in effect)
  • Control counts (Rev 5): Low ≈ 156, Moderate = 323, High = 421 (legacy references; CR26 class-based counts being published by PMO)
  • CR26 Certification Classes (official mapping, NTC-0004): A = new pilot/transitional baseline (entry via external frameworks such as SOC 2 Type II through Program Certification; holders have a 2-year window to obtain B/C/D), B = current LI-SaaS + Low baselines, C = current Moderate baseline (majority of federal deployments, incl. CUI), D = current High baseline.
  • FedRAMP 20x: Now the primary authorization pathway — continuous authorization built on Key Security Indicators (KSIs), machine-readable evidence, modular API-driven submissions, and automated validation. Traditional SSP/SAP/SAR templates remain for legacy paths.
  • CR26 status: finalized June 25, 2026; optional early adoption since July 4, 2026; mandatory January 1, 2027.
  • Legacy FedRAMP Ready: the Ready designation was retired/relabeled Legacy FedRAMP Ready on July 28, 2026 — no new submissions. Rev5 Ready holders must convert by the later of their annual-assessment expiration or November 17, 2026; the status disappears entirely December 31, 2027.
  • Certification Class pipelines: Class A open since August 3, 2026; Classes B/C open August 31, 2026; Class D pilot expected late 2026 with a formal option in early 2027.
  • Rev5 wind-down: new Rev5 applications are not accepted after June 11, 2027; Rev5 sunsets December 31, 2028.
  • JAB P-ATO: Fully suspended; FedRAMP PMO is the sole authorization body.
  • Machine-readable mandate (RFC-0024/NOTICE-0009, operationalized in CR26) — applies to the Rev5 process only, explicitly NOT to FedRAMP 20x: since 2PM ET September 30, 2026 (now in force), NEW Rev5 initial-certification packages must be machine-readable with no grace period (including packages already In Process for agency authorization) [LMR-GEN-ICR]; existing Rev5-certified providers must submit a full machine-readable package at each annual assessment completed after that date [LMR-GEN-OAR]. Approved formats: NIST OSCAL, or any public-domain standardized format that 5+ certified CSPs agree to maintain (FedRAMP-validated); CR26 JSON schemas and a validator are published. Human-readable versions must still be produced on request. Non-compliance: public notification until 2PM ET September 30, 2027, then certification revocation.
  • Security Inbox: All authorized CSPs must maintain a dedicated Security Inbox (no CAPTCHAs or barriers) for urgent vulnerability directives — effective January 5, 2026.
  • Key templates updated: SSP, SAR, SAP, POA&M, CIS/CRM, IIW, ISCP — all updated to align with Rev 5 (Dec 2024 releases).

1. Readiness & Gap Assessment

Approach
  1. Clarify scope — Ask the user: What is the CSO (Cloud Service Offering)? IaaS/PaaS/SaaS? Target Certification Class under CR26?
  2. Identify authorization path — FedRAMP 20x (primary, preferred) vs. legacy Agency Authorization package (still available for complex systems during CR26 transition)
  3. Run through the readiness checklist — See references/readiness-checklist.md
  4. Surface gaps — Map current state to required controls; flag missing documentation, unimplemented controls, and architectural deficiencies
  5. Prioritize — Group gaps by: (a) blockers for readiness review, (b) items addressable before 3PAO assessment, (c) POA&M candidates

FedRAMP Ready retired July 28, 2026 (now "Legacy FedRAMP Ready"). Advise CSPs by pipeline instead: Class A (open since August 3, 2026) for external-framework entry, Classes B/C from August 31, 2026 for full certification; legacy Rev5 Ready holders must convert by the later of annual-assessment expiration or November 17, 2026.

Key Readiness Questions to Ask the User
  • Are you targeting FedRAMP 20x (preferred) or a legacy authorization package?
  • What cloud platform (AWS GovCloud, Azure Government, GCP, on-prem hybrid)?
  • Are you leveraging any existing FedRAMP-authorized IaaS/PaaS (e.g., AWS GovCloud FedRAMP High)?
  • Do you have FIPS 140-2/3 validated encryption in place?
  • Is your authorization boundary defined and documented?
  • Do you have a vulnerability scanning program (OS, DB, web app, container)?
  • Are security policies and procedures documented?
  • Do you have an Incident Response Plan (IRP) and Contingency Plan (CP) that have been tested?
  • Are your Rev5 authorization package artifacts machine-readable (OSCAL or an approved format)? Mandatory for new Rev5 packages from Sept 30, 2026; for existing providers at the next annual assessment after that date. (20x has its own machine-readable model.)
Output Format
  • Produce a gap table: Control Family | Current State | Gap | Priority | Owner
  • Summarize top 5–10 high-priority gaps as prose
  • Note the target Certification Class and whether FedRAMP 20x is feasible

2. ATO Documentation

The core FedRAMP authorization package consists of:

Authorization Package
├── System Security Plan (SSP) + Appendices A–Q
├── Security Assessment Plan (SAP) + Appendices A–D  [3PAO-prepared]
├── Security Assessment Report (SAR) + Appendices A–F  [3PAO-prepared]
└── Plan of Action & Milestones (POA&M)  [SSP Appendix O]

Important: Word/Excel templates are being retired for Rev5 — new Rev5 packages must be machine-readable (OSCAL or approved format) from September 30, 2026; existing providers convert at their next annual assessment. Human-readable renditions on request. Templates: https://www.fedramp.gov/documents-templates/

Document Guidance

For detailed guidance on each document type, read the appropriate reference file:

  • SSP → references/ssp-guide.md
  • POA&M → references/poam-guide.md
  • SAP / SAR → references/sap-sar-guide.md
  • Supporting appendices → references/appendices-guide.md
General Writing Principles for All ATO Docs
  1. Describe only what is implemented — Do not document planned or aspirational controls; these trigger findings and must go in POA&M instead
  2. Be specific — Reference exact tools, filenames, section numbers, policy names; vague language causes findings
  3. Mind the verbs — Each control requirement uses specific verbs (track, document, enforce, test). Address each verb explicitly
  4. Shared responsibility — For any customer-configurable or shared control, create a clear "Customer Responsibility" section
  5. Keep it consistent — Architecture diagrams, data flows, inventory, and control statements must all be internally consistent

3. NIST 800-53 Control Mapping

Control Families (Rev 5)
IDFamilyNotes
ACAccess ControlIAM, RBAC, least privilege, remote access
ATAwareness & TrainingSecurity + privacy training (new in Rev 5)
AUAudit & AccountabilityLog retention, SIEM, audit review
CAAssessment, Authorization & MonitoringConMon, 3PAO, ATO
CMConfiguration ManagementBaselines, change control, CMDB
CPContingency PlanningBCP/DR, tested annually
IAIdentification & AuthenticationMFA, PIV, FIPS 140-2/3 crypto
IRIncident ResponseIRP, tested annually, reporting SLAs
MAMaintenanceRemote maintenance controls
MPMedia ProtectionData at rest, media sanitization
PEPhysical & EnvironmentalDatacenters; often inherited from IaaS
PLPlanningSSP, rules of behavior
PMProgram ManagementEnterprise-level security program
PSPersonnel SecurityScreening, termination procedures
PTPII Processing & TransparencyNew family in Rev 5 — privacy controls
RARisk AssessmentVulnerability scanning, MITRE ATT&CK scoring
SASystem & Services AcquisitionSDLC, supply chain
SCSystem & Communications ProtectionEncryption in transit, network segmentation
SISystem & Information IntegrityPatching, malware, integrity monitoring
SRSupply Chain Risk ManagementNew family in Rev 5 — SCRM
Show full SKILL.md (891 more words)Show less
CR26 Certification Class Mapping

Under CR26, the FedRAMP PMO is aligning control baselines to Certification Classes. When users describe their system, map to a class:

  • Class A (Pilot/Transitional): New baseline introduced under 20x — entry into the federal market via external frameworks (initially SOC 2 Type II) through Program Certification; Class A holders have a 2-year window to obtain a Class B, C, or D certification through full assessment
  • Class B (replaces LI-SaaS + Low): Systems handling non-sensitive federal information where a breach would cause limited harm
  • Class C (replaces Moderate): Most common — the majority of federal cloud deployments, including systems handling CUI
  • Class D (replaces High): Federal information where compromise has severe or catastrophic effect (e.g., law enforcement, financial, health data)

Legacy references: Many existing FedRAMP documents still reference Low/Moderate/High/LI-SaaS. These map to LI-SaaS/Low → Class B, Moderate → Class C, High → Class D (Class A is new — it has no legacy equivalent). During the CR26 transition, old and new labels are linked. Advise CSPs to check fedramp.gov for the latest.

Mapping Workflow
  1. Ask: What types of federal data will the system process/store/transmit?
  2. Determine target Certification Class (A, B, C, or D) under CR26
  3. Select NIST 800-53 Rev 5 baseline using the class mapping (B ↔ Low, C ↔ Moderate, D ↔ High)
  4. Cross-reference with FedRAMP parameter requirements (FedRAMP often sets stricter parameters than base NIST)
  5. For inherited controls, identify which are fully/partially inherited from leveraged FedRAMP IaaS/PaaS and document in CIS/CRM workbook
Rev 4 → Rev 5 Key Changes to Highlight
  • New control families: PT (Privacy), SR (Supply Chain)
  • Password controls revised: No more forced rotation schedules; requires compromised-password lists and password strength meters (NIST 800-63b alignment)
  • Privacy integrated: AT-3 now mandates privacy training; many families have privacy-specific enhancements
  • Threat-based methodology: MITRE ATT&CK framework informs control prioritization

4. Architecture Guidance

Authorization Boundary

The boundary defines what is IN scope for FedRAMP. This is one of the most common sources of findings and delays.

Key principles:

  • Everything that processes, stores, or transmits federal data must be inside the boundary
  • External services connected to in-scope systems must be FedRAMP-authorized OR documented with compensating controls
  • Boundary must be depicted in a clear network/data flow diagram (required in SSP)
Cloud Platform Considerations

AWS GovCloud (US)

  • AWS GovCloud is FedRAMP High authorized — most PE and some SC controls are fully inherited
  • Use AWS Config, CloudTrail, GuardDuty, Security Hub to satisfy AU, RA, SI controls
  • Ensure use of GovCloud region endpoints (not standard commercial) to stay in boundary
  • FIPS endpoints available for IA controls

Azure Government

  • Azure Government is FedRAMP High authorized
  • Azure Policy + Defender for Cloud maps well to CM, RA, SI
  • Use Azure Blueprints / Policy Initiatives aligned to FedRAMP Moderate/High

Google Cloud (FedRAMP-authorized regions)

  • Assured Workloads for FedRAMP compliance
  • Chronicle SIEM for AU controls
Architecture Patterns That Support FedRAMP
  • Zero Trust — aligns directly with AC, IA, SC control families
  • Immutable infrastructure — simplifies CM (configuration drift is a common finding)
  • Centralized logging — SIEM/log aggregation addresses AU family comprehensively
  • Automated vulnerability scanning — Required; must cover OS, DB, web app, and containers (if used)
  • Machine-readable tooling (OSCAL-native or approved format) — new Rev5 packages require it from Sept 30, 2026; existing Rev5 providers at the next annual assessment
Common Architecture Findings
  • Undocumented external connections leaving the boundary
  • FIPS-non-compliant encryption algorithms in transit or at rest
  • Overly broad IAM roles / lack of least privilege
  • Missing MFA on privileged accounts
  • Vulnerability scans not covering all boundary components
  • Logging gaps (not all components sending logs to centralized SIEM)
  • Rev5 packages not yet machine-readable ahead of the Sept 30, 2026 intake cutoff (or the provider's first post-cutoff annual assessment)

5. Continuous Monitoring

Once authorized, CSPs must maintain compliance through ConMon activities:

Monthly Requirements
  • Vulnerability scan results submitted to agency AOs
  • POA&M updates (open findings, remediation progress)
  • Inventory updates (new/removed assets)
  • ConMon Monthly Executive Summary (template updated Nov 2024)
Annual Requirements
  • Full security assessment by 3PAO using Annual Assessment Controls Selection Worksheet
  • Updated SSP and appendices
  • Tested IRP and CP
  • SAR and updated POA&M
POA&M Management
  • All open findings must have: risk level, owner, milestone dates, remediation plan
  • Vendor Dependencies (VDs): when a finding depends on a third-party fix — document and track
  • Deviation Requests (DRs): false positives and risk adjustments require AO approval
  • SLA for remediation (FedRAMP ConMon Performance Management Guide): High = 30 days, Moderate = 90 days, Low = 180 days from identification. Where Critical is distinguished from High (e.g., scanner ratings), treat it as High-or-stricter (≤30 days, prioritized immediately)

Output Formatting Guide

Match output format to request type:

Request TypePreferred Format
Gap assessmentTable + prose summary
SSP control narrativeProse paragraphs (one per control/enhancement)
POA&M entryStructured table row with all required fields
Architecture reviewBullet findings + recommended remediations
Control mapping questionTable: Control ID | Requirement | How to Implement
Readiness overviewExecutive summary prose + priority action list

When generating document content, always note: "Use official FedRAMP templates from fedramp.gov — this content should be inserted into the appropriate template section."


Reference Files

Load these when more depth is needed:

  • references/readiness-checklist.md — Full readiness checklist (75+ items)
  • references/ssp-guide.md — SSP section-by-section writing guide
  • references/poam-guide.md — POA&M structure, field definitions, SLA table
  • references/sap-sar-guide.md — SAP/SAR overview and review tips for CSPs
  • references/appendices-guide.md — Guide to all SSP appendices (A–Q)
  • references/control-families.md — Deep-dive on each of the 20 control families

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in plugins/fedramp/skills/fedramp of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/appendices-guide.md
  • references/control-families.md
  • references/poam-guide.md
  • references/readiness-checklist.md
  • references/sap-sar-guide.md
  • references/ssp-guide.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Fedramp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fedramp compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fedramp this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4.4kAutomated safety check: PassMIT
Google Cloud PAM Helpergoogle/skills21k—~3.2kAutomated safety check: PassApache-2.0
Iamitsmostafa/aws-agent-skills1.2k—~1.8kAutomated safety check: PassMIT
Container Securityhardw00t/ai-security-arsenal105—~2.8kAutomated safety check: PassNone
Security Architecture Reviewcbrock84/headcount2k—~1.1kAutomated safety check: PassMIT
AWS Essentialsericrisco/rsc-harness180—~2.9kAutomated safety check: NotesMIT

Similar skills

  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    SecurityAuto-check passed
  • Iam

    itsmostafa/aws-agent-skills

    AWS Identity and Access Management for users, roles, policies, and permissions.

    1.2k GitHub stars~1.8k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Reviews a design or change for security before it ships — authentication and authorization, data handling, secrets, dependencies, and the secure-development practices around it.

    2k GitHub stars~1.1k tokensUpdated 22 days ago
    SecurityAuto-check passed
  • AWS Essentials

    ericrisco/rsc-harness

    A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or…

    180 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment.

    135 GitHub stars~898 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    946 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed

Questions about Fedramp

What does Fedramp do?

Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Fedramp is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

When should I use Fedramp?

Fedramp fits situations like: A user asks about FedRAMP authorization; ATO (Authority to Operate); cloud security for federal government; NIST SP 800-53 controls.

How do I install Fedramp in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill fedramp -a claude-code`. Or copy the skill folder (plugins/fedramp/skills/fedramp in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/fedramp in your project. Claude Code loads it when a task matches its description.

How do I install Fedramp in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill fedramp -a codex`. Or copy the skill folder (plugins/fedramp/skills/fedramp in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/fedramp in your project. Codex loads it when a task matches its description.

Can I use Fedramp in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill fedramp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fedramp, .gemini/skills/fedramp, .github/skills/fedramp and .opencode/skills/fedramp in your project.

What does Fedramp need to run?

SKILL.md names no scripts, command-line tools or credentials: Fedramp is instructions for the agent only.

Does Fedramp access the network?

SKILL.md names 1 domain. As links in the text: fedramp.gov. This is read from the text; nothing was executed.

Is Fedramp safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fedramp use?

Fedramp is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fedramp use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Fedramp?

Skills that share tags, products or a category with Fedramp: Google Cloud PAM Helper (google/skills, 21k stars), Iam (itsmostafa/aws-agent-skills, 1.2k stars), Container Security (hardw00t/ai-security-arsenal, 105 stars) and Security Architecture Review (cbrock84/headcount, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fedramp?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.