Skip to content

Certification Package & SDR Maintenance

This document establishes the organization's policy for producing and maintaining the FedRAMP Certification Package, and the procedures by which GRC-ITSM keeps it current. It covers what the package contains, where each part comes from, how often the artifacts regenerate and reach the trust center, the metadata every artifact carries, the machine-readable discipline the artifacts follow, and how independent verification and validation results enter the package.

It implements the FedRAMP rule families that govern the package from the FedRAMP Consolidated Rules for 2026: FedRAMP Certification (FRC), Certification Package Overview (CPO), Security Decision Record (SDR), and Independent Verification and Validation (IVV).

This document owns the package and its maintenance. It does not own the content of the operational reports the package draws on, and it does not own the trust center surfaces that serve the package. See "Related documents" below.

Quick Summary

The FedRAMP Certification Package has three parts: a Certification Package Overview, a Security Decision Record, and a real or example Ongoing Certification Report. All three generate from live platform data rather than being authored by hand, regenerate weekly, and land in the trust center's Certification Documents surface automatically. Each artifact carries required version and update metadata, and machine-readable output is produced as schema-valid JSON. An independent assessment runs at least annually, and its results enter the package unmodified.

Related documentation

  • Compliance -- the platform surfaces that hold the Components, Implemented Requirements, and Implementation Statements the Security Decision Record renders from

Download the KB article (Markdown)


Framework applicability

Framework What this document satisfies
FedRAMP 20x (Class C, primary) FRC-CSO-FCP, FRC-CSO-PKG, FRC-CSO-JSN, FRC-CSO-MRA; CPO-CSO-OVR, CPO-CSO-MTD, CPO-CSX-CPM; SDR-CSO-FRR, SDR-CSO-MTD, SDR-CSX-KSI, SDR-CSX-KMT; IVV-CSO-FIA, IVV-CSO-SEI, IVV-CSO-SEE, IVV-CSO-ICP, IVV-CSO-DUS, IVV-CSO-STE, IVV-CSO-USR, IVV-CSX-AIA
FedRAMP Rev5 (Class C) The same general and provider rules, with CPO-CSF-CPM in place of CPO-CSX-CPM and without the 20x-only SDR rules (SDR-CSX-KSI, SDR-CSX-KMT), plus SDR-CSF-CTF (Rev5 control summaries) and IVV-CSF-AIA, IVV-CSF-MCA, IVV-CSF-ACF, IVV-CSF-PCA

Six rules in scope vary by class, and this document carries the Class C values: package maintenance cadence on 20x (CPO-CSX-CPM, MUST at least once every 2 weeks at Class C), package maintenance cadence on Rev5 (CPO-CSF-CPM, MUST at least once every year at Class C), the independent assessment obligation (IVV-CSO-FIA, MUST at least once per year at Class C), the independent assessment scope on 20x (IVV-CSX-AIA, MUST annually at Class C), the independent assessment scope on Rev5 (IVV-CSF-AIA, MUST annually at Class C), and the historical metrics obligation in the Security Decision Record (SDR-CSX-KMT, MUST at Class C). The Organization-Defined Values table carries the Class C settings.


Policy

  • P-1. The organization identifies a target FedRAMP Certification Profile and applies every relevant FedRAMP Practice to the offering (FRC-CSO-FCP, MUST). The profile is recorded in the ODV table and drives which rules, Key Security Indicators, and Rev5 controls the package must address.
  • P-2. The FedRAMP Certification Package has three parts, and all three are maintained (FRC-CSO-PKG, MUST): a Certification Package Overview, a Security Decision Record, and a real or example Ongoing Certification Report.
  • P-3. Package artifacts are generated from live system data, not authored by hand. The Certification Package Overview generates from the system information and point-of-contact records. The Security Decision Record generates from the documentation assets, which are the Components, the Implemented Requirements, and the Implementation Statements, together with the tickets associated with those assets. No part of either artifact is transcribed from a separate document that could drift from the system it describes.
  • P-4. Generation is automatic and on a regular schedule, and placement is automatic too. The artifacts regenerate automatically on a regular schedule and land in the trust center's Certification Documents surface without a manual upload step. There is no interval in which a fresh artifact exists but has not been published.
  • P-5. Regeneration exceeds the required maintenance cadence. Artifacts regenerate weekly. That is more often than the 2-week floor for 20x Class C (CPO-CSX-CPM, MUST) and far more often than the annual floor for Rev5 Class C (CPO-CSF-CPM, MUST).
  • P-6. How a rule is followed is answered by the implementation narratives, not by a summary written for the package (SDR-CSO-FRR, MUST). Each rule reaches its explanation through the rule attributions carried on the Implemented Requirements and Implementation Statements, so the Security Decision Record shows the same narrative the system is documented and assessed against.
  • P-7. Verification and validation are answered by the validation records (SDR-CSO-FRR, MUST). The dated validation runs behind each check are the verification that an implementation is appropriate and the validation that it is in place and working as intended. The Security Decision Record summarizes those records rather than making a separate assertion.
  • P-8. Machine-readable output is schema-valid (FRC-CSO-JSN, MUST). Where a rule carries a FedRAMP JSON schema, the corresponding artifact is produced as JSON that validates against that schema.
  • P-9. Human-readable and machine-readable views are consistent because they share a source. Both renderings are generated by the same automation from the same live records, so consistency is a property of the architecture and not a reconciliation step (CDS-CSO-CBF, MUST; owned by the Certification Data Sharing procedures).
  • P-10. The organization is accountable for everything in the package, including content supplied by third parties (FRC-CSO-MRA, MUST). Assessor deliverables, advisory input, and output from external tools are the organization's responsibility for accuracy and completeness once they enter the package.
  • P-11. Every published artifact carries the metadata the rules require, and carrying it is an organizational commitment. The Security Decision Record requires version, date and time of last update, and source of update (SDR-CSO-MTD, MUST). The Certification Package Overview requires the same three plus the name, title, and contact information of the official responsible and accountable for the package (CPO-CSO-MTD, MUST). See "Artifact metadata" for the required set and the commitment.
  • P-12. An independent assessment happens at least once a year (IVV-CSO-FIA, MUST at Class C). The assessment is completed with a FedRAMP Recognized independent assessment service or with FedRAMP. On 20x it covers all Key Security Indicators (IVV-CSX-AIA, MUST). On Rev5 it covers the Class C control set the rule enumerates (IVV-CSF-AIA, MUST), all applicable controls across every 3 years (IVV-CSF-MCA, MUST), and every control that had a negative finding in the previous assessment (IVV-CSF-ACF, MUST).
  • P-13. The organization supplies evidence, and the evidence is the output of its own verification and validation (IVV-CSO-SEI and IVV-CSO-SEE, both MUST). Assessors receive the implementation evidence and the effectiveness evidence the system already produces, from the source of truth rather than from screenshots assembled for the assessment.
  • P-14. Assessment results enter the package on receipt and are not edited (IVV-CSO-ICP, MUST). Deliverables are uploaded to Certification Documents when they arrive, without inappropriate modification. The assessor independently verifies that inclusion is unmodified (IVV-IAS-VIP, MUST on the assessor).
  • P-15. Assessor summaries and the organization's responses are incorporated into the package artifacts. The per-Practice assessment summary the assessor supplies is included in the Security Decision Record, alongside any response or clarification the organization offers to the assessor's comments (SDR-CSO-FRR and IVV-IAS-SUM). The assessor's overall summary of the assessment, including failures and areas of dispute, is included in the Certification Package Overview (IVV-IAS-OSA). Assessor text is carried as written; the organization's response sits adjacent to it and never replaces it.
  • P-16. Representative sampling is documented whenever it is used (IVV-CSO-DUS, MUST). Where verification or validation relies on a representative sample rather than the full population (IVV-CSO-USR, MAY), the sample and the reasoning behind it are documented and explained.
  • P-17. Assessors get technical explanations, not just artifacts (IVV-CSO-STE, SHOULD). The organization supplies explanations, demonstrations, and supporting information about the technical capabilities behind each rule, as needed for the assessor to complete verification and validation.
  • P-18. The Ongoing Certification Report component of the package is satisfied by a real or example report. The report is assembled from the live source reports per the Continuous Monitoring and Reporting procedures. Where an application is made before the first real report has been issued, an example report satisfies FRC-CSO-PKG.
  • P-19. The procedure reviews itself persistently. The ISSO reviews this document for effectiveness on the cadence in the ODV table, together with the package's completeness against the rules in scope.

Organization-defined values

Value Setting Default (Class C) Force
Target FedRAMP Certification Profile [profile] Identified, with all relevant FedRAMP Practices applied (FRC-CSO-FCP) MUST
Package composition Certification Package Overview, Security Decision Record, and a real or example Ongoing Certification Report All three present (FRC-CSO-PKG) MUST
Certification Package Overview source The system information and point-of-contact records Generated from live system data N/A
Security Decision Record source The Components, Implemented Requirements, and Implementation Statements, and the tickets associated with them Generated from live system data N/A
Artifact regeneration cadence Weekly, automatically 20x: at least once every 2 weeks (CPO-CSX-CPM). Rev5: at least once every year (CPO-CSF-CPM) MUST
Artifact placement Automatic into the trust center's Certification Documents surface Published where necessary parties can reach it N/A
Machine-readable format JSON validated against the FedRAMP schema carried by each rule Schema-valid JSON wherever a rule carries a schema (FRC-CSO-JSN) MUST
Security Decision Record metadata Version, date and time of last update, source of update Required content of every published record (SDR-CSO-MTD) MUST
Certification Package Overview metadata Version, date and time of last update, source of update, plus the accountable official's name, title, and contact information Required content of every published overview (CPO-CSO-MTD) MUST
Accountable official for the package [name, title, contact] Named in the Certification Package Overview (CPO-CSO-MTD) MUST
Independent assessment cadence [assessment month] each year At least once per year, with a FedRAMP Recognized independent assessment service or FedRAMP (IVV-CSO-FIA) MUST at Class C
Independent assessment scope, 20x All Key Security Indicators All Key Security Indicators, annually (IVV-CSX-AIA) MUST
Independent assessment scope, Rev5 The Class C control set enumerated by the rule, plus controls with prior negative findings The enumerated annual set (IVV-CSF-AIA), all applicable controls every 3 years (IVV-CSF-MCA), prior negative findings in the next assessment (IVV-CSF-ACF) MUST
Independent assessment service [FedRAMP Recognized independent assessment service] FedRAMP Recognized, or FedRAMP itself (IVV-CSO-FIA) MUST
Assessment results handling Uploaded to Certification Documents on receipt, unmodified In the package without inappropriate modification (IVV-CSO-ICP) MUST
Assessor summary incorporation Per-Practice summaries and organizational responses in the Security Decision Record; the overall summary in the Certification Package Overview Included by the provider (IVV-IAS-SUM, IVV-IAS-OSA) MUST on the assessor to supply
Representative sampling [scope, if any] Documented and explained wherever used (IVV-CSO-DUS) MUST
Historical metrics in the Security Decision Record Per-Key-Security-Indicator metric summaries over the past 30 days, and summaries up to the past year where available Class C also requires all daily metric data up to the past year where available (SDR-CSX-KMT) MUST at Class C
Ongoing Certification Report in the package Real once the first report is issued; an example before that A real or example report following CCM-OCR-AVL (FRC-CSO-PKG) MUST
Package maintenance effectiveness review [cadence] Persistently, reviewed at least annually N/A

Roles and responsibilities

  • ISSO. Owns this procedure and the completeness of the package against the rules in scope. Reviews each regenerated artifact set on the review cadence, coordinates the annual independent assessment, receives assessor deliverables, and authors the organization's responses to assessor comments.
  • System Owner. Accountable for the offering and for the package. Gives final approval on this document and authorizes exceptions. Named, or names the accountable official, in the Certification Package Overview metadata (CPO-CSO-MTD).
  • Trust center administrators. Maintain the Certification Documents surface and its folder structure, and upload assessor deliverables and package documents that do not arrive through automatic generation.
  • Independent assessment service. Performs the annual verification and validation, supplies the per-Practice assessment summaries and the overall summary, and verifies that its results were included in the package without inappropriate modification (IVV-IAS-VIM, IVV-IAS-VEF, IVV-IAS-SUM, IVV-IAS-OSA, IVV-IAS-VIP).

Package composition

The FedRAMP Certification Package is three artifacts, and each has a distinct source.

flowchart TD
    SI["System information<br/>and point-of-contact records"] --> CPO["Certification Package Overview"]
    A["Components, Implemented Requirements,<br/>Implementation Statements"] --> SDR["Security Decision Record"]
    T["Tickets associated with<br/>those assets"] --> SDR
    V["Validation records<br/>(dated runs)"] --> SDR
    R["Live source reports"] --> OCR["Ongoing Certification Report"]
    CPO --> P["FedRAMP Certification Package"]
    SDR --> P
    OCR --> P
    P --> CD["Trust center:<br/>Certification Documents"]
Part Source Rule
Certification Package Overview The system information and point-of-contact records CPO-CSO-OVR (MUST)
Security Decision Record The Components, Implemented Requirements, and Implementation Statements, plus their associated tickets and validation records SDR-CSO-FRR (MUST)
Ongoing Certification Report The live source reports, assembled per the Continuous Monitoring and Reporting procedures FRC-CSO-PKG (MUST), CCM-OCR-AVL

The Certification Package Overview

The overview is generated in both human-readable and JSON form from the system information and point-of-contact records (CPO-CSO-OVR, MUST). It carries the information the rule enumerates by reference to other rules: the package metadata (CPO-CSO-MTD), the public information and public service list (CDS-CSO-PUB and CDS-CSO-SVC), the relevant policies reference (CDS-CSO-IRP), the assessment scope content covering information resources, information flows and security categories, and third-party information resources (MAS-CSO-IIR, MAS-CSO-FLO, MAS-CSO-TPR), the cryptographic module documentation (CMU-CSO-CMD), and the independent assessment results included in the package (IVV-CSO-ICP). It also carries the assessor's overall summary of the assessment (IVV-IAS-OSA).

The Security Decision Record

The Security Decision Record is generated in both human-readable and JSON form from the documentation assets and their tickets. For each applicable FedRAMP rule it carries the seven items SDR-CSO-FRR requires, and each item resolves to something the system already holds rather than to prose written for the record.

What the rule requires Where it comes from
Explanation of how the rule is followed, or the reason and resulting customer risk for not following it The Implementation Statement and Implemented Requirement narratives, reached through the rule attributions carried on those assets
Verification that the implementation is appropriate for the rule (or that the reason for not implementing is accepted by a senior official) The validation records: the dated runs behind each check
Validation that the implementation is in place and working as intended (or that the reason for not implementing is accepted by a senior official) The validation records
Independent verification The annual independent assessment results
Independent validation The annual independent assessment results
Responses or clarifications to the independent verification or validation comments The organization's responses, carried adjacent to the assessor's text
Rule-specific artifacts, where applicable The artifacts held against the relevant assets and tickets

On 20x, the record also carries a short, high-level summary per Key Security Indicator (SDR-CSX-KSI, MUST): the measures that demonstrate the indicator and their objectives, the cycle of any persistently implemented measure, verification that the measures demonstrate the indicator, verification that the automation in place is accurate and sufficient, and validation that the measures are accurately produced and working as intended. It carries historical metrics per indicator as well (SDR-CSX-KMT, MUST at Class C): a summary of each metric over the past 30 days, a summary up to the past year where available, and, at Class C, all daily metric data up to the past year where available.

On Rev5, the record carries a short, high-level summary per applicable control (SDR-CSF-CTF, MUST): the organization-defined parameter values, the implementation status as one of Implemented, Partially Implemented, Planned, Alternative Implementation, or Not Applicable, the mechanisms or activities that address the control including any inheritance from another offering, the verification and the validation in place, the independent verification and validation, any responses to the assessor's comments, and any control-specific artifacts.

The record does not restate the system

The Security Decision Record is a rendering of the documentation assets and the validation records, not a parallel document. Correcting a narrative or adding a validation run changes the record at the next regeneration. There is nothing to update twice.

The Ongoing Certification Report

The package requires a real or example Ongoing Certification Report following the report availability rule (FRC-CSO-PKG, MUST; CCM-OCR-AVL). The report is assembled from the live source reports in the report catalog, and that assembly is documented procedure owned by the Continuous Monitoring and Reporting Policy and Procedures. Regular automated assembly of the report is planned; until it is in place, assembly follows the documented procedure. Where an application is made before the first report has been issued, the package's report component is satisfied with an example report.


Generation and maintenance cadence

Package maintenance is a persistent obligation, not a pre-submission activity. Both certification types require the package to be kept up to date and complete on a cadence.

Obligation Required at Class C What the organization does
Maintain the package up to date and complete, 20x (CPO-CSX-CPM, MUST) At least once every 2 weeks Artifacts regenerate weekly
Maintain the package up to date and complete, Rev5 (CPO-CSF-CPM, MUST) At least once every year Artifacts regenerate weekly

Three properties make the weekly cadence hold without operator effort:

  • Generation is automatic and scheduled. Generation runs automatically on a regular schedule and reads live system data at the moment it runs.
  • Placement is automatic. Generated artifacts land in the trust center's Certification Documents surface directly. There is no manual upload step to forget, and no window in which a current artifact is unpublished.
  • Currency is a property of the source, not of the artifact. Because the artifacts render from the documentation assets, tickets, and validation records, the package is as current as the system's own records. Keeping the package current is the same work as operating the system.

Artifact metadata

Both published artifacts require basic metadata, and both requirements are MUST.

Artifact Required metadata Rule
Security Decision Record Version; date and time of last update; source of update SDR-CSO-MTD (MUST)
Certification Package Overview Version; date and time of last update; source of update; and the name, title, and contact information of the official responsible and accountable for the package CPO-CSO-MTD (MUST)

Metadata is required content, and carrying it is a commitment

The set above is the required content of every published Security Decision Record and Certification Package Overview. The organization commits to carrying that metadata in every published artifact, and to naming a real accountable official with current contact information in the overview. The accountable official is recorded in the ODV table.


Machine-readable discipline

The package is dual-format throughout, and the machine-readable half follows three rules.

  • Schema validity (FRC-CSO-JSN, MUST). Where a rule carries a FedRAMP JSON schema, the artifact for that rule is produced as JSON that validates against the schema. Schema-valid output is a generation requirement, not a post-hoc check on a hand-built file.
  • Consistency between formats (CDS-CSO-CBF, MUST). The human-readable and machine-readable renderings come from the same automation reading the same live records. No separately maintained machine-readable copy exists, so there is nothing to reconcile. This rule is owned by the Certification Data Sharing and Trust Center Policy and Procedures.
  • Responsibility for all content, including third-party content (FRC-CSO-MRA, MUST). Assessor deliverables, advisory service input, and output from external tooling become the organization's responsibility for accuracy and completeness the moment they enter the package. Third-party origin is never a reason a package statement went unchecked.

The profile obligation sits behind all of this: the organization identifies its target FedRAMP Certification Profile and applies every relevant FedRAMP Practice to the offering (FRC-CSO-FCP, MUST). The profile determines which rules, Key Security Indicators, and Rev5 controls the Security Decision Record must address, and therefore what completeness means for this system.


Independent verification and validation

An independent assessment is an annual obligation at Class C, and its results are part of the package.

flowchart TD
    A["Organization verifies and validates<br/>its own measures"] --> B["Evidence supplied to the assessor<br/>(IVV-CSO-SEI, IVV-CSO-SEE)"]
    B --> C["Assessor verifies implementation<br/>and validates effectiveness"]
    C --> D["Assessor supplies per-Practice summaries<br/>and an overall summary"]
    D --> E["Deliverables uploaded to<br/>Certification Documents on receipt,<br/>unmodified (IVV-CSO-ICP)"]
    D --> F["Per-Practice summaries and organizational<br/>responses into the Security Decision Record"]
    D --> G["Overall summary into the<br/>Certification Package Overview"]
    E --> H["Assessor verifies inclusion<br/>is unmodified (IVV-IAS-VIP)"]

Scope and cadence

Obligation Required at Class C Force
Complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service or FedRAMP (IVV-CSO-FIA) At least once per year MUST
Include all Key Security Indicators in the assessment, 20x (IVV-CSX-AIA) Annually MUST
Include the enumerated Class C Rev5 control set in the assessment (IVV-CSF-AIA) Annually MUST
Include all applicable Rev5 controls across assessments (IVV-CSF-MCA) Every 3 years, not necessarily in one assessment MUST
Include Rev5 controls that had negative findings in the previous assessment (IVV-CSF-ACF) In the next assessment MUST
Include all applicable Rev5 Controls in each independent assessment (IVV-CSF-PCA) Each assessment SHOULD

Evidence the organization supplies

The evidence an assessor receives is the output of the organization's own verification and validation, which the system already produces continuously.

  • Implementation evidence (IVV-CSO-SEI, MUST) is the result of verification: proof that the documented measure is actually in place, shown from the source of truth rather than from a screenshot.
  • Effectiveness evidence (IVV-CSO-SEE, MUST) is the result of validation: proof that the implemented measure has its intended outcome.
  • Technical explanations (IVV-CSO-STE, SHOULD) accompany the evidence: explanations, demonstrations, and supporting information about the technical capabilities behind each rule, supplied as needed for the assessor to complete the work.
  • Representative samples (IVV-CSO-USR, MAY) are used only where appropriate, and their use is documented and explained whenever it happens (IVV-CSO-DUS, MUST).

Continuous validation is what makes assessment evidence cheap

The validation records that answer the Security Decision Record's verification and validation items are the same records an assessor reviews. Because they accumulate as the system operates, there is no separate evidence-collection exercise ahead of the assessment. The Continuous Monitoring and Reporting procedures own how those records are produced.

Handling assessment results

Upload on receipt, unmodified. Assessment deliverables are uploaded to the trust center's Certification Documents surface when they arrive, without inappropriate modification (IVV-CSO-ICP, MUST). The assessor independently verifies that the information it supplied appears in the package unmodified (IVV-IAS-VIP, MUST on the assessor).

Incorporation into the artifacts. The assessor supplies a high-level summary of its process and findings for each FedRAMP Practice, which belongs in the Security Decision Record, and an overall summary of the assessment including failures and areas of dispute, which belongs in the Certification Package Overview (IVV-IAS-SUM and IVV-IAS-OSA, both MUST on the assessor). The organization commits to incorporating both, together with its own responses and clarifications to the assessor's comments, as required by the fourth, fifth, and sixth items of SDR-CSO-FRR for the per-Practice content, and by IVV-IAS-OSA for the overall summary in the Certification Package Overview. Assessor text is carried as the assessor wrote it; the organization's response sits adjacent to it and never replaces or edits it.

There is no separate assessment plan or report

FedRAMP does not require a Security Assessment Plan or a Security Assessment Report for 20x or Rev5 certifications. The information those documents used to carry belongs in the Security Decision Record and the Certification Package Overview.


Records, retention, and metrics

Per artifact, the record retains the published artifact in Certification Documents, the version and update metadata the artifact is required to carry, and the system it belongs to. Per independent assessment, the record retains the assessor's deliverables as received, the per-Practice and overall summaries, the organization's responses, the sampling documentation where sampling was used, and the dates of receipt and of publication. Historical certification data is retained for the duration of the certification, in Certification Documents, per the Certification Data Sharing procedures (CDS-CSO-HAD, MUST).

Metrics reviewed with these procedures: elapsed time since the last successful regeneration of each artifact against the maintenance cadence, generation failures and their resolution time, schema validation failures on machine-readable output, rules and controls with no narrative or no validation record behind them, time from receipt of assessor deliverables to publication, and the count of open assessor findings and disputes carried in the record.


Authority, review, and revision

Issued under the authority of the System Owner and binding on all personnel who maintain the FedRAMP Certification Package. Exceptions require written System Owner approval and are documented.

The ISSO reviews this document for effectiveness persistently on the cadence in the ODV table, and when frameworks, the system, or lessons learned warrant; the System Owner gives final approval. The annual plan and policy review task under the Annual cadence parent is where that review is tracked.


This article owns the package and its maintenance. Adjacent content is owned elsewhere.

Document What it owns
Continuous Monitoring and Reporting Policy and Procedures The Ongoing Certification Report and its source reports, the Quarterly Review, the validation records and their cadences, and the metrics that feed the Security Decision Record
Certification Data Sharing and Trust Center Policy and Procedures The trust center and its surfaces, including the Certification Documents surface the package artifacts are published to, the access model, historical snapshots, and consistency between formats
Change Management Policy and Procedures Significant change notification and the change history that accompanies certification data
Asset and Inventory Management Procedures The assessment scope content the Certification Package Overview draws on

FedRAMP coverage

FedRAMP Certification general provider responsibilities: FedRAMP Certification Profile (MUST), FedRAMP Certification Package (MUST), FedRAMP JSON Schemas (MUST), Maintain Responsibility and Accountability (MUST) (FRC-CSO). Certification Package Overview: Overview of the Cloud Service Offering (MUST), Certification Package Overview Metadata (MUST), Certification Package Maintenance for 20x (MUST at Class C, varies by class), Certification Package Maintenance for Rev5 (MUST at Class C, varies by class) (CPO). Security Decision Record: FedRAMP Rules (MUST), Security Decision Record Metadata (MUST), Key Security Indicators (MUST), Key Security Indicator Metrics (MUST at Class C, varies by class), Rev5 Controls (MUST) (SDR). Independent Verification and Validation, provider rules: FedRAMP Independent Assessments (MUST at Class C, varies by class), Supply Evidence of Implementation (MUST), Supply Evidence of Effectiveness (MUST), Inclusion in Certification Package (MUST), Document Use of Representative Samples (MUST), Supply Technical Explanations (SHOULD), Use Representative Samples (MAY), Annual Independent Assessments for 20x (MUST, varies by class), Annual Independent Assessments for Rev5 (MUST, varies by class), Mandatory Control Assessment (MUST), Assessment of Rev5 Controls with Findings (MUST), Preferred Control Assessment (SHOULD) (IVV-CSO, IVV-CSX, IVV-CSF). Assessor rules referenced because their output enters the package: Assessment Summary (MUST), Overall Summary of Assessment (MUST), Verify Inclusion in Certification Package (MUST), Verify Implementation (MUST), Validate Effectiveness (MUST) (IVV-IAS).