Skip to content

Trust Center

The Trust Center is the self-service portal through which agency and customer users reach their system's certification data. It carries five surfaces:

Trust Center home page showing the five surface cards: Request Services, My Requests & Tickets, Policies & Procedures, ConMon Reports, and Certification Documents

Surface What it serves
Request Services Submit requests, ask questions, and open tickets for changes, incidents, outages, and user access
My Requests & Tickets Every request you have submitted, with its current status
Policies & Procedures The published library of policies, procedures, and operational standards governing the environment
ConMon Reports Live views of current system state
Certification Documents Point-in-time authorization deliverables: security plans, assessments, and supporting evidence

Getting access

For how accounts are granted, the full tour of the surfaces, and programmatic access over the REST API, see the Trust Center Access Guide.


ConMon Reports

Ten reports, each in a FedRAMP shape, reading live system state. Because they read live records, the numbers change as the system changes -- for a fixed snapshot you can cite, use Certification Documents.

Continuous Monitoring Reports list showing the ten report names and their FedRAMP-shape descriptions

Report What it contains
Public Information The publicly shareable profile of each FedRAMP-listed system (CDS-CSO-PUB)
System Information System Security Plan header information, covering the FedRAMP front-matter fields
System POCs Points of Contact -- one row per POC and role, covering System Owner, Incident POC, and ISSO
Inventory Active cloud and hardware assets in FedRAMP Integrated Inventory Workbook (IIW) format
Open POA&M Items Open POA&M items in FedRAMP POA&M Template format, one row per CVE or vulnerability
Closed POA&M Items Closed POA&M items in the same format
Vulnerability Details Non-accepted vulnerabilities in the FedRAMP Vulnerability Detail Report (VER-RPT-VDT) shape
Accepted Vulnerabilities Accepted vulnerabilities in the FedRAMP Accepted Vulnerability Info (VER-RPT-AVI) shape
Reportable Incidents Alert and Incident tickets evaluated as externally reportable, in the FedRAMP Incident Report (IEC-CSO-IIR/OIR/FIR) shape
Significant Changes Change Request tickets in the FedRAMP Significant Change Notification (SCN-CSO-INF) shape

Reports are scoped to your own system: you see your system's records and nothing else, and sensitive fields are excluded from shared reports.


Policies & Procedures

The published library of policy, procedure, and operational-standard articles the system's controls are measured against. Search or browse by topic; each article carries its topic tags.

Policies & Procedures surface listing the published procedure articles with their topic tags


Certification Documents

Point-in-time artifacts for the certification package, organized by system with folder selection. This includes the FedRAMP-schema JSON files (Security Decision Record, Certification Overview, Vulnerability Detail) plus uploaded package documents, with historical snapshots saved as each Ongoing Certification Report is issued.