Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

What replaced the FedRAMP SSP in 2026

FedRAMP SSP: A Clear Guide to the 2 Documents That Replaced It

The FedRAMP SSP — the several-hundred-page System Security Plan a cloud provider wrote once and maintained badly — no longer exists in the form most people are still searching for. Under the Consolidated Rules for 2026 it has been replaced by two artifacts: a Certification Package Overview and a Security Decision Record.

If you arrived here looking for a FedRAMP SSP template, this guide is the answer to the question behind that search: what a provider actually has to produce in 2026, what happened to the old plan, and which kinds of SSP are unaffected by the change.

FedRAMP SSP replaced by the Certification Package Overview and Security Decision Record
One narrative document became two maintained records, both required in human-readable and JSON form.

What replaced the FedRAMP SSP

The Certification Package Overview

FedRAMP states plainly that the Certification Package Overview replaces the historically required base System Security Plan for FedRAMP Rev5. Its job is a clear, concise and consistent summary of the offering and of what the package contains, so a customer can understand the service at a high level without reading the whole package.

It carries the metadata (provider contact information, version number, date and source of the last update), the public information about what is shared and listed, the scope — information resources, data flows, security categories and third-party resources — cryptographic module information, and, for Class C certifications, the overall assessment summary supplied by the independent assessor. It is supplied in both human-readable and JSON forms against a published schema, and for Rev5 Class C it is updated at least annually and ideally after significant changes.

The Security Decision Record

The Security Decision Record is the part that replaced the substance of the old plan. FedRAMP describes it as a persistently maintained, verified and validated record of the security decisions the provider made across the lifecycle of the offering. For each applicable FedRAMP rule it holds:

  • an explanation of how the rule is followed, or the reason for not following it and the resulting risk to customers;
  • verification that the implementation is appropriate;
  • validation that it works as intended;
  • the independent assessor’s verification and validation;
  • the provider’s responses to verification and validation comments; and
  • any rule-specific artifacts.

Plus the same basic metadata — version, last update, and the source of the update — and, like the overview, it is supplied in both human-readable and JSON formats. For Rev5 certifications this is where control implementation status and mechanisms are recorded, with the independent assessment results attached to them.

Why the FedRAMP SSP was retired

The old plan had a structural problem: it was a narrative written to be read once, at authorization, while the thing it described changed weekly. Everything downstream inherited that — plans of action and milestones that tracked a snapshot, continuous monitoring that reported against a document nobody re-read, and assessment findings recorded in a separate place from the control they concerned.

The 2026 model treats the record as the live artifact. A decision, its justification, its verification, its independent validation and its evidence all sit together, versioned, in a format a machine can read. That is why the retirement of the SSP came in the same set of changes as the retirement of the POA&M, broader continuous monitoring, availability reporting, and the requirement to publish a Secure Configuration Guide for customers.

Old model Consolidated Rules for 2026
Base System Security Plan, narrative Certification Package Overview plus Security Decision Record
Document produced for authorization Record maintained across the lifecycle
Human-readable only, in practice Human-readable and JSON, against a schema
Findings and POA&Ms tracked separately Verification, validation and responses held against each rule

The 20x path: declarative statements instead of narrative

On the FedRAMP 20x path the shift goes further. Rather than describing controls in prose, providers demonstrate Key Security Indicators — statements that summarize the security capabilities a high-quality cloud service should prove and measure. The rules are written as simple declarative statements intended to be addressed one by one, and the package materials are structured so the evidence can be validated rather than read.

For a provider deciding which path to take, the document burden is a real input: 20x asks for engineering capability to produce and keep producing machine-readable evidence, while Rev5 asks for a maintained decision record against the SP 800-53 control set. New Rev5 applications close on 11 June 2027, which limits how long that choice remains open.

Which System Security Plans still exist

Three things called an SSP are frequently conflated, and only one of them was retired:

  • The provider’s base FedRAMP SSP — replaced, as described above.
  • The agency’s System Security Plan — still required. An agency authorizing a cloud service documents its own configuration, its own implemented controls and its testing in its own plan, and is explicitly told not to copy the provider’s package into it.
  • The NIST SP 800-171 system security plan — untouched by any of this. Defense contractors handling controlled unclassified information still produce and maintain one, and it is assessed under a separate program.

So the honest answer to “where do I download a FedRAMP SSP template” is that a provider should not be starting from one, an agency needs its own plan rather than a FedRAMP one, and a contractor searching for an SSP template almost always wants the 800-171 version.

What to do if you hold an old FedRAMP SSP

  1. Split it. The descriptive front matter — scope, data flows, categorization, third-party resources, crypto modules — becomes the Certification Package Overview. The control-by-control content becomes Security Decision Record entries.
  2. Restate implementations as decisions. Each entry answers how the rule is followed, or why it is not and what risk that leaves the customer. That second half is new, and it is where an honest record earns trust.
  3. Attach the evidence to the entry. Verification, validation, the assessor’s comments and your responses belong with the rule, not in a separate findings tracker.
  4. Produce the JSON. Both artifacts are required in human-readable and JSON form against FedRAMP’s schemas, so the record needs to live somewhere that can emit both, not in a word processor.
  5. Write the Secure Configuration Guide. It is now a separate deliverable and it is what agencies use to confirm your service supports their intended implementation.

Frequently asked questions

Is the FedRAMP SSP really gone?
The provider’s base System Security Plan for Rev5 is. FedRAMP’s own guidance says the Certification Package Overview replaces it, and the Security Decision Record replaced the traditional plan’s control content.

What formats are required?
Both the Certification Package Overview and the Security Decision Record must be supplied in human-readable and JSON formats, referencing FedRAMP’s published schemas.

Does this apply to 20x as well as Rev5?
The Security Decision Record applies across the certification model; the Certification Package Overview is the Rev5 replacement for the base SSP. On 20x, Key Security Indicators and declarative rule statements carry the load that narrative used to.

Do agencies still write an SSP?
Yes. The agency documents its own configuration and implemented controls in its own plan and references what it inherits.

How often must the package be updated?
The record is maintained continuously. For Rev5 Class C certifications the package is updated at least annually, and FedRAMP encourages updates after significant changes rather than waiting.

Where this leaves you

The retirement of the FedRAMP SSP is not a naming change. It moves the program from a document produced for an event to a record maintained for a lifecycle, in a format that can be validated rather than read. If you are a provider, stop maintaining a narrative and start maintaining decisions, each with its justification, its evidence and its independent validation attached. If you are an agency, the plan you need is still your own — and the provider’s package is evidence you reference, not text you inherit.

References

More on federal cloud authorization

Documentation templates for a federal authorization package are in the FedRAMP Authorization Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.