Description
The FedRAMP Toolkit is written for the Consolidated Rules for 2026
FedRAMP’s Consolidated Rules for 2026 took effect on 4 July 2026. They retired the System Security Plan in favour of a Certification Package Overview and a Security Decision Record, eliminated the Plan of Action and Milestones in favour of an Accepted Weaknesses List, turned Continuous Monitoring into Ongoing Certification, made the 20x path generally available, and require the core artifacts in JSON against FedRAMP’s published schemas as well as in a document a person can read.
New Rev5 applications must follow the rules from 1 January 2027; every grace period ends on 1 February 2028. A template pack built on the old package model answers questions FedRAMP has stopped asking.
The FedRAMP Toolkit was rebuilt in September 2026 for those rules. It is 52 editable templates, 47 Word documents and 5 Excel workbooks, in 11 folders, with 8 JSON companion files generated from FedRAMP’s schemas of 24 June 2026, and it serves both the Rev5 and the 20x certification paths, which now share the same rulesets and the same NIST SP 800-53 Rev 5 control baseline.
What the FedRAMP Toolkit maps to
The 15 documents written for the 2026 rules in the FedRAMP Toolkit carry the FedRAMP rule identifiers they answer: 25 rule identifiers across 14 rulesets (AFC, CCM, CDS, CMU, CPO, FRC, IEC, IVV, MAS, SCG, SCN, SDR, VDR, VER). Each document states them in its control table and in a Rules basis panel that says what the rule requires.
- The Certification Package Overview and the Security Decision Record, the two artifacts that replaced the base SSP, with their field structure generated from the FedRAMP schemas so the Word headings and the JSON keys cannot drift apart.
- The Organizational Requirements Register, for the parameters FedRAMP no longer prescribes and now expects the provider to set and justify.
- The Accepted Weaknesses List, Ongoing Certification Plan, Ongoing Certification Report and Significant Change Notification, replacing the POA&M, the ConMon strategy and report, and the Significant Change Request.
- The Incident Report, Vulnerability Detail Report and Historical VER Activity Record, for enhanced vulnerability detection and response.
- The Independent Assessment Service Record, Key Security Indicators Register, Minimum Assessment Scope Record and Secure Configuration Guide.
The JSON half of the FedRAMP Toolkit
FedRAMP requires the Certification Package Overview and the Security Decision Record in human-readable form and in JSON, with OSCAL optional. Eight documents in the FedRAMP Toolkit ship with a JSON companion: a typed template generated from the published schema of the same name, every property present, enumerated fields seeded with a legal value, and dates and URIs given the right placeholder shape. Each was validated structurally against its schema (version 0.1.4, dated 24 June 2026). Fill the Word document, copy each value to the key of the same name, validate, publish.
The Rev 5 baseline half
The rules changed the package, not the control baseline. The FedRAMP Toolkit carries a full worked example of the NIST SP 800-53 Rev 5 Moderate baseline material for a fictional provider, Acme Cloud Services and its AcmeCloud Government Platform, updated for the 2026 terminology and pointed at the new artifacts rather than at an SSP.
The FedRAMP Toolkit’s baseline half holds 18 control-family policies from Access Control to Supply Chain Risk Management; FIPS 199 categorization, the Privacy Threshold Analysis and Privacy Impact Assessment, the Digital Identity Worksheet, Rules of Behavior and User Guide; the Information System Contingency Plan, Incident Response Plan and Configuration Management Plan; the Security Assessment Plan and Report, the Readiness Assessment Report, and the Annual Assessment Plan and Report.
Five workbooks complete the FedRAMP Toolkit: the CIS Workbook, the Customer Responsibility Matrix, the Integrated Inventory Workbook, the Risk Exposure Table and the Separation of Duties Matrix. Every name, date and figure in the example is invented and marked for replacement.
Written against fedramp.gov, and dated
Every rule identifier, artifact name, schema field and deadline in the FedRAMP Toolkit was read on fedramp.gov on 6 September 2026: the Consolidated Rules for 2026, the 11 published JSON schemas, and the deadlines page. The How to Use guide reproduces the deadline table and tells you to check the page before you commit to a date. Where the rules leave a choice to the provider, the pack says so rather than inventing a FedRAMP figure.
Where the FedRAMP Toolkit sits beside the rest of the catalogue
The NIST SP 800-53 Toolkit carries the control catalogue itself for organisations outside FedRAMP; the CMMC Toolkit serves defence contractors under NIST SP 800-171; the NIST CSF 2.0 Toolkit is the outcome-based framework many agencies ask for alongside. The FedRAMP Toolkit is the certification package layer for cloud service providers selling to the U.S. federal government.
Honest about the boundaries
- The FedRAMP Toolkit is written for Certification Classes A and B. Classes C and D require months of historical vulnerability metrics that no template can supply; the Historical VER Activity Record gives you the structure to record them.
- No document pack gets an offering certified, the FedRAMP Toolkit included. Certification rests on the decisions you make, the evidence you hold and the assessment your 3PAO performs.
- A Rev5 package submitted before 4 July 2026 and still in process under the earlier rules is reviewed against the artifacts it was submitted with; use this pack to prepare the transition every offering must complete by 1 February 2028.
- FedRAMP updates its schemas in place with a new version number; the FedRAMP Toolkit records the version it was built on. Record the version you validated against and re-check before each submission.
What you get in the FedRAMP Toolkit
Every file in the FedRAMP Toolkit, by folder. Word documents marked (+ JSON) ship with their schema companion.
| Folder | Files | What it holds |
|---|---|---|
| 00 Programme | 3 | Document index, How to Use guide, Toolkit FAQ |
| 01 Certification Package | 4 | Certification Package Overview and Security Decision Record, each with its JSON companion |
| 02 Organizational Requirements | 1 | The register of provider-set parameters |
| 03 Ongoing Certification | 7 | Accepted Weaknesses List, Ongoing Certification Plan and Report, Significant Change Notification, with JSON companions |
| 04 Vulnerability and Incident | 6 | Incident Report, Vulnerability Detail Report, Historical VER Activity Record, with JSON companions |
| 05 Scope and Assurance | 4 | Independent Assessment Service Record, Key Security Indicators Register, Minimum Assessment Scope Record, Secure Configuration Guide |
| 06 Categorization and Privacy | 6 | FIPS 199, PTA, PIA, Digital Identity Worksheet, Rules of Behavior, User Guide |
| 07 Operational Plans | 3 | Contingency, incident response and configuration management plans |
| 08 Assessment | 5 | Security Assessment Plan and Report, Readiness Assessment Report, Annual Assessment Plan and Report |
| 09 Workbooks | 5 | CIS Workbook, Customer Responsibility Matrix, Integrated Inventory Workbook, Risk Exposure Table, Separation of Duties Matrix |
| 10 Control Family Policies | 18 | Eighteen NIST SP 800-53 Rev 5 control-family policies, AC to SR |
00 Programme
- How to Use This Toolkit (PDF)
- Toolkit FAQ (PDF)
- Document Index
01 Certification Package
- Certification Package Overview (+ JSON)
- Security Decision Record (+ JSON)
02 Organizational Requirements
- Organizational Requirements Register
03 Ongoing Certification
- Accepted Weaknesses List (+ JSON)
- Ongoing Certification Plan
- Ongoing Certification Report (+ JSON)
- Significant Change Notification (+ JSON)
04 Vulnerability and Incident
- Incident Report (+ JSON)
- Vulnerability Detail Report (+ JSON)
- Historical VER Activity Record (+ JSON)
05 Scope and Assurance
- Independent Assessment Service Record
- Key Security Indicators Register
- Minimum Assessment Scope Record
- Secure Configuration Guide
06 Categorization and Privacy
- Digital Identity Worksheet
- FIPS 199 Categorization
- Privacy Impact Assessment
- Privacy Threshold Analysis
- Rules of Behavior
- User Guide
07 Operational Plans
- Configuration Management Plan
- Incident Response Plan
- Information System Contingency Plan
08 Assessment
- Annual Assessment Plan
- Annual Assessment Report
- Readiness Assessment Report
- Security Assessment Plan
- Security Assessment Report
09 Workbooks
- CIS Workbook (Excel)
- Customer Responsibility Matrix (Excel)
- Integrated Inventory Workbook (Excel)
- Risk Exposure Table (Excel)
- Separation of Duties Matrix (Excel)
10 Control Family Policies
- Access Control Policy (AC)
- Awareness and Training Policy (AT)
- Audit and Accountability Policy (AU)
- Assessment Authorization and Monitoring Policy (CA)
- Configuration Management Policy (CM)
- Contingency Planning Policy (CP)
- Identification and Authentication Policy (IA)
- Incident Response Policy (IR)
- Maintenance Policy (MA)
- Media Protection Policy (MP)
- Physical and Environmental Protection Policy (PE)
- Planning Policy (PL)
- Personnel Security Policy (PS)
- Risk Assessment Policy (RA)
- System and Services Acquisition Policy (SA)
- System and Communications Protection Policy (SC)
- System and Information Integrity Policy (SI)
- Supply Chain Risk Management Policy (SR)
ISO 27001 Toolkit - 165 Comprehensive Templates 




































This toolkit makes the authorization process much easier to navigate with clear and practical templates. It is a valuable resource for keeping compliance documentation organized and consistent.