Primary sources (FedRAMP)
FedRAMP 20x Overview — Accessed 2026-04-27. Program scope, automation-first model, KSI framing, Phase One / Phase Two structure.
FedRAMP 20x Documentation index — Accessed 2026-04-27. Standards published under 20x including Minimum Assessment Scope and Key Security Indicators.
Key Security Indicators — 20x docs — Accessed 2026-04-27. KSI taxonomy and machine-readable definitions.
FedRAMP 20x Phase One — Accessed 2026-04-27. Phase One scope, Low-baseline KSI count (~56), pilot authorization references.
RFC-0005 Minimum Assessment Scope Standard — Accessed 2026-04-27. Standard replacing prior boundary policy. Comment period 2025-04-24 to 2025-05-25, closed.
RFC-0005 Community Discussion (closed) — Accessed 2026-04-27. Verbatim standard language, commenter exchange. Direct quote of inclusion test: > “The Minimum Assessment Scope includes all information > resources managed by a cloud service provider and their cloud > service offering that: 1. Handle federal information; and/or > 2. Likely impact confidentiality, integrity, or availability > of federal information.”
Direct quote of exclusion language: > “Information resources and metadata that do not meet condition > (1) or (2) are outside the Minimum Assessment Scope.”
RFC-0006 20x Phase One Key Security Indicators — Accessed 2026-04-27. Phase One KSI catalog.
RFC-0014 Phase Two Key Security Indicators — Accessed 2026-04-27. Phase Two KSI additions for Moderate.
RFC-0024 Rev5 Machine-Readable Packages — Accessed 2026-04-27. OSCAL-aligned machine-readable package format that 20x KSI evidence rides on.
FedRAMP — Realizing the FedRAMP Authorization Act (Jan 2026) — Accessed 2026-04-27. Statutory grounding for the 20x direction.