Fast FedRAMP Authorization

Fast FedRAMP Authorization

Book a rapid FedRAMP demo—get authorized in six months or less.

FedRAMP Class A: What Your SOC 2 Type II Actually Gets You

FedRAMP Class A What Your SOC 2 Type II Actually Gets You
Facebook
Twitter
Pinterest
LinkedIn

For most of the history of the FedRAMP program, it has been more or less isolated. Despite sharing much of the same cybersecurity DNA with other frameworks, like CMMC and ISO 27001, no formal reciprocity ever came into being.

That meant any organization seeking FedRAMP authorization needed to go through the process from the ground up, regardless of whether or not they already had something like a CMMC certification, an ISO 27001 certification, or even GovRAMP, which was explicitly made to replicate FedRAMP at the state and local level.

Well, needless to say, a lot of things have been changing with FedRAMP recently. FedRAMP certifications are a whole new world with the release of FedRAMP 20x, and more changes are doubtless on the horizon.

One of those changes is a small crack in the door to reciprocity. To be clear, full reciprocity with any framework is not yet available. However, for certain CSPs in certain situations with certain existing framework certifications, an accelerated path to FedRAMP certification may be available.

Yes, that's a lot of hedging, so let's dig in and explain what we're talking about.

BLUF - Bottom Line Up Front

FedRAMP stayed separate from other frameworks and had no reciprocity. FedRAMP 20x adds Classes A–D. Class A fits pilots, public data, or very low risk and gives two years to move to higher classes. Cloud providers with a recent SOC 2 Type II, GovRAMP, or FedRAMP Rev5 can take a faster path to Class A. SOC 2 Type II is not equal to FedRAMP and needs a gap analysis, FedRAMP documents, and ConMon setup.

The Concept of Reciprocity

First, let's define reciprocity, equivalency, and the concept of using an external framework for faster access to FedRAMP certification.

The Concept Of Reciprocity

Basically, there are four ways that two security frameworks can relate to one another.

The first is simple: they don't. There are a lot of frameworks out there, and some of them simply have very little to do with the sorts of security that something like FedRAMP manages. Having one doesn't help you with the other in any way.

The second is conceptual overlap. This is when you have two frameworks that have similar goals, but different implementations. ISO 27001 and FedRAMP are a prime example; they both secure information to a high standard, they both encompass things like access control and data encryption, but they use different standards and methods for evaluation.

Third is rule-based overlap. This is quite common in the local information security space. Frameworks like PCI DSS, HIPAA, CMMC, and FedRAMP all share a lot of similar DNA. Domestic frameworks largely draw from NIST publications like 800-53, which means satisfying these goals and rules allows you to use the same artifacts and documentation as proof for multiple frameworks. This is where equivalency would live, if it was established.

Fourth is substantial overlap. This is where true reciprocity happens; when two frameworks share virtually all of their goals and data, achieving one would be able to grant you the other after a short review. This is where reciprocity would live.

The difference is important. Equivalency is a technical similarity that does not automatically grant the secondary framework's certification; reciprocity is a formal agreement between two programs to count each other as equal.

FedRAMP 20x Reciprocity: Is It Real?

Unfortunately, as far as FedRAMP is concerned, reciprocity is not yet real. There have been rumblings for years that reciprocity could be established, first between FedRAMP and CMMC, then between CMMC and ISO 27001, and finally using CMMC as the bridge to establish it between FedRAMP and ISO 27001.

That hasn't happened.

FedRAMP 20x Reciprocity Is It Real

In fact, FedRAMP's current documentation explicitly says that it does not support or provide equivalency or reciprocity. One of the major stumbling blocks is actually how CMMC is limited to a DoD ecosystem, so any reciprocity would be up to their stricter standards, not the FedRAMP program's determination.

That said, there's one potential avenue for something. It's not reciprocity, or even equivalency. It has to do with Class A.

FedRAMP 20x Class A: The Gateway to Certification

One of the changes in FedRAMP 20x is a shift in terminology, away from Levels and towards Classes. The change from Li-SaaS/Low/Moderate/High to Class A/B/C/D seems simple, but there's more to it than you'd think.

Certification Class vs Impact Level

First: impact levels still exist. This is something you might not even know if you've just read simple rundowns of the new 20x program and the changes made to FedRAMP as a whole.

Certification Class Vs Impact Level

That's because it's now a division between CSP and agency.

  • Agencies classify the protection needs of their information by impact level and security category.
  • CSPs classify the protection they offer using a certification class.

This is a major change from how things used to work. In the past, a CSP needed to classify their security by impact level, which allowed them to work with agencies with a matching or lower impact level. Now, it's two sides of the same coin, with a risk assessment in the middle.

Agencies classify based on impact level, which allows them to determine how much risk they can take on, and how much assurance they need from their CSPs that their information is being handled appropriately.

CSPs aim for a classification based on the assurance level they are capable of providing.

"Agencies should not treat Certification Classes as one-for-one replacements for Low, Moderate, or High impact levels. A cloud service's Certification Class can help an agency understand what evidence is available, but the agency still has to decide whether the service is appropriate for the agency's specific use, configuration, integrations, data, mission, and risk tolerance." – FedRAMP.gov

Despite this division, there's still a fairly close mapping, at least between low/moderate/high and B/C/D. This is especially notable with High and Class D, which are not yet available with FedRAMP 20x because the pilot is ongoing.

The Rundown on Class A

What we really need to focus on today, though, is Class A. While you might be tempted to think this is just the equivalent of Li-SaaS, it's really not.

The Rundown On Class A

FedRAMP describes it as:

"Adequate for use in pilots, during configuration and testing, or for extremely low or negligible risk use cases such as processing public information or getting started with very few users."

You may notice this has a few key differences from the old Li-SaaS impact level. Li-SaaS was specifically for low-impact systems that do not store personally identifiable information other than login information. Because it has basically no confidential information to protect, but is still technically part of the ecosystem, it was the lowest available baseline.

Class A adds to this by expanding it. It's not just for low-security use cases, but also for short-term pilot programs, initial roll-outs that need agency partnership to implement properly, and small-scale use cases that would otherwise be onerous to implement a Class B or C standard for.

This is slightly less new than you might think, solely because a lot of agencies and CSPs were using Li-SaaS as a pilot certification already, since no formalized pilot system existed. Under FedRAMP 20x, this is simply institutionalized, so agencies and CSPs aren't skirting the rules and instead work inside of them.

There are a few key details for Class A.

  • CSPs getting a Class A certification have two years to bump up to a B, C, or D certification. This was formerly one year, but was expanded due to the amount of work involved.
  • CSPs with existing external framework certifications may be able to use those to obtain Class A certification much more easily. The specific list of certifications and what they get you is limited but slated to expand over time.
  • No reciprocity is intended or will be granted between Class A and other frameworks.
  • External frameworks are not meant to gain this utility with Class B or higher certifications.

It's this second point that's key to our discussion today. FedRAMP has made the decision to allow certain external frameworks to serve as a starting point to onboard into the FedRAMP program.

Right now, there are only three available. One is GovRAMP, which is explicitly designed to be as close as possible to FedRAMP, so it's an easy choice to include. Another is FedRAMP Rev5, which, being FedRAMP already, is also an easy inclusion. The third is the most interesting, and it's one of the most common non-governmental security frameworks used by CSPs applying to FedRAMP; SOC 2 Type II.

Achieving FedRAMP 20x Class A with SOC 2 Type II

In case you're one of the few organizations out there that isn't already aware, let's talk a little about SOC 2.

Achieving FedRAMP 20x Class A With SOC 2 Type II

SOC is the System and Organization Controls framework, developed by AICPA, the American Institute of Certified Public Accountants. AICPA has done a lot of work over the decades to establish security and trust, with projects like WebTrust and the SOC 2 and SOC 3 reports serving as modern trust frameworks.

SOC 2 is specifically an organizational process outline that establishes security controls across five principles: Security, Availability, Process Integrity, Confidentiality, and Privacy of Customer Data.

AICPA sets out this framework, and businesses can establish security across the controls outlined in the framework. Then, AICPA performs an audit and delivers a report. A Type I audit and report is a quick snapshot meant for largely internal use, while the Type II audit is a more comprehensive, ongoing, long-term audit. A Type II report watches your operations for 6-12 months and writes a detailed report on your security.

There are other SOC types and reports, but they aren't relevant to our discussion with FedRAMP.

Make no mistake; SOC 2 Type II is not an easy audit to pass. It's also not a certification, just a report. But, when handled properly, it covers most of the bases of a low-impact FedRAMP certification. That's why FedRAMP has made the decision to establish the path between SOC 2 Type II and FedRAMP Class A.

What Do You Get with a Class A Certification Using SOC 2 Type II?

The big benefit of earning a FedRAMP Class A certification is being able to get a listing on the FedRAMP marketplace. The FedRAMP marketplace is where government agencies shop for new cloud service providers, and it serves as a public indicator of trust. Any CSP capable of passing a FedRAMP assessment to earn a certification has done some serious work into security, and the higher the class, the better.

What Do You Get With A Class A Certification Using SOC 2 Type II

Critically, Class A is still a full certification. It's not a provisional status like the former FedRAMP Ready or In Process designations. This allows agencies to actually do work, rather than wait for the full certification before starting, which was an unnecessary delay.

Class A is also an on-ramp to Class B, C, or even D. Once you have your foot in the door, you can access a lot of information, tools, and expertise to help make your path to a higher-tier certification easier and faster.

How to Use SOC 2 Type II to Earn a FedRAMP Class A Certification

The reason we discussed reciprocity and equivalency up above is to make one thing clear here: SOC 2 Type II is not reciprocal or equivalent to FedRAMP Class A. Instead, CSPs can leverage a SOC 2 Type II report as a significant part of the proof and requirements necessary to achieve FedRAMP certification.

How To Use SOC 2 Type II To Earn A FedRAMP Class A Certification

If you have a SOC 2 Type II report that has been completed within the last 12 months, you can use it as a starting point for FedRAMP Class A certification. It is not an automatic pass; instead, it's just proof that a good portion of the work is done. You still have a lot to do:

  • Perform a gap analysis between your SOC 2 Type II and the FedRAMP Class A standards.
  • Create FedRAMP-specific documentation, evidence, and proof.
  • Address FedRAMP Class A rules that are mandatory for your organization.
  • Compile a FedRAMP-valid certification package and make it available through a validated trust center.
  • Prepare for and implement the necessary monitoring and reporting for ConMon requirements.

It's still a lot of work, but it's less work than it would be otherwise.

While using SOC 2 Type II to achieve a Class A certification is a great stepping stone, it's not necessarily appropriate for everyone. CSPs that intend to go for DoD work with CMMC probably don't need to bother, if you're already most of the way to a B or C there's no reason to grab A on the way, and if you're hoping to settle at A and never improve, you're missing the point.

Class A certification is a stepping stone to higher tiers of FedRAMP certification, and SOC 2 Type II is a stepping stone to Class A. Climb the ladder, get those government contracts, and establish yourself as part of the ecosystem.

Here at Ignyte, we can help. The Ignyte Platform is already configured for both SOC 2 and FedRAMP, so it's easy to start with a completed SOC 2 Type II report, get an easy gap analysis between it and FedRAMP's rules, and get right to work. To see how it can help you achieve FedRAMP as quickly and easily as possible, just reach out for a customized demo today.

Stay up to date with everything Ignyte