FedRAMP Readiness Score
20-question self-assessment. NIST 800-53 Rev 5 + FedRAMP Moderate + High aligned.
Questions
All privileged accounts (admin/elevated) require phishing-resistant MFA (FIDO2 / certificate-based, not SMS)?
Just-in-time + just-enough access (PIM) enforced for all privileged role activations?
Conditional Access policies restrict by device compliance + location + risk?
All data encrypted at rest (FIPS 140-2 validated modules)?
All data encrypted in transit (TLS 1.2+, no insecure ciphers)?
Customer-managed keys (CMK / BYOK) for sensitive workloads?
Centralized audit log with 1-year minimum hot retention (3-year for High)?
Audit logs streamed to tamper-evident WORM storage?
Quarterly audit log integrity verification + reporting?
Documented incident response plan tested via tabletop annually?
SIEM integration with 24/7 SOC monitoring (in-house or managed)?
Breach notification workflow under 72-hour SLA?
All systems hardened to CIS Benchmark or DISA STIG baseline?
Configuration drift monitoring (Microsoft Defender for Cloud or equivalent)?
Tested disaster recovery runbook with RTO + RPO documented?
Quarterly backup restoration test (not just backup completion check)?
Identity provider supports SAML 2.0 + OIDC + scoped service principals?
Service accounts inventoried + rotated on schedule (90-180 days)?
Endpoint detection + response (EDR) deployed to all systems?
Vulnerability scanning at least monthly + remediation SLA documented?
Your Score
Recommendation
12-18 month roadmap. Full FedRAMP readiness engagement required.
Schedule Your FedRAMP Discovery
29 years Microsoft + federal experience. FRBNY + NASA + DoD pedigree.