Skip to main content

FedRAMP Readiness Score

By Errin O'Connor, Founder & Chief AI Architect, EPC Group

FedRAMP Readiness Score

20-question self-assessment. NIST 800-53 Rev 5 + FedRAMP Moderate + High aligned.

Questions

1.Access Control

All privileged accounts (admin/elevated) require phishing-resistant MFA (FIDO2 / certificate-based, not SMS)?

2.Access Control

Just-in-time + just-enough access (PIM) enforced for all privileged role activations?

3.Access Control

Conditional Access policies restrict by device compliance + location + risk?

4.Encryption

All data encrypted at rest (FIPS 140-2 validated modules)?

5.Encryption

All data encrypted in transit (TLS 1.2+, no insecure ciphers)?

6.Encryption

Customer-managed keys (CMK / BYOK) for sensitive workloads?

7.Audit + Accountability

Centralized audit log with 1-year minimum hot retention (3-year for High)?

8.Audit + Accountability

Audit logs streamed to tamper-evident WORM storage?

9.Audit + Accountability

Quarterly audit log integrity verification + reporting?

10.Incident Response

Documented incident response plan tested via tabletop annually?

11.Incident Response

SIEM integration with 24/7 SOC monitoring (in-house or managed)?

12.Incident Response

Breach notification workflow under 72-hour SLA?

13.Configuration Management

All systems hardened to CIS Benchmark or DISA STIG baseline?

14.Configuration Management

Configuration drift monitoring (Microsoft Defender for Cloud or equivalent)?

15.Contingency Planning

Tested disaster recovery runbook with RTO + RPO documented?

16.Contingency Planning

Quarterly backup restoration test (not just backup completion check)?

17.Identification + Authentication

Identity provider supports SAML 2.0 + OIDC + scoped service principals?

18.Identification + Authentication

Service accounts inventoried + rotated on schedule (90-180 days)?

19.System + Information Integrity

Endpoint detection + response (EDR) deployed to all systems?

20.System + Information Integrity

Vulnerability scanning at least monthly + remediation SLA documented?

Your Score

0
out of 100
Significant Gaps
Answered0/20
Yes0
No0

Recommendation

12-18 month roadmap. Full FedRAMP readiness engagement required.

Discuss with FedRAMP team

Schedule Your FedRAMP Discovery

Microsoft + federal experience since 1997. FRBNY + NASA + DoD pedigree.

Related EPC Group Services

AI assistant — not human