FedRAMP process

| RMF | FedRAMP | ARTIFACTS | RESPONSIBILITY |
| N/A | Initiate | SA&A Package | Agency(Review Package) |
| N/A | Apply | Request Form | Agency or Cloud Service Provider(CSP) |
| Categorization | Implement | FIPS199, RAR, PTA, PIA, SORNand E-Authentication | Third Party Assessor Organization(3PAO) |
| Control Selection | Implement | Security Control baseline | Third Party Assessor Organization(3PAO) |
| Implementation | Document | SSP, CMP, CP, and CP test | Cloud Service Provider(CSP) |
| Assessment | Assess | SAP, ST&E, and SAR | Third Party Assessor Organization(3PAO) |
| Authorization | Authorize | POAM and ATO | Joint Authorization Board(JAB) or Agency |
| Continuous Monitoring | Monitor | POAM, SSP, and SAR | JAB(review package), Agency(review package) and CSP (Provide package) |
| N/A | Report | N/A | Agency |