// US Standards
FedRAMP Compliance Software
US government cloud security authorisation framework.
Framework at a glance
Short name
FedRAMP
Version
—
Category
US Standards
Controls
40
What FedRAMP covers
40 controls across 35 domains — every one tracked, owned and evidenced in Cyber Horizon.
Policy
1 controls- AC-1 Access Control Policy
Identity & Access
3 controls- AC-2 FedRAMP Account Management
- AC-6 Least Privilege
- IA-2(1) MFA — Privileged Accounts
Access Control
1 controls- AC-3 Access Enforcement
Remote Access
1 controls- AC-17 Remote Access
Logging
3 controls- AU-2 Event Logging
- AU-3 Audit Record Content
- AU-6 Audit Review and Reporting
Log Integrity
1 controls- AU-9 Protection of Audit Information
Assessment
1 controls- CA-2 Security Assessments
Network Security
1 controls- CA-3 System Interconnections
Monitoring
2 controls- CA-7 Continuous Monitoring
- PE-6 Monitoring Physical Access
Baseline
1 controls- CM-2 Baseline Configuration
Hardening
1 controls- CM-6 Configuration Settings
System Hardening
1 controls- CM-7 Least Functionality
Business Continuity
1 controls- CP-4 Contingency Plan Testing
Backup
1 controls- CP-9 System Backup
Recovery
1 controls- CP-10 System Recovery
Authentication
1 controls- IA-2 Identification & Authentication
Credentials
1 controls- IA-5 Authenticator Management
IR
1 controls- IR-4 Incident Handling
Tracking
1 controls- IR-5 Incident Monitoring
Operations
1 controls- IR-6 Incident Reporting
Remote Maintenance
1 controls- MA-4 Non-local Maintenance
Media
1 controls- MP-5 Media Transport
Physical Access
1 controls- PE-2 Physical Access Authorisations
Physical Security
1 controls- PE-3 Physical Access Control
Documentation
1 controls- PL-2 System Security Plan
People
1 controls- PL-4 Rules of Behaviour
HR
1 controls- PS-3 Personnel Screening
Risk Management
1 controls- RA-3 Risk Assessment
Vulnerability Management
1 controls- RA-5 Vulnerability Scanning
Supply Chain
1 controls- SA-9 External System Services
Network
1 controls- SC-7 Boundary Protection
Encryption
1 controls- SC-8 Transmission Confidentiality
Cryptography
1 controls- SC-12 Cryptographic Key Management
Data Management
1 controls- SC-28 Protection of Information at Rest
Integrity
1 controls- SI-7 Software and Firmware Integrity
How Cyber Horizon automates FedRAMP
Every FedRAMP control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is FedRAMP?
US government cloud security authorisation framework.
How many controls does FedRAMP have?
FedRAMP has 40 controls in Cyber Horizon's catalogue, organised across 35 domains.
How does Cyber Horizon help with FedRAMP?
Cyber Horizon maps FedRAMP into a shared control library alongside every other framework you run, so evidence collected once counts towards FedRAMP and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More US Standards frameworks
See FedRAMP mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of FedRAMP in Cyber Horizon.