FedRAMP Control Checklist

FedRAMP Moderate Control Checklist

This checklist is organized by implementation phase and maps each action to the corresponding NIST 800-53 Moderate baseline control.


Phase 1: Foundation & Assessment (Days 1-7)

Multi-Account & Governance (Day 1)

Audit & Logging (Day 2)

Configuration Management (Day 3)

Compliance Monitoring (Day 4)

Threat Detection (Day 5)

Identity & Access (Day 6)

Baseline Assessment (Day 7)


Phase 2: Network & Access Hardening (Days 8-14)

VPC Architecture (Days 8-9)

Application Protection (Day 10)

AWS Service Access (Day 11)

Encryption at Rest (Day 12)

Secrets Management (Day 13)

Network Inspection (Day 14)


Phase 3: Application Security (Days 15-21)

Container Image Security (Days 15-16)

Software Supply Chain (Day 17)

Code Security (Day 18)

API Security (Day 19)

User Authentication (Day 20)

Penetration Testing (Day 21)


Phase 4: Documentation & ATO (Days 22-30)

System Documentation (Day 22)

Control Implementation Mapping (Days 23-24)

POA&M Tracking (Day 25)

Incident Response (Day 26)

Business Continuity (Day 27)

Evidence Automation (Day 28)

Readiness Review (Day 29)

3PAO Engagement (Day 30)


NIST 800-53 Moderate Baseline Summary

Total Controls: 325 (across 20 control families)

Family Short Name Count Checklist Coverage
AC Access Control 22
AT Awareness and Training 4
AU Audit and Accountability 13
CA Assessment, Authorization, Continuous Monitoring 9
CM Configuration Management 10
CP Contingency Planning 13
IA Identification and Authentication 8
IR Incident Response 10
MA Maintenance 7
MP Media Protection 8
PE Physical and Environmental Protection 15
PL Planning 11
PS Personnel Security 8
RA Risk Assessment 5
SA System and Services Acquisition 16
SC System and Communications Protection 40
SI System and Information Integrity 14

Document Version: 1.0
Last Updated: 2026-05-06
Maintained by: BE EASY ENTERPRISES Federal Compliance Team