FeaturesCompliance Reports

FedRAMP Moderate Evidence Report

NIST SP 800-53 Rev 5 configuration change control evidence for FedRAMP Moderate — CM-3, CM-4, CA-7, and SA-11.

Overview

The Federal Risk and Authorization Management Program (FedRAMP) is the US federal government's standardized approach to security assessment and authorization for cloud products and services. FedRAMP Moderate is the baseline for most SaaS offerings serving federal agencies.

Koalr's FedRAMP report generates evidence for four NIST SP 800-53 Rev 5 controls directly addressable by engineering change management data. The report is designed for delivery to a Third-Party Assessment Organization (3PAO) during your FedRAMP authorization process.

Controls covered

CM-3 — Configuration Change Control

Control language: The organization determines the types of changes to the system that are configuration-controlled, reviews proposed changes, and approves or disapproves such changes with explicit consideration for security impact analyses.

Koalr evidence: Peer review and approval recorded for every merged pull request. The report surfaces approval coverage and lists changes merged without required approval as control exceptions.

CM-4 — Security Impact Analysis

Control language: The organization analyzes changes to the system to determine potential security impacts prior to change implementation.

Koalr evidence: Automated deploy risk scoring runs on every PR before merge. DDL migrations, blast radius, and CODEOWNERS signals are recorded as security impact indicators.

CA-7 — Continuous Monitoring

Control language: The organization develops a continuous monitoring strategy and implements a continuous monitoring program.

Koalr evidence: Koalr continuously ingests PR, review, and deployment data from your connected repositories. Every merge generates a live evidence record — no manual data collection required.

SA-11 — Developer Security Testing and Evaluation

Control language: The organization requires the developer of the system to create and implement a security assessment plan, perform code review, and perform threat and vulnerability analyses.

Koalr evidence: Automated review quality scoring, rubber-stamp detection, and risk signal analysis before merge. The report surfaces rubber-stamp approvals and reviews completed without substantive feedback as SA-11 exceptions.

Report output

  • Dark navy cover page with NIST SP 800-53 control badges (CM-3, CM-4, CA-7, SA-11) and metadata block prepared for FedRAMP Third-Party Assessment Organization (3PAO)
  • Executive summary with six KPI tiles
  • Per-control detail blocks with status badge and evidence count
  • Change log table with approval, CODEOWNERS, and risk columns
  • Page number footer with CONFIDENTIAL marking
  • Machine-readable CSV export

Generating a report

  1. Navigate to ComplianceFedRAMP Moderate
  2. Select your reporting period (typically aligned with your continuous monitoring cadence — monthly or quarterly)
  3. Click Download evidence package (PDF) or Export CSV

Continuous monitoring workflow

FedRAMP requires continuous monitoring (CA-7) with monthly reporting to your agency Authorizing Official (AO). Koalr fits naturally into this cadence:

  1. Monthly: Run the FedRAMP report for the past 30 days and attach to your Plan of Action and Milestones (POAM)
  2. Quarterly: Pair with vulnerability scan results for a comprehensive CA-7 package
  3. Annually: Run a full year-to-date report for your annual assessment

3PAO review notes

  • The PDF cover page names "FedRAMP Third-Party Assessment Organization (3PAO)" in the Prepared For field
  • Evidence is scoped to the GitHub repositories connected to your Koalr organization — ensure FedRAMP-boundary repositories are connected
  • For the complete NIST SP 800-53 control set (400+ controls at Moderate baseline), pair Koalr's change management evidence with your broader System Security Plan (SSP) and POAM documentation

Integration requirements

  • GitHub (required) — provides all change management data
  • Recommended: Separate Koalr organization for FedRAMP boundary vs commercial to maintain boundary isolation

Disclaimer

This report is designed to support FedRAMP evidence collection for the covered NIST SP 800-53 controls. It does not constitute a formal FedRAMP authorization. Engage a FedRAMP-accredited 3PAO for your FedRAMP assessment.