Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

FedRAMP (NIST SP 800-53 Rev 5)

US federal cloud audit & accountability.

Applies to: Cloud providers serving US federal agencies.

What the signed record shows

Audit-record generation, protection, account attribution, and incident detail.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: 44 U.S.C. 3607-3616; NIST SP 800-53 R5 AU/AC/CM/IR

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the programme requires, section by section

FedRAMP, authorized under the FedRAMP Authorization Act (44 U.S.C. 3607-3616), enacted 23 December 2022 as part of Public Law 117-263 (NDAA FY2023), implemented by OMB Memorandum M-24-15. FedRAMP Rev 5 baselines are built on NIST SP 800-53 Revision 5. Control families this mapper evidences from the per-event signed record:

AU (Audit and Accountability)
AU-2 event logging, AU-3 content of audit records, AU-6 audit review/analysis, AU-9 protection of audit information, AU-11 audit record retention, AU-12 audit record generation.
AC (Access Control)
AC-2 account management records.
CM (Configuration Management)
CM-3 configuration change control records.
IR (Incident Response)
IR-4 incident handling, IR-6 incident reporting.

Taken from the Regulayer entry for this instrument, which is built against the primary text.