Resources

Long-form guides on the compliance work, from how the authorization boundary is drawn to how the evidence behind it maps to controls across frameworks. More guides are added over time.

Compliance guides

Drawing boundaries and mapping controls to the evidence behind a FedRAMP authorization or a NIST 800-171 posture.

  • OSCAL evidence pipelines for FedRAMP

    How a machine-readable SSP, backed by continuous evidence collection, turns a FedRAMP package from a static document into a live view of your system.

    OSCAL, FedRAMP

  • Scoping a CMMC Level 2 assessment

    A working note on drawing the CUI boundary before a CMMC Level 2 assessment, so the scope is defensible and the 110 NIST 800-171 controls apply where they should.

    CMMC

  • One control, three frameworks: a crosswalk that holds

    NIST 800-53, NIST 800-171, and CMMC ask many of the same questions. A single control implementation and one evidence artifact can answer all three, if the mapping is built with care.

    NIST 800-53, NIST 800-171, CMMC

Resources · TRGR