GovRAMP Core Controls

This document outlines the 60 prioritized security controls required for GovRAMP Core Status. These controls are selected from the NIST SP 800-53, Rev. 5 framework and aligned with the Moderate Impact Baseline. Service providers pursuing Core should use this resource to understand the control expectations and begin preparing evidence for PMO-led review.

3PAO Package for Moderate Impact with CJIS Overlay

This package includes required templates and sample policies for every NIST 800-53 control family, along with templates for Rules of Behavior, Incident Response Plan, Configuration Management Plan, Information System Contingency Plan, and Supply Chain Risk Management.