Secure system

Once Again, the Proof Is in the Evidence and FedRAMP Is the Blind Spot

Our 2026 State of the DIB research found something worth sitting with. Self-reported SPRS scores hit their highest point ever. Confidence in those scores hit its lowest. Eighty-three percent of contractors have a documented SSP. Only 65% are very or extremely confident the number they submitted is right.

That is not a documentation problem. Contractors are writing the plans. They are buying the tools. They are spending the money.

The problem is that a growing share of the boundary now sits in somebody else’s cloud, which means a growing share of the evidence is somebody else’s to produce, and most contractors never went and got it.

Key takeaway: FedRAMP claims without evidence can collapse your SPRS score

If you are inheriting controls from a cloud provider based on a FedRAMP marketing claim you cannot substantiate, your SPRS score may be an estimate, not a defensible assertion.

A caveat before I go further

Part of what follows comes from an unofficial hallway conversation with DIBCAC at an industry event. It was open talk in the room, not a published finding. No methodology, no sample size, no report to link. Take it with a grain of salt and weigh it accordingly.

I’m including it anyway because it lines up with what we see in the field, and because the mechanism it describes holds up on its own whether or not the anecdote does. What assessors are describing is a scoring problem driven by cloud services, contractors leaning on providers who claim FedRAMP status they cannot substantiate.

That is not a data point. It’s a hypothesis. But it’s a testable one, and the test costs you an afternoon.

The common failure mode: “We moved CUI to SaaS, so we inherited compliance”

It looks like this:

A contractor moves CUI into a SaaS platform. The vendor’s website says FedRAMP. Maybe it says FedRAMP Ready. Maybe it says FedRAMP Moderate equivalent. The contractor writes the inheritance into the SSP, claims the controls, scores themselves accordingly, and moves on.

Nobody ever asked the vendor to prove it.

Then an assessor shows up and asks one question: show me the body of evidence. There isn’t one. The inheritance collapses, and it doesn’t collapse one control at a time. Every control that was riding on that provider goes unsupported at once, plus 3.1.20 on top. A score that looked fine on paper falls off a cliff.

What FedRAMP Moderate “equivalency” actually requires

DOD CIO settled this in the December 2023 memo, and the bar is higher than most people assume.

FedRAMP Moderate equivalency requires a third-party assessment organization to assess the offering against the full FedRAMP Moderate baseline and produce a real body of evidence. SSP, security assessment report, continuous monitoring. Not a subset. Not a self-attestation. Not a roadmap.

A vendor’s marketing page is not a body of evidence. A sales engineer’s assurance is not a body of evidence. “We’re pursuing authorization” is a plan, not a control.

FedRAMP Ready vs Authorized

FedRAMP Ready is a designation that means a 3PAO thinks the provider is likely to achieve authorization. It is not authorization. If you inherited controls off the word “Ready,” you inherited nothing.

Three questions to validate any cloud service in your CUI boundary (quick test)

For every cloud service in your CUI boundary:

  1. Is it listed on the FedRAMP Marketplace as Authorized? If yes, capture the package ID and CRM.
  2. If the claim is equivalency, do you hold the 3PAO assessment artifacts? Not a summary letter. The evidence.
  3. Does the vendor’s customer responsibility matrix actually match what your SSP says you’re inheriting?

If you can’t answer all three for every service, your score is an estimate, not an assertion. And under an affirming official, an estimate signed as an assertion is a different category of problem entirely.

Bottom line: controls you cannot evidence are controls you do not have

None of this is new. It’s the same principle that has governed this program since the beginning. A policy existing does not mean it is followed, and a control claimed does not mean it is implemented.

Do not assume effectiveness based on existence. Go get the evidence. Or stop claiming the control.