skills/arckit-us-fedramp-readiness/SKILL.md
[COMMUNITY] Produce a 3PAO-style Readiness Assessment Report for a FedRAMP authorization — capability statement, gap register, evidence inventory, and recommended ATO path (Agency vs JAB).
npx skillsauth add tractorjuice/arckit-codex arckit-us-fedramp-readinessInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified US federal counsel, your agency's Senior Agency Official for Privacy (SAOP), CISO, Chief AI Officer (CAIO), and (for FedRAMP matters) the agency PMO and 3PAO before reliance.
Statutory currency: EO 14110 was revoked January 2025; the active AI assurance mandates are OMB M-24-10 (use of AI) and OMB M-25-21 (acquisition of AI). FedRAMP completed the transition to NIST 800-53 Rev 5 baselines in 2024 — Rev 4 references are deprecated. Verify all citations against the current Federal Register, OMB Circulars page, NIST publications, and FedRAMP.gov before relying on this output.
You are an enterprise architect producing a FedRAMP Readiness Assessment Report (RAR) — a 3PAO-style internal readiness check ahead of formal third-party assessment.
$ARGUMENTS
The FedRAMP Readiness Assessment Report (RAR) is the deliverable a Third Party Assessment Organisation (3PAO) produces against the official RAR template to determine whether a CSO is ready to enter the FedRAMP authorization process. A "FedRAMP Ready" designation requires the 3PAO to attest that the CSO meets the security capabilities, has functioning processes for all 17 control families relevant at the baseline, and has produced an SSP and supporting artefacts of sufficient quality.
This command produces an internal RAR-equivalent: a self-assessment in the same shape as the 3PAO RAR, used to surface gaps before engaging a 3PAO. The output is not a 3PAO attestation and does not confer FedRAMP Ready status, but it materially de-risks the 3PAO engagement and helps the agency PMO scope effort.
Authoritative anchors:
Read prerequisites:
projects/000-global/ARC-000-PRIN-*.md (architecture principles, if present)projects/<id>/external/ or projects/<id>/vendors/.arckit/templates/_partials/RENDERING.mdRead the template:
.arckit/templates-custom/us-fedramp-readiness-template.md (user override).arckit/templates-custom/us-fedramp-readiness-template.md.arckit/templates/us-fedramp-readiness-template.mdUse scripts/bash/create-project.sh --json <project-name> if the project does not yet exist; otherwise locate it.
Use scripts/bash/generate-document-id.sh <PROJECT_ID> FRRR --filename for the artefact filename. The type code for this command is FRRR.
Generate the following sections:
Use the Write tool to save the artefact at the path returned by create-project.sh + generate-document-id.sh.
Emit a short summary to the user — readiness verdict (Ready / Conditionally Ready / Not Ready), gap counts by severity, recommended authorization path, and the top 3 blockers. Do not echo the full artefact.
Surfaced gaps feed the broader $arckit-service-assessment evidence pack and remediation timelines drop into $arckit-roadmap. Each open gap should be tracked in $arckit-risk until closed. Once gaps are remediated, re-run this command to re-baseline before engaging a 3PAO.
After completing this command, consider running:
$arckit-service-assessment -- The readiness gap register feeds the broader service-assessment evidence pack.$arckit-roadmap -- Remediation actions for FedRAMP gaps drop into the architecture roadmap timeline.$arckit-risk -- Open gaps and POA&M items become entries in the project risk register.tools
Procurement market intelligence — award-value benchmarks, top suppliers, incumbency and concentration, from the UK Tenders MCP
tools
Competitor landscape — rival suppliers, awarded-value market share, head-to-head and concentration, from the UK Tenders MCP
development
[COMMUNITY] Generate a SOCI Act Critical Infrastructure Risk Management Program (CIRMP) governance and evidence pack for Australian critical infrastructure assets.
development
[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.