FedRAMP Certification Advisory
Advisory across FedRAMP certification under the 2026 Consolidated Rules: choosing among Certification Classes A through D, meeting Key Security Indicators, structuring evidence, and preparing for assessment. We advise the team that owns the certification; we do not produce its artifacts or meet its ongoing requirements on its behalf.
DoD Impact Level Authorization
Advisory for Department of Defense Impact Level 4 and Impact Level 5 authorization under the DoD Cloud Computing SRG: what the authorization asks of the system and the engineering team, how it differs from FedRAMP certification, and how to sequence the two. IL5 now requires CNSSI 1253, the National Security System designation, and we advise on meeting those controls.
CNSSI 1253 and National Security System Controls
Advisory on CNSSI 1253, the National Security System designation now required for Impact Level 5: which controls apply to a given system, and how to meet them in a running system rather than on paper.
FedRAMP Secure Configuration Guide
Producing the customer-facing configuration guidance FedRAMP requires under SCG-CSO-RSC: how an agency securely accesses, configures, operates, and decommissions top-level administrative accounts, and what the settings only those accounts can reach actually do. Required of providers certified in Classes B, C, and D.
3PAO Selection
Choosing an independent assessor, and knowing what to ask before signing. Assessors differ in the architectures they have actually assessed, how they handle findings mid-assessment, their throughput, and whether they have worked at your certification class or Impact Level. REM5 does not perform assessments — we help you pick the organization that will.
Authorization Maintenance
Keeping an authorization alive after the award: continuous monitoring, significant change handling, vulnerability response within required timelines, and the reporting cadence that agencies and sponsors rely on.
This is the floor for most advisory engagements — the control matrix and the gap list. Everything below it is where the controls are actually met.