Skip to content
This repository has been archived by the owner on Oct 16, 2019. It is now read-only.

FedRamp Certification #38

Open
BKozisek7 opened this issue Jul 30, 2018 · 1 comment
Open

FedRamp Certification #38

BKozisek7 opened this issue Jul 30, 2018 · 1 comment

Comments

@BKozisek7
Copy link

BKozisek7 commented Jul 30, 2018

Question/Comment on TTS Bug Bounty RFQ

Name and affiliation

Brett Kozisek
Director
Synack Inc.

Section of RFQ documents

RFQ Section 12 - Addendum - https://github.com/18F/tts-buy-bug-bounty/blob/master/2018-procurement/RFQ.md#120-attachments https://github.com/18F/tts-buy-bug-bounty/blob/master/2018-procurement/Addendum%20-%20Commercial%20Contract%20Clauses.md
The Commercial Contract Clauses document calls for the vendor to obtain FedRamp certification for their platform.

Question/Comment

Can the government confirm the type of certification that is expected (i.e. PaaS, SaaS)?

Is it the intent of the government to sponsor the vendor in their certification?

Is there any other support provided by the Government for the vendor throughout this process?

@MichelleMcNellis
Copy link
Member

As is indicated in the RFQ section 12 Clause Addendum, FedRAMP Tailored or a FedRAMP Low assessment would be sufficient. A FedRAMP Moderate or High assessment would qualify, but is not necessary. GSA will sponsor the vendor for a FedRAMP Tailored certification, which involves working with the vendor to assist in the FedRAMP process. For more information about FedRAMP Tailored, please see https://tailored.fedramp.gov/.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants