[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-161362-105":53,"doc-detail-161362-en":127},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":120,"head_meta":122,"extra_data":124,"updated_unix":126},105,"en","fedramp-ato-letter-template","FedRAMP ATO Letter Template","","FedRAMP Authority to Operate (ATO) letter template for notifying a Cloud Service Provider (CSP) that a federal agency has completed review of the CSP cloud system security authorization package. It confirms compliance with FedRAMP requirements using FIPS security categorization and the provided Security Assessment results. The letter grants an ATO based on meeting information security requirements and outlines ongoing conditions aligned with OMB Circular A-130, including continuous monitoring, closure of POA&M items, and management of significant changes or critical vulnerabilities. It includes signature block fields for the authorizing official.",{"@graph":63,"@context":119},[64,80,102],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":41,"@type":70,"position":76},"https://docshare.wps.com/template/letters/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/fedramp-ato-letter-template/161362/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/fedramp-ato-letter-template/161362.png","ImageObject",442,249,{"name":88,"@type":89},"Finn","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-29","2026-08-30",true,{"@type":98,"interactionType":99,"userInteractionCount":101},"InteractionCounter",{"@type":100},"ViewAction",6,{"@type":103,"mainEntity":104},"FAQPage",[105,111,115],{"name":106,"@type":107,"acceptedAnswer":108},"What does the FedRAMP ATO letter confirm for the cloud system owner?","Question",{"text":109,"@type":110},"It confirms that the federal agency completed the review of the CSP cloud system security authorization package, and that the system meets FedRAMP information security requirements, resulting in an Authority to Operate.","Answer",{"name":112,"@type":107,"acceptedAnswer":113},"How does the letter determine compliance with FedRAMP requirements?",{"text":114,"@type":110},"It references FIPS security categorization (Low, Moderate, or High) and the provided Security Assessment results used during the authorization review.",{"name":116,"@type":107,"acceptedAnswer":117},"What conditions must the CSP meet to keep the ATO in effect?",{"text":118,"@type":110},"The CSP must implement continuous monitoring activities as documented in the FedRAMP continuous monitoring requirements and its Continuous Monitoring Plan, mitigate all open POA&M action items, and identify and manage significant changes or critical vulnerabilities under applicable federal laws, guidelines, and policies.","https://schema.org",{"og:url":78,"og:type":121,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":123,"canonical":78},"index,follow",{"doc_id":125,"site_id":56},161362,1788098199,{"code":4,"msg":5,"data":128},{"doc_id":125,"user_id":129,"nickname":88,"user_avatar":130,"doc_module":9,"category_id":40,"category_name":41,"doc_title":59,"doc_description":61,"doc_content":131,"file_id":132,"file_url":133,"file_type":134,"file_size":135,"view_count":101,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":73,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":126,"read_time":9},34359740700684,"https://ap-avatar.wpscdn.com/avatar/1f400023980c374ae676?_k=1777273430885731487","{agency logo}\n{Insert Date}\n{Cloud System Owner Name}\n{Insert Cloud Service Name} Cloud System Owner\n{Insert Address}\nTo: {CSP System Owner Name}\nThe {Federal Agency/Office} has completed the review of the {Insert CSP and cloud service name} Cloud system’s security authorization package that meets the Federal Risk and Authorization Management Program (FedRAMP) requirements.  Based on the Federal Information Processing Standard (FIPS) security categorization of “{Low, Moderate, or High}” and the provided Security Assessment, the {Federal Agency/Office} has determined that the {Insert CSP and cloud service name} Cloud system meets the information security requirements and is granted an Authority to Operate.\nThe security authorization of the information system will remain in effect for a length of time in alignment with Office of Management and Budget Circular A-130 as long as:\n{Insert CSP name} satisfies the requirement of implementing continuous monitoring activities as documented in FedRAMP’s continuous monitoring requirements and {Insert CSP name} Continuous Monitoring Plan;\n{Insert CSP name} mitigates all open POA&M action items, agreed to in the Security Assessment Report (SAR) and as developed during the continuous monitoring activities; and\nSignificant changes or critical vulnerabilities are identified and managed in accordance with applicable Federal law, guidelines, and policies.\n{Federal Agency/Office} is leveraging the documentation provided within the FedRAMP secure repository as a key element of the Authority to Operate (ATO).  Based on the documentation within the FedRAMP secure repository and customer-specific tailoring and operating procedures, the {Federal Agency/Office} believes the security authorization package accurately documents the {Insert CSP name} cloud system and clearly defines outstanding risk considerations.\nSIGNED:\n{Authorizing Official}\n{Title}\n{Office}\n{Agency}\n{Street Address}\n{City, State, Zip}\n{Phone}\n{Email}\ncc FedRAMP PMO at \u0013 HYPERLINK \"mailto:info@FedRAMP.gov\" \\h \u0014info@FedRAMP.gov\u0015","cbCaiqzXw5QzBXbC","https://ap.wps.com/l/cbCaiqzXw5QzBXbC","docx",21343,"English","## Purpose and Review Outcome\n## Security Authorization Grant (ATO)\n## Conditions to Maintain Authorization\n## Signature and Contact Information","[{\"question\":\"What does the FedRAMP ATO letter confirm for the cloud system owner?\",\"answer\":\"It confirms that the federal agency completed the review of the CSP cloud system security authorization package, and that the system meets FedRAMP information security requirements, resulting in an Authority to Operate.\"},{\"question\":\"How does the letter determine compliance with FedRAMP requirements?\",\"answer\":\"It references FIPS security categorization (Low, Moderate, or High) and the provided Security Assessment results used during the authorization review.\"},{\"question\":\"What conditions must the CSP meet to keep the ATO in effect?\",\"answer\":\"The CSP must implement continuous monitoring activities as documented in the FedRAMP continuous monitoring requirements and its Continuous Monitoring Plan, mitigate all open POA\\u0026M action items, and identify and manage significant changes or critical vulnerabilities under applicable federal laws, guidelines, and policies.\"}]","FedRAMP ATO Letter Template | DOCX"]