[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-163146-105":53,"doc-detail-163146-en":127},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":120,"head_meta":122,"extra_data":124,"updated_unix":126},105,"en","fedramp-security-assessment-report-sar-template-prepared-by","FedRAMP Security Assessment Report (SAR) Template - Prepared by","","FedRAMP Security Assessment Report (SAR) template provides a structured, reusable framework for documenting point-in-time security assessment results for a cloud service offering (CSO). The template guides independent assessors (IAs/3PAOs/IAOs) in completing required sections, aligning with the CSO security assessment plan (SAP), and ensuring compliance with FedRAMP requirements to avoid retesting delays. It supports risk posture reporting through executive summary content and appendix deliverables such as the Risk Exposure Table, SRTM, vulnerability scan results, and review findings.",{"@graph":63,"@context":119},[64,80,102],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":36,"@type":70,"position":76},"https://docshare.wps.com/template/forms/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/fedramp-security-assessment-report-sar-template-prepared-by/163146/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/fedramp-security-assessment-report-sar-template-prepared-by/163146.png","ImageObject",442,249,{"name":88,"@type":89},"Rizky","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-27","2026-08-31",true,{"@type":98,"interactionType":99,"userInteractionCount":101},"InteractionCounter",{"@type":100},"ViewAction",6,{"@type":103,"mainEntity":104},"FAQPage",[105,111,115],{"name":106,"@type":107,"acceptedAnswer":108},"Who is this FedRAMP SAR template intended to be used by?","Question",{"text":109,"@type":110},"FedRAMP recognized 3PAOs or independent assessment organizations populate this SAR template. Authorizing officials (AOs) review the completed SAR to make risk-based authorization decisions.","Answer",{"name":112,"@type":107,"acceptedAnswer":113},"What is the purpose of the SAR template in FedRAMP assessments?",{"text":114,"@type":110},"The SAR template documents the risk posture of a CSO based on a point-in-time security assessment and aggregates results required for initial, annual, or significant change assessments.",{"name":116,"@type":107,"acceptedAnswer":117},"What key appendix artifacts does the template reference for reporting risks and evidence?",{"text":118,"@type":110},"The template ties findings to appendix deliverables including the Risk Exposure Table (RET), the SRTM workbook, vulnerability scan results, documentation review findings, auxiliary documents, and a penetration test report.","https://schema.org",{"og:url":78,"og:type":121,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":123,"canonical":78},"index,follow",{"doc_id":125,"site_id":56},163146,1788138757,{"code":4,"msg":5,"data":128},{"doc_id":125,"user_id":129,"nickname":88,"user_avatar":130,"doc_module":9,"category_id":35,"category_name":36,"doc_title":59,"doc_description":61,"doc_content":131,"file_id":132,"file_url":133,"file_type":134,"file_size":135,"view_count":101,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":136,"language":137,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":138,"faqs":139,"seo_title":140,"seo_description":61,"update_tm":126,"read_time":8},962085564807,"https://ap-avatar.wpscdn.com/davatar_6f874abed73319feea01a86fa6f0fab8","TEMPLATE REVISION HISTORY\nHow to contact us\nFor questions about FedRAMP, or for questions about this document including how to use it, contact \u0013 HYPERLINK \"mailto:info@FedRAMP.gov\" \\h \u0014info@FedRAMP.gov.\u0015\nFor more information about FedRAMP, see \u0013 HYPERLINK \"http://www.fedramp.gov\" \\h \u0014www.FedRAMP.gov\u0015.\nDelete this Template Revision History page and all other instructional text from your final version of this document.\n\u000f\n\u000f\nPrepared by\nPrepared for\nDocument Revision History\n\u0013 SUBJECT  \\* MERGEFORMAT \u0015\u000f\n\u0013 SUBJECT  \\* MERGEFORMAT \u0015TABLE OF CONTENTS\u0013  \u0015\n\u0013 TOC \\o \"1-1\" \\h \\z \\t \"Heading 2,2,Heading 3,3\" \u0014\u0013 HYPERLINK \\l \"_Toc184297586\" \u00141\tIntroduction\t\u0013 PAGEREF _Toc184297586 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297587\" \u00141.1\tAbout This Document\t\u0013 PAGEREF _Toc184297587 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297588\" \u00141.2\tWho Should Use This Document?\t\u0013 PAGEREF _Toc184297588 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297589\" \u00142\tExecutive Summary\t\u0013 PAGEREF _Toc184297589 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297590\" \u00142.1\tPurpose\t\u0013 PAGEREF _Toc184297590 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297591\" \u00142.2\tApplicable Laws, Regulations, Standards, and Guidance\t\u0013 PAGEREF _Toc184297591 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297592\" \u00142.3\tScope\t\u0013 PAGEREF _Toc184297592 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297593\" \u00142.3.1\tControls Assessed\t\u0013 PAGEREF _Toc184297593 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297594\" \u00143\tSystem Overview\t\u0013 PAGEREF _Toc184297594 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297595\" \u00143.1\tSystem Description\t\u0013 PAGEREF _Toc184297595 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297596\" \u00144\tAssessment Methodology\t\u0013 PAGEREF _Toc184297596 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297597\" \u00144.1\tDeviations from the SAP\t\u0013 PAGEREF _Toc184297597 \\h \u001416\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297598\" \u00144.2\tThe SRTM\t\u0013 PAGEREF _Toc184297598 \\h \u001416\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297599\" \u00144.3\tConsideration of Threats\t\u0013 PAGEREF _Toc184297599 \\h \u001416\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297600\" \u00144.4\tDocument Results\t\u0013 PAGEREF _Toc184297600 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297601\" \u00145\tRisks Known for Interconnected Systems and External Services\t\u0013 PAGEREF _Toc184297601 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297602\" \u0014Appendix A Risk Exposure Table\t\u0013 PAGEREF _Toc184297602 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297603\" \u0014Appendix B Security Requirements Traceability Matrix (SRTM) Workbook\t\u0013 PAGEREF _Toc184297603 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297604\" \u0014Appendix C Vulnerability Scan Results\t\u0013 PAGEREF _Toc184297604 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297605\" \u0014Appendix D Documentation Review Findings\t\u0013 PAGEREF _Toc184297605 \\h \u001431\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297606\" \u0014Appendix E Auxiliary Documents\t\u0013 PAGEREF _Toc184297606 \\h \u001431\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc184297607\" \u0014Appendix F Penetration Test Report\t\u0013 PAGEREF _Toc184297607 \\h \u001432\u0015\u0015\n\u0015\nIntroduction\nAbout This Document\nThis document is developed as a template when creating a FedRAMP Security Assessment Report (SAR). This template should be used for all initial authorization assessments, annual assessments, and significant change assessments.\nIndependent assessors (IAs) must complete this SAR template based upon a specific cloud service offering’s (CSO’s) security assessment as captured in the CSO’s security assessment plan (SAP). This SAR documents the risk posture for a CSO based on a point-in-time security assessment.\nA CSP must keep in mind that an IA must follow all FedRAMP requirements in preparing this SAR. Failure to follow FedRAMP requirements may result in retesting, delaying the authorization process.\nThis document uses the term authorizing official (AO). For systems pursuing a FedRAMP Agency Authorization, AO refers to each leveraging agency’s AO.\nWho Should Use This Document?\nThis SAR template is intended to be populated by a FedRAMP recognized third party assessment organization (3PAO) or an independent assessment organization (IAO) when documenting the results of a FedRAMP security assessment. AOs will review this completed SAR to make risk-based authorization decisions.\nIt is incumbent upon a CSP to ensure that their 3PAO assessors hold the appropriate","cbCaigvcemGUmppS","https://ap.wps.com/l/cbCaigvcemGUmppS","docx",149146,32,"English","# Introduction\n## About This Document\n## Who Should Use This Document?\n# Executive Summary\n## Purpose\n## Applicable Laws, Regulations, Standards, and Guidance\n## Scope\n## Controls Assessed\n# System Overview\n## System Description\n# Assessment Methodology\n## Deviations from the SAP\n## The SRTM\n## Consideration of Threats\n## Document Results\n# Risks Known for Interconnected Systems and External Services\n# Appendix A Risk Exposure Table\n# Appendix B Security Requirements Traceability Matrix (SRTM) Workbook\n# Appendix C Vulnerability Scan Results\n# Appendix D Documentation Review Findings\n# Appendix E Auxiliary Documents\n# Appendix F Penetration Test Report","[{\"question\":\"Who is this FedRAMP SAR template intended to be used by?\",\"answer\":\"FedRAMP recognized 3PAOs or independent assessment organizations populate this SAR template. Authorizing officials (AOs) review the completed SAR to make risk-based authorization decisions.\"},{\"question\":\"What is the purpose of the SAR template in FedRAMP assessments?\",\"answer\":\"The SAR template documents the risk posture of a CSO based on a point-in-time security assessment and aggregates results required for initial, annual, or significant change assessments.\"},{\"question\":\"What key appendix artifacts does the template reference for reporting risks and evidence?\",\"answer\":\"The template ties findings to appendix deliverables including the Risk Exposure Table (RET), the SRTM workbook, vulnerability scan results, documentation review findings, auxiliary documents, and a penetration test report.\"}]","FedRAMP Security Assessment Report (SAR) Template - Prepared by | DOCX"]