FedRAMP 20x Package Supplements: Separate Apps from the Certified Offering
Make the scope decision first. MAS-CSO-SUP permits material about resources outside the offering in a supplement, but those resources are not certified and must be marked and separated. Preserve the specific delivery and operating-model conditions in the MAS-CSO-IIR software note.
In this article
Main question
How should Class B and C providers share supplemental app materials without blurring certification scope?
FedRAMP 20x package supplemental materials can help an agency understand related software without blurring what is certified. For Class B and C providers, begin with the scope decision, then clearly separate material about resources outside the cloud service offering.
An app's product name or its location in a document library does not explain its operating model. Establish who operates the resource, where it is delivered and how it relates to the offering before deciding how to present its security material.
Make the scope decision before assembling the supplement
MAS-CSO-IIR requires providers to identify the offering's resources for assessment, including resources likely to handle federal customer data or affect the confidentiality, integrity or availability of that data in the offering. Its notes address software delivered separately for installation on agency systems and not operated in a shared responsibility model, typically including clients or agents not fully managed by the provider. Software meeting those stated conditions is outside the offering for FedRAMP. FedRAMP Minimum Assessment Scope
Preserve the conditions when explaining the distinction. The note does not say every resource called an agent or client is automatically excluded. If the product includes connected cloud resources, assess their relationship to the offering under the scope rule instead of treating the desktop or mobile label as the answer.
For an internal review, record the resource's operating model, the responsible parties and the information flows that explain the scope decision. These are practical documentation suggestions.
Mark and separate resources outside the offering
MAS-CSO-SUP permits additional material about resources outside the offering in a Certification Package supplement. Those resources will not be FedRAMP Certified and MUST be clearly marked and separated from the offering. The note explains that useful examples include app security materials and supplemental collateral. FedRAMP MAS-CSO-SUP
A useful presentation gives the reader the scope distinction before they open a document. As an editorial label, consider: “Supplemental information about a resource outside this certified cloud service offering.” Adapt the wording to the actual resource and scope decision; this is not an official label template.
Keep navigation clear enough that a customer does not mistake the supplement's contents for the list of certified services. The agency onboarding guide can help connect those materials to the customer's own configuration and operating responsibilities.
Build a small supplement index
Suggested index fields include the resource name and version, its relationship to the offering, the relevant scope explanation, the security material available and a contact for questions. Link to the source document instead of maintaining several disconnected copies.
For example, an agency-installed client might have its own deployment guidance and update process. The supplement can organize that information while making clear that inclusion in the package does not certify the client. The provider should still describe the certified cloud services the client connects to accurately.
Apply the sensitive package-data review to the documents being shared. A resource's placement in a supplement does not eliminate the need to consider the information disclosed.
Recheck the presentation when the product changes
As an operating practice, revisit the scope explanation when management responsibility, delivery model or data flows change. Review customer-facing descriptions and package navigation together so a stale label does not outlive the decision it was meant to explain.
The MAS page lists July 4, 2026 for obtaining initial certification and January 1, 2027 for maintaining ongoing certification, with the grace period ending on the first independent assessment started after January 1, 2027. Keep the applicable timing and source version with the scope review.
The supplement is useful when the customer can distinguish the certified offering, the related external resource and the documentation that helps them use both appropriately.
Frequently asked questions
Does including app material in a package certify the app?
MAS-CSO-SUP says resources outside the offering included in a supplement will not be FedRAMP Certified and must be clearly marked and separated.
Are all clients and agents automatically outside scope?
No. The MAS-CSO-IIR note describes separately delivered software for installation on agency systems that is not operated in a shared responsibility model. Evaluate the actual operating model rather than the product label.
Is the suggested supplement index an official template?
No. It is an editorial way to organize resource identity, scope explanation and useful document references.
Next step
If you want to turn this guidance into an execution plan, the product side handles control mapping, SSP drafting, and evidence collection.
Related articles
FedRAMP 20x: Do You Need a Separate Government Deployment?
Compare shared and dedicated deployment designs for Class B/C using the shared-infrastructure policy, actual assessment scope and agency needs.
FedRAMP 20x: Handle Denied Agency Package Access Requests
Handle denied agency package-access requests for Class B/C providers using a compatible trust center, preserving the five-business-day notification trigger.
FedRAMP 20x: Reconcile Agency Access Records in Your Trust Center
Reconcile Class B/C trust-center permission history and access activity, with the right six-month summary retention and request-specific retrieval.