FedRAMP 20x: Maintain a Policy and Procedure Reference Index
CDS-CSO-IRP requires relevant policies and procedures plus a human-readable and machine-readable reference with seven information categories. Keep entries linked to controlled sources and refresh them with document changes. CDS-CSO-CBF requires automated consistency between the two formats.
In this article
Main question
What belongs in a Class B or C policy and procedure reference, and how can it stay current?
A FedRAMP 20x policy procedure reference index helps readers find the right document and understand its current version. For Class B and C package owners, keep the reference connected to the actual policies and procedures being supplied.
The operating problem is familiar: a policy changes, but the package still points to an old file, summary or version. Treat the reference as maintained information with a clear source and owner.
Supply the policies and their reference information
CDS-CSO-IRP requires all relevant policies and procedures in the Certification Data, including a human-readable and machine-readable reference explaining at least seven categories about each included document. FedRAMP Certification Data Sharing
Those categories are:
- The policy or procedure name.
- The file, document, webpage or equivalent name.
- A brief summary.
- The document's word count.
- Its current version.
- The date of its last update.
- Related FedRAMP Practices, if applicable.
The requirement includes supplying the relevant policies and procedures themselves. An index alone does not replace that part of the rule. Keep the reference useful by connecting it to the controlled document rather than treating it as a standalone list of titles.
Refresh the reference when the document changes
As an implementation practice, use the document's revision process to refresh its reference entry. Recheck the summary, word count, version, update date and related practices after substantive edits. Confirm the displayed file or page name still leads to the intended material.
For example, a procedure may be split into two documents. Review whether the old entry should now lead to two current references and whether each new summary explains the resulting scope. Preserve a way to understand the change internally without leaving the reader to guess which document applies.
Assign an owner for each reference or document family. This is an editorial operating suggestion, not a fixed FedRAMP refresh interval or prescribed index schema.
Keep the human and machine views consistent
CDS-CSO-CBF requires automation to ensure consistency between human-readable and machine-readable information when Certification Data is provided in both formats. FedRAMP CDS-CSO-CBF
One implementation option is to maintain a single reference record and generate both views from it. Another is an automated comparison between maintained representations. Test that a version or word-count change appears consistently in the output your readers and tools consume.
The JSON validation workflow can support validation where your implementation uses JSON. Keep the reference-format obligation distinct from the format of every underlying policy document.
Test access and keep history understandable
As a practical retrieval exercise, choose several entries and open their source documents through the intended access path. Check that the current reference points to current content and that the reader can distinguish it from retained historical material.
The package history guide addresses report-aligned snapshots. Use the sensitive-data guide when reviewing what information is shared with recipients.
The CDS page lists July 4, 2026 for initial certification and January 1, 2027 for ongoing certification, with grace ending on the first independent assessment started after January 1, 2027. Keep the applicable Class B or C context with your implementation.
A useful index lets a reader identify the document, understand its purpose and retrieve the stated version, while automation keeps the two reference views aligned.
Frequently asked questions
Can the index replace the actual policies and procedures?
No. CDS-CSO-IRP requires supplying all relevant policies and procedures as well as the reference information.
Is word count part of the required reference?
Yes. CDS-CSO-IRP includes document word count among the seven listed information categories.
Must related practices always be listed?
The rule includes related FedRAMP Practices if applicable. Preserve that qualifier when maintaining the reference.
Next step
If you want to turn this guidance into an execution plan, the product side handles control mapping, SSP drafting, and evidence collection.
Related articles
FedRAMP 20x: Do You Need a Separate Government Deployment?
Compare shared and dedicated deployment designs for Class B/C using the shared-infrastructure policy, actual assessment scope and agency needs.
FedRAMP 20x: Handle Denied Agency Package Access Requests
Handle denied agency package-access requests for Class B/C providers using a compatible trust center, preserving the five-business-day notification trigger.
FedRAMP 20x: Reconcile Agency Access Records in Your Trust Center
Reconcile Class B/C trust-center permission history and access activity, with the right six-month summary retention and request-specific retrieval.