FedRAMP 20x Class C: Organize Shared and Per-Service Package Materials
CDS-CSO-PSM permits Class C per-service materials and encourages a comprehensive shared set with separate information for unique service aspects. Use an index and stable references to make the structure usable. Keep service organization distinct from outside-resource supplements and report history.
In this article
Main question
How can Class C providers organize shared and per-service certification materials?
FedRAMP 20x per-service certification materials can help an agency find the information relevant to the services it actually adopts. For a Class C provider, organize common material once and make the unique aspects of each service easy to identify.
The practical challenge is navigation and consistency. A customer should be able to move from a service name to its relevant material without reading duplicate descriptions that drift apart when the offering changes.
Understand the Class C option
CDS-CSO-PSM says Class C providers MAY supply per-service Certification materials. Its notes say providers determine separate services based on improving the experience of agencies that may adopt only some services. They encourage a single comprehensive set of shared material, with separate material for each service's unique aspects, to reduce burden. FedRAMP Certification Data Sharing
This is an option for organizing material. Use it to make the relationship between common and service-specific information clearer. The cited rule concerns the supplied materials; maintain the offering's scope explanation alongside that structure.
The CDS page lists July 4, 2026 for initial certification and January 1, 2027 for ongoing certification, with grace ending on the first independent assessment started after January 1, 2027. Keep the Class C applicability and timing with your implementation decision.
Start from the customer's service choices
As an implementation exercise, list the services an agency can adopt and the questions it needs answered for each. Identify which explanations are common and which differ in a way that matters to customer use.
For example, two services may use the same workforce access process but expose different customer configuration options. A common reference can describe the shared process, while service-specific material explains the different settings. This is an organizational example, not an official division of package content.
A useful index can contain the service name, shared references, unique material, current version, owner and access instructions. These suggested fields help a reader understand which pieces to combine.
Manage shared changes through references
Give each shared document a clear owner and stable reference. When it changes, check the service-specific material that relies on it. If a service has an exception to the common explanation, make the difference explicit rather than duplicating the whole document with a small hidden edit.
In an internal review, choose one service and follow its references as a customer would. Can the reader tell which common material applies, what is unique, and where to ask a question? Then choose a second service and check whether the shared references still communicate the same version and meaning.
The agency onboarding guide can help connect this navigation to the customer's actual configuration and operating responsibilities.
Distinguish service organization from other package views
Material about resources outside the offering has a separate rule: MAS-CSO-SUP permits supplements for those resources, which are not certified and must be clearly marked and separated. FedRAMP Minimum Assessment Scope
Use the supplement guide for that distinction. Use the package history guide for retrieving the data aligned to earlier reports.
As a design practice, label these views by their purpose: the current material relevant to a service, supplemental information about outside resources, and historical material associated with a report. Keeping those purposes visible makes the package easier to use and maintain as the offering grows.
Frequently asked questions
Must every Class C provider produce per-service materials?
CDS-CSO-PSM uses MAY for Class C. It is an option for supplying the material.
Who decides what constitutes a separate service for this purpose?
The rule's notes place that decision with providers, based on the experience of agencies that may adopt only some services.
Should common material be copied into every service section?
The official notes encourage a single comprehensive set for shared aspects and separate material only for unique aspects, to reduce burden.
Next step
If you want to turn this guidance into an execution plan, the product side handles control mapping, SSP drafting, and evidence collection.
Related articles
FedRAMP 20x: Do You Need a Separate Government Deployment?
Compare shared and dedicated deployment designs for Class B/C using the shared-infrastructure policy, actual assessment scope and agency needs.
FedRAMP 20x: Handle Denied Agency Package Access Requests
Handle denied agency package-access requests for Class B/C providers using a compatible trust center, preserving the five-business-day notification trigger.
FedRAMP 20x: Reconcile Agency Access Records in Your Trust Center
Reconcile Class B/C trust-center permission history and access activity, with the right six-month summary retention and request-specific retrieval.