Most teams come to FedRAMP looking for a list. What are the steps, in order, from deciding to pursue authorization to handing an assessor a finished package. This is that list. It is also a map of where the time actually goes, because the checklist is short and the work behind each item is not.
Carry one framing through it. A FedRAMP authorization is an evidence problem before it is a security problem. The controls are published and knowable. The work is proving, control by control, that your system meets them, in a form an assessor will accept. Keep that in mind at every step below.
Step 1: Set your impact level.
Before anything else, decide whether you are pursuing Low, Moderate, or High. The level is set by the sensitivity of the data your system handles, under FIPS 199, and it determines how many controls you implement and how much evidence you produce. Most federal SaaS targets Moderate. Get this wrong in either direction and you either over-build for a year or restart the package. The full breakdown is in FedRAMP impact levels, explained and FedRAMP High vs Moderate, and how to choose.
Step 2: Define the authorization boundary.
Draw the line around what is in scope: the systems, services, and data flows the assessment will cover. The boundary sizes the entire authorization. Every control you implement and every piece of evidence you produce traces back to what sits inside it. Draw it too wide and you prove controls on infrastructure you never needed. Draw it too tight and the package comes back when a data flow crosses a line your diagram says is not there. Settle the boundary before you write a word of the package.
Step 3: Write the System Security Plan.
The System Security Plan, the SSP, is the core document of the authorization. It describes your system and states how each control is met. This is the heaviest writing task in the process, and it is where most teams underestimate the work, because every control needs a narrative that ties the claim to the evidence behind it. The components an assessor expects are covered in the essential components of a System Security Plan.
Step 4: Reach readiness.
Before the full assessment, most teams go through a readiness step. A 3PAO, an accredited third-party assessment organization, reviews your system against the baseline and documents whether it is ready for a full assessment. A system that clears this earns the FedRAMP Ready designation, recorded in a Readiness Assessment Report. Readiness is where gaps surface cheaply, before the expensive assessment finds them. Treat it as a rehearsal you want to fail in private.
Step 5: Complete the full security assessment.
The 3PAO runs the formal assessment. They write a Security Assessment Plan, test your controls against it, and document the results in a Security Assessment Report, the SAR. This is the independent review the whole package has been building toward. The assessor's job is to determine whether the evidence proves each control on its own, without your explanation beside it.
Step 6: Build the POA&M.
No package is perfect at assessment. Findings get logged in a Plan of Action and Milestones, the POA&M: what was found, how you will fix it, and by when. The POA&M is a living document. It follows you from assessment into the life of the authorization, and a clean, current POA&M is one of the clearest signals that a team is on top of its system.
Step 7: Get the authorization decision.
A federal agency reviews the completed package and, if the evidence holds, issues the Authority to Operate, the ATO. That is the authorization. With it, your system lists on the FedRAMP Marketplace and federal customers can buy. The path and the parties have shifted as the program has changed over the last two years, so confirm the current route for your situation. The destination is the same: an agency accepts the package and authorizes the system.
Step 8: Maintain it through continuous monitoring.
Reaching authorization starts a recurring obligation. You hold it through continuous monitoring: monthly vulnerability scans, a POA&M kept current, remediation on deadline, plus an annual 3PAO assessment and an annual penetration test. This obligation runs for as long as you hold the authorization. The full cadence is laid out in FedRAMP continuous monitoring, the monthly and annual obligations.
What the checklist does not show.
The steps are clean. The work inside them is not evenly distributed. The schedule and the budget concentrate in two places: producing evidence for every control, and writing the narratives that connect that evidence to the requirement in a form an assessor accepts. That translation work is where the months and the hundreds of thousands of dollars go. The security requirements are real, and they are rarely the bottleneck. The bottleneck is proof.
One naming note. FedRAMP renamed the authorization to a Certification and the impact levels to Certification Classes in 2026, with Moderate now Class C. The steps in this checklist did not change. The language is catching up to the new taxonomy.
Where SentrIQ fits.
SentrIQ is built for the part of this checklist that costs the most: the evidence and the narratives. The platform ingests live system evidence and your policy documents, maps them to the FedRAMP control families, and generates assessor-credible authorization artifacts, with every output traceable back to the evidence that produced it. The checklist still has to be worked. SentrIQ compresses the step that consumes most of the calendar. If FedRAMP is between you and federal revenue, that is the bottleneck worth attacking first.