ISO/IEC 17020 accredited inspection body · Cleared facility (FCL)
Home / Services / FedRAMP Assessment Services

Independent assessment

FedRAMP Assessment Services

Independent security assessment for commercial cloud service providers and government agencies, delivered under our accredited inspection capability.

Accredited independent assessment

Assessment is a discipline with a standard attached to it.

DASATECH is an ISO/IEC 17020 accredited inspection organization. That accreditation is an external judgment about impartiality and technical competence, assessed by a third party against an international standard rather than asserted in a capability statement.

For cloud service providers, we assess control implementation against the applicable FedRAMP baseline and produce the assessment artifacts an agency reviewer or the FedRAMP PMO expects. For agencies, we provide independent assessment of cloud services under consideration, and of systems already in the boundary.

Where we perform the assessment, we do not also build the package. Independence is not a marketing position; it is the thing being accredited.

What independence actually requires
  • Assessment staff separated from any advisory work on the same system
  • Documented, repeatable test procedures rather than assessor preference
  • Evidence retained and traceable from finding back to source artifact
  • Impartiality reviewed under a formal management system
  • Findings reported as observed, not negotiated down to a comfortable number
SSPREV. 5 BASELINEFIPS 199CIS / CRMPoliciesISCPCMPIRPRules of BehaviorUser GuidePTA / PIAArchitectureConMon PlanInventory
The package under assessment: an SSP and the artifacts that must corroborate it.

We assess what the package claims against what the environment actually does.

How it runs

Engagement sequence

Assessment planning

1–2 weeks

Scope, boundary confirmation, sampling methodology and test procedures are documented in the SAP and agreed before any testing begins.

Evidence examination

2–3 weeks

Documentation, configuration and control artifacts are examined against the applicable baseline, with interviews of the personnel who operate each control.

Technical testing

2–3 weeks

Vulnerability assessment, configuration testing and penetration testing aligned to NIST SP 800-115 and FedRAMP penetration testing guidance.

Reporting

1–2 weeks

Determinations are documented control by control, with the evidence relied on recorded for each and findings risk-rated.

Retest and closure

As scheduled

Remediated findings are retested and closure evidence issued.

Deliverables

Assessment deliverables

Every document is produced in the template the receiving party expects, and is written to be read by an assessor rather than filed.

  • SAPSecurity Assessment Plan with defined scope, sampling and test procedures
  • SARSecurity Assessment Report with per-control determinations and evidence
  • RETPenetration test report against FedRAMP penetration testing guidance
  • POA&MFindings formatted for direct entry into the provider POA&M
  • BRIEFAssessment briefing for the sponsoring agency or authorizing official
  • RETESTValidation of remediated findings and closure evidence

Outcome

What an accredited assessment is worth

  • An assessment result a reviewing agency has reason to rely on
  • Findings that arrive in the form your POA&M and ConMon process already use
  • Fewer clarification cycles between provider, assessor and sponsoring agency
  • A defensible record of how each determination was reached
  • Impartiality that survives scrutiny, because it is externally accredited

Tell us what the contract requires. We’ll tell you what it takes.

A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.