Security Assessment Plan
A Security Assessment Plan (SAP) is a document that describes which security controls will be evaluated and how the assessment will be conducted before a system is authorized to operate. It lays out the procedures, methods, and scope that assessors follow so that testing is consistent and thorough. In FedRAMP, this plan is generally prepared by an independent Third-Party Assessment Organization (3PAO).
A Security Assessment Plan (SAP) is a formal document that identifies the security controls and enhancements to be assessed and specifies the assessment procedures, methodologies, and scope used to evaluate a system's security posture. In the FedRAMP context, the SAP is generally developed by a Third-Party Assessment Organization (3PAO) and is used for both initial authorization assessments and, under a separate annual template, ongoing annual assessments of a Cloud Service Provider's (CSP's) system. The SAP is the planning artifact that precedes execution of testing; its results are documented separately in the corresponding Security Assessment Report (SAR). Note that the SAP itself is an assessment-planning document and does not by itself constitute an authorization decision, and template requirements and applicable revisions change over time, so readers should verify the current authoritative FedRAMP template and guidance. This entry does not address DoD RMF, CMMC, or non-FedRAMP agency-specific SAP requirements, which may differ.
Why it matters
The Security Assessment Plan is the document that gives an authorization assessment its structure and defensibility. Without a documented plan specifying which controls will be evaluated and how, an assessment risks being inconsistent, incomplete, or difficult to reproduce. In the FedRAMP context, the SAP is generally developed by an independent Third-Party Assessment Organization (3PAO), and this independence is a central reason the artifact carries weight: it establishes up front what the assessor intends to test and by what methods, so that an Authorizing Official can later trust the assessment results captured in the corresponding Security Assessment Report (SAR).
Who it's relevant to
Inside SAP
Common questions
Answers to the questions practitioners most commonly ask about SAP.