Skip to main content
Category: Authorization & Accreditation

Security Assessment Report (SAR)

Also known as: SAR, Security Assessment Report
Simply put

A Security Assessment Report (SAR) is a document that records the results of a security assessment, describing what an independent assessor found when reviewing a system's controls. It generally summarizes identified weaknesses, the risks that remain, and recommendations for correcting problems. The SAR helps decision-makers understand a system's security posture, but on its own it does not grant permission to operate a system.

Formal definition

The SAR provides a disciplined and structured approach for documenting the findings of the security control assessor and recommendations for correcting any identified deficiencies. In most implementations it presents the results of assessing the security controls in a system against the applicable baseline, including a summary of the residual risks remaining at the conclusion of the assessment. Within the FedRAMP process, a SAR is generally produced for initial authorization assessments, annual (continuous monitoring) assessments, and significant change assessments, and documents the assessment results for a Cloud Service Offering (CSO) as prepared by the control assessment team. Practitioners should note that the SAR is an assessment artifact, distinct from the authorization decision itself: it informs, but does not constitute, an Authority to Operate (ATO), which is a separate risk-acceptance determination made by an authorizing official. Specific content, templates, and applicability vary by governing program and revision, and readers should confirm requirements against the current official FedRAMP and NIST source material.

Why it matters

The Security Assessment Report is the evidentiary bridge between a technical security assessment and an authorizing official's risk-based decision. Because it documents the assessor's findings, the residual risks remaining at the conclusion of the assessment, and recommendations for correcting identified deficiencies, the SAR gives decision-makers a structured, independent basis for understanding a system's actual security posture rather than relying on self-attestation. Without a credible SAR, an authorizing official would be accepting risk without a disciplined record of what was tested and what weaknesses were found.

A persistent and expert-flagged mistake is conflating the SAR with the authorization itself. The SAR is an assessment artifact that informs but does not constitute an Authority to Operate (ATO). The ATO is a separate risk-acceptance determination made by an authorizing official; the SAR is one of the inputs to that determination. Confusing the assessment with the authorization can lead organizations to believe a system is cleared for operation simply because an assessment was completed, when in fact no risk-acceptance decision has yet been made.

It is also important to recognize that a SAR describes a system's posture at a point in time. Within the FedRAMP process, a SAR is generally produced for initial authorization assessments, annual (continuous monitoring) assessments, and significant change assessments, which reflects the reality that security posture and residual risk evolve. An ATO is time-bound and subject to continuous monitoring, so the SAR should be understood as a recurring input to ongoing risk management rather than a one-time deliverable. Specific content, templates, and applicability vary by governing program and revision, and readers should confirm current requirements against official FedRAMP and NIST source material.

Who it's relevant to

Authorizing Officials
Authorizing officials rely on the SAR as a primary input to their risk-acceptance decisions. The report's summary of residual risks and assessor findings supports an informed ATO determination, but officials should treat the SAR as informing rather than constituting the authorization, and should remember that any resulting ATO is time-bound and subject to continuous monitoring.
Security Control Assessors and Assessment Teams
Assessors and control assessment teams produce the SAR, documenting findings against the applicable baseline and providing recommendations for correcting identified deficiencies. In the FedRAMP context, these teams prepare the SAR documenting the assessment results for a Cloud Service Offering across initial, annual, and significant change assessments, and should follow the current official template and program guidance.
Cloud Service Providers (CSPs)
CSPs pursuing or maintaining a FedRAMP authorization for a Cloud Service Offering are the subject of the assessment the SAR documents. Because a SAR is generally expected for initial authorization, annual continuous monitoring, and significant change assessments, CSPs should plan for recurring assessments rather than a single point-in-time review.
Compliance Officers and ISSMs
Compliance officers and information system security managers use the SAR to understand where residual risks and weaknesses lie and to drive remediation planning. They play a role in ensuring that recommendations are tracked and that the SAR is not mistaken for either an authorization decision or evidence that a system is fully secure.
Auditors and Oversight Reviewers
Auditors and oversight reviewers reference the SAR as documented evidence of what was assessed, what was found, and what risk remained at the conclusion of the assessment. They should verify that the report reflects the applicable baseline and current program requirements, and confirm specifics against official FedRAMP and NIST source material given that templates and applicability vary by revision.

Inside SAR

Assessment Findings
A documented record of the results from testing and evaluating security controls, generally indicating whether each assessed control was satisfied, other than satisfied, or otherwise deficient based on the assessor's determinations.
Identified Weaknesses and Deficiencies
A description of control weaknesses, vulnerabilities, or deficiencies discovered during the assessment, which typically inform the development of a Plan of Action and Milestones (POA&M) and the authorizing official's risk determination.
Assessment Methods and Scope
Information about how controls were assessed, such as examine, interview, and test methods, along with the scope of the system boundary and controls evaluated, so the reader can understand the basis and limits of the findings.
Risk-Related Information
Analysis intended to support the authorizing official's risk-based decision, generally characterizing the severity or potential impact of identified weaknesses as of the time of assessment.
Assessor Recommendations
Recommendations from the assessor regarding remediation or corrective actions, which are advisory inputs to the authorization decision rather than binding directives.

Common questions

Answers to the questions practitioners most commonly ask about SAR.

Does a favorable Security Assessment Report mean my system is authorized to operate?
No. This is a common and important distinction to correct: assessment is not authorization. The SAR generally documents the assessor's findings on how effectively controls are implemented, but it does not itself grant an Authority to Operate (ATO). Under the Risk Management Framework, the SAR is an input the authorizing official (AO) weighs, along with other authorization package artifacts, when making a risk-based authorization decision. Authorization is a separate, distinct step reserved to the AO.
If my SAR shows all controls as compliant, does that mean my system is secure?
Not necessarily. Compliance as reflected in a SAR should not be equated with security. A SAR generally represents a point-in-time evaluation of control implementation against an applicable baseline and assessment procedures. It does not guarantee protection against evolving threats, nor does it substitute for ongoing security operations. This is why continuous monitoring accompanies authorization rather than ending at the SAR.
Who prepares the SAR, and can the system owner write it?
The SAR is generally produced by the assessor or assessment team that conducts the control assessment. Independence expectations vary by program, impact level, and agency tailoring, and separation between those who implement controls and those who assess them is a recurring theme in the applicable guidance. Confirm the specific independence and preparation requirements against your program's current authoritative direction, as these can differ across federal civilian, DoD, and other contexts.
What typically goes into a SAR alongside the findings?
A SAR generally documents the assessment findings for the controls evaluated, including identified weaknesses or deficiencies and supporting evidence or rationale. In most implementations it feeds related artifacts such as a plan of action and milestones (POA&M) for unresolved findings. For the precise required contents and format, consult the current authoritative assessment guidance and any agency-specific templates rather than assuming a fixed structure.
How does the SAR relate to the rest of the authorization package?
The SAR is generally one component of the authorization package that the authorizing official reviews. It is typically read together with other package artifacts and the results feed decisions about remediation and residual risk. Because the SAR reflects a point-in-time evaluation, its findings are also expected to be revisited through continuous monitoring rather than treated as final.
How long does a SAR remain valid?
A SAR generally reflects the state of the system at the time of assessment, so its usefulness diminishes as the system, threat environment, or control implementation changes. Rather than treating it as indefinitely valid, organizations should reassess in accordance with their continuous monitoring strategy and any reassessment or reauthorization requirements that apply. Verify the specific timing expectations against your program's current authoritative guidance.

Common misconceptions

A completed SAR means the system is authorized to operate.
The SAR documents assessment results only; it is an input to the authorization decision. Assessment and authorization are distinct steps, and an Authority to Operate is issued separately by the authorizing official, remains time-bound, and is subject to continuous monitoring.
A SAR with findings marked satisfied demonstrates the system is secure.
Compliance reflected in assessment findings is not equivalent to security. The SAR reports the state of assessed controls at a point in time within a defined scope and does not guarantee ongoing security across changing conditions or unassessed areas.
The SAR is a static, one-time deliverable.
Assessment results generally need to be maintained current as part of continuous monitoring; findings can change as the environment, controls, and threats evolve, so a SAR reflects conditions as of the applicable assessment rather than a permanent status.

Best practices

Clearly document the assessment scope, system boundary, and methods used so readers can understand what was and was not evaluated.
Ensure findings feed directly into the Plan of Action and Milestones (POA&M) so identified weaknesses are tracked to remediation.
Keep the SAR distinct from the authorization decision, treating it as an input the authorizing official uses rather than as an approval itself.
Characterize the severity and potential impact of weaknesses to support the authorizing official's risk-based decision.
Update assessment results as part of continuous monitoring rather than treating the SAR as a one-time deliverable.
Verify terminology, control references, and format requirements against the current authoritative guidance applicable to your system type, as agency tailoring and revisions may differ.