The free FedRAMP Customer Responsibility Matrix Template
A CRM template clarifying which NIST 800-53 controls are provider-, customer-, or shared-responsibility in a FedRAMP system.
The short version
What is the FedRAMP Customer Responsibility Matrix?
A FedRAMP Customer Responsibility Matrix (CRM) is a control-by-control template that states, for every NIST 800-53 control in a cloud system, whether the provider, the customer, or both are responsible for implementing it. It pairs with the System Security Plan and gives customer teams the implementation guidance they need to complete the controls they inherit when they use a FedRAMP-authorized service.
Updated . Free to download, no credit card required.
FedRAMP Customer Responsibility Matrix Template
A CRM template clarifying which NIST 800-53 controls are provider-, customer-, or shared-responsibility in a FedRAMP system.
- Control-by-control responsibility designations
- Provider / customer / shared / inherited columns
- Customer-implementation guidance prompts
- Alignment to the SSP and SAR
Frequently asked questions
Turn the template into a live program
Start a free trial and the underlying control library lands in your workspace, ready to assess, assign, and report.
No credit card required · 30-day free trial · Cancel anytime