7 Most Common FedRAMP
Assessment Findings
Table of Contents
ToggleRanked Residual Findings from Lazarus Alliance FedRAMP 3PAO Assessments
Based on N = 12 completed formal assessments • January 2025 – June 2026 • Updated August 2026
These rankings reflect the NIST SP 800-53 control areas that most frequently generated residual findings (partially implemented or not satisfied) across N = 12 formal FedRAMP assessments conducted by Lazarus Alliance as an A2LA-accredited FedRAMP 3PAO. Rankings are based on frequency of residual findings after initial evidence review.
Relative Frequency of Top Residual Finding Areas (N = 12)
AU — Audit & Accountability
Primary issue observed: Incomplete event coverage, insufficient audit record content, weak or undocumented review cadence, or inadequate log protection and retention.
Why it fails: CSPs often log some events but miss required event types, cannot demonstrate that logs are reviewed on a defined schedule, or fail to protect log integrity and retention for the required period.
Remediation focus: Map required audit events to actual sources; ensure content meets AU-3; define and evidence review procedures; protect and retain logs appropriately.
CM — Configuration Management
Primary issue observed: Baselines not maintained as living, version-controlled artifacts; change control gaps; incomplete or outdated component inventories.
Why it fails: Generic hardening guides are presented as production baselines. Change processes exist on paper but lack operational evidence. Inventories drift from the actual authorization boundary.
Remediation focus: Establish authoritative baselines per component type; version-control them; document the change process with evidence; keep inventories current and mapped to the boundary.
AC — Access Control
Primary issue observed: Account management lifecycle gaps, incomplete least-privilege evidence, and insufficient remote access documentation.
Why it fails: Policies describe intent, but operational proof (joiner/mover/leaver records, periodic access reviews, privileged account inventories) is incomplete or inconsistent across the boundary.
Remediation focus: Demonstrate the full account lifecycle; show periodic reviews; prove least privilege with concrete role and permission evidence; document all remote access paths.
IA — Identification & Authentication
Primary issue observed: Multifactor authentication coverage gaps; authenticator management weaknesses; incomplete federation or external identity evidence.
Why it fails: MFA may exist for some paths but not for all privileged, remote, or federated access that can reach the authorization boundary. Authenticator lifecycle evidence is often thin.
Remediation focus: Inventory every relevant access path; enforce MFA consistently; retain configuration and access evidence that demonstrates enforcement.
SI — System & Information Integrity
Primary issue observed: Flaw remediation timelines not consistently met or evidenced; incomplete vulnerability scanning coverage; monitoring gaps.
Why it fails: Scanning may exist but miss portions of the boundary, lack authenticated context, or fail to show timely remediation and documented risk acceptance.
Remediation focus: Ensure full boundary coverage; define and meet remediation SLAs; retain scan results, tickets, and risk acceptance records.
CA — Assessment, Authorization, and Monitoring
Primary issue observed: Weak POA&M quality; continuous monitoring evidence that does not demonstrate ongoing operational effectiveness.
Why it fails: POA&Ms are vague, lack milestones or residual risk statements, or have unclear ownership. Continuous monitoring is treated as a point-in-time activity rather than an operational program.
Remediation focus: Write specific, time-bounded, owned POA&Ms; produce continuous monitoring artifacts that show recurring review and response, not one-time reports.
SC — System & Communications Protection
Primary issue observed: Boundary protection gaps; incomplete encryption implementation evidence; unclear control of external system connections.
Why it fails: Data-flow diagrams are incomplete or outdated; external connections that can reach the boundary are under-documented; cryptographic module validation evidence is missing or misapplied.
Remediation focus: Maintain accurate boundary and data-flow documentation; inventory and control external connections; retain clear evidence of encryption in transit and at rest where required.
Summary Ranking Table
| Rank | Family | Example Controls | Core Issue |
|---|---|---|---|
| 1 | AU — Audit & Accountability | AU-2, AU-3, AU-6, AU-12 | Event coverage, content, review, protection |
| 2 | CM — Configuration Management | CM-2, CM-3, CM-6, CM-8 | Baselines, change control, inventories |
| 3 | AC — Access Control | AC-2, AC-3, AC-6, AC-17 | Account lifecycle, least privilege, remote access |
| 4 | IA — Identification & Authentication | IA-2, IA-5, IA-8 | MFA coverage, authenticator management |
| 5 | SI — System & Information Integrity | SI-2, SI-3, SI-4 | Flaw remediation, scanning, monitoring |
| 6 | CA — Assessment, Authorization, Monitoring | CA-2, CA-5, CA-7 | POA&M quality, continuous monitoring |
| 7 | SC — System & Communications Protection | SC-7, SC-8, SC-13 | Boundary, external connections, encryption |
Cross-Cutting Evidence Problems
Across these findings, the same evidence weaknesses appeared repeatedly:
- SSP and control implementation statements that did not match the implemented architecture
- Screenshots and exports without system identifiers, dates, or configuration context
- Incomplete or non-representative log samples
- Missing or generic configuration baselines
- Unsupported inheritance claims without current customer responsibility matrices
- POA&M entries that were vague or lacked residual risk and ownership
In this dataset, 92% (11 of 12) of assessments required at least one additional evidence cycle after the initial package.
Related Benchmark Metrics (N = 12)
- Median formal assessment duration: 42 business days
- Assessments with ≥1 POA&M: 92% (11 of 12)
- Average evidence volume: ~3,400 artifacts
- Tightly bounded vs complex multi-component: 58% / 42%
Full context: 2026 FedRAMP Assessment Benchmark Report (Lazarus Alliance).
Authors & How to Cite
Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
A2LA-accredited FedRAMP 3PAO leadership; Authorized CMMC C3PAO; PCI DSS QSA firm principal.
How to Cite
Peters, M. D. (2026). 7 Most Common FedRAMP Assessment Findings. Lazarus Alliance, Inc. Data drawn from the 2026 FedRAMP Assessment Benchmark Report (N = 12).
About Lazarus Alliance
Lazarus Alliance is an A2LA-accredited FedRAMP Third-Party Assessment Organization (3PAO), an authorized CMMC C3PAO (CPN 10251), a PCI DSS Qualified Security Assessor (QSA), and a veteran-owned small business headquartered in Scottsdale, Arizona.
Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580 • [email protected]
https://lazarusalliance.com
© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Findings are observational aggregates from anonymized assessments and do not predict individual outcomes.
Scottsdale, Arizona • 1-888-896-7580 • lazarusalliance.com
Data Source
This analysis is based on the 2026 FedRAMP Assessment Benchmark Report, Lazarus Alliance's aggregate analysis of 12 completed formal FedRAMP assessment engagements conducted between January 2025 and June 2026.
Additional Analysis
- How Long Does a FedRAMP Assessment Take?
- How Much Evidence Does a FedRAMP Assessment Require?
- FedRAMP Authorization Boundary Complexity
- 7 Most Misunderstood FedRAMP Requirements Observed in Assessments
- FedRAMP POA&M Benchmarks
Talk with one of our experts
Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.
We're here to answer any questions you may have.
