7 Most Common FedRAMP Assessment Findings | Lazarus Alliance

7 Most Common FedRAMP
Assessment Findings

Ranked Residual Findings from Lazarus Alliance FedRAMP 3PAO Assessments

Based on N = 12 completed formal assessments  •  January 2025 – June 2026  •  Updated August 2026

These rankings reflect the NIST SP 800-53 control areas that most frequently generated residual findings (partially implemented or not satisfied) across N = 12 formal FedRAMP assessments conducted by Lazarus Alliance as an A2LA-accredited FedRAMP 3PAO. Rankings are based on frequency of residual findings after initial evidence review.

Relative Frequency of Top Residual Finding Areas (N = 12)

#1

AU — Audit & Accountability

Examples: AU-2, AU-3, AU-6, AU-12

Primary issue observed: Incomplete event coverage, insufficient audit record content, weak or undocumented review cadence, or inadequate log protection and retention.

Why it fails: CSPs often log some events but miss required event types, cannot demonstrate that logs are reviewed on a defined schedule, or fail to protect log integrity and retention for the required period.

Remediation focus: Map required audit events to actual sources; ensure content meets AU-3; define and evidence review procedures; protect and retain logs appropriately.

#2

CM — Configuration Management

Examples: CM-2, CM-3, CM-6, CM-8

Primary issue observed: Baselines not maintained as living, version-controlled artifacts; change control gaps; incomplete or outdated component inventories.

Why it fails: Generic hardening guides are presented as production baselines. Change processes exist on paper but lack operational evidence. Inventories drift from the actual authorization boundary.

Remediation focus: Establish authoritative baselines per component type; version-control them; document the change process with evidence; keep inventories current and mapped to the boundary.

#3

AC — Access Control

Examples: AC-2, AC-3, AC-6, AC-17

Primary issue observed: Account management lifecycle gaps, incomplete least-privilege evidence, and insufficient remote access documentation.

Why it fails: Policies describe intent, but operational proof (joiner/mover/leaver records, periodic access reviews, privileged account inventories) is incomplete or inconsistent across the boundary.

Remediation focus: Demonstrate the full account lifecycle; show periodic reviews; prove least privilege with concrete role and permission evidence; document all remote access paths.

#4

IA — Identification & Authentication

Examples: IA-2, IA-5, IA-8

Primary issue observed: Multifactor authentication coverage gaps; authenticator management weaknesses; incomplete federation or external identity evidence.

Why it fails: MFA may exist for some paths but not for all privileged, remote, or federated access that can reach the authorization boundary. Authenticator lifecycle evidence is often thin.

Remediation focus: Inventory every relevant access path; enforce MFA consistently; retain configuration and access evidence that demonstrates enforcement.

#5

SI — System & Information Integrity

Examples: SI-2, SI-3, SI-4

Primary issue observed: Flaw remediation timelines not consistently met or evidenced; incomplete vulnerability scanning coverage; monitoring gaps.

Why it fails: Scanning may exist but miss portions of the boundary, lack authenticated context, or fail to show timely remediation and documented risk acceptance.

Remediation focus: Ensure full boundary coverage; define and meet remediation SLAs; retain scan results, tickets, and risk acceptance records.

#6

CA — Assessment, Authorization, and Monitoring

Examples: CA-2, CA-5, CA-7

Primary issue observed: Weak POA&M quality; continuous monitoring evidence that does not demonstrate ongoing operational effectiveness.

Why it fails: POA&Ms are vague, lack milestones or residual risk statements, or have unclear ownership. Continuous monitoring is treated as a point-in-time activity rather than an operational program.

Remediation focus: Write specific, time-bounded, owned POA&Ms; produce continuous monitoring artifacts that show recurring review and response, not one-time reports.

#7

SC — System & Communications Protection

Examples: SC-7, SC-8, SC-13

Primary issue observed: Boundary protection gaps; incomplete encryption implementation evidence; unclear control of external system connections.

Why it fails: Data-flow diagrams are incomplete or outdated; external connections that can reach the boundary are under-documented; cryptographic module validation evidence is missing or misapplied.

Remediation focus: Maintain accurate boundary and data-flow documentation; inventory and control external connections; retain clear evidence of encryption in transit and at rest where required.

Summary Ranking Table

RankFamilyExample ControlsCore Issue
1AU — Audit & AccountabilityAU-2, AU-3, AU-6, AU-12Event coverage, content, review, protection
2CM — Configuration ManagementCM-2, CM-3, CM-6, CM-8Baselines, change control, inventories
3AC — Access ControlAC-2, AC-3, AC-6, AC-17Account lifecycle, least privilege, remote access
4IA — Identification & AuthenticationIA-2, IA-5, IA-8MFA coverage, authenticator management
5SI — System & Information IntegritySI-2, SI-3, SI-4Flaw remediation, scanning, monitoring
6CA — Assessment, Authorization, MonitoringCA-2, CA-5, CA-7POA&M quality, continuous monitoring
7SC — System & Communications ProtectionSC-7, SC-8, SC-13Boundary, external connections, encryption

Cross-Cutting Evidence Problems

Across these findings, the same evidence weaknesses appeared repeatedly:

  • SSP and control implementation statements that did not match the implemented architecture
  • Screenshots and exports without system identifiers, dates, or configuration context
  • Incomplete or non-representative log samples
  • Missing or generic configuration baselines
  • Unsupported inheritance claims without current customer responsibility matrices
  • POA&M entries that were vague or lacked residual risk and ownership

In this dataset, 92% (11 of 12) of assessments required at least one additional evidence cycle after the initial package.

Related Benchmark Metrics (N = 12)

  • Median formal assessment duration: 42 business days
  • Assessments with ≥1 POA&M: 92% (11 of 12)
  • Average evidence volume: ~3,400 artifacts
  • Tightly bounded vs complex multi-component: 58% / 42%

Full context: 2026 FedRAMP Assessment Benchmark Report (Lazarus Alliance).

Authors & How to Cite

Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
A2LA-accredited FedRAMP 3PAO leadership; Authorized CMMC C3PAO; PCI DSS QSA firm principal.

How to Cite
Peters, M. D. (2026). 7 Most Common FedRAMP Assessment Findings. Lazarus Alliance, Inc. Data drawn from the 2026 FedRAMP Assessment Benchmark Report (N = 12).

About Lazarus Alliance

Lazarus Alliance is an A2LA-accredited FedRAMP Third-Party Assessment Organization (3PAO), an authorized CMMC C3PAO (CPN 10251), a PCI DSS Qualified Security Assessor (QSA), and a veteran-owned small business headquartered in Scottsdale, Arizona.

Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580  •  [email protected]
https://lazarusalliance.com

© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Findings are observational aggregates from anonymized assessments and do not predict individual outcomes.

Talk with one of our experts

Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.

We're here to answer any questions you may have.

Download our company brochure.