7 Most Common FedRAMP
Assessment Findings
Table of Contents
ToggleRanked Residual Findings from Lazarus Alliance FedRAMP 3PAO Assessments
Based on N = 12 completed formal assessments • January 2025 – June 2026 • Updated August 2026
These rankings reflect the NIST SP 800-53 control areas that most frequently generated residual findings (partially implemented or not satisfied) across N = 12 formal FedRAMP assessments conducted by Lazarus Alliance as an A2LA-accredited FedRAMP 3PAO. Rankings are based on frequency of residual findings after initial evidence review.
Relative Frequency of Top Residual Finding Areas (N = 12)
AU — Audit & Accountability
Primary issue observed: Incomplete event coverage, insufficient audit record content, weak or undocumented review cadence, or inadequate log protection and retention.
Why it fails: CSPs often log some events but miss required event types, cannot demonstrate that logs are reviewed on a defined schedule, or fail to protect log integrity and retention for the required period.
Remediation focus: Map required audit events to actual sources; ensure content meets AU-3; define and evidence review procedures; protect and retain logs appropriately.
CM — Configuration Management
Primary issue observed: Baselines not maintained as living, version-controlled artifacts; change control gaps; incomplete or outdated component inventories.
Why it fails: Generic hardening guides are presented as production baselines. Change processes exist on paper but lack operational evidence. Inventories drift from the actual authorization boundary.
Remediation focus: Establish authoritative baselines per component type; version-control them; document the change process with evidence; keep inventories current and mapped to the boundary.
AC — Access Control
Primary issue observed: Account management lifecycle gaps, incomplete least-privilege evidence, and insufficient remote access documentation.
Why it fails: Policies describe intent, but operational proof (joiner/mover/leaver records, periodic access reviews, privileged account inventories) is incomplete or inconsistent across the boundary.
Remediation focus: Demonstrate the full account lifecycle; show periodic reviews; prove least privilege with concrete role and permission evidence; document all remote access paths.
IA — Identification & Authentication
Primary issue observed: Multifactor authentication coverage gaps; authenticator management weaknesses; incomplete federation or external identity evidence.
Why it fails: MFA may exist for some paths but not for all privileged, remote, or federated access that can reach the authorization boundary. Authenticator lifecycle evidence is often thin.
Remediation focus: Inventory every relevant access path; enforce MFA consistently; retain configuration and access evidence that demonstrates enforcement.
SI — System & Information Integrity
Primary issue observed: Flaw remediation timelines not consistently met or evidenced; incomplete vulnerability scanning coverage; monitoring gaps.
Why it fails: Scanning may exist but miss portions of the boundary, lack authenticated context, or fail to show timely remediation and documented risk acceptance.
Remediation focus: Ensure full boundary coverage; define and meet remediation SLAs; retain scan results, tickets, and risk acceptance records.
CA — Assessment, Authorization, and Monitoring
Primary issue observed: Weak POA&M quality; continuous monitoring evidence that does not demonstrate ongoing operational effectiveness.
Why it fails: POA&Ms are vague, lack milestones or residual risk statements, or have unclear ownership. Continuous monitoring is treated as a point-in-time activity rather than an operational program.
Remediation focus: Write specific, time-bounded, owned POA&Ms; produce continuous monitoring artifacts that show recurring review and response, not one-time reports.
SC — System & Communications Protection
Primary issue observed: Boundary protection gaps; incomplete encryption implementation evidence; unclear control of external system connections.
Why it fails: Data-flow diagrams are incomplete or outdated; external connections that can reach the boundary are under-documented; cryptographic module validation evidence is missing or misapplied.
Remediation focus: Maintain accurate boundary and data-flow documentation; inventory and control external connections; retain clear evidence of encryption in transit and at rest where required.
Summary Ranking Table
| Rank | Family | Example Controls | Core Issue |
|---|---|---|---|
| 1 | AU — Audit & Accountability | AU-2, AU-3, AU-6, AU-12 | Event coverage, content, review, protection |
| 2 | CM — Configuration Management | CM-2, CM-3, CM-6, CM-8 | Baselines, change control, inventories |
| 3 | AC — Access Control | AC-2, AC-3, AC-6, AC-17 | Account lifecycle, least privilege, remote access |
| 4 | IA — Identification & Authentication | IA-2, IA-5, IA-8 | MFA coverage, authenticator management |
| 5 | SI — System & Information Integrity | SI-2, SI-3, SI-4 | Flaw remediation, scanning, monitoring |
| 6 | CA — Assessment, Authorization, Monitoring | CA-2, CA-5, CA-7 | POA&M quality, continuous monitoring |
| 7 | SC — System & Communications Protection | SC-7, SC-8, SC-13 | Boundary, external connections, encryption |
Cross-Cutting Evidence Problems
Across these findings, the same evidence weaknesses appeared repeatedly:
- SSP and control implementation statements that did not match the implemented architecture
- Screenshots and exports without system identifiers, dates, or configuration context
- Incomplete or non-representative log samples
- Missing or generic configuration baselines
- Unsupported inheritance claims without current customer responsibility matrices
- POA&M entries that were vague or lacked residual risk and ownership
In this dataset, 92% (11 of 12) of assessments required at least one additional evidence cycle after the initial package.
Related Benchmark Metrics (N = 12)
- Median formal assessment duration: 42 business days
- Assessments with ≥1 POA&M: 92% (11 of 12)
- Average evidence volume: ~3,400 artifacts
- Tightly bounded vs complex multi-component: 58% / 42%
Full context: 2026 FedRAMP Assessment Benchmark Report (Lazarus Alliance).
Authors & How to Cite
Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
A2LA-accredited FedRAMP 3PAO leadership; Authorized CMMC C3PAO; PCI DSS QSA firm principal.
How to Cite
Peters, M. D. (2026). 7 Most Common FedRAMP Assessment Findings. Lazarus Alliance, Inc. Data drawn from the 2026 FedRAMP Assessment Benchmark Report (N = 12).
About Lazarus Alliance
Lazarus Alliance is an A2LA-accredited FedRAMP Third-Party Assessment Organization (3PAO), an authorized CMMC C3PAO (CPN 10251), a PCI DSS Qualified Security Assessor (QSA), and a veteran-owned small business headquartered in Scottsdale, Arizona.
Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580 • [email protected]
https://lazarusalliance.com
© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Findings are observational aggregates from anonymized assessments and do not predict individual outcomes.
Scottsdale, Arizona • 1-888-896-7580 • lazarusalliance.com
Talk with one of our experts
Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.
We're here to answer any questions you may have.
