FedRAMP Scope Questionnaire

This questionnaire helps Cloud Service Providers (CSPs) define the scope of a Cloud Service Offering (CSO) for a FedRAMP 20x Certification or applicable Rev5 transition assessment with Lazarus Alliance.

For FedRAMP 20x, scope determination focuses on identifying the information resources, components, services, dependencies, connections, third-party resources, security measures, evidence sources, and Key Security Indicators (KSIs) necessary to demonstrate that the CSO meets the applicable FedRAMP Certification requirements.

Lazarus Alliance uses the information provided here to help determine the appropriate FedRAMP Certification Class and assessment scope and to prepare for independent verification and validation activities. The questionnaire also identifies whether the offering is pursuing a 20x or Rev5 path so that the appropriate assessment requirements can be applied.

About this Questionnaire

Lazarus Alliance is a FedRAMP Recognized independent assessment service, historically referred to as a Third-Party Assessment Organization (3PAO). We perform independent verification and validation assessments supporting Cloud Service Providers pursuing and maintaining FedRAMP Certification.

FedRAMP 20x introduces a certification model organized around Certification Classes, persistent security evidence, Key Security Indicators (KSIs), machine-readable information, and independent verification and validation. Classes A, B and C are currently available.

This questionnaire helps establish the appropriate FedRAMP path, Certification Class, Cloud Service Offering scope, information resources, third-party dependencies, security measures, evidence sources, and independent assessment requirements before assessment activities begin.

For CSPs continuing through an applicable Rev5 transition path, Lazarus Alliance can also use the questionnaire to identify the applicable Rev5 baseline and traditional assessment requirements.

Lazarus Alliance, an accredited FedRAMP Third-Party Assessment Organization (3PAO), is historically about 46% faster than traditional 3PAO firms meaning that your authorizations can be achieved in 5–9 months. — Michael Peters, CEO & Founder"

Source Information:

https://lazarusalliance.com/services/audit-compliance/fedramp/

Section 1: General Information

Section 2: System Description and Authorization Boundary

Section 3: Data Flows and External Connections

Section 4: Components and Assets

Section 5: Facilities and Physical Scope

Section 6: Personnel and Roles

Section 7: Documentation and Readiness Confirmation

Section 8: Next Steps

Thank you for completing this questionnaire. A Lazarus Alliance FedRAMP 3PAO Cybervisor will be in contact with you soon.

For the official FedRAMP templates (including the SSP and RAR), refer to the FedRAMP website (fedramp.gov) and the 3PAO Readiness Assessment Report Guide.

Frequently Asked Questions

Cloud Service Providers (CSPs) pursuing or maintaining FedRAMP authorization—whether for initial, readiness, annual assessments, or continuous monitoring—should complete it when working with Lazarus Alliance as their 3PAO. In 2026, this is especially relevant for CSPs preparing for or transitioning under FedRAMP 20x pilots and updates, such as enhanced automation, real-time evidence, and continuous monitoring approaches.

The questionnaire is organized into several key sections:

  • Section 1: General Information (CSO name, CSP details, point of contact, FedRAMP baseline, service type, etc.)
  • Section 2: System Description and Authorization Boundary
  • Section 3: Data Flows and External Connections
  • Section 4: Components and Assets
  • Section 5: Facilities and Physical Scope
  • Section 6: Personnel and Roles
  • Section 7: Documentation and Readiness Confirmation
  • Section 8: Next Steps

It includes a mix of text descriptions, yes/no confirmations, and supporting details based on your existing documentation.

FedRAMP 20x (modernization program emphasizing automation, real-time evidence, and streamlined processes) entered Phase Two in early 2026, with pilot cohorts, RFCs (e.g., machine-readable packages, marketplace expansions), and timeline milestones through March 2026. Completing this questionnaire helps validate your boundary and readiness for these updates, ensuring compatibility with emerging requirements like continuous monitoring and Rev5 transitions.

A Lazarus Alliance FedRAMP 3PAO Cybervisor will contact you shortly after submission to review responses, advise on impact level (Low, Moderate, High, LI-SaaS), authorization path, and alignment with 2026 FedRAMP developments (including 20x pilots and new guidance from fedramp.gov). This leads to scheduling your full assessment.

Lazarus Alliance remains historically about 46% faster than traditional 3PAO firms. In 2024–2025 real-world averages (and continuing into 2026 with 20x efficiencies), authorizations often complete in 5–9 months, depending on CSO complexity, baseline, and readiness—positioning CSPs well for accelerated 20x-era timelines.

As an accredited 3PAO with the FedRAMP Authorized AI-Enabled Continuum GRC platform, Lazarus Alliance offers expert guidance on impact levels, authorization paths, and 20x modernization (automation, real-time monitoring). This helps CSPs achieve faster FedRAMP Marketplace listing while navigating 2026 program changes like Phase Two pilots and new RFCs.

It supports all current FedRAMP baselines (LI-SaaS, Low, Moderate, High), service models (IaaS, PaaS, SaaS, Other), and overlays (e.g., DoD). In 2026, it accommodates transitions to new designations, Rev5 Certified Levels, and 20x pilot requirements for modernized assessment