Security Decision Record (SDR)
Under FedRAMP 20x the Security Decision Record is the core package artifact. It replaces the traditional System Security Plan (SSP) as the CSP's machine-readable record of security decisions. FedRAMP publishes the JSON Schema; scm.cc validates against that schema and does not invent fields.
Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.
Technical detail
The pinned schema is dated 2026-06-24 (schemaVersion 1.1.1). Required top-level properties are certificationPackageOverviewUri and fedRampRequirements. Optional sections include metadata, portsAndProtocols, securityControls, and keySecurityIndicators. Independent assessment sections stay empty unless an assessor actually filled them — scm.cc does not fabricate ksiAssessment or frrAssessment.
How to implement
Build the SDR from real decisions and evidence. Use the SDR Builder tool when it ships; until then the in-app assembler in sdr.ts emits schema-shaped JSON from stored KSI evaluations with empty assessor sections. Examples on this hub use no customer data.
Common mistakes
- Treating a generated SDR as an assessor-approved SSP or SAR. - Filling independent-assessment fields without an independent assessor. - Adding properties that are not in the official schema.
Pinned schema fields (2026-06-24)
| Property | Required | Schema title |
|---|---|---|
| certificationPackageOverviewUri | yes | certificationPackageOverviewUri |
| metadata | no | Security Decision Record Metadata |
| portsAndProtocols | no | Ports and Protocols |
| securityControls | no | NIST 800-53 Security Controls |
| fedRampRequirements | yes | FedRAMP Requirements |
| keySecurityIndicators | no | FedRAMP Key Security Indicators |
Build one with the SDR Builder (in progress). scm.cc does not fill independent-assessment fields.
Questions teams ask
- Does the SDR replace the SSP?
- Yes, under 20x the SDR is the core package artifact in place of a traditional System Security Plan. Confirm the current FedRAMP SDR reference.
- Can scm.cc sign an SDR as an assessor?
- No. scm.cc is not a FedRAMP Recognized Independent Assessor. Assessor sections stay empty unless an assessor filled them.
Related hub pages
Primary sources
- Security Decision Record (replaces the SSP) (retrieved 2026-09-27)
- FedRAMP Certification reference (classes, KSI metrics window) (retrieved 2026-09-27)
Last verified 2026-09-27. FedRAMP.gov is authoritative.