Security Decision Record (SDR)

Under FedRAMP 20x the Security Decision Record is the core package artifact. It replaces the traditional System Security Plan (SSP) as the CSP's machine-readable record of security decisions. FedRAMP publishes the JSON Schema; scm.cc validates against that schema and does not invent fields.

Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.

Technical detail

The pinned schema is dated 2026-06-24 (schemaVersion 1.1.1). Required top-level properties are certificationPackageOverviewUri and fedRampRequirements. Optional sections include metadata, portsAndProtocols, securityControls, and keySecurityIndicators. Independent assessment sections stay empty unless an assessor actually filled them — scm.cc does not fabricate ksiAssessment or frrAssessment.

How to implement

Build the SDR from real decisions and evidence. Use the SDR Builder tool when it ships; until then the in-app assembler in sdr.ts emits schema-shaped JSON from stored KSI evaluations with empty assessor sections. Examples on this hub use no customer data.

Common mistakes

- Treating a generated SDR as an assessor-approved SSP or SAR. - Filling independent-assessment fields without an independent assessor. - Adding properties that are not in the official schema.

Pinned schema fields (2026-06-24)

PropertyRequiredSchema title
certificationPackageOverviewUriyescertificationPackageOverviewUri
metadatanoSecurity Decision Record Metadata
portsAndProtocolsnoPorts and Protocols
securityControlsnoNIST 800-53 Security Controls
fedRampRequirementsyesFedRAMP Requirements
keySecurityIndicatorsnoFedRAMP Key Security Indicators

Build one with the SDR Builder (in progress). scm.cc does not fill independent-assessment fields.

Questions teams ask

Does the SDR replace the SSP?
Yes, under 20x the SDR is the core package artifact in place of a traditional System Security Plan. Confirm the current FedRAMP SDR reference.
Can scm.cc sign an SDR as an assessor?
No. scm.cc is not a FedRAMP Recognized Independent Assessor. Assessor sections stay empty unless an assessor filled them.

Related hub pages

Primary sources

Last verified 2026-09-27. FedRAMP.gov is authoritative.

Explore the knowledge hub