R
RampReady
Your compliance starting point

Compliance
Britannica

The Compliance Command Center — official resources, documentation, and field manuals for every major federal and commercial compliance framework.

FedRAMP
Federal Risk and Authorization Management Program

The US government standard for cloud service providers seeking to sell to federal agencies. Covers Low, Moderate, and High impact levels plus the new FedRAMP 20x pathway.

CMMC
Cybersecurity Maturity Model Certification

DoD framework requiring defense contractors to demonstrate cybersecurity maturity across three levels. Mandatory for all DoD contracts involving Controlled Unclassified Information.

GovRAMP
Government Risk and Authorization Management Program

State and local government cloud security authorization program, rebranded from StateRAMP. Helps government entities verify cloud vendors meet security standards.

DoD RMF
Risk Management Framework for DoD IT

The six-step NIST Risk Management Framework as implemented by the Department of Defense. Required for all DoD information systems before achieving an Authority to Operate.

SOC 2
System and Organization Controls 2

AICPA framework for service organizations covering security, availability, processing integrity, confidentiality, and privacy. Type II reports cover a period of time and are most commonly required.

PCI DSS
Payment Card Industry Data Security Standard

Global standard for organizations that handle cardholder data. Version 4.0.1 is the current standard with new requirements phasing in through 2025 and beyond.

MITRE ATT&CK
Adversarial Tactics, Techniques & Common Knowledge

Globally accessible knowledge base of adversary tactics and techniques based on real-world observations. Used for threat modeling, red teaming, and detection engineering.

Independent resource hub. Not affiliated with any framework body. Field manual links are affiliate links. Always verify at official sources.