R
RampReady
Practitioner Compliance Field Manuals

Federal Compliance
Field Manuals

Practitioner-grade references for CMMC, FedRAMP 20x, DoD RMF, NIST AI RMF, PCI DSS, and SOC 2. Written by a 30-year DoD and commercial compliance veteran — for ISSOs, assessors, auditors, and GRC practitioners doing the real work.

CMMC
Best Seller
CMMC Level 2 Assessment Field Guide
View on Amazon
CMMC Level 2 Assessment Field Guide
C3PAO Edition
The C3PAO practitioner's reference for conducting CMMC Level 2 assessments. Covers all 110 practices across 14 domains with assessment objectives, evidence requirements, and interview guidance aligned to the CMMC Assessment Guide v2.13 and 32 CFR Part 170.
CMMC Level 2 ISSO / Implementer Field Guide
View on Amazon
CMMC Level 2 ISSO / Implementer Field Guide
OSC Edition
Built for ISSOs and security engineers implementing CMMC Level 2 at an OSC. Covers all 110 NIST SP 800-171 practices with implementation guidance, documentation requirements, SSP construction, and POA&M management under 32 CFR Part 170.
CMMC Level 2 Readiness Field Guide
View on Amazon
CMMC Level 2 Readiness Field Guide
Documentation & Scoping
The documentation and scoping companion to CMMC Level 2. Covers CUI identification, scoping decisions, system boundary definition, SSP structure, and POA&M construction — the documentation layer that assessors evaluate before they look at a single control.
CMMC Level 1 Field Guide
View on Amazon
CMMC Level 1 Field Guide
ISSO / Implementer Edition
The practitioner guide to CMMC Level 1 self-assessment and FAR 52.204-21 compliance. Covers all 15 FCI safeguarding practices across 6 domains with implementation guidance and annual self-assessment requirements.
New
CMMC ESP & MSP Field Manual
View on Amazon
CMMC ESP & MSP Field Manual
Scoping, SPD & Assessment for MSPs
The definitive guide for MSPs, MSSPs, and cloud providers operating in the Defense Industrial Base. Covers ESP and MSP determination, Security Protection Data triggers, CSP routing, inheritance, CRM construction, and assessment treatment under 32 CFR Part 170.
New
Prime Contractor Flow-Down Field Manual
View on Amazon
Prime Contractor Flow-Down Field Manual
DFARS & CMMC Across the Supply Chain
The mid-tier contractor's guide to DFARS and CMMC flow-down requirements. Covers prime-to-sub obligations, DFARS 252.204-7012 and 7021 clause requirements, subcontractor oversight, CUI flow-down, and supply chain compliance management.
New
NIST SP 800-171 Self-Assessment Field Manual
View on Amazon
NIST SP 800-171 Self-Assessment Field Manual
OSA / Self-Assessor Edition
A step-by-step guide to planning, conducting, scoring, and documenting a NIST SP 800-171 self-assessment. Covers the OSA methodology, SPRS score calculation, assessment evidence requirements, and POA&M development for DoD contractors.
New
CUI Field Manual
View on Amazon
CUI Field Manual
Identifying, Marking, Handling & Safeguarding
The complete practitioner guide to the CUI Program under 32 CFR Part 2002. Covers CUI identification and determination, marking discipline, the CUI Registry, safeguarding requirements, contractor obligations under DFARS 252.204-7012, and the CUI-to-CMMC compliance chain.
FedRAMP
New
FedRAMP 20x Field Manual
View on Amazon
FedRAMP 20x Field Manual
CR26 Edition — 20x Certification Guide
The practitioner's guide to FedRAMP 20x certification under the Consolidated Rules for 2026. Covers the CR26 authorization pathway, all 46 Key Security Indicators, KSI assessment methodology, and the technical and documentation requirements for CSPs pursuing 20x authorization.
New
FedRAMP 20x ISSO Field Manual
View on Amazon
FedRAMP 20x ISSO Field Manual
CR26 Edition — Operating & Maintaining
Built for ISSOs operating a FedRAMP 20x authorized cloud service. Covers continuous monitoring under CR26, KSI maintenance, evidence collection, ConMon reporting, significant change management, and the operational discipline required to sustain a 20x authorization.
Cloud Authorization Field Manual
View on Amazon
Cloud Authorization Field Manual
High Edition — 410 Controls
Complete coverage of all 410 FedRAMP High baseline controls across 18 control families. Includes implementation guidance, parameter values, assessment considerations, and field techniques for CSPs pursuing or maintaining FedRAMP High authorization.
Cloud Authorization Field Manual
View on Amazon
Cloud Authorization Field Manual
Moderate Edition — 323 Controls
Complete coverage of all 323 FedRAMP Moderate baseline controls. The most widely used baseline in the FedRAMP marketplace, covering all 18 control families with implementation guidance, parameter values, and field techniques.
Cloud Authorization Field Manual
View on Amazon
Cloud Authorization Field Manual
Low Edition — 156 Controls
Complete coverage of all 156 FedRAMP Low baseline controls for CSPs targeting the entry-level federal authorization. Covers all 18 control families with implementation guidance and assessment considerations.
Artificial Intelligence
NIST AI RMF Field Manual
View on Amazon
NIST AI RMF Field Manual
Govern · Map · Measure · Manage
Operationalizing the NIST AI Risk Management Framework. Covers all four core functions — Govern, Map, Measure, Manage — with 72 subcategories, the NIST AI 600-1 Generative AI Profile, 12 GenAI risk categories, and actionable implementation guidance.
New
AI Internal Audit Field Manual
View on Amazon
AI Internal Audit Field Manual
Planning, Executing & Reporting AI Audits
The practitioner guide to auditing AI governance, risk management, and controls. Covers audit universe development, AI-specific risk assessment, governance program auditing, vendor AI assessment audits, and reporting to boards and senior leadership.
New
ISO 42001 AI Governance Field Manual
View on Amazon
ISO 42001 AI Governance Field Manual
AI Management System — ISO/IEC 42001
A practitioner's implementation guide to ISO/IEC 42001, the international standard for AI management systems. Covers AIMS design and implementation, risk management, vendor oversight, internal controls, and audit readiness for ISO 42001 certification.
Coming Soon
AI Governance Program Field Manual
AI Governance Program Field Manual
Structure · Policy · Risk · Audit
Building and running an enterprise AI governance program. Covers governance structure, policy frameworks, AI risk inventory, oversight bodies, assessment methodologies, monitoring, and audit readiness across commercial and regulatory AI governance requirements.
Coming Soon
Coming Soon
AI Risk & Vendor Governance Field Manual
Risk Registers · Due Diligence · Monitoring
A practitioner's guide to AI risk registers, third-party AI assessments, vendor due diligence, and continuous monitoring. Covers the full AI vendor governance lifecycle from initial assessment through contract requirements and ongoing monitoring programs.

ⓘ Book links are Amazon affiliate links (rampready-20). Purchases support this resource hub at no extra cost to you.