| Security Decision Record (SDR) | JSON + Markdown (FedRAMP 2026-06-24 schema) | Per-rule and per-KSI implementation, validation and assessment statements for the Class A package, with SOC 2 Type II control mappings and a gap statement for each partially implemented rule. | Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed |
| Ongoing Certification Report (OCR) — example | JSON + Markdown (FedRAMP 2026-06-24 schema) | Schema-conformant example of the quarterly report of certification-data changes, planned changes, accepted vulnerabilities, agencies and reportable incidents, labeled as an example. The first report is due 2026-12-01. | Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed |
| Information-resources inventory (MAS-CSO-IIR) | JSON + Markdown (generated), with generator, sources and derivation method | Every cloud account, project and third-party service that handles federal customer data or can affect its confidentiality, integrity or availability, with location, boundary membership, encryption and CUI routing. | Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed |
| SOC 2 Type II report | PDF (restricted use) | Prescient Assurance LLC, issued 2026-08-31, Security Trust Services Criteria, period 2026-04-15 to 2026-07-15, unqualified opinion, no exceptions on 131 tested controls. This is the approved alternative security framework assessment that Class A rests on (FRC-CLA-ASF). Independent verification and validation of the certification package by a FedRAMP Recognized independent assessment service is optional at Class A (FRC-CLA-IVV), and none is engaged for this submission. An independent assessor is engaged for the Class C assessment that follows. The management representation letter accompanying the report is retained in the evidence repository and supplied with the application and on request to fedramp@specset.com. | Trust center (trust.specset.com), restricted resource, view only, no NDA — published today |
| SOC 2 Type II engagement documentation | PDF (restricted use) | Verified engagement documentation for the completed examination, dated 2026-08-25. The next report is planned after the 2026-07-16 to 2027-07-15 period ends and before 2027-08-31. The renewal engagement letter for that period is signed by the assessor; the client signature is pending. Gap: no assessor bridge or gap letter covers 2026-07-16 to the application date. Plan: settle the bridge-letter position with the assessor before the application is filed, and supply the letter with the assessment materials if one is issued. | Retained in the evidence repository; supplied with the Class A application and on request to fedramp@specset.com |
| Incident Response Procedure | Markdown / PDF | Detection, triage, FedRAMP reportability evaluation, initial and final incident reporting (IEC-CSO-EFR / IIR / OIR / FIR), and the FedRAMP Security Inbox procedure. | Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed |
| Vulnerability Management Procedure | Markdown / PDF | Persistent detection (Dependabot security alerts and CodeQL code scanning on the application and infrastructure repositories, Artifact Registry image scanning of deployed digests), PAIN-based evaluation within 14 days, Class A remediation timeframes, and adoption of the VDR / VER rulesets ahead of the 2026-12-07 mandate. | Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed |
| Security policies | PDF / web | The policy set maintained in Vanta, with employee acceptance recorded there: information security, access control, data management, cryptography, operations security (which carries the change management requirements), acceptable use, password, mobile device, data leakage prevention and third-party management policies, plus the incident response plan and the business continuity and disaster recovery plan. Gap: the revised business continuity and disaster recovery plan that aligns the recovery time objective with the recovery plan is pending approval, and the approved version still records the earlier objective. Plan: approve the revision by 2026-11-30, before the 2026-12-01 Ongoing Certification Report. | Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed |
| Vulnerability activity reports | Markdown + JSON, monthly | Monthly vulnerability detection and response activity (VER-TFR-MRH). First report 2026-10-01. | Published as a restricted trust-center resource, no NDA, from 2026-10-01 |
| Recovery plan | Markdown / PDF | The recovery plan for the offering (KSI-RPL-ARP): service recovery objectives of RTO 24 elapsed hours and RPO 15 minutes (KSI-RPL-RRO), per-datastore backup and recovery procedures aligned to those objectives (KSI-RPL-ABO), and the recovery testing cadence (KSI-RPL-TRC). Delivered as supporting-evidence document 12, "Recovery and Backup Configuration". | Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed |
| Training effectiveness review (KSI-CED-RAT) | JSON | Four-category review of security training effectiveness for all staff, completed 2026-09-12, with follow-up actions. Next review 2026-12-01. | Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed |
| Incident register and simulated Final Incident Report | Markdown + JSON (FedRAMP incident report schema) | Incident register entries, the quarterly review record, and a simulated tabletop exercise with its reportability evaluation and schema-valid Final Incident Report. | Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed |
| Class A supporting evidence documents | Twelve PDFs, each with its source exports as appendices | Twelve documents, one per artifact the Security Decision Record cites by name, so a reviewer opens exactly what the record points to: change management record; network boundary and Cloud Armor configuration; egress enforcement verification; identity and access configuration; staff authentication verification; training effectiveness review; incident response records; encryption and secrets configuration; vulnerability detection baseline and exception EX-2026-001; information resources inventory sources; assessment materials and schedule; and recovery and backup configuration. Each states the facts, the rule identifiers it evidences and its source records, with the machine-readable export appended. | Supplied with the Class A application; published as a restricted trust-center resource, no NDA, when that application is filed |
| Service availability (CDS-CSO-AVR) | Web page + JSON | Current status, 90-day per-service history and incidents, hosted independently of the offering; machine-readable at https://status.specset.com/index.json. | Public: https://status.specset.com |
| Secure configuration guidance | Web page | Customer-side configuration guidance (single sign-on, roles, CUI mode). The Secure Configuration Guide rules (SCG-CSO) apply to Classes B, C and D, not to Class A, so no guide is required for this application. Gap: not yet published. Plan: publish it on the Trust Center and link it from serviceProperties.secureConfigurationGuidance in this document before the Class C application. | Not yet published |