{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json",
  "$schemaVersion": "0.1.3",
  "type": "object",
  "title": "FedRAMP Certification Package Overview (FRC-CSO-PKG)",
  "description": "Identification, service properties, contacts, and supporting documentation for a Cloud Service Offering per FRC-CSO-PKG.",
  "required": [
    "serviceIdentification",
    "serviceProperties",
    "contactInformation"
  ],
  "properties": {
    "serviceIdentification": {
      "type": "object",
      "title": "Service Identification",
      "description": "Basic identification details for the Cloud Service Offering.",
      "required": [
        "providerName",
        "serviceName",
        "serviceAcronym",
        "serviceDescription",
        "certificationType",
        "fedRampPackageId",
        "website",
        "logo"
      ],
      "properties": {
        "fedRampPackageId": {
          "type": "string",
          "title": "FedRAMP ID",
          "description": "Unique identifier assigned to the CSP by FedRAMP. If no FedRAMP ID is available, use the CSP's name and acronym."
        },
        "ueiNumber": {
          "type": "string",
          "title": "UEI Number",
          "description": "Unique Entity Identifier (UEI) assigned to the CSP by SAM.gov. If no UEI is available leave this blank. (CDS-CSO-PUB)"
        },
        "providerName": {
          "type": "string",
          "title": "Provider Name",
          "description": "Name of the Cloud Service Provider."
        },
        "serviceName": {
          "type": "string",
          "title": "Service Name",
          "description": "Full name of the Cloud Service Offering."
        },
        "serviceAcronym": {
          "type": "string",
          "title": "Service Acronym",
          "description": "Short acronym or abbreviation for the Cloud Service Offering."
        },
        "serviceDescription": {
          "type": "string",
          "title": "Service Description",
          "description": "A detailed description of the Cloud Service Offering. May use Markdown for formatting (CDS-CSO-PUB)."
        },
        "certificationType": {
          "type": "string",
          "title": "Certification Type",
          "description": "The FedRAMP certification type for the Cloud Service Offering.",
          "enum": [
            "20x",
            "Rev5"
          ]
        },
        "website": {
          "type": "string",
          "format": "uri",
          "title": "Website",
          "description": "Official website for the Cloud Service Offering (CDS-CSO-PUB)."
        },
        "logo": {
          "$ref": "https://fedramp.gov/schemas/fedramp-common-definitions-schema-2026-06-24.json#/$defs/logoUri",
          "title": "Logo",
          "description": "URL of the CSP logo. Must point to a PNG, JPEG, GIF, SVG, WebP, ICO, BMP, or TIFF file (CDS-CSO-PUB)."
        }
      }
    },
    "serviceProperties": {
      "type": "object",
      "title": "Service Properties",
      "description": "Technical and operational properties of the Cloud Service Offering.",
      "required": [
        "serviceType",
        "deploymentModel"
      ],
      "properties": {
        "serviceType": {
          "type": "array",
          "title": "Service Model",
          "description": "Cloud service model(s). Select all that apply (CDS-CSO-PUB).",
          "items": {
            "type": "string",
            "enum": [
              "SaaS",
              "PaaS",
              "IaaS"
            ]
          },
          "minItems": 1
        },
        "deploymentModel": {
          "type": "string",
          "title": "Deployment Model",
          "description": "Deployment model of the system (CDS-CSO-PUB).",
          "enum": [
            "Public Cloud",
            "Government-Only Cloud",
            "Hybrid Cloud",
            "Community Cloud",
            "Government Community Cloud"
          ]
        },
        "businessCategory": {
          "type": "array",
          "title": "Business Category",
          "description": "Business Category(s) supported by the service (CDS-CSO-PUB).",
          "items": {
            "type": "string",
            "enum": [
              "Accounting",
              "Analytics",
              "Artificial Intelligence (AI)",
              "Collaboration",
              "Communication",
              "Construction",
              "Contact Center",
              "Content Management System (CMS)",
              "Customer Relations Management (CRM)",
              "Customer Service",
              "Cybersecurity & Risk Management",
              "Data Management",
              "Design & Multimedia",
              "Development Tools",
              "Education & Training",
              "Finance",
              "Fleet Management",
              "Governance, Risk, and Compliance (GRC)",
              "Grant Management",
              "Health & Wellness",
              "Human Resources",
              "Law Enforcement",
              "Learning Management",
              "Legal & Policy",
              "Marketing & Sales",
              "Media",
              "Mobile Device Management (MDM)",
              "Network Management",
              "Operations Management",
              "Research",
              "Storage",
              "System Administration",
              "Talent Development",
              "Talent Management",
              "Travel Management",
              "Virtual Private Network (VPN)"
            ]
          },
          "minItems": 1,
          "maxItems": 10
        },
        "trustCenter": {
          "$ref": "#/$defs/repository",
          "title": "Trust Center",
          "description": "The URL and any access instructions needed for the Cloud Service Provider's FedRAMP Trust Center (CDS-CSO-UTC). Note: Rules for FedRAMP-Compatible Trust Centers are explained in the Certification Data Sharing Rules under the FedRAMP-Compatible Trust Centers section (id: CDS-TRC)."
        },
        "secureConfigurationGuidance": {
          "$ref": "#/$defs/repository",
          "title": "Secure Configuration Guidance",
          "description": "The URL and any access instructions needed for the Cloud Service Provider's Secure Configuration Guide (SCG-CSO-RSC)."
        },
        "additionalRepositories": {
          "type": "array",
          "title": "Repositories",
          "description": "Repository locations for system authorization documentation, policies, procedures, and assessment reports.",
          "items": {
            "$ref": "#/$defs/repository"
          }
        },
        "nextOngoingCertificationReportDate": {
          "type": "string",
          "format": "date",
          "title": "Next Ongoing Certification Report Date",
          "description": "The date of the next ongoing certification report for the Cloud Service Provider (CDS-CSO-PUB)."
        }
      }
    },
    "contactInformation": {
      "type": "array",
      "title": "Contact Information",
      "description": "Key contacts for the Cloud Service Provider. Must include at least one Security Contact and one Sales Contact (CDS-CSO-PUB).",
      "items": {
        "$ref": "#/$defs/contactInfo"
      },
      "allOf": [
        {
          "contains": {
            "required": [
              "contactType"
            ],
            "properties": {
              "contactType": {
                "title": "Contact Type",
                "description": "The role or category of this contact.",
                "const": "Security"
              }
            }
          }
        },
        {
          "contains": {
            "required": [
              "contactType"
            ],
            "properties": {
              "contactType": {
                "title": "Contact Type",
                "description": "The role or category of this contact.",
                "const": "Sales"
              }
            }
          }
        }
      ]
    },
    "assessor": {
      "type": "object",
      "title": "Independent Assessor",
      "description": "The Independent Assessment Service that performs verification and validation for the Cloud Service Offering (CDS-CSO-PUB).",
      "required": [
        "name",
        "assessorID"
      ],
      "properties": {
        "name": {
          "type": "string",
          "title": "Assessor Name",
          "description": "Name of the independent assessor."
        },
        "assessorID": {
          "type": "string",
          "title": "Assessor's FedRAMP ID",
          "description": "Unique identifier assigned to the assessor by FedRAMP.",
          "pattern": "^\\d{6}$"
        }
      }
    },
    "certifiedServices": {
      "type": "array",
      "title": "Certified Services",
      "description": "List of services offered by the provider that are included in this certification (CDS-CSO-SVC).",
      "items": {
        "type": "object",
        "title": "Certified Service",
        "description": "A service offered by the provider that is included in this certification.",
        "required": [
          "serviceName",
          "serviceDescription",
          "dateAvailable"
        ],
        "properties": {
          "serviceName": {
            "type": "string",
            "title": "Service Name",
            "description": "Name of the service as it appears on the provider's website and in marketing materials."
          },
          "serviceDescription": {
            "type": "string",
            "title": "Service Description",
            "description": "Description of the service. May use Markdown for formatting."
          },
          "dateAvailable": {
            "type": "string",
            "format": "date",
            "title": "Date Available",
            "description": "Date the service became available or was certified."
          }
        }
      }
    },
    "thirdPartyInformationResources": {
      "type": "object",
      "title": "Third-Party Information Resources",
      "description": "Third-party information resources within the Minimum Assessment Scope for the Cloud Service Offering (MAS-CSO-TPR).",
      "properties": {
        "certified": {
          "type": "array",
          "title": "FedRAMP Certified",
          "description": "FedRAMP Certified third-party information resources.",
          "items": {
            "type": "object",
            "required": [
              "fedRampCertifiedThirdPartyInformationResource",
              "useCase"
            ],
            "properties": {
              "fedRampCertifiedThirdPartyInformationResource": {
                "type": "string",
                "title": "FedRAMP ID",
                "description": "Unique FedRAMP ID of the third-party information resource."
              },
              "useCase": {
                "type": "string",
                "title": "Use Case",
                "description": "How this resource is used in the context of this offering."
              }
            }
          }
        },
        "nonCertified": {
          "type": "array",
          "title": "Non-FedRAMP Certified",
          "description": "Non-FedRAMP Certified third-party information resources.",
          "items": {
            "type": "object",
            "required": [
              "name",
              "provider",
              "useCase"
            ],
            "properties": {
              "name": {
                "type": "string",
                "title": "Name",
                "description": "Name of the third-party information resource."
              },
              "provider": {
                "type": "string",
                "title": "Provider",
                "description": "Name of the provider of the third-party information resource."
              },
              "website": {
                "type": "string",
                "format": "uri",
                "title": "Website",
                "description": "Website of the third-party information resource."
              },
              "useCase": {
                "type": "string",
                "title": "Use Case",
                "description": "How this resource is used in the context of this offering."
              }
            }
          }
        }
      }
    }
  },
  "$defs": {
    "repository": {
      "type": "object",
      "title": "Repository",
      "description": "A repository location for system authorization documentation, policies, procedures, assessment reports, etc.",
      "required": [
        "repositoryType",
        "url",
        "repositoryDescription",
        "authenticationRequired"
      ],
      "properties": {
        "repositoryType": {
          "type": "array",
          "title": "Repository Type",
          "description": "The type(s) or categories of this repository. A single repository may satisfy multiple type requirements.",
          "items": {
            "type": "string"
          },
          "minItems": 1,
          "examples": [
            [
              "Secure Configuration Guidance"
            ],
            [
              "Trust Center",
              "Assessment Reports"
            ]
          ]
        },
        "url": {
          "type": "string",
          "format": "uri",
          "title": "Repository URL",
          "description": "URL of the repository."
        },
        "repositoryDescription": {
          "type": "string",
          "title": "Repository Description",
          "description": "Description of the repository contents."
        },
        "authenticationRequired": {
          "type": "boolean",
          "title": "Authentication Required",
          "description": "Whether authentication is required to access the repository."
        },
        "accessRequestInstructions": {
          "type": "string",
          "title": "Access Request Instructions",
          "description": "Instructions for requesting access to the repository. May use Markdown for formatting."
        }
      },
      "if": {
        "required": [
          "authenticationRequired"
        ],
        "properties": {
          "authenticationRequired": {
            "title": "Authentication Required",
            "description": "Whether authentication is required to access the repository.",
            "const": true
          }
        }
      },
      "then": {
        "required": [
          "accessRequestInstructions"
        ]
      }
    },
    "contactInfo": {
      "type": "object",
      "title": "Contact",
      "description": "A contact for the Cloud Service Provider.",
      "required": [
        "contactType"
      ],
      "properties": {
        "contactType": {
          "type": "string",
          "title": "Contact Type",
          "description": "The role or category of this contact.",
          "examples": [
            "Primary",
            "Security",
            "Sales"
          ]
        },
        "contactName": {
          "type": "string",
          "title": "Name",
          "description": "Name of the contact. May be a specific person or the role of the contact."
        },
        "contactEmail": {
          "type": "string",
          "format": "email",
          "title": "Email",
          "description": "Email address of the contact."
        },
        "contactPhone": {
          "type": "string",
          "title": "Phone Number",
          "description": "Phone number in ###-###-#### format (e.g. 202-555-0123).",
          "pattern": "^[0-9]{3}-[0-9]{3}-[0-9]{4}$"
        }
      }
    }
  }
}
