# Security Assessment Plan (SAP) | Secureframe

> Understand Security Assessment Plans (SAP), how SAPs define the scope and methodology for FedRAMP assessments, SAP contents, and the SAP’s role in the RMF process.

canonical: https://secureframe.com/glossary/sap

A Security Assessment Plan (SAP) is developed by a Third-Party Assessment Organization (3PAO) and outlines the specific procedures and methodologies that will be used during the security assessment for FedRAMP authorization.

## What is a Security Assessment Plan (SAP)?

A Security Assessment Plan (SAP) is developed by a [Third-Party Assessment Organization (3PAO)](https://secureframe.com/glossary/3pao) and outlines the specific procedures and methodologies that will be used during the security assessment for [FedRAMP authorization](https://secureframe.com/blog/fedramp). 

Designed to guide the assessor through the assessment process and ensure a systematic and consistent approach, the SAP specifies:

- assessment procedures
- scope
- techniques
- tools
- roles and responsibilities

While the SAP specifies the how of a FedRAMP assessment, the Security Assessment Report (SAR) explains the result of that assessment process.
