Secure Configuration Guide
Available Procore for Government Tools are engineered consistent with the FedRAMP Moderate baseline.
Available Procore for Government Tools are engineered consistent with the FedRAMP Moderate baseline.
ID - SCG-CSO-RSC
Changelog: 2026-02-04: Combined all required and recommended SCG information; removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes.
Providers MUST create, maintain, and make available recommendations for securely configuring their cloud services (the Secure Configuration Guide) that includes at least the following information:
Required: Instructions on how to securely access, configure, operate, and decommission top-level administrative accounts that control enterprise access to the entire cloud service offering.
Required: Explanations of security-related settings that can be operated only by top-level administrative accounts and their security implications.
Recommended: Explanations of security-related settings that can be operated only by privileged accounts and their security implications.
Access
Configuration
Decommissioning
Security Related Settings
Admin Accounts
Privileged Accounts
Security Impact
ID - SCG-CSO-AUP
Changelog: 2026-02-04: This requirement is new in v-0.9.0 to clarify expectations.
Providers must include instructions in the FedRAMP authorization package that explain how to obtain and use the Secure Configuration Guide.
Guidance: Agencies and Organizations can request a copy of Procore’s Authorization Package via the FedRAMP Marketplace or sending an email request to info@fedramp.gov or support@procore.gov
ID -SCG-CSO-PUB
Former ID: FRR-RSC-09
Changelog: 2026-02-04: Clarified wording; removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes.
Providers SHOULD make the Secure Configuration Guide available publicly.
Guidance: The Procore Secure Configuration Guide can be found at Secure Configuration Guide.