{ "info": { "title": "FedRAMP Consolidated Rules for 2026", "description": "This datafile contains the Consolidated Rules for FedRAMP in structured machine-readable text. It includes definitions, requirements, recommendations, and key security indicators.", "version": "2026.09.13.02", "last_updated": "2026-09-13", "default_artifacts": { "FRR": [ "Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.", "Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.", "Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.", "Independent verification.", "Independent validation." ], "KSI": [ "Explanation of measures (and their objectives) that demonstrate the Key Security Indicator, or an explanation of the reason and resulting risk to customers for not having measures available for that Key Security Indicator.", "Explanation of the cycle for any measures that are implemented persistently (if applicable).", "Verification that the measures demonstrate the Key Security Indicator, or that the reason for not having them is accepted.", "Verification that the automation in place is accurate and sufficient to demonstrate appropriate measures for the Key Security Indicator, or that automation is not necessary for each measure.", "Validation that the measures are accurately produced and are in place and working as intended, or that the reason for not having them is valid." ] } }, "FRD": { "info": { "name": "FedRAMP Definitions", "short_name": "FRD", "web_name": "definitions", "purpose": "FedRAMP Definitions establish a shared understanding for terms when the plain-language meaning is not precise enough to support consistent use across the rules. When a defined term appears in a rule, the definition is a critical part of that rule and must be followed precisely, even if the term is commonly used differently elsewhere; when no definition exists, the plain-language meaning is expected.", "status": "stable", "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2026-07-04", "optional_adoption": "2026-07-04", "grace": { "default": "2026-05-04", "until_next_assessment": false } } } }, "data": { "all": { "FRD-ACV": { "term": "Accepted Vulnerability", "definition": "A vulnerability that the provider does not intend to fully mitigate or remediate, OR that has not or will not be fully mitigated or remediated within the maximum overdue period in FedRAMP Vulnerability Detection and Response rules.", "tag": "Vulnerability", "alts": ["accepted vulnerability", "accepted vulnerabilities"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-ADP": { "term": "Adaptive Change", "definition": "A type of significant change that does not routinely recur and does not introduce substantive potential security risks that need to be assessed in depth.", "note": "Adaptive changes typically require careful planning that focuses on engineering execution instead of customer adoption, can be verified with minor changes to existing automated validation procedures, and do not require large changes to operational procedures, deployment plans, or documentation.", "tag": "Significant Changes", "alts": ["adaptive", "adaptive change", "adaptive changes"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-ADV": { "term": "Advisor", "definition": "An entity that helps a provider understand, prepare for, or maintain FedRAMP Certification without replacing the provider's responsibility or the assessor's independence.", "tag": "Stakeholder", "alts": ["advisor", "advisors"], "do_not_link": true, "ignore_in_terms": true, "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-AGY": { "term": "Agency", "definition": "Has the meaning given in 44 U.S. Code § 3502 (1), which is \"any executive department, military department, Government corporation, Government controlled corporation, or other establishment in the executive branch of the Government (including the Executive Office of the President), or any independent regulatory agency, but does not include—(A) the Government Accountability Office; (B) Federal Election Commission; (C) the governments of the District of Columbia and of the territories and possessions of the United States, and their various subdivisions; or (D) Government-owned contractor-operated facilities, including laboratories engaged in national defense research and production activities.\"", "tag": "Stakeholder", "alts": ["agency", "agencies"], "do_not_link": true, "ignore_in_terms": true, "reference": "44 U.S. Code § 3502 (1)", "reference_url": "https://www.govinfo.gov/app/details/USCODE-2023-title44/USCODE-2023-title44-chap35-subchapI-sec3502", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-AAP": { "term": "All Affected Parties", "definition": "All federal entities whose interests are affected directly or are likely to be affected directly in the event of a vulnerability or incident related to federal customer data. This always includes FedRAMP and directly impacted federal customer agencies.", "tag": "Stakeholder", "alts": ["all affected parties"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-ANA": { "term": "All Necessary Assessors", "definition": "All entities who participate in the FedRAMP assessment of a cloud service offering in the context of a FedRAMP Certification. This always includes FedRAMP and any FedRAMP Recognized independent assessor contracted by a provider to perform a FedRAMP assessment.", "tag": "Stakeholder", "alts": ["all necessary assessors"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-ANP": { "term": "All Necessary Parties", "definition": "All entities whose interests are affected directly by activity related to a specific cloud service offering in the context of FedRAMP Certifications. This always includes FedRAMP and any agency customer who is using the cloud service offering, but may include additional parties depending on agreements made by the cloud service provider (such as consultants or independent assessors). Potential agency customers or third-party cloud service providers should also be included in most cases but this is not a mandatory requirement under FedRAMP because the cloud service provider may choose who they wish to do business with.", "tag": "Stakeholder", "alts": ["all necessary parties"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-ART": { "term": "Artifacts", "definition": "Security-related materials that supply information regarding or evidence of functions, policies, decisions, procedures, operations, or other such activities, for the purposes of obtaining and maintaining a FedRAMP Certification. All such artifacts are considered FedRAMP Certification Data and are included in the FedRAMP Certification Package.", "tag": "Certification", "alts": ["artifact", "artifacts"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-ASR": { "term": "Assessor", "definition": "An assessor that performs assessment, verification, or validation activities for a cloud service offering seeking to obtain or maintain FedRAMP Certification; FedRAMP is the final assessor for FedRAMP Certification, but FedRAMP Recognized independent assessment services are typically also utilized.", "note": "FedRAMP has transitioned from using the historical term \"Third-Party Assessment Organization (3PAO)\" to align with the explicit terminology used in the FedRAMP Authorization Act and to avoid the confusion caused when the same organizations provide both assessment and advisory services to different customers while being referred to as a 3PAO.", "tag": "Stakeholder", "alts": ["assessor", "assessors"], "do_not_link": true, "ignore_in_terms": true, "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-CCL": { "term": "Certification Class", "definition": "The category of assurance that a cloud service offering supplies to federal government customers following FedRAMP Practices, increasing from minimal assurance at Class A to significant assurance at Class D; currently available categories are Class A, B, C, or D.", "tag": "Certification", "alts": ["Certification Class", "Certification Classes"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-CCC": { "term": "Certification Class Change", "definition": "A type of significant change that is likely to change the FedRAMP Certification class for the entire cloud service offering (e.g. from Class B to Class C or from Class D to Class C).", "tag": "Significant Changes", "alts": ["certification class change", "certification class changes"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-CRD": { "term": "Certification Data", "definition": "The collective information required by FedRAMP for initial and ongoing FedRAMP Certification of a cloud service offering, including the FedRAMP Certification Package.", "note": "In FedRAMP documentation, certification data always refers to FedRAMP Certification Data unless otherwise specified.", "tag": "Certification", "alts": ["certification data"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-CRP": { "term": "Certification Package", "definition": "Has meaning from 44 USC § 3607 (b)(8) given to \"authorization package\", which is \"the essential information that can be used by an agency to determine whether to authorize the operation of an information system or the use of a designated set of common controls for all cloud computing products and services [certified] by FedRAMP.\"", "note": "In FedRAMP documentation, certification package always refers to a FedRAMP Certification Package unless otherwise specified.", "tag": "Certification", "alts": ["certification package", "certification packages"], "reference": "44 USC § 3607 (b)(8)", "reference_url": "https://fedramp.gov/docs/authority/law/#b-additional-definitions", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-CPH": { "term": "Certification Path", "definition": "The underlying source of the FedRAMP Certification, either from a federal agency sponsored authorization to operate or directly from FedRAMP itself. The agency path is a legacy path that is only available for FedRAMP Rev5 and still requires review and approval from FedRAMP.", "tag": "Certification", "alts": ["Certification Path", "Certification Paths"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-CPF": { "term": "Certification Profile", "definition": "The combination of a FedRAMP Certification Type (Rev5 or 20x), FedRAMP Certification Path (Program or Agency), and FedRAMP Certification Class (A, B, C, or D) for a cloud service offering.", "tag": "Certification", "alts": ["Certification Profile", "Certification Profiles"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-CTY": { "term": "Certification Type", "definition": "The form of assurance that a cloud service offering supplies to federal government customers following FedRAMP Practices, either Rev5 or 20x. Rev5 follows a legacy approach based primarily on documented plans while 20x follows a modern approach based primarily on measured outcomes.", "tag": "Certification", "alts": ["Certification Type", "Certification Types"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-CSO": { "term": "Cloud Service Offering", "definition": "A specific, packaged cloud computing product or service supplied by a cloud service provider for use by customers, that is the subject of a FedRAMP Certification.", "note": "The FedRAMP Minimum Assessment Scope defines the full scope of the cloud service offering from the perspective of a FedRAMP Certification.", "alts": ["cloud service offering", "cloud service offerings"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-DCE": { "term": "Debilitating Customer Effect", "definition": "An unwanted customer effect that interrupts use of the cloud service for most users or compromises the integrity or confidentiality of most federal customer data. If the adverse customer effect is unknown then it should be treated as if it is debilitating until proven otherwise.", "tag": "Customer Effect", "alts": [ "debilitating customer effect", "debilitating customer effects" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-DTM": { "term": "Deterministic Telemetry", "definition": "Verifiable data collected directly from an authoritative source that represents a factual and reproducible observation of the attributes of a system such as the system's state, configuration, or behavior.", "note": "Probabilistic inferences, generative outputs, or predictive assessments such as those produced using generative transformer models (commonly referred to as “Generative AI”) do not constitute a factual record of the system state and must not be used to generate deterministic telemetry.", "alts": ["deterministic telemetry"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-DCF": { "term": "Disruptive Customer Effect", "definition": "An unwanted customer effect that interrupts use of the cloud service for many users for less than 24 hours, or that compromises the integrity or confidentiality of large amounts or many types of federal customer data.", "tag": "Customer Effect", "alts": ["disruptive customer effect", "disruptive customer effects"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-DFT": { "term": "Drift", "definition": "Changes to information resources that cause deviations from the intended and assessed state; common forms of drift include changes to configurations, deployed software, privileges, running processes, and availability.", "alts": ["drift", "drifts", "drifting"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FPV": { "term": "False Positive Vulnerability", "definition": "A detected vulnerability that is not actually present in an exploitable state in the information resource", "notes": [ "This includes situations where vulnerable software or code exist on a machine-based information resource but are not loaded, running, or otherwise in an operating state required for exploitation.", "This only applies if the vulnerability is not and was not present; a remediated vulnerability or a fully mitigated vulnerability cannot also be a false positive vulnerability." ], "tag": "Vulnerability", "alts": [ "false positive vulnerability", "false positive vulnerabilities" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FCD": { "term": "Federal Customer Data", "definition": "All electronic information, content, and materials that an agency or its authorized users upload, store, or otherwise supply to a cloud service for processing or storage. This does NOT include account information, service metadata, analytics, telemetry, or other similar metadata generated by the cloud service provider.", "note": "In the context of FedRAMP Certification, \"federal customer data\" ONLY ever refers to data owned by federal agency customers. Agreements and contracts with specific agencies may require providers to protect additional data or even transfer ownership of telemetry or usage data to the agency; always consult a lawyer that is familiar with company agreements and contracts when determining the scope of federal customer data.", "alts": ["federal customer data"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FCR": { "term": "FedRAMP Certification Report", "definition": "A report that is produced by FedRAMP documenting the results of a FedRAMP Certification assessment. This report is typically produced after the initial FedRAMP Certification assessment on the Program Certification Path and updated as necessary during ongoing FedRAMP Certification, but may be produced at any time by FedRAMP as part of ongoing FedRAMP Certification activities for any cloud service offering (such as corrective action). Cloud service offerings must include these reports in their FedRAMP Certification Package.", "tag": "Certification", "alts": [ "FedRAMP Certification Report", "FedRAMP certification report", "certification report" ], "reference": "FedRAMP Certification Act (44 USC § 3608)", "reference_url": "https://www.fedramp.gov/docs/authority/law/#sec-3608-federal-risk-and-authorization-management-program", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FCT": { "term": "FedRAMP Certified", "definition": "The status of a cloud service offering that has received FedRAMP Certification and meets the legal requirement to be FedRAMP authorized.", "note": "FedRAMP uses \"FedRAMP Certified\" as the current program term for cloud service offerings that satisfy the statutory concept of FedRAMP authorization.", "tag": "Certification", "alts": [ "FedRAMP Certified", "FedRAMP certified", "certified", "FedRAMP authorized", "FedRAMP Authorized", "authorized" ], "reference": "FedRAMP Certification Act (44 USC § 3608)", "reference_url": "https://www.fedramp.gov/docs/authority/law/#sec-3608-federal-risk-and-authorization-management-program", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FIN": { "term": "FedRAMP Independent Assessment", "definition": "An independent verification and validation assessment, performed by a FedRAMP Recognized independent assessment service or FedRAMP following FedRAMP rules. These assessments are typically first performed to obtain an initial FedRAMP Certification then repeated on an annual basis to maintain FedRAMP Certification.", "alts": [ "FedRAMP independent assessment", "FedRAMP independent assessments" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FPR": { "term": "FedRAMP Practices", "definition": "The security measures, safeguards, precautions, procedures, activities, policies, capabilities, mechanisms, etc. that are expected to be in place by FedRAMP to demonstrate that information resources are properly protected, expressed in FedRAMP 20x Key Security Indicators or FedRAMP Rev5 Controls and supplemented by FedRAMP rules.", "alts": ["FedRAMP Practice", "FedRAMP Practices"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FRA": { "term": "FedRAMP Recognized", "definition": "The status of independent assessment services that are recognized by FedRAMP to perform assessment activities on behalf of FedRAMP for cloud service offerings seeking to obtain or maintain FedRAMP Certification.", "alts": ["FedRAMP Recognized", "FedRAMP Recognition"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FRI": { "term": "FedRAMP Reportable Incident", "definition": "An incident that affects the confidentiality or integrity of federal customer data or is likely to affect the confidentiality or integrity of federal customer data.", "tag": "Incident", "alts": [ "FedRAMP Reportable Incident", "FedRAMP Reportable Incidents" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FSI": { "term": "FedRAMP Security Inbox", "definition": "An email address that follows the FedRAMP Security Inbox rules.", "alts": ["security inbox", "security inboxes", "FSI"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FIR": { "term": "Final Incident Report (FIR)", "definition": "A final report after recovery from an incident that is supplied by FedRAMP Certified cloud service providers to FedRAMP and agency customers, following FedRAMP Incident Evaluation and Communication rules.", "tag": "Incident", "alts": [ "final incident report", "final incident reports", "FIR", "FIRs" ], "updated": [ { "date": "2026-07-02", "comment": "Update terminology from \"Response\" to \"Communication\" in FedRAMP Incident Evaluation rules." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-FMV": { "term": "Fully Mitigated Vulnerability", "definition": "A vulnerability where the likelihood of exploitation or Potential Agency Impact N-rating has been reduced from the original evaluation until either are negligible, but the vulnerability is still detected.", "tag": "Vulnerability", "alts": [ "fully mitigated vulnerability", "fully mitigated vulnerabilities", "fully mitigate vulnerabilities" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-HAN": { "term": "Handle", "definition": "Has the plain language meaning inclusive of any possible action taken with information, such as access, collect, control, create, display, disclose, disseminate, dispose, maintain, manipulate, process, receive, review, store, transmit, use... etc.", "alts": ["handle", "handles", "handled", "handling"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-INT": { "term": "Incident", "definition": "Has the meaning given in 44 USC § 3552 (b)(2) which is \"an occurrence that (A) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (B) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.\"", "tag": "Incident", "alts": ["incident", "incidents"], "reference": "44 USC § 3552 (b)(2)", "reference_url": "https://www.govinfo.gov/app/details/USCODE-2024-title44/USCODE-2024-title44-chap35-subchapII-sec3552", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-IRS": { "term": "Information Resource", "definition": "Has the meaning from 44 USC § 3502 (6): \"information and related resources, such as personnel, equipment, funds, and information technology.\" This includes any aspect of the cloud service offering, both technical and managerial, including everything that makes up the business of the offering from non-machine-based information resources like organizational policies, procedures, employees, etc. to machine-based information resources like hardware, software, cloud services, code, etc.", "note": "Information resources are either machine-based or non-machine-based; any requirement or recommendation that references information resources without specifying a type is inclusive of all information resources.", "tag": "Information Resource", "alts": ["information resource", "information resources"], "reference": "44 USC § 3502 (6)", "reference_url": "https://www.govinfo.gov/app/details/USCODE-2023-title44/USCODE-2023-title44-chap35-subchapI-sec3502", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-INC": { "term": "Initial Certification", "definition": "The first FedRAMP Certification of a cloud service offering based on the applicable FedRAMP Practices.", "tag": "Certification", "alts": ["initial certification", "initial certifications"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-IFA": { "term": "Initial FedRAMP Assessment", "definition": "The first full assessment of a cloud service offering obtaining FedRAMP Certification, coordinated by the provider with all necessary assessors, that results in a FedRAMP Certification.", "tag": "Assessment", "alts": ["initial FedRAMP assessment", "IFRA"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-IIR": { "term": "Initial Incident Report (IIR)", "definition": "An initial report about an incident that is supplied by FedRAMP Certified cloud service providers to FedRAMP and agency customers, following FedRAMP FedRAMP Incident Evaluation and Communication rules.", "tag": "Incident", "alts": [ "initial incident report", "initial incident reports", "IIR", "IIRs" ], "updated": [ { "date": "2026-07-02", "comment": "Update terminology from \"Response\" to \"Communication\" in FedRAMP Incident Evaluation rules." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-IRV": { "term": "Internet-Reachable Vulnerability (IRV)", "definition": "A vulnerability in a machine-based information resource that might be exploited or otherwise triggered by a payload originating from a source on the public internet.", "notes": [ "This includes machine-based information resources that have no direct route to/from the internet but receive payloads or otherwise take action triggered by internet activity.", "Internet-reachability applies only to the specific vulnerable machine-based information resources processing the payload.", "The opposite of this is a Not Internet-reachable Vulnerability (NIRV)." ], "tag": "Vulnerability", "alts": [ "internet-reachable vulnerability", "internet-reachable vulnerabilities", "IRV", "IRVs", "NIRV", "NIRVs" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-KEV": { "term": "Known Exploited Vulnerability (KEV)", "definition": "Has the meaning given in CISA Binding Operational Directive 26-04, which is any vulnerability identified in CISA's Known Exploited Vulnerabilities catalog.", "tag": "Vulnerability", "alts": [ "known exploited vulnerability", "known exploited vulnerabilities", "KEV", "KEVs" ], "reference": "CISA BOD 26-04", "reference_url": "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-LKY": { "term": "Likely", "definition": "A reasonable degree of probability based on context.", "alts": ["likely", "likelihood"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-LEV": { "term": "Likely Exploitable Vulnerability (LEV)", "definition": "A vulnerability that is not fully mitigated AND is reachable by a likely threat actor; AND a likely threat actor with knowledge of the vulnerability would likely gain unauthorized access, cause harm, disrupt operations, or otherwise have an undesired adverse impact within the cloud service offering by exploiting the vulnerability.", "notes": [ "At the absolute minimum, any vulnerability that an automated unauthenticated system can exploit over the internet is a likely exploitable vulnerability.", "The opposite of this is a Not Likely Exploitable Vulnerability (NLEV)." ], "tag": "Vulnerability", "alts": [ "likely exploitable vulnerability", "likely exploitable vulnerabilities", "LEV", "LEVs", "NLEV", "NLEVs" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-MBI": { "term": "Machine-Based (Information Resources)", "definition": "Any information technology information resource—including systems, processes, software, hardware, services, cloud-native capabilities, and any other such capability, component, or resource—that relies primarily on mechanical or electronic devices (i.e. computers) for operation.", "note": "All other information resources that do not rely on computers are non-machine-based information resources.", "tag": "Information Resource", "alts": ["machine-based", "machine based"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-MGN": { "term": "Machine-Generated", "definition": "Automatically produced by a computer process, application, or other mechanism without the intervention or manipulation of a human during production.", "alts": ["machine-generated"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-MRD": { "term": "Machine-Readable", "definition": "Has the meaning from 44 U.S. Code § 3502 (18) which is \"the term \"machine-readable\", when used with respect to data, means data in a format that can be easily processed by a computer without human intervention while ensuring no semantic meaning is lost\"", "alts": ["machine-readable"], "reference": "44 U.S. Code § 3502 (18)", "reference_url": "https://www.govinfo.gov/app/details/USCODE-2023-title44/USCODE-2023-title44-chap35-subchapI-sec3502", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-MAY": { "term": "MAY", "definition": "The rule is truly optional. Parties SHOULD address such rules in their security documentation by explaining their decisions about how they handle such rules.", "note": "This definition only applies when the term is used in all capital letters in FedRAMP materials, otherwise the plain language meaning applies.", "tag": "Force of the Rule", "alts": [], "do_not_link": true, "ignore_in_terms": true, "updated": [ { "date": "2026-09-13", "comment": "Added force to FedRAMP Definitions for clarity." } ] }, "FRD-MCE": { "term": "Minimal Customer Effect", "definition": "An unwanted customer effect that is only noticeable by some users. This includes minor inconveniences such as reduced performance.", "tag": "Customer Effect", "alts": ["minimal customer effect", "minimal customer effects"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-MST": { "term": "MUST", "definition": "The rule is an absolute requirement. Parties MUST meet such rules and address them in their security documentation. Failure to follow the rule is a vulnerability likely requiring corrective action and/or the denial of initial or ongoing FedRAMP Certification.", "note": "This definition only applies when the term is used in all capital letters in FedRAMP materials, otherwise the plain language meaning applies.", "tag": "Force of the Rule", "alts": [], "do_not_link": true, "ignore_in_terms": true, "updated": [ { "date": "2026-09-13", "comment": "Added force to FedRAMP Definitions for clarity." } ] }, "FRD-MNT": { "term": "MUST NOT", "definition": "The rule is an absolute prohibition. Parties MUST meet such rules and address them in their security documentation. Failure to follow the rule is a vulnerability likely requiring corrective action and/or the denial of initial or ongoing FedRAMP Certification.", "note": "This definition only applies when the term is used in all capital letters in FedRAMP materials, otherwise the plain language meaning applies.", "tag": "Force of the Rule", "alts": [], "do_not_link": true, "ignore_in_terms": true, "updated": [ { "date": "2026-09-13", "comment": "Added force to FedRAMP Definitions for clarity." } ] }, "FRD-NCE": { "term": "Narrow Customer Effect", "definition": "An unwanted customer effect that interrupts use of the cloud service for some users for less than 12 hours, or that compromises the integrity or confidentiality of an extremely limited amount and type of federal customer data.", "tag": "Customer Effect", "alts": ["narrow customer effect", "narrow customer effects"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-ONC": { "term": "Ongoing Certification", "definition": "The continued FedRAMP Certification of a cloud service offering based on the applicable FedRAMP Practices.", "tag": "Certification", "alts": ["ongoing certification", "ongoing certifications"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-OCR": { "term": "Ongoing Certification Report (OCR)", "definition": "A regular report that is supplied by FedRAMP Certified cloud service providers to agency customers, following FedRAMP Collaborative Continuous Monitoring rules.", "alts": ["ongoing certification report", "OCR", "OCRs"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-OIR": { "term": "Ongoing Incident Report (OIR)", "definition": "A recurring report about an ongoing incident that is supplied by FedRAMP Certified cloud service providers to FedRAMP and agency customers, following the FedRAMP Incident Evaluation and Communication rules.", "tag": "Incident", "alts": [ "ongoing incident report", "ongoing incident reports", "OIR", "OIRs" ], "updated": [ { "date": "2026-07-02", "comment": "Update terminology from \"Response\" to \"Communication\" in FedRAMP Incident Evaluation rules." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-ODV": { "term": "Overdue Vulnerability", "definition": "A vulnerability that the provider intends to fully mitigate or remediate but has not or will not do so within the time frames recommended or required by FedRAMP.", "tag": "Vulnerability", "alts": ["overdue vulnerability", "overdue vulnerabilities"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-PMV": { "term": "Partially Mitigated Vulnerability", "definition": "A vulnerability where the likelihood or Potential Agency Impact N-rating has been reduced from the original evaluation but the risk of exploitation still exists and the vulnerability is still detected.", "tag": "Vulnerability", "alts": [ "partially mitigated vulnerability", "partially mitigated vulnerabilities", "partially mitigate vulnerabilities" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-PFA": { "term": "Persistent FedRAMP Assessment", "definition": "Follow-on assessments of a cloud service offering focused on Key Security Indicators, coordinated by the provider with all necessary assessors, to maintain FedRAMP Certification or change its FedRAMP Certification class.", "tag": "Assessment", "alts": ["persistent FedRAMP assessment", "PFRA"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-PER": { "term": "Persistently", "definition": "Occurring in a firm, steady way that is repeated over a long period of time in spite of obstacles or difficulties. Persistent activities may vary between actors, may occur irregularly, and may include interruptions or waiting periods between cycles. These attributes of persistent activities should be intentional, understood, and documented; the status of persistent activities will always be known.", "note": "The use of persistently indicates a process that may not always occur continuously (without interruption or gaps) or regularly (on a consistent, predictable basis) but will repeat frequently in cycles. It aligns generally with historical misuse of \"continuous\" in federal information security policies.", "alts": ["persistently", "persistent"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-PAI": { "term": "Potential Agency Impact", "definition": "The estimated cumulative effect of unauthorized access, disruption, harm, or other adverse impacts to all agencies using the cloud service that are likely to result from security incidents or the exploitation of vulnerabilities in the cloud service offering; as estimated following appropriate FedRAMP rules to calculate the Potential Agency Impact N-rating (PAIN).", "note": "Potential Agency Impact N-rating (PAIN) levels are defined in VER-EVA-EPA (Estimate Potential Agency Impact)", "alts": [ "potential agency impact", "potential agency impacts", "PAIN", "Potential Agency Impact N-rating" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-PAC": { "term": "Privileged Account", "definition": "An account with elevated privileges that enables administrative functions over some aspect of the cloud service offering that may affect the confidentiality, integrity, or availability of information beyond those given to normal users; levels of privilege may vary wildly.", "note": "Any references to privileged accounts in FedRAMP materials should be presumed to apply to privileged roles or other similar capabilities that are used to assign privileges to privileged accounts.", "tag": "Accounts", "alts": ["privileged account", "privileged accounts"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-PRO": { "term": "Promptly", "definition": "Without unnecessary delay.", "note": "The use of promptly in FedRAMP materials frames conveys a need for urgent action where the expected time frame will vary by circumstance but earlier action is more likely to improve security outcomes and increase the security posture of a cloud service offering.", "alts": ["promptly", "prompt"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-PRV": { "term": "Provider", "definition": "The cloud service provider responsible for a cloud service offering in the context of FedRAMP Certification.", "note": "FedRAMP Consolidated Rules frequently refer to providers without using the full term \"cloud service provider\" or acronym \"CSP\".", "tag": "Stakeholder", "alts": [ "provider", "providers", "cloud service provider", "cloud service providers" ], "do_not_link": true, "ignore_in_terms": true, "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-QTR": { "term": "Quarterly Review", "definition": "A regular synchronous meeting hosted by a FedRAMP Certified cloud service provider for agency customers, following FedRAMP Collaborative Continuous Monitoring rules.", "tag": "Certification", "alts": ["quarterly review", "quarterly reviews"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-RGL": { "term": "Regularly", "definition": "Performing the activity on a consistent, predictable, and repeated basis, at set intervals, automatically if possible, following a documented plan. These intervals may vary as appropriate between different activities.", "alts": ["regularly", "regular"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-RMV": { "term": "Remediated Vulnerability", "definition": "A vulnerability that has been neutralized or eliminated and is no longer detected.", "tag": "Vulnerability", "alts": [ "remediated vulnerability", "remediated vulnerabilities", "remediate vulnerabilities" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-RSP": { "term": "Responsibly", "definition": "In a way that shows that you have good judgment and the ability to act correctly and make decisions on your own.", "note": "Refrain from broadcasting any details that might assist adversaries in their endeavors, disclosing vulnerabilities prior to full remediation, or providing overly specific technical information that could potentially facilitate further compromise.", "alts": ["responsibly"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-RTR": { "term": "Routine Recurring Change", "definition": "The type of significant change that regularly and routinely recurs as part of ongoing operations, vulnerability mitigation, or vulnerability remediation.", "tag": "Significant Changes", "alts": [ "routine recurring", "routine recurring change", "routine recurring changes" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-SCT": { "term": "Security Category", "definition": "Has the meaning from NIST FIPS 199, which is \"The characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on organizational operations, organizational assets, or individuals.\" Security categories are often referred to as \"impact levels\" and include Low, Moderate, and High.", "alts": [ "security category", "security categories", "impact level", "impact levels" ], "reference": "NIST FIPS 199 Standards for Security Categorization of Federal Information and Information Systems", "reference_url": "https://csrc.nist.gov/pubs/fips/199/final", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-SDR": { "term": "Security Decision Record (SDR)", "definition": "A persistently maintained, verified, and validated record of the security decisions made by a provider over the lifecycle of a cloud service offering. The Security Decision Record replaces the traditional System Security Plan and documents how applicable FedRAMP Practices are addressed, including implementation rationale, resulting customer risk, assessment findings, and supporting artifacts.", "alts": [ "security decision record", "security decision records", "SDR" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-SHD": { "term": "SHOULD", "definition": "There may exist valid reasons in particular circumstances to ignore this rule, but the full implications must be understood and carefully weighed. Parties MUST address such rules in their security documentation by explaining their decisions about how they handle such rules.", "note": "This definition only applies when the term is used in all capital letters in FedRAMP materials, otherwise the plain language meaning applies.", "tag": "Force of the Rule", "alts": [], "do_not_link": true, "ignore_in_terms": true, "updated": [ { "date": "2026-09-13", "comment": "Added force to FedRAMP Definitions for clarity." } ] }, "FRD-SNT": { "term": "SHOULD NOT", "definition": "There may exist valid reasons in particular circumstances when the particular action is acceptable or even useful, but the full implications must be understand and carefully weighed. Parties MUST address such rules in their security documentation by explaining their decisions about how they handle such rules.", "note": "This definition only applies when the term is used in all capital letters in FedRAMP materials, otherwise the plain language meaning applies.", "tag": "Force of the Rule", "alts": [], "do_not_link": true, "ignore_in_terms": true, "updated": [ { "date": "2026-09-13", "comment": "Added force to FedRAMP Definitions for clarity." } ] }, "FRD-SGC": { "term": "Significant Change", "definition": "Has the meaning given in NIST SP 800-37 Rev. 2 which is \"a change that is likely to substantively affect the security or privacy posture of a system.\"", "tag": "Significant Changes", "alts": ["significant change", "significant changes"], "reference": "NIST SP 800-37 Rev. 2", "reference_url": "https://csrc.nist.gov/pubs/sp/800/37/r2/final", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-TPR": { "term": "Third-Party Information Resource", "definition": "Any information resource that is not entirely included in the Minimum Assessment Scope for the cloud service offering obtaining FedRAMP Certification.", "tag": "Information Resource", "alts": [ "third-party information resource", "third-party information resources" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-TLA": { "term": "Top-Level Administrative Account", "definition": "The most privileged account with the highest level of access within a cloud service offering for a customer organization, typically with complete control over all aspects of the cloud service offering, including managing resources, users, access, privileges, and the account itself.", "note": "Any references to top-level administrative accounts in FedRAMP materials should be presumed to apply to top-level administrative roles or other similar capabilities that are used to assign top-level administrative account privileges.", "tag": "Accounts", "alts": [ "top-level administrative account", "top-level administrative accounts" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-TRF": { "term": "Transformative Change", "definition": "The type of significant change that introduces substantive potential security risks that are likely to affect existing risk determinations and must be assessed in depth.", "note": "Transformative changes typically introduce major features or capabilities that may change how a customer uses the service (in whole or in part) and require extensive updates to security assessments, operational procedures, deployment plans, and documentation.", "tag": "Significant Changes", "alts": [ "transformative", "transformative change", "transformative changes" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-TRC": { "term": "Trust Center", "definition": "A secure repository or service used by cloud service providers to store and share FedRAMP Certification Data. Trust centers are the complete and definitive source for FedRAMP Certification Data and must follow the FedRAMP Certification Data Sharing rules to be FedRAMP-compatible.", "note": "In FedRAMP documentation, all references to trust centers indicate FedRAMP-compatible trust centers unless otherwise specified.", "alts": ["trust center", "trust centers"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-VLN": { "term": "Validation", "definition": "Confirmation through objective evidence that implemented security capabilities and related certification data are suitable for their intended FedRAMP Certification use and support the expected security outcomes for a cloud service offering.", "note": "This adapts the ISO conformity assessment concept of validation to the FedRAMP Certification context.", "alts": ["validation", "validate", "validated"], "reference": "ISO/IEC 27001:2022", "reference_url": "https://www.iso.org/standard/27001", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-VRF": { "term": "Verification", "definition": "Confirmation through objective evidence that specified FedRAMP Practices have been fulfilled for a cloud service offering.", "note": "This adapts the ISO conformity assessment concept of verification to the FedRAMP Certification context.", "alts": ["verification", "verify", "verified"], "reference": "ISO/IEC 27001:2022", "reference_url": "https://www.iso.org/standard/27001", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-VUL": { "term": "Vulnerability", "definition": "Has the meaning given to \"security vulnerability\" in 6 USC § 650 (25), which is \"any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of [...] management, operational, and technical controls used to protect against an unauthorized effort to adversely affect the confidentiality, integrity, and availability of an information system or its information.\" This includes gaps in Rev5 Controls and 20x Key Security Indicators, software vulnerabilities, misconfigurations, exposures, weak credentials, insecure services, and all other such potential weaknesses in protection (intentional or unintentional).", "tag": "Vulnerability", "alts": ["vulnerability", "vulnerabilities"], "reference": "6 USC § 650 (25)", "reference_url": "https://www.govinfo.gov/app/details/USCODE-2024-title6/USCODE-2024-title6-chap1-subchapXVIII-sec650", "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-VLD": { "term": "Vulnerability Detection", "definition": "The systematic process of discovering and identifying security vulnerabilities in information resources through assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, supply chain monitoring, and other capabilities. This process includes the initial discovery of a vulnerability's existence and the determination of affected information resources within a cloud service offering.", "note": "This definition applies to other forms such as \"detect vulnerabilities\" or simply \"detection\" / \"detected\" used in FedRAMP materials.", "tag": "Vulnerability", "alts": [ "vulnerability detection", "detect vulnerabilities", "detect", "detection", "detected" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRD-VLR": { "term": "Vulnerability Response", "definition": "The systematic process of tracking, evaluating, mitigating, monitoring, remediating, assessing exploitation, reporting, and otherwise managing detected vulnerabilities.", "note": "This definition applies to other forms such as \"respond to vulnerabilities\" or simply \"response\" / \"responded\" used in FedRAMP materials.", "tag": "Vulnerability", "alts": [ "vulnerability response", "respond to vulnerabilities", "respond", "response", "responded" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } }, "FRR": { "AFC": { "info": { "name": "Addressing FedRAMP Communication", "short_name": "AFC", "web_name": "addressing-fedramp-communication", "purpose": "The Addressing FedRAMP Communication rules (formerly FedRAMP Security Inbox) ensure FedRAMP can reliably contact the security and compliance staff responsible for every FedRAMP-authorized cloud service offering. These rules also set expectations for urgent communications, response time testing, and routing important messages separately from general support or customer service channels.", "status": "stable", "tag": "assurance", "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-01-05", "maintain": "2026-01-05", "grace": { "default": "2026-07-01", "until_next_assessment": false } } }, "subsets": { "FRP": { "name": "FedRAMP Responsibilities", "description": "These rules apply to FedRAMP when communicating with cloud service providers.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["FedRAMP"] } }, "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to providers with any type of FedRAMP Certification.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } }, "data": { "all": { "FRP": { "AFC-FRP-VRE": { "name": "Verified Emails", "statement": "FedRAMP MUST send messages to cloud service providers using an official @fedramp.gov or @gsa.gov email address with properly configured Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication Reporting and Conformance (DMARC) email authentication.", "note": "Anyone at GSA can send email from @fedramp.gov or @gsa.gov - FedRAMP team members will typically have \"FedRAMP\" or \"F20B\" in their name but this is not universal or enforceable. The nature of government enterprise IT services makes it difficult for FedRAMP to isolate FedRAMP-specific team members with enforceable identifiers.", "force": "MUST", "affects": ["FedRAMP"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-FRP-CDS": { "name": "Criticality Designators", "statement": "FedRAMP MUST convey the criticality of the message in the subject line, IF the message requires an elevated reaction, using one of the following designators:", "following_information": [ "**Emergency:** There is a potential incident or crisis such that FedRAMP requires an extremely urgent reaction; emergency messages will contain aggressive timeframes for reaction and failure to meet these timeframes will result in corrective action.", "**Emergency Test:** FedRAMP requires an extremely urgent reaction to confirm the functionality and effectiveness of the FedRAMP Security Inbox; emergency test messages will contain aggressive timeframes for reaction and failure to meet these timeframes will result in corrective action.", "**Important:** There is an important issue that FedRAMP requires the cloud service provider to address; important messages will contain reasonable timeframes for reaction and failure to meet these timeframes may result in corrective action." ], "note": "Messages sent by FedRAMP without one of these designators are considered general communications and do not require an elevated reaction; these may be resolved in the normal course of business by the cloud service provider.", "force": "MUST", "affects": ["FedRAMP"], "terms": ["FedRAMP Security Inbox", "Incident"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-FRP-UFS": { "name": "Use FedRAMP_Security Email in Emergencies", "statement": "FedRAMP MUST send Emergency and Emergency Test designated messages from fedramp_security@gsa.gov OR fedramp_security@fedramp.gov.", "force": "MUST", "affects": ["FedRAMP"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-FRP-PNT": { "name": "Public Notice of Emergency Tests", "statement": "FedRAMP MUST post a public notice at least 10 business days in advance of sending an Emergency Test message; such notices MUST include explanation of the likely expected actions and timeframes for the Emergency Test message.", "notes": [ "Public notice may include blog posts, social media posts, announcements during Community Updates, or e-blasts.", "As this process matures, additional confirmed options may become available." ], "force": "MUST", "affects": ["FedRAMP"], "timeframe_type": "bizdays", "timeframe_num": 10, "notification": [ { "party": "Everyone", "method": "web", "target": "https://www.fedramp.gov/notices", "name": "FedRAMP Public Notices" } ], "terms": ["Likely"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-FRP-RQA": { "name": "Required Actions", "statement": "FedRAMP MUST clearly specify the required actions in the body of messages that require an elevated reaction.", "force": "MUST", "affects": ["FedRAMP"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-FRP-ERT": { "name": "Elevated Reaction Timeframes", "statement": "FedRAMP MUST clearly specify the expected timeframe for completing required actions in the body of messages that require an elevated reaction; timeframes for actions will vary depending on the situation but the default timeframes to provide an estimated resolution time for Emergency and Emergency Test designated messages will be as follows:", "following_information": [ "**Class D:** within 12 hours", "**Class C:** by 3:00 p.m. Eastern Time on the 2nd business day", "**Class B:** by 3:00 p.m. Eastern Time on the 3rd business day", "**Class A:** by 3:00 p.m. Eastern Time on the 5th business day" ], "note": "FedRAMP Class D Certified cloud service providers are expected to address Emergency messages (including tests) from FedRAMP with a reaction time appropriate to operating a service where failure to react rapidly might have a severe or debilitating customer effect on the U.S. Government; some Emergency messages may require faster reaction and all such messages should be addressed as quickly as possible.", "force": "MUST", "affects": ["FedRAMP"], "terms": ["Debilitating Customer Effect", "FedRAMP Certified"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-FRP-COR": { "name": "Explain Corrective Actions", "statement": "FedRAMP MUST clearly specify the corrective actions that will result from failure to complete the required actions in the body of messages that require an elevated reaction; such actions may vary from negative ratings in the FedRAMP Marketplace to suspension of FedRAMP Certification depending on the severity of the event.", "force": "MUST", "affects": ["FedRAMP"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-FRP-RPM": { "name": "Reaction Metrics", "statement": "FedRAMP MAY track and publicly share the time required by cloud service providers to take the actions specified in messages that require an elevated reaction.", "force": "MAY", "affects": ["FedRAMP"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "CSO": { "AFC-CSO-INB": { "name": "Maintain a FedRAMP Security Inbox", "statement": "Providers MUST establish and maintain an email address to receive messages from FedRAMP; this inbox is a FedRAMP Security Inbox (FSI).", "danger": "Be careful using a personal email tied to an individual for this inbox due to the significant risk to future communications after a change in personnel!", "notes": [ "Unless otherwise notified, FedRAMP will use the listed Security Email on the Marketplace for these notifications.", "If a provider establishes a new inbox in reaction to this guidance that is different from the Security Email then they must follow the AFC-CSO-NOC (Notification of Changes) rules to notify FedRAMP." ], "related": ["AFC-CSO-NOC"], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": ["Email address to receive messages from FedRAMP"] }, "terms": ["FedRAMP Security Inbox"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-CSO-NOC": { "name": "Notification of Changes", "statement": "Providers MUST immediately notify FedRAMP of any changes to the email address for their FedRAMP Security Inbox.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "Process, manual or automated, to notify FedRAMP of changes in the FedRAMP Security Inbox" ] }, "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51829466938011", "name": "[CSP] Notification of Changes" } ], "terms": ["FedRAMP Security Inbox"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-CSO-TFG": { "name": "Trust @fedramp.gov and @gsa.gov", "statement": "Providers MUST treat any email originating from an @fedramp.gov or @gsa.gov email address as if it was sent from FedRAMP by default; if such a message is confirmed to originate from someone other than FedRAMP then the FedRAMP Security Inbox rules no longer apply.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "Configuration settings for FSI mailbox", "Automated validation to check FSI mailbox configuration" ] }, "terms": ["FedRAMP Security Inbox"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-CSO-RCV": { "name": "Receive Email Without Disruption", "statement": "Providers MUST receive and react to email messages from FedRAMP without disruption and without requiring additional actions from FedRAMP.", "note": "This requirement is intended to prevent cloud service providers from requiring FedRAMP to complete a CAPTCHA, log into a customer portal, or otherwise take service-specific actions that might prevent the security team from receiving the message.", "force": "MUST", "affects": ["Providers"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-CSO-CRA": { "name": "Complete Required Actions", "statement": "Providers MUST complete the required actions in Emergency or Emergency Test designated messages sent by FedRAMP within the timeframe included in the message.", "note": "Timeframes may vary by FedRAMP Certification class.", "force": "MUST", "affects": ["Providers"], "terms": ["Certification Class"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-CSO-EMR": { "name": "Emergency Message Routing", "statement": "Providers MUST route Emergency designated messages sent by FedRAMP to a senior security official for their awareness.", "note": "Senior security officials are determined by the provider.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "Configuration settings for FSI mailbox", "Automated validation to check FSI mailbox configuration" ] }, "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-CSO-IMA": { "name": "Important Message Actions", "statement": "Providers SHOULD complete the required actions in Important designated messages sent by FedRAMP within the timeframe specified in the message.", "note": "Timeframes may vary by FedRAMP Certification class.", "force": "SHOULD", "affects": ["Providers"], "terms": ["Certification Class"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AFC-CSO-ACK": { "name": "Acknowledge Receipt", "statement": "Providers SHOULD promptly and automatically acknowledge the receipt of messages received from FedRAMP in their FedRAMP Security Inbox.", "force": "SHOULD", "affects": ["Providers"], "terms": ["FedRAMP Security Inbox", "Promptly"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "AGU": { "info": { "name": "Agency Use of FedRAMP Certified Cloud Services", "short_name": "AGU", "web_name": "agency-use", "purpose": "The Agency Use rules summarize the many demands made on agencies by the FedRAMP Authorization Act and OMB Memorandum M-24-15 in a simple, clear, easy-to-follow set of FedRAMP-style rules. These rules align agency policies, authorization letters, machine-readable tools, secure configuration review, continuous monitoring, and communication with FedRAMP so certifications can be reused consistently across government.", "status": "placeholder", "tag": "gov", "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2026-07-04", "optional_adoption": "2026-07-04", "grace": { "default": "2026-07-04", "until_next_assessment": false } } }, "subsets": { "AGC": { "name": "General Agency Responsibilities", "description": "These rules apply to agencies based on the FedRAMP Authorization Act, OMB M-24-15, and related FedRAMP policies.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["A", "B", "C", "D"], "affects": ["Agencies"] } }, "USE": { "name": "Use of FedRAMP Certifications", "description": "These rules apply when agencies use FedRAMP Certifications to make agency authorization decisions.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["A", "B", "C", "D"], "affects": ["Agencies"] } }, "SPN": { "name": "Agency Sponsored Certifications", "description": "These rules apply when an agency sponsors a FedRAMP Rev5 Certification after completing an agency authorization.", "applicability": { "types": ["Rev5"], "paths": ["Agency"], "classes": ["B", "C", "D"], "affects": ["Agencies"] } } } }, "data": { "all": { "AGC": { "AGU-AGC-AIP": { "name": "Agency Internal Policies", "statement": "Agencies MUST maintain agency-wide policy that aligns with the requirements in OMB Memorandum M-24-15.", "force": "MUST", "affects": ["Agencies"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-AGC-NAA": { "name": "Notify FedRAMP After Authorization", "statement": "Agencies MUST notify FedRAMP upon authorizing the use of a cloud service within the scope of FedRAMP, supplying at least the following information:", "following_information": [ "A copy of the agency's Authorization to Operate letter for the information system leveraging the cloud service, following agency policy and templates.", "All other supplemental information requested in the Submit an ATO Letter form by FedRAMP." ], "force": "MUST", "affects": ["Agencies"], "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51447926193691", "name": "Submit an ATO Letter" } ], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-AGC-GRC": { "name": "Governance, Risk, and Compliance Tools", "statement": "Agencies MUST ensure that internal governance, risk, compliance, and inventory tools can produce and ingest machine-readable artifacts using formats identified by FedRAMP, including at least:", "following_information": [ "Open Security Controls Assessment Language (OSCAL)", "JSON" ], "force": "MUST", "affects": ["Agencies"], "terms": ["Artifacts", "Machine-Readable"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-AGC-NAI": { "name": "Notify Additional Information Requests", "statement": "Agencies MUST notify FedRAMP after requesting any additional information or materials from a FedRAMP Certified cloud service offering beyond those required by FedRAMP.", "note": "Agencies are expected to notify FedRAMP under OMB Memorandum M-24-15 section IV (a).", "force": "MUST", "affects": ["Agencies"], "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51822364715035", "name": "[For Agencies] Additional Information, Security Requirements, or Certification Change, or After Request Form" } ], "terms": ["Cloud Service Offering", "FedRAMP Certified"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-AGC-NAR": { "name": "No Additional Security Requirements", "statement": "Agencies MUST NOT require additional information or materials from FedRAMP Certified cloud service offerings beyond those required by FedRAMP UNLESS the head of the agency or an authorized delegate determines there is a demonstrable need and notifies FedRAMP; this does not apply to seeking clarification or asking general questions about FedRAMP Certification Data.", "note": "This is related to the Presumption of Adequacy for a FedRAMP Certification and notification is mandated by OMB Memorandum M-24-15 section IV (a).", "force": "MUST NOT", "affects": ["Agencies"], "notification": [ { "party": "FedRAMP", "method": "email", "target": "info@fedramp.gov", "name": "info@fedramp.gov" } ], "terms": [ "Certification Data", "Cloud Service Offering", "FedRAMP Certified" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-AGC-TPP": { "name": "No Certification Type or Path Preferences", "statement": "Agencies MUST NOT require cloud service offerings to obtain or maintain a specific FedRAMP Certification Type or FedRAMP Certification Path, UNLESS the head of the agency or an authorized delegate determines there is a demonstrable need and notifies FedRAMP.", "note": "This is related to the Presumption of Adequacy for a FedRAMP Certification and notification is mandated by OMB Memorandum M-24-15 section IV (a).", "force": "MUST NOT", "affects": ["Agencies"], "notification": [ { "party": "FedRAMP", "method": "email", "target": "info@fedramp.gov", "name": "info@fedramp.gov" } ], "terms": [ "Certification Path", "Certification Type", "Cloud Service Offering", "FedRAMP Certified" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-AGC-WKG": { "name": "FedRAMP Working Groups", "statement": "Agencies SHOULD participate in FedRAMP working groups, communities of practice, and stakeholder engagements to supply feedback and align practices across government.", "force": "SHOULD", "affects": ["Agencies"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-AGC-LIA": { "name": "Agency Liaison Program", "statement": "Agencies SHOULD assign at least 1 federal employee to be an active participant in the FedRAMP Agency Liaison program.", "reference": "Agency Liaison Program", "reference_url": "https://www.fedramp.gov/2026/agencies/support/liaisons", "force": "SHOULD", "affects": ["Agencies"], "terms": [], "updated": [ { "date": "2026-09-13", "comment": "Fixed broken reference URL for the Agency Liaison Program." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-AGC-SIN": { "name": "Shared FedRAMP Inbox", "statement": "Agencies SHOULD establish and maintain a dedicated shared FedRAMP agency inbox to serve as the official point of contact for communications between FedRAMP and the agency.", "note": "A shared FedRAMP agency inbox may follow an agency-specific format such as agency-fedramp@agency.gov.", "force": "SHOULD", "affects": ["Agencies"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "USE": { "AGU-USE-ABU": { "name": "Authorization Before Use", "statement": "Agencies MUST complete the Authorization to Operate process for federal information systems that use FedRAMP Certified cloud service offerings.", "note": "FedRAMP provides technical assistance to help agencies navigate this process.", "reference": "Using a FedRAMP Certified Cloud Service Offering", "reference_url": "https://www.fedramp.gov/2026/agencies/use", "force": "MUST", "affects": ["Agencies"], "terms": ["Cloud Service Offering", "FedRAMP Certified"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-USE-RCF": { "name": "Resolve Certification Package Conflicts", "statement": "Agencies MUST collaborate with FedRAMP when discrepancies or conflicts arise between agency-specific security determinations and the FedRAMP Certification Package.", "force": "MUST", "affects": ["Agencies"], "terms": ["Certification Package"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-USE-RSG": { "name": "Review Secure Configuration Guides", "statement": "Agencies MUST review the Secure Configuration Guides supplied by Providers and configure relevant security settings.", "force": "MUST", "affects": ["Agencies"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-USE-AFR": { "name": "Accept FedRAMP Rules", "statement": "Agencies MUST allow FedRAMP Certified cloud service offerings to follow FedRAMP rules.", "force": "MUST", "affects": ["Agencies"], "terms": ["Cloud Service Offering", "FedRAMP Certified"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-USE-NFC": { "name": "Notify FedRAMP of Monitoring Concerns", "statement": "Agencies MUST notify FedRAMP if information presented in an Ongoing Certification Report, Quarterly Review, or other FedRAMP Certification Data causes significant concerns for the authorizing official that would likely result in rescission of their Authorization to Operate.", "note": "Agencies are expected to notify FedRAMP under OMB Memorandum M-24-15 section IV (a).", "force": "MUST", "affects": ["Agencies"], "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51821301979547", "name": "Report Concerns on Ongoing Certifications" } ], "terms": [ "Certification Data", "FedRAMP Certification Report", "Likely", "Ongoing Certification", "Ongoing Certification Report (OCR)", "Quarterly Review" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-USE-ROR": { "name": "Review Ongoing Certification Reports", "statement": "Agencies SHOULD review each Ongoing Certification Report to understand how changes to the cloud service offering may impact the risk tolerance documented in the agency Authorization to Operate for the federal information system that includes the cloud service offering in its boundary.", "note": "This agency review supports agency responsibilities under 44 USC § 35, OMB Circular A-130, FIPS-200, and OMB Memorandum M-24-15.", "force": "SHOULD", "affects": ["Agencies"], "terms": [ "Cloud Service Offering", "FedRAMP Certification Report", "Ongoing Certification", "Ongoing Certification Report (OCR)" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-USE-DSO": { "name": "Designate Senior Official", "statement": "Agencies SHOULD designate a federal senior information security official to review Ongoing Certification Reports and represent the agency at Quarterly Reviews for cloud service offerings included in agency information systems.", "force": "SHOULD", "affects": ["Agencies"], "terms": [ "Cloud Service Offering", "Ongoing Certification", "Quarterly Review" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-USE-NPC": { "name": "Notify Provider of Concerns", "statement": "Agencies SHOULD formally notify the cloud service provider if information presented in an Ongoing Certification Report, Quarterly Review, or other FedRAMP Certification Data causes significant concerns for the authorizing official that would likely result in rescission of their Authorization to Operate.", "force": "SHOULD", "affects": ["Agencies"], "notification": [ { "party": "Provider", "method": "varies", "target": "varies by provider", "name": "The provider's security contact email or form." } ], "terms": [ "Certification Data", "FedRAMP Certification Report", "Likely", "Ongoing Certification", "Ongoing Certification Report (OCR)", "Quarterly Review" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-USE-RIR": { "name": "Review All Information Resources", "statement": "Agencies SHOULD consider third-party information resources used by the cloud service offering during initial and ongoing authorization activities.", "force": "SHOULD", "affects": ["Agencies"], "terms": [ "Cloud Service Offering", "Information Resource", "Third-Party Information Resource" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "AGU-USE-CLA": { "name": "Using FedRAMP Class A Certifications", "statement": "Agencies SHOULD NOT authorize the use of a FedRAMP Class A Certified cloud service offering for more than 12 months UNLESS the cloud service offering is actively seeking a FedRAMP Class B, C, or D Certification.", "force": "SHOULD NOT", "affects": ["Agencies"], "terms": ["Cloud Service Offering", "FedRAMP Certified"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "SPN": { "AGU-SPN-MRC": { "name": "Most Recent Consolidated Rules", "statement": "Agencies MUST follow the most recent FedRAMP Consolidated Rules when initiating agency-sponsored FedRAMP Certification.", "force": "MUST", "affects": ["Agencies"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "CCM": { "info": { "name": "Collaborative Continuous Monitoring", "short_name": "CCM", "web_name": "collaborative-continuous-monitoring", "purpose": "The Collaborative Continuous Monitoring rules help agencies use shared, current authorization information from providers as part of each agency's own Information Security Continuous Monitoring strategy. These rules reduce unnecessary manual burden by encouraging automated monitoring and review while allowing each agency to make its own risk-based decisions about ongoing authorization.", "status": "stable", "tag": "assurance", "subsets": { "AGM": { "name": "Agency Guidance", "description": "These rules for agencies apply to all agencies using a FedRAMP Certification.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Agencies"] } }, "OCR": { "name": "Ongoing Certification Reports", "description": "These rules for Ongoing Certification Reports apply to providers with any type of FedRAMP Certification.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "QTR": { "name": "Quarterly Reviews", "description": "These rules for Quarterly Reviews apply to providers with any type of FedRAMP Certification.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } }, "20x": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } } }, "rev5": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2027-01-01", "maintain": "2027-04-02", "optional_adoption": "2026-07-04", "grace": { "default": "2027-10-01", "until_next_assessment": false } } } } }, "data": { "all": { "AGM": { "CCM-AGM-ROR": { "name": "Review Ongoing Reports", "statement": "Agencies MUST review each Ongoing Certification Report to understand how changes to the cloud service offering may impact the previously agreed-upon risk tolerance documented in the agency's Authorization to Operate of a federal information system that includes the cloud service offering in its boundary.", "note": "This is required by 44 USC § 35, OMB A-130, FIPS-200, and M-24-15.", "force": "MUST", "affects": ["Agencies"], "terms": [ "Cloud Service Offering", "FedRAMP Certification Report", "Ongoing Certification", "Ongoing Certification Report (OCR)" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-AGM-CSC": { "name": "Consider Security Category", "statement": "Agencies SHOULD consider the Security Category noted in their Authorization to Operate of the federal information system that includes the cloud service offering in its boundary and assign appropriate information security resources for reviewing Ongoing Certification Reports, attending Quarterly Reviews, and other ongoing FedRAMP Certification Data.", "force": "SHOULD", "affects": ["Agencies"], "terms": [ "Certification Data", "Cloud Service Offering", "Ongoing Certification", "Quarterly Review", "Security Category" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "OCR": { "CCM-OCR-AVL": { "name": "Report Availability", "statement": "Providers MUST supply an Ongoing Certification Report to all necessary parties every 3 months, covering the entire period since the previous summary, in a consistent format that is human readable; this report MUST include high-level summaries of at least the following information (if applicable):", "following_information": [ "Changes to FedRAMP Certification Data", "Planned changes to FedRAMP Certification Data during at least the next 3 months", "Accepted vulnerabilities", "Transformative changes", "Updated recommendations or best practices for security, configuration, usage, or similar aspects of the cloud service offering", "A list of all agencies that are directly using the product", "FedRAMP Reportable Incidents or an attestation that no such incidents occurred", "Lessons learned and changes planned or made as a result of FedRAMP Reportable Incidents (if such occurred)" ], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "Most recent Ongoing Certification Report. If the report is not available, the provider MUST provide a sample report that includes all required information.", "How the report will be delivered" ] }, "schema": { "name": "FedRAMP Ongoing Certification Report (CCM-OCR-AVL)", "url": "https://fedramp.gov/schemas/fedramp-ongoing-certification-report-schema-2026-06-24.json" }, "timeframe_type": "months", "timeframe_num": 3, "terms": [ "Accepted Vulnerability", "All Necessary Parties", "Certification Data", "Cloud Service Offering", "FedRAMP Certification Report", "FedRAMP Reportable Incident", "Incident", "Ongoing Certification", "Ongoing Certification Report (OCR)", "Transformative Change", "Vulnerability" ], "updated": [ { "date": "2026-09-13", "comment": "Added (if applicable) to clarify that some of these items are not always required depending on the FedRAMP Certification Type or Class." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-OCR-NRD": { "name": "Next Report Date", "statement": "Providers MUST supply the target date for their next Ongoing Certification Report with other public FedRAMP Certification Data.", "force": "MUST", "affects": ["Providers"], "terms": [ "Certification Data", "FedRAMP Certification Report", "Ongoing Certification", "Ongoing Certification Report (OCR)" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-OCR-FBM": { "name": "Feedback Mechanism", "statement": "Providers MUST supply an asynchronous mechanism for all necessary parties to provide feedback or ask questions about each Ongoing Certification Report.", "note": "This could be email by default but providers are encouraged to consider something more interactive as appropriate.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": ["How to access the feedback mechanism."] }, "terms": [ "All Necessary Parties", "FedRAMP Certification Report", "Ongoing Certification", "Ongoing Certification Report (OCR)" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-OCR-AFS": { "name": "Anonymized Feedback Summary", "statement": "Providers MUST supply an anonymized and desensitized summary of the feedback, questions, and answers about each Ongoing Certification Report as an addendum to the Ongoing Certification Report OR in the next Ongoing Certification Report.", "note": "This is intended to encourage sharing of information and decrease the burden on the cloud service provider - providing this summary will reduce duplicate questions from agencies and ensure FedRAMP has access to this information. It is generally in the provider's interest to update this addendum frequently throughout the quarter.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": ["How the summary will be delivered"] }, "terms": [ "FedRAMP Certification Report", "Ongoing Certification", "Ongoing Certification Report (OCR)" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-OCR-LSI": { "name": "Limit Sensitive Information", "statement": "Providers MUST NOT irresponsibly disclose sensitive information in an Ongoing Certification Report that would likely have an adverse effect on the cloud service offering.", "force": "MUST NOT", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "FedRAMP Certification Report", "Likely", "Ongoing Certification", "Ongoing Certification Report (OCR)" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-OCR-SOR": { "name": "Spread Out Reports", "statement": "Providers SHOULD establish a regular 3 month cycle for Ongoing Certification Reports that is spread out from the beginning, middle, or end of each quarter.", "note": "This recommendation is intended to discourage hundreds of cloud service providers from releasing their Ongoing Certification Reports during the first or last week of each quarter because that is the easiest way for a single provider to track this deliverable; the result would overwhelm agencies with many cloud services. Widely used cloud service providers are encouraged to work with their customers to identify ideal timeframes for this cycle.", "force": "SHOULD", "affects": ["Providers"], "terms": ["Ongoing Certification", "Regularly"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-OCR-RPS": { "name": "Responsible Public Certification Report Sharing", "statement": "Providers MAY responsibly supply some or all of the information an Ongoing Certification Report to the public or other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.", "force": "MAY", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "FedRAMP Certification Report", "Likely", "Ongoing Certification", "Ongoing Certification Report (OCR)", "Responsibly" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "QTR": { "CCM-QTR-MTG": { "name": "Quarterly Review Meeting", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications MAY host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.", "force": "MAY", "timeframe_type": "months", "timeframe_num": 3, "artifacts": { "all": [ "selected ordinal recurrence for the synchronous Quarterly Review cycle if applicable." ] } }, "b": { "statement": "Providers with Class B Certifications SHOULD host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 3, "artifacts": { "all": [ "selected ordinal recurrence for the Ongoing Certification Report cycle if applicable OR explanation for why Ongoing Certification Reports are not being delivered." ] } }, "c": { "statement": "Providers with Class C Certifications MUST host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.", "force": "MUST", "timeframe_type": "months", "timeframe_num": 3, "artifacts": { "all": [ "selected ordinal recurrence for the Ongoing Certification Report cycle." ] } }, "d": { "statement": "Providers with Class D Certifications MUST host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.", "force": "MUST", "timeframe_type": "months", "timeframe_num": 3, "artifacts": { "all": [ "selected ordinal recurrence for the Ongoing Certification Report cycle." ] } } }, "affects": ["Providers"], "terms": [ "All Necessary Parties", "Ongoing Certification", "Quarterly Review" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-QTR-REG": { "name": "Meeting Registration Info", "statement": "Providers MUST supply either a registration link or a downloadable calendar file with meeting information for Quarterly Reviews to all necessary parties.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": ["URL to the registration page or calendar file."] }, "terms": ["All Necessary Parties", "Quarterly Review"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-QTR-NRD": { "name": "Next Review Date", "statement": "Providers MUST publicly supply the target date for their next Quarterly Review with other public FedRAMP Certification Data.", "force": "MUST", "affects": ["Providers"], "terms": ["Certification Data", "Quarterly Review"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-QTR-NID": { "name": "No Irresponsible Disclosure", "statement": "Providers MUST NOT irresponsibly disclose sensitive information in a Quarterly Review that would likely have an adverse effect on the cloud service offering.", "force": "MUST NOT", "affects": ["Providers"], "terms": ["Cloud Service Offering", "Likely", "Quarterly Review"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-QTR-SAR": { "name": "Schedule Around Reports", "statement": "Providers SHOULD regularly schedule Quarterly Reviews to occur at least 3 business days after releasing an Ongoing Certification Report AND within 10 business days of such release.", "force": "SHOULD", "affects": ["Providers"], "timeframe_type": "bizdays", "timeframe_num_min": 3, "timeframe_num_max": 10, "terms": [ "FedRAMP Certification Report", "Ongoing Certification", "Ongoing Certification Report (OCR)", "Quarterly Review", "Regularly" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-QTR-ACT": { "name": "Additional Content", "statement": "Providers SHOULD supply additional information in Quarterly Reviews that the provider determines is of interest, use, or otherwise relevant to agencies.", "force": "SHOULD", "affects": ["Providers"], "terms": ["Quarterly Review"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-QTR-RTR": { "name": "Record/Transcribe Reviews", "statement": "Providers SHOULD record or transcribe Quarterly Reviews and supply them to all necessary parties.", "force": "SHOULD", "affects": ["Providers"], "terms": ["All Necessary Parties", "Quarterly Review"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-QTR-RTP": { "name": "Restrict Third Parties", "statement": "Providers SHOULD NOT invite third parties to attend Quarterly Reviews intended for agencies unless they have specific relevance.", "note": "This is because agencies are less likely to actively participate in meetings with third parties; the cloud service provider's independent assessor should be considered relevant by default.", "force": "SHOULD NOT", "affects": ["Providers"], "terms": ["Likely", "Quarterly Review"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-QTR-SRR": { "name": "Share Recordings Responsibly", "statement": "Providers MAY responsibly supply recordings or transcriptions of Quarterly Reviews to the public or other parties ONLY if the provider removes all agency information (comments, questions, names, etc.) AND determines doing so will NOT likely have an adverse effect on the cloud service offering.", "force": "MAY", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "Likely", "Quarterly Review", "Responsibly" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CCM-QTR-SCR": { "name": "Share Content Responsibly", "statement": "Providers MAY responsibly supply content prepared for a Quarterly Review to the public or other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.", "force": "MAY", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "Likely", "Quarterly Review", "Responsibly" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "CDS": { "info": { "name": "Certification Data Sharing", "short_name": "CDS", "web_name": "certification-data-sharing", "purpose": "The Certification Data Sharing rules allow providers to store and share FedRAMP Certification Data through the platform they choose as long as it follows FedRAMP rules for access, accuracy, and transparency. This helps customers and the public review consistent, current security and compliance information while recognizing that the information usually remains the provider's intellectual property and is not federal information.", "status": "stable", "tag": "boundary", "subsets": { "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to providers for FedRAMP Certifications of any type.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "TRC": { "name": "FedRAMP-Compatible Trust Centers", "description": "These rules apply to trust centers that are FedRAMP-compatible.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "UTC": { "name": "Using a Trust Center", "description": "These rules apply to providers that are using a FedRAMP-compatible trust center instead of USDA Connect; they DO NOT apply to providers using USDA Connect.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } }, "20x": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } } }, "rev5": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2027-01-01", "maintain": "2027-08-01", "optional_adoption": "2026-07-04", "grace": { "default": "2028-02-01", "until_next_assessment": false } } }, "subsets": { "CSF": { "name": "Rev5-Specific Provider Responsibilities", "description": "These rules apply to providers for FedRAMP Rev5 Certifications.", "applicability": { "types": ["Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } } }, "data": { "all": { "CSO": { "CDS-CSO-PUB": { "name": "Public Information", "statement": "Providers MUST publicly share up-to-date information about the cloud service offering in both human-readable and JSON formats, including at least the following information that is available and applicable:", "following_information": [ "FedRAMP ID", "Service Model", "Deployment Model", "Business Category", "UEI Number", "Sales Contact Information", "Security Contact Information", "Product Website Link", "Link to Product Logo", "Overall Service Description", "Detailed list of specific services and their security categories (see CDS-CSO-SVC (Public Service List) (Service List))", "Link to Secure Configuration Guidance", "Overview of documentation supplied by the provider for the cloud service offering", "Link to Trust Center landing page that includes instructions on accessing information in the trust center", "Next Ongoing Certification Report date (see CCM-OCR-NRD (Next Report Date))", "Current FedRAMP Recognized independent assessment service" ], "note": "Generally, this information should be available on a public webpage or publicly shared in a FedRAMP-compatible trust center.", "related": ["CDS-CSO-SVC", "CCM-OCR-NRD"], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "URL to the human-readable data.", "URL to the machine-readable data." ] }, "schema": { "name": "FedRAMP Certification Package Overview (FRC-CSO-PKG)", "url": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json" }, "terms": [ "Cloud Service Offering", "FedRAMP Certification Report", "FedRAMP Recognized", "Ongoing Certification", "Ongoing Certification Report (OCR)", "Security Category", "Trust Center" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-SVC": { "name": "Public Service List", "statement": "Providers MUST publicly share a detailed list of specific services and their security categories that are included in the cloud service offering using clear feature or service names that align with standard public marketing materials; this list MUST be complete enough for a potential customer to determine which services are and are not included in the FedRAMP Minimum Assessment Scope without requesting access to underlying FedRAMP Certification Data.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "URL to the human-readable data.", "URL to the machine-readable data (if applicable)." ] }, "schema": { "name": "FedRAMP Certification Package Overview (FRC-CSO-PKG)", "url": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json" }, "terms": [ "Certification Data", "Cloud Service Offering", "Security Category" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-FID": { "name": "Always Include FedRAMP ID", "statement": "Providers MUST always include the FedRAMP ID of the related cloud service offering in all FedRAMP Certification Data once assigned, including all reports, notifications, and other communication that results from FedRAMP rules.", "notes": [ "The FedRAMP ID is supplied by FedRAMP after a cloud service offering is registered to be listed on the FedRAMP Marketplace - providers will need to use a placeholder until the FedRAMP ID is assigned.", "Many providers have multiple cloud service offerings or use internal names that don't align to public materials; using the FedRAMP ID ensures we can easily align the communication with a specific cloud service offering." ], "force": "MUST", "affects": ["Providers"], "terms": ["Certification Data", "Cloud Service Offering"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-FRC": { "name": "FedRAMP Certification Reports", "statement": "Providers MUST include FedRAMP Certification Reports with their FedRAMP Certification Data without inappropriate modifications, and make such reports available within 2 weeks of receiving the materials from FedRAMP.", "note": "FedRAMP provides Certification Reports for all cloud service offerings following the Program Certification path as part of the initial and ongoing FedRAMP Certification process, and may provide Certification Reports for cloud service offerings following the Agency Certification path.", "force": "MUST", "affects": ["Providers"], "timeframe_type": "weeks", "timeframe_num": 2, "terms": [ "Certification Data", "Certification Path", "Cloud Service Offering" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-AVR": { "name": "Availability Reporting", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications SHOULD maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service SHOULD be available even if the primary cloud service offering is unavailable.", "note": "This service may be separate from the trust center.", "force": "SHOULD" }, "b": { "statement": "Providers with Class B Certifications MUST maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service MUST be available even if the primary cloud service offering is unavailable.", "note": "This service may be separate from the trust center.", "force": "MUST" }, "c": { "statement": "Providers with Class C Certifications MUST maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service MUST be available even if the primary cloud service offering is unavailable.", "note": "This service may be separate from the trust center.", "force": "MUST" }, "d": { "statement": "Providers with Class D Certifications MUST maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service MUST be available even if the primary cloud service offering is unavailable.", "note": "This service may be separate from the trust center.", "force": "MUST" } }, "affects": ["Providers"], "terms": [ "All Necessary Parties", "Cloud Service Offering", "Incident", "Machine-Readable" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-UTC": { "name": "Use Trust Centers", "statement": "Providers MUST use a FedRAMP-compatible trust center to store and share FedRAMP Certification Data with all necessary parties.", "note": "Rules for FedRAMP-Compatible Trust Centers are explained in the Certification Data Sharing Rules under the FedRAMP-Compatible Trust Centers section (id: CDS-TRC).", "force": "MUST", "affects": ["Providers"], "schema": { "name": "FedRAMP Certification Package Overview (FRC-CSO-PKG)", "url": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json" }, "terms": [ "All Necessary Parties", "Certification Data", "Trust Center" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-CBF": { "name": "Consistency Between Formats", "statement": "Providers MUST use automation to ensure information remains consistent between human-readable and machine-readable formats when FedRAMP Certification Data is provided in both formats.", "force": "MUST", "affects": ["Providers"], "terms": ["Certification Data", "Machine-Readable"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-RIS": { "name": "Responsible Information Sharing", "statement": "Providers MUST provide sufficient information in FedRAMP Certification Data to support agency authorization decisions but SHOULD NOT include sensitive information that would likely enable a threat actor to gain unauthorized access, cause harm, disrupt operations, or otherwise have a negative adverse impact on the cloud service offering.", "note": "This is not a license to exclude accurate risk information, but specifics that would likely lead to compromise should be abstracted. A breach of confidentiality with FedRAMP Certification Data should be anticipated by a secure cloud service provider.", "force": "MUST", "affects": ["Providers"], "examples": [ { "id": "Tips on sensitive information in FedRAMP Certification Data", "key_tests": [ "Passwords, API keys, access credentials, etc.", "Excessive detail about methodology that exposes weaknesses", "Personally identifiable information about employees" ], "examples": [ "DON'T: \"In an emergency, an administrator with physical access to a system can log in using \"secretadmin\" with the password \"pleasewutno\"\"", "DO: \"In an emergency, administrators with physical access can log in directly.\"", "DON'T: \"All backup MFA credentials are stored in a SuperSafe Series 9000 safe in the CEOs office.\"", "DO: \"All backup MFA credentials are stored in a UL Class 350 safe in a secure location with limited access.\"", "DON'T: \"During an incident, the incident response team lead by Jim Smith (555-0505) will open a channel at the conference line (555-0101 #97808 passcode 99731)...\"", "DO: \"During an incident, the incident response team will coordinate over secure channels.\"" ] } ], "terms": [ "Certification Data", "Cloud Service Offering", "Likely" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-IRP": { "name": "Include Relevant Policies", "statement": "Providers MUST supply all relevant policies and procedures in the FedRAMP Certification Data, including a human-readable and machine-readable reference that explains at least the following about each included policy and procedure:", "following_information": [ "Name of policy or procedure", "Name of file, document, web page, etc.", "Brief summary of policy or procedure", "Word count of document", "Current version", "Date of last update", "Related FedRAMP Practices (if applicable)" ], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": ["Explanation of how to access this information."] }, "terms": [ "Certification Data", "FedRAMP Practices", "Machine-Readable" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-HAD": { "name": "Historical FedRAMP Certification Data", "statement": "Providers MUST supply snapshots of FedRAMP Certification Data aligned to Ongoing Certification Reports to all necessary parties; these snapshots MUST be available for the duration of FedRAMP Certification.", "note": "Historical snapshots do not need to be reconstructed for periods before the provider's first Ongoing Certification Report, but should be maintained for all subsequent Ongoing Certification Reports.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": ["Explanation of how to access this information."] }, "terms": [ "All Necessary Parties", "Certification Data", "FedRAMP Certification Report", "Ongoing Certification", "Ongoing Certification Report (OCR)" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-PSM": { "name": "Per-Service Certification Materials", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications MAY supply per-service FedRAMP Certification materials.", "force": "MAY", "artifacts": { "all": [ "Explanation of the supplied materials, including how to access and use them." ] } }, "b": { "statement": "Providers with Class B Certifications MAY supply per-service FedRAMP Certification materials.", "force": "MAY", "artifacts": { "all": [ "Explanation of the supplied materials, including how to access and use them." ] } }, "c": { "statement": "Providers with Class C Certifications MAY supply per-service FedRAMP Certification materials.", "force": "MAY", "artifacts": { "all": [ "Explanation of the supplied materials, including how to access and use them." ] } }, "d": { "statement": "Providers with Class D Certifications MUST supply per-service FedRAMP Certification materials.", "force": "MUST", "artifacts": { "all": [ "Explanation of the supplied materials, including how to access and use them." ] } } }, "notes": [ "Providers determine what they consider to be separate services, based on maximizing the customer experience for agencies who may only adopt some services and not others.", "Providers are encouraged to provide a single comprehensive set of materials for all shared aspects of the service offering and only provide separate materials for unique aspects of each service to minimize the burden on providers and agencies." ], "affects": ["Providers"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-CSO-RPS": { "name": "Responsible Public Package Sharing", "statement": "Providers MAY responsibly share some or all of the information in a FedRAMP Certification Package publicly or with other parties if the provider determines doing so will NOT likely have an adverse effect on the cloud service offering.", "force": "MAY", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of if and how this information is shared with other parties." ] }, "terms": [ "Certification Package", "Cloud Service Offering", "Likely", "Responsibly" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "TRC": { "CDS-TRC-USH": { "name": "Uninterrupted Sharing", "statement": "Trust centers MUST share FedRAMP Certification Data with all necessary parties without interruption.", "note": "\"Without interruption\" means that parties should not have to request manual approval each time they need to access FedRAMP Certification Data or go through a complicated process. The preferred way of ensuring access without interruption is to use on-demand just-in-time access provisioning.", "force": "MUST", "affects": ["Providers"], "terms": [ "All Necessary Parties", "Certification Data", "Trust Center" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-TRC-PAC": { "name": "Programmatic Access", "statement": "Trust centers MUST provide documented programmatic access to all FedRAMP Certification Data, including programmatic access to human-readable materials.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": ["URL to the documentation for programmatic access."] }, "terms": ["Certification Data", "Trust Center"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-TRC-AAI": { "name": "Agency Access Inventory", "statement": "Trust centers MUST maintain an inventory and history of federal agency users or systems with access to FedRAMP Certification Data and MUST make this information available to FedRAMP upon request.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how FedRAMP can obtain this information." ] }, "terms": ["Certification Data", "Trust Center"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-TRC-ACL": { "name": "Access Logging", "statement": "Trust centers MUST log access to FedRAMP Certification Data and store summaries of access for at least six months; such information, as it pertains to specific parties, SHOULD be made available upon request by those parties.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how the appropriate parties can obtain this log information." ] }, "terms": ["Certification Data", "Trust Center"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-TRC-HMR": { "name": "Human and Machine-Readable Certification Data", "statement": "Trust centers SHOULD make FedRAMP Certification Data available to view and download in both human-readable and machine-readable formats.", "force": "SHOULD", "affects": ["Providers"], "terms": [ "Certification Data", "Machine-Readable", "Trust Center" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-TRC-SSM": { "name": "Self-Service Access Management", "statement": "Trust centers SHOULD include features that encourage all necessary parties to provision and manage access to FedRAMP Certification Data for their users and services directly.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "URL or explanation how to access documentation of these features and capabilities." ] }, "terms": [ "All Necessary Parties", "Certification Data", "Trust Center" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "UTC": { "CDS-UTC-AAD": { "name": "Agency Access Denial", "statement": "Providers MUST notify FedRAMP within 5 business days of denying an agency access request for FedRAMP Certification Data.", "force": "MUST", "affects": ["Providers"], "timeframe_type": "bizdays", "timeframe_num": 5, "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51829826617243", "name": "[CSP] Agency Access Denial" } ], "terms": ["Certification Data"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CDS-UTC-AGA": { "name": "Agency Access", "statement": "Providers SHOULD supply access to the FedRAMP Certification Package with agencies upon request.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "URL or explanation of how to request these materials.", "Explanation of how the provider decides whether or not to share these materials or other related policies." ] }, "terms": ["Certification Package"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "rev5": { "CSF": { "CDS-CSF-TCM": { "name": "Trust Center Migration", "statement": "Providers MUST notify all necessary parties when migrating to a trust center and MUST provide information in their existing USDA Connect Community Portal secure folders explaining how to use the trust center to obtain FedRAMP Certification Data.", "force": "MUST", "affects": ["Providers"], "notification": [ { "party": "FedRAMP", "method": "email", "target": "info@fedramp.gov", "name": "info@fedramp.gov" }, { "party": "Agency Customers", "method": "varies", "target": "varies by agency", "name": "Agency Security Contact" } ], "terms": [ "All Necessary Parties", "Certification Data", "Trust Center" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "CMU": { "info": { "name": "Cryptographic Module Use", "short_name": "CMU", "web_name": "cryptographic-module-use", "purpose": "The Cryptographic Module Use rules clarify how providers should select and use cryptographic modules. These rules allow risk-based decisions for some services while still encouraging validated cryptographic modules whenever they are technically feasible and reasonable.", "status": "stable", "tag": "boundary", "subsets": { "CSO": { "name": "Cloud Service Provider Responsibilities", "description": "These rules apply to providers for FedRAMP Certifications.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } }, "20x": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } } }, "rev5": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2027-01-01", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-06-01", "until_next_assessment": false } } } } }, "data": { "all": { "CSO": { "CMU-CSO-CMD": { "name": "Cryptographic Module Documentation", "statement": "Providers MUST document the cryptographic modules used in each service (or groups of services that use the same modules) where cryptographic services are used to protect federal customer data, including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules." ] }, "terms": ["Federal Customer Data", "Validation"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CMU-CSO-UVM": { "name": "Using Validated Cryptographic Modules", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications MAY use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.", "force": "MAY", "artifacts": { "all": [ "List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules." ] } }, "b": { "statement": "Providers with Class B Certifications MAY use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.", "force": "MAY", "artifacts": { "all": [ "List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules." ] } }, "c": { "statement": "Providers with Class C Certifications SHOULD use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.", "force": "SHOULD", "artifacts": { "all": [ "List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules." ] } }, "d": { "statement": "Providers with Class D Certifications MUST use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.", "force": "MUST", "artifacts": { "all": [ "List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules." ] } } }, "affects": ["Providers"], "terms": ["Federal Customer Data", "Validation"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CMU-CSO-CAT": { "name": "Configuration of Agency Tenants", "statement": "Providers SHOULD configure agency tenants by default to use cryptographic services that use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when such modules are available.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "List of cryptographic modules used by default including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules." ] }, "terms": ["Validation"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "CPO": { "info": { "name": "Certification Package Overview", "short_name": "CPO", "web_name": "certification-package-overview", "purpose": "The Certification Package Overview rules outline the expectations for a simple overview of the cloud service offering that must be included within a FedRAMP Certification Package. This overview replaces the historically required base System Security Plan for FedRAMP Rev5 and is intended to provide a clear, concise, and consistent summary of the offering and the information included in the package to help customers understand the offering at a high level.", "status": "stable", "tag": "materials", "subsets": { "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to providers for FedRAMP Certifications of any type.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } }, "20x": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } }, "subsets": { "CSX": { "name": "20x-Specific Provider Responsibilities", "description": "These rules apply to providers for FedRAMP 20x Certifications.", "applicability": { "types": ["20x"], "paths": ["Program"], "classes": ["A", "B", "C", "D"], "affects": ["Providers"] } } } }, "rev5": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2027-01-01", "maintain": "2027-07-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-07-01", "until_next_assessment": true } } }, "subsets": { "CSF": { "name": "Rev5-Specific Provider Responsibilities", "description": "These rules apply to providers for FedRAMP Rev5 Certifications.", "applicability": { "types": ["Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } } }, "data": { "all": { "CSO": { "CPO-CSO-OVR": { "name": "Overview of the Cloud Service Offering", "statement": "Providers MUST supply a Certification Package Overview within their FedRAMP Certification Package, in both human-readable and JSON formats, that includes at least all of the information required by the following rules:", "following_information": [ "Certification Package Overview: CPO-CSO-MTD (Certification Package Overview Metadata)", "Certification Data Sharing: CDS-CSO-PUB (Public Information)", "Certification Data Sharing: CDS-CSO-SVC (Public Service List)", "Certification Data Sharing: CDS-CSO-IRP (Include Relevant Policies)", "Minimum Assessment Scope: MAS-CSO-IIR (Identify Information Resources)", "Minimum Assessment Scope: MAS-CSO-FLO (Information Flows and Security Categories)", "Minimum Assessment Scope: MAS-CSO-TPR (Third-Party Information Resources)", "Using Cryptographic Modules: CMU-CSO-CMD (Cryptographic Module Documentation)", "Independent Verification and Validation: IVV-CSO-ICP (Inclusion in Certification Package)" ], "notes": [ "For FedRAMP Rev5, the Certification Package Overview replaces the historically required System Security Plan (not including appendices).", "This list of rules may not apply to all FedRAMP Certification Classes or Types - if a rule does not apply then the information is not required." ], "related": [ "CPO-CSO-MTD", "CDS-CSO-PUB", "CDS-CSO-SVC", "MAS-CSO-IIR", "MAS-CSO-FLO", "MAS-CSO-TPR", "CMU-CSO-CMD", "CDS-CSO-IRP", "IVV-CSO-ICP" ], "force": "MUST", "affects": ["Providers"], "schema": { "name": "FedRAMP Certification Package Overview Schema", "url": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json" }, "terms": [ "Certification Class", "Certification Data", "Certification Package", "Information Resource", "Initial Incident Report (IIR)", "Security Category", "Third-Party Information Resource", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CPO-CSO-MTD": { "name": "Certification Package Overview Metadata", "statement": "Providers MUST also include the following basic metadata in their Certification Package Overview:", "following_information": [ "Name, title, and contact information of official that is responsible and accountable for the FedRAMP Certification Package", "Version", "Date and time of last update", "Source of update" ], "force": "MUST", "affects": ["Providers"], "terms": ["Certification Package"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "CPO-CSO-OSA": { "name": "Overall Summary of Assessment in Certification Package", "varies_by_class": { "a": { "statement": "Providers seeking Class A Certification MAY also include an overall summary of their FedRAMP independent assessment in their Certification Package Overview.", "force": "MAY" }, "b": { "statement": "Providers seeking Class B Certification MUST also include the overall summary of their FedRAMP independent assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), in their Certification Package Overview.", "force": "MUST" }, "c": { "statement": "Providers seeking Class C Certification MUST also include the overall summary of their FedRAMP independent assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), in their Certification Package Overview.", "force": "MUST" }, "d": { "statement": "Providers seeking Class D Certification MUST also include the overall summary of their FedRAMP independent assessment, supplied by the assessor per IVV-IAS-OSA (Overall Summary of Assessment), in their Certification Package Overview.", "force": "MUST" } }, "related": ["IVV-IAS-OSA"], "affects": ["Providers"], "terms": [ "Certification Package", "FedRAMP Independent Assessment" ], "updated": [ { "date": "2026-06-25", "comment": "Added after official launch to clarify that the provider is required to supply this artifact." } ] } } }, "20x": { "CSX": { "CPO-CSX-CPM": { "name": "Certification Package Maintenance for 20x", "varies_by_class": { "a": { "statement": "Providers with 20x Class A Certifications SHOULD persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 3 months.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 3 }, "b": { "statement": "Providers with 20x Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every month.", "force": "MUST", "timeframe_type": "months", "timeframe_num": 1 }, "c": { "statement": "Providers with 20x Class C Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 2 weeks.", "force": "MUST", "timeframe_type": "weeks", "timeframe_num": 2 }, "d": { "statement": "Providers with 20x Class D Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every week.", "force": "MUST", "timeframe_type": "weeks", "timeframe_num": 1 } }, "notes": [ "Providers are expected to maintain their FedRAMP Certification Package using automation as changes occur to ensure they are never out of date.", "This rule does not require or expect persistent human review of all materials in this cadence." ], "affects": ["Providers"], "terms": ["Certification Package", "Persistently"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "rev5": { "CSF": { "CPO-CSF-CPM": { "name": "Certification Package Maintenance for Rev5", "varies_by_class": { "b": { "statement": "Providers with Rev5 Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every year.", "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 }, "c": { "statement": "Providers with Rev5 Class C Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every year.", "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 }, "d": { "statement": "Providers with Rev5 Class D Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every six months.", "force": "MUST", "timeframe_type": "months", "timeframe_num": 6 } }, "notes": [ "This maximum timeframe for Rev5 is the absolutely poorest worst case for horrible customer experience and is based on legacy FedRAMP Rev5 allowing providers to leave their packages unmaintained for up to a year. Rev5 providers should maintain their packages far more frequently than this requirement to ensure potential customers have access to up-to-date information, updating it at least after every transformative significant change.", "FedRAMP 20x Certifications expect providers to maintain their FedRAMP Certification Packages as changes occur to ensure they are never out of date." ], "affects": ["Providers"], "terms": [ "Certification Package", "Persistently", "Significant Change", "Transformative Change" ], "updated": [ { "date": "2026-07-14", "comment": "Removed reference to class A. All class A certifications are 20x." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "FRC": { "info": { "name": "FedRAMP Certification", "short_name": "FRC", "web_name": "fedramp-certification", "purpose": "This ruleset explains how cloud service offerings obtain and maintain FedRAMP Certification across certification classes and paths.", "status": "stable", "tag": "other", "subsets": { "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to cloud service providers obtaining and maintaining any FedRAMP Certification.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["A", "B", "C", "D"], "affects": ["Providers"] } }, "CLA": { "name": "FedRAMP Class A Certification Rules", "description": "These are specific rules that apply to providers seeking FedRAMP Class A Certifications.", "applicability": { "types": ["20x"], "paths": ["Program"], "classes": ["A"], "affects": ["Providers"] } }, "APP": { "name": "Applying for FedRAMP Certification", "description": "These rules apply to cloud service providers who have met all other relevant rules and are ready to apply for any FedRAMP Certification.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["A", "B", "C", "D"], "affects": ["Providers"] } }, "APS": { "name": "Applying for FedRAMP Certification with an Agency Sponsor", "description": "These rules apply to cloud service providers with an Agency Sponsor who have met all other relevant rules and are ready to apply for any FedRAMP Certification.", "applicability": { "types": ["Rev5"], "paths": ["Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "CCL": { "name": "Changing Certification Class", "description": "These rules apply to cloud service providers when changing their FedRAMP Certification Class.", "applicability": { "types": ["Rev5"], "paths": ["Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } }, "20x": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } }, "subsets": { "CSX": { "name": "20x-Specific Provider Responsibilities", "description": "These rules apply to providers for FedRAMP 20x Certifications.", "applicability": { "types": ["20x"], "paths": ["Program"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } }, "rev5": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2027-01-01", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } }, "subsets": { "CSF": { "name": "Rev5-Specific Provider Responsibilities", "description": "These rules apply to providers for FedRAMP Rev5 Certifications.", "applicability": { "types": ["Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } } }, "data": { "all": { "CSO": { "FRC-CSO-FCP": { "name": "FedRAMP Certification Profile", "statement": "Providers MUST identify a target FedRAMP Certification Profile and apply all relevant FedRAMP Practices to the cloud service offering.", "note": "Information resources (including third-party information resources) MAY vary by security category as appropriate to the type of information handled by or impacted by the information resource.", "force": "MUST", "affects": ["Providers"], "terms": [ "Certification Profile", "Cloud Service Offering", "FedRAMP Practices", "Handle", "Information Resource", "Security Category", "Third-Party Information Resource" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CSO-PKG": { "name": "FedRAMP Certification Package", "statement": "Providers seeking a Certification MUST supply a complete FedRAMP Certification Package to FedRAMP for initial certification; the FedRAMP Certification Package MUST include at least the following information:", "following_information": [ "Information about the Cloud Service Offering following CPO-CSO-OVR (Overview of the Cloud Service Offering)", "Implementation, Validation, and Assessment information for each relevant FedRAMP requirement/control/ksi as defined in SDR-CSO-FRR (FedRAMP Rules)", "A real or example Ongoing Certification Report following CCM-OCR-AVL (Report Availability)" ], "related": ["CPO-CSO-OVR", "SDR-CSO-FRR", "CCM-OCR-AVL"], "force": "MUST", "affects": ["Providers"], "schema": { "name": "FedRAMP Certification Package Overview (FRC-CSO-PKG)", "url": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json" }, "terms": [ "Certification Package", "Cloud Service Offering", "FedRAMP Certification Report", "Initial Certification", "Ongoing Certification", "Ongoing Certification Report (OCR)", "Security Decision Record (SDR)", "Validation" ], "updated": [ { "date": "2026-06-25", "comment": "Removed dangling mention of Class B from a last-minute merger of rules; apologies for confusion, this rule applies to all classes." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CSO-JSN": { "name": "FedRAMP JSON Schemas", "statement": "Providers MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule.", "note": "FedRAMP JSON schemas are designed to be lightweight and flexible to establish a minimum set of structured information while allowing providers to improve on the format and structure of the information as needed to meet their needs and the needs of their customers.", "force": "MUST", "affects": ["Providers"], "terms": ["Machine-Readable"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CSO-MRA": { "name": "Maintain Responsibility and Accountability", "statement": "Providers MUST maintain responsibility and accountability for the accuracy and completeness of all information in the FedRAMP Certification Package, especially when they engage a third party (such as an independent assessor, advisory service, or external tools) to supply information on their behalf.", "force": "MUST", "affects": ["Providers"], "terms": ["Certification Package"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CSO-POP": { "name": "Pick One Program Certification Type", "statement": "Providers MUST NOT seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering; pick one type.", "note": "This rule does not prevent a provider from seeking and maintaining a FedRAMP Rev5 Agency Certification and a FedRAMP 20x Program Certification for the same cloud service offering, however, doing so is strongly discouraged due to the increased complexity and risk of confusion for all parties.", "force": "MUST NOT", "affects": ["Providers"], "terms": ["Cloud Service Offering"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "CLA": { "FRC-CLA-ASF": { "name": "Approved Alternative Security Frameworks", "statement": "Providers seeking a FedRAMP Class A Certification MUST have completed a certification or equivalent process, including an independent assessment if applicable, from one of the following alternative security frameworks within the past 12 months:", "following_information": [ "FedRAMP Rev5 (including FedRAMP Ready) at any historical Impact Level", "SOC 2 Type II", "GovRAMP at any Impact Level" ], "force": "MUST", "affects": ["Providers"], "terms": ["Security Category"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CLA-EAM": { "name": "External Assessment Materials", "statement": "Providers seeking a FedRAMP Class A Certification MUST supply the following materials from their alternative security framework assessment to all necessary parties:", "following_information": [ "SOC 2 Type II: Complete report, bridge or gap letter (if applicable), verified audit engagement documentation, estimated schedule for upcoming report, supplemental compliance evidence (if applicable)", "FedRAMP Ready: Readiness Assessment Report, Security Assessment Plan, and any other materials required by FedRAMP.", "GovRAMP: Readiness Assessment Report, Security Assessment Plan, and any other materials required by GovRAMP." ], "force": "MUST", "affects": ["Providers"], "terms": ["All Necessary Parties", "Verification"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CLA-MFR": { "name": "Mandatory FedRAMP Rules for Class A", "statement": "Providers seeking a Class A FedRAMP Certification MUST address all rules in this FedRAMP Class A Certification subset (FRC-CLA) AND the following additional FedRAMP Class A rules; the appropriate artifacts or information mapping for all rules MUST be supplied in the FedRAMP Certification Package.", "following_information": [ "FedRAMP Certification: FRC-CSO-PKG (FedRAMP Certification Package)", "FedRAMP Certification: FRC-CSO-JSN (FedRAMP JSON Schemas)", "FedRAMP Certification: FRC-CSO-POP (Pick One Program Certification Type)", "Minimum Assessment Scope: MAS-CSO-IIR (Identify Information Resources)", "Certification Data Sharing: CDS-CSO-PUB (Public Information)", "Certification Data Sharing: CDS-CSO-UTC (Use Trust Centers)", "Certification Data Sharing: CDS-UTC-AAD (Agency Access Denial)", "Addressing FedRAMP Communication: AFC-CSO-INB (Maintain a FedRAMP Security Inbox)", "Addressing FedRAMP Communication: AFC-CSO-RCV (Receive Email Without Disruption)", "Addressing FedRAMP Communication: AFC-CSO-CRA (Complete Required Actions)", "Incident Evaluation and Communication: IEC-CSO-EFR (Evaluate FedRAMP Reportability)", "Incident Evaluation and Communication: IEC-CSO-FIR (Final Incident Report)", "Vulnerability Detection and Response: VDR-CSO-DET (Vulnerability Detection)", "Collaborative Continuous Monitoring: CCM-OCR-AVL (Report Availability)", "Collaborative Continuous Monitoring: CCM-OCR-NRD (Next Report Date)", "Independent Verification and Validation: IVV-CSX-AIA (Annual Independent Assessments for 20x)", "Key Security Indicators: KSI-CMT-LMC (Logging Changes)", "Key Security Indicators: KSI-CNA-RNT (Restricting Network Traffic)", "Key Security Indicators: KSI-CED-RAT (Reviewing All Training)", "Key Security Indicators: KSI-IAM-AAM (Automating Account Management)", "Key Security Indicators: KSI-IAM-APM (Adopting Passwordless Methods)", "Key Security Indicators: KSI-INR-RIR (Reviewing Incident Response Procedures)", "Key Security Indicators: KSI-SVC-SIN (Securing Information)" ], "notes": [ "Some of these specific FedRAMP rules may not have similar counterparts in external frameworks and providers will need to implement new processes to follow these rules.", "In general, for each of these FedRAMP requirements, providers should include a sufficiently detailed summary that reviewers will not need to dig into the related security framework materials to understand the related decisions - just saying \"see SOC 2 report\" is not particularly helpful.", "Information about how the provider addresses the included Key Security Indicators are required to receive a class A certification even if the provider intends to pursue a Rev 5 Program Certification path in the future." ], "related": [ "FRC-CSO-POP", "MAS-CSO-IIR", "CDS-CSO-PUB", "CDS-CSO-UTC", "CDS-UTC-AAD", "AFC-CSO-INB", "AFC-CSO-RCV", "AFC-CSO-CRA", "IEC-CSO-EFR", "IEC-CSO-FIR", "VDR-CSO-DET", "CCM-OCR-AVL", "CCM-OCR-NRD", "IVV-CSX-AIA", "FRC-CSO-PKG", "FRC-CSO-JSN", "KSI-CMT-LMC", "KSI-CNA-RNT", "KSI-CED-RAT", "KSI-IAM-AAM", "KSI-INR-RIR", "KSI-SVC-SIN", "KSI-IAM-APM" ], "force": "MUST", "affects": ["Providers"], "terms": [ "Artifacts", "Certification Data", "Certification Package", "Certification Path", "Certification Type", "FedRAMP Security Inbox", "Final Incident Report (FIR)", "Incident", "Information Resource", "Initial Incident Report (IIR)", "Ongoing Certification Report (OCR)", "Trust Center", "Validation", "Verification", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-07-14", "comment": "Clarified that providers MUST address the Key Security Indicators even if they intend to pursue a Rev 5 Program Certification path in the future." }, { "date": "2026-07-01", "comment": "Removed reference to Independent Verification and Validation: IVV-CSF-AIA (Annual Independent Assessments for Rev5); Removed CDS-CSO-AVR (Availability Reporting) since this rule is defined as SHOULD and included in FRC-CLA-RFR (Recommended FedRAMP Rules for Class A)" }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CLA-RFR": { "name": "Recommended FedRAMP Rules for Class A", "statement": "Providers seeking a Class A FedRAMP Certification SHOULD address the following additional recommended FedRAMP Class A rules (if applicable):", "following_information": [ "Certification Data Sharing: CDS-CSO-AVR (Availability Reporting)", "Certification Package Overview: CPO-CSF-CPM (Certification Package Maintenance for Rev5)", "Certification Package Overview: CPO-CSX-CPM (Certification Package Maintenance for 20x)", "Incident Evaluation and Communication: IEC-CSO-IIR (Initial Incident Report)", "Incident Evaluation and Communication: IEC-CSO-OIR (Ongoing Incident Reports)", "Vulnerability Detection and Response: VDR-TFR-MVX (Persistent Machine Verification and Validation for 20x)", "Vulnerability Detection and Response: VDR-TFR-PCD (Persistently Complete Detection)", "Vulnerability Detection and Response: VDR-TFR-PDD (Persistent Drift Detection)", "Vulnerability Detection and Response: VDR-TFR-PSD (Persistent Sample Detection)", "Vulnerability Detection and Response: VDR-TFR-PVR (Mitigation and Remediation Expectations)", "Vulnerability Evaluation and Reporting: VER-TFR-EVU (Evaluate Vulnerabilities Quickly)" ], "related": [ "CDS-CSO-AVR", "CPO-CSF-CPM", "CPO-CSX-CPM", "IEC-CSO-IIR", "IEC-CSO-OIR", "VDR-TFR-MVX", "VDR-TFR-PCD", "VDR-TFR-PDD", "VDR-TFR-PSD", "VDR-TFR-PVR", "VER-TFR-EVU" ], "force": "SHOULD", "affects": ["Providers"], "terms": [ "Certification Data", "Certification Package", "Drift", "Incident", "Initial Incident Report (IIR)", "Ongoing Incident Report (OIR)", "Persistently", "Validation", "Verification", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CLA-OFR": { "name": "Address Optional FedRAMP Rules for Class A", "statement": "Providers seeking a Class A FedRAMP Certification MAY address the following additional optional FedRAMP Class A rules (if applicable):", "following_information": [ "Collaborative Continuous Monitoring: CCM-QTR-MTG (Quarterly Review Meeting)", "Certification Data Sharing: CDS-CSO-PSM (Per-Service Certification Materials)", "Cryptographic Module Use: CMU-CSO-UVM (Using Validated Cryptographic Modules)", "FedRAMP Certification: FRC-APP-FIA (Fresh Independent Assessment)", "Independent Verification and Validation: IVV-CSO-FIA (FedRAMP Independent Assessments)", "Security Decision Record: SDR-CSX-KMT (Key Security Indicator Metrics)", "Vulnerability Evaluation and Reporting: VER-TFR-IRI (Internet-Reachable Incidents)", "Vulnerability Evaluation and Reporting: VER-TFR-MRH (Historical Activity)", "Vulnerability Evaluation and Reporting: VER-TFR-NRI (Non-Internet-Reachable Incidents)" ], "related": [ "CCM-QTR-MTG", "CDS-CSO-PSM", "CMU-CSO-UVM", "FRC-APP-FIA", "IVV-CSO-FIA", "SDR-CSX-KMT", "VER-TFR-IRI", "VER-TFR-MRH", "VER-TFR-NRI" ], "force": "MAY", "affects": ["Providers"], "terms": [ "Certification Data", "FedRAMP Independent Assessment", "Incident", "Quarterly Review", "Security Decision Record (SDR)", "Validation", "Verification", "Vulnerability" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CLA-IVV": { "name": "Optional Independent Verification and Validation", "statement": "Providers seeking a FedRAMP Class A Certification MAY have the FedRAMP Certification Package independently verified and validated by a FedRAMP Recognized assessor before submission to FedRAMP.", "force": "MAY", "affects": ["Providers"], "terms": [ "Certification Package", "FedRAMP Recognized", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "APP": { "FRC-APP-MLF": { "name": "Marketplace Listing First", "statement": "Providers MUST be listed in the FedRAMP Marketplace before applying for FedRAMP Certification, including:", "following_information": [ "FedRAMP Marketplace: MKT-CSO-MLR (Marketplace Listing Requirements),", "FedRAMP Marketplace: MKT-CSO-PML (Provider Marketplace Listing Requests)", "FedRAMP Marketplace: MKT-IIP-AGU (Agency Use Cases)", "FedRAMP Marketplace: MKT-IIP-DCP (Demonstrating Continuous Progress)" ], "related": [ "MKT-CSO-MLR", "MKT-CSO-PML", "MKT-IIP-AGU", "MKT-IIP-DCP" ], "force": "MUST", "affects": ["Providers"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-APP-AFC": { "name": "Applying for FedRAMP Certification", "statement": "Providers MUST complete the FedRAMP Certification Application Form in full to request an initial assessment by FedRAMP.", "force": "MUST", "affects": ["Providers"], "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51137131584283", "name": "[For CSPs] FedRAMP Certification Application Form" } ], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-APP-FCP": { "name": "Fresh FedRAMP Certification Package", "statement": "Providers MUST supply a fresh initial FedRAMP Certification Package that shows the current status of the cloud service offering as verified and validated by the provider within the previous 7 days.", "force": "MUST", "affects": ["Providers"], "terms": [ "Certification Package", "Cloud Service Offering", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-APP-FIA": { "name": "Fresh Independent Assessment", "varies_by_class": { "a": { "statement": "Providers seeking Class A Certification MAY supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.", "force": "MAY", "timeframe_type": "months", "timeframe_num": 3 }, "b": { "statement": "Providers seeking Class B Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.", "force": "MUST", "timeframe_type": "months", "timeframe_num": 3 }, "c": { "statement": "Providers seeking Class C Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.", "force": "MUST", "timeframe_type": "months", "timeframe_num": 3 }, "d": { "statement": "Providers seeking Class D Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.", "force": "MUST", "timeframe_type": "months", "timeframe_num": 3 } }, "affects": ["Providers"], "terms": ["FedRAMP Independent Assessment", "FedRAMP Recognized"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-APP-NTP": { "name": "No Third-Party Applicants", "statement": "Providers MUST NOT use a third party to apply for a FedRAMP Certification on their behalf; this includes independent assessment services.", "notes": [ "FedRAMP previously allowed independent assessment services to submit applications on behalf of providers, but this caused confusion about who was responsible for the application and the information in it. Providers should apply directly to ensure clear accountability.", "Providers may use third parties to help them prepare their application and assessment materials for submission." ], "force": "MUST NOT", "affects": ["Providers"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-APP-USA": { "name": "Updating Stale Assessments", "statement": "Providers MAY freshen a stale initial independent verification and validation assessment by having a FedRAMP Recognized independent assessment service review any changes between the original assessment and the current status of the cloud service offering in place of a full re-assessment, UNLESS the stale assessment is more than 9 months old.", "force": "MAY", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "FedRAMP Recognized", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "APS": { "FRC-APS-ATO": { "name": "Agency Authorization to Operate", "statement": "Providers seeking a FedRAMP Rev5 Agency Certification MUST have completed the Authorization to Operate (ATO) process with their agency sponsor for the cloud service offering, concluding with a formal signed ATO letter that the agency has sent over official government channels to FedRAMP.", "force": "MUST", "affects": ["Providers"], "terms": ["Cloud Service Offering"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "CCL": { "FRC-CCL-UCC": { "name": "Upgrading Certification Class", "statement": "Providers MUST apply for a new FedRAMP Certification to upgrade their Certification Class; all applicable requirements MUST be met in advance.", "notes": [ "Upgrade paths include moving from A to B, C, or D; B to C or D; and C to D.", "The preferred path is to incrementally update the implementation and assurance commitments within the current Certification Class until the provider has met all requirements for the target Certification Class, then apply for the new Certification Class." ], "force": "MUST", "affects": ["Providers"], "terms": ["Certification Class"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CCL-DCC": { "name": "Downgrading Certification Class", "statement": "Providers MUST apply for a new FedRAMP Certification to downgrade their Certification Class.", "notes": [ "Downgrade paths include moving from D to C, B, or A; C to B or A; or B to A.", "FRC-CCL-DNP (Downgrade Notification Period) applies - please DO NOT downgrade Certification Class with providing advance notification to all necessary parties!" ], "related": ["FRC-CCL-DNP"], "force": "MUST", "affects": ["Providers"], "terms": ["All Necessary Parties", "Certification Class"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CCL-DNP": { "name": "Downgrade Notification Period", "statement": "Providers SHOULD notify all necessary parties at least 120 days in advance of an intended downgrade or cancellation of FedRAMP Certification.", "note": "Downgrading or canceling FedRAMP Certification will have severe negative consequences for the provider and their agency customers and should only be done after careful consideration and planning... but if it must be done, notify all necessary parties as soon as possible.", "force": "SHOULD", "affects": ["Providers"], "terms": ["All Necessary Parties"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "20x": { "CSX": { "FRC-CSX-VVK": { "name": "Automated Verification and Validation of Key Security Indicators", "varies_by_class": { "a": { "statement": "Providers seeking 20x Class A Certification MAY implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators.", "force": "MAY" }, "b": { "statement": "Providers seeking 20x Class B Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 1 automated method for each Key Security Indicator.", "force": "SHOULD" }, "c": { "statement": "Providers seeking 20x Class C Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 2 automated methods for each Key Security Indicator.", "force": "MUST" }, "d": { "statement": "Providers seeking 20x Class D Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 4 automated methods for each Key Security Indicator.", "force": "MUST" } }, "affects": ["Providers"], "terms": ["Persistently", "Validation", "Verification"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CSX-MOT": { "name": "Metrics Over Time for Key Security Indicators", "varies_by_class": { "a": { "statement": "Providers seeking 20x Class A Certification MAY supply historical metrics for Key Security Indicators.", "force": "MAY" }, "b": { "statement": "Providers seeking 20x Class B Certification SHOULD supply historical metrics for Key Security Indicators.", "force": "SHOULD" }, "c": { "statement": "Providers seeking 20x Class C Certification MUST supply historical metrics including status from persistent validation over at least the past 6 months for all Key Security Indicators.", "force": "MUST" }, "d": { "statement": "Providers seeking 20x Class D Certification MUST provide historical metrics including status from persistent validation over at least the past 18 months for all Key Security Indicators.", "force": "MUST" } }, "note": "For initial FedRAMP Certification, providers will need to have mechanisms in place and agree to meet this requirement in the event the cloud service has not been operating with related metrics available for the required period prior to applying for initial certification.", "affects": ["Providers"], "terms": ["Initial Certification", "Persistently", "Validation"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CSX-VVR": { "name": "Automated Verification and Validation of FedRAMP Rules", "varies_by_class": { "a": { "statement": "Providers seeking 20x Class A Certification MAY implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.", "force": "MAY" }, "b": { "statement": "Providers seeking 20x Class B Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.", "force": "SHOULD" }, "c": { "statement": "Providers seeking 20x Class C Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.", "force": "SHOULD" }, "d": { "statement": "Providers seeking 20x Class D Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.", "force": "SHOULD" } }, "note": "Different rules will be easy to automate for different providers, depending on the implementation, so FedRAMP generally leaves this implementation up to providers based on what makes the most sense for their own business and approach.", "affects": ["Providers"], "terms": [ "Persistently", "Security Decision Record (SDR)", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CSX-MAS": { "name": "Application within MAS", "statement": "Providers SHOULD apply ALL Key Security Indicators to ALL aspects of their cloud service offering that are within the FedRAMP Minimum Assessment Scope.", "force": "SHOULD", "affects": ["Providers"], "terms": ["Cloud Service Offering"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "rev5": { "CSF": { "FRC-CSF-BSL": { "name": "FedRAMP Rev5 Baselines", "varies_by_class": { "b": { "statement": "Providers seeking FedRAMP Rev5 Class B Certification MUST include at least the following NIST SP 800-53 Rev. 5 controls in their Security Decision Record:", "rev5_controls_list": { "AC": [ "AC-01", "AC-02", "AC-03", "AC-07", "AC-08", "AC-14", "AC-17", "AC-18", "AC-19", "AC-20", "AC-22" ], "AT": ["AT-01", "AT-02", "AT-02 (02)", "AT-03", "AT-04"], "AU": [ "AU-01", "AU-02", "AU-03", "AU-04", "AU-05", "AU-06", "AU-08", "AU-09", "AU-11", "AU-12" ], "CA": [ "CA-01", "CA-02", "CA-02 (01)", "CA-03", "CA-06", "CA-07", "CA-07 (04)", "CA-08", "CA-09" ], "CM": [ "CM-01", "CM-02", "CM-04", "CM-05", "CM-06", "CM-07", "CM-08", "CM-10", "CM-11" ], "CP": [ "CP-01", "CP-02", "CP-03", "CP-04", "CP-09", "CP-10" ], "IA": [ "IA-01", "IA-02", "IA-02 (01)", "IA-02 (02)", "IA-02 (08)", "IA-02 (12)", "IA-04", "IA-05", "IA-05 (01)", "IA-06", "IA-07", "IA-08", "IA-08 (01)", "IA-08 (02)", "IA-08 (04)", "IA-11" ], "IR": [ "IR-01", "IR-02", "IR-04", "IR-05", "IR-06", "IR-07", "IR-08" ], "MA": ["MA-01", "MA-02", "MA-04", "MA-05"], "MP": ["MP-01", "MP-02", "MP-06", "MP-07"], "PE": [ "PE-01", "PE-02", "PE-03", "PE-06", "PE-08", "PE-12", "PE-13", "PE-14", "PE-15", "PE-16" ], "PL": [ "PL-01", "PL-02", "PL-04", "PL-04 (01)", "PL-08", "PL-10", "PL-11" ], "PS": [ "PS-01", "PS-02", "PS-03", "PS-04", "PS-05", "PS-06", "PS-07", "PS-08", "PS-09" ], "RA": [ "RA-01", "RA-02", "RA-03", "RA-03 (01)", "RA-05", "RA-05 (02)", "RA-05 (11)", "RA-07" ], "SA": [ "SA-01", "SA-02", "SA-03", "SA-04", "SA-04 (10)", "SA-05", "SA-08", "SA-09", "SA-22" ], "SC": [ "SC-01", "SC-05", "SC-07", "SC-08", "SC-08 (01)", "SC-12", "SC-13", "SC-15", "SC-20", "SC-21", "SC-22", "SC-28", "SC-28 (01)", "SC-39" ], "SI": [ "SI-01", "SI-02", "SI-03", "SI-04", "SI-05", "SI-12" ], "SR": [ "SR-01", "SR-02", "SR-02 (01)", "SR-03", "SR-05", "SR-08", "SR-10", "SR-11", "SR-11 (01)", "SR-11 (02)", "SR-12" ] }, "force": "MUST" }, "c": { "statement": "Providers seeking FedRAMP Rev5 Class C Certification MUST include at least the following NIST SP 800-53 Rev. 5 controls in their Security Decision Record:", "rev5_controls_list": { "AC": [ "AC-01", "AC-02", "AC-02 (01)", "AC-02 (02)", "AC-02 (03)", "AC-02 (04)", "AC-02 (05)", "AC-02 (07)", "AC-02 (09)", "AC-02 (12)", "AC-02 (13)", "AC-03", "AC-04", "AC-04 (21)", "AC-05", "AC-06", "AC-06 (01)", "AC-06 (02)", "AC-06 (05)", "AC-06 (07)", "AC-06 (09)", "AC-06 (10)", "AC-07", "AC-08", "AC-11", "AC-11 (01)", "AC-12", "AC-14", "AC-17", "AC-17 (01)", "AC-17 (02)", "AC-17 (03)", "AC-17 (04)", "AC-18", "AC-18 (01)", "AC-18 (03)", "AC-19", "AC-19 (05)", "AC-20", "AC-20 (01)", "AC-20 (02)", "AC-21", "AC-22" ], "AT": [ "AT-01", "AT-02", "AT-02 (02)", "AT-02 (03)", "AT-03", "AT-04" ], "AU": [ "AU-01", "AU-02", "AU-03", "AU-03 (01)", "AU-04", "AU-05", "AU-06", "AU-06 (01)", "AU-06 (03)", "AU-07", "AU-07 (01)", "AU-08", "AU-09", "AU-09 (04)", "AU-11", "AU-12" ], "CA": [ "CA-01", "CA-02", "CA-02 (01)", "CA-02 (03)", "CA-03", "CA-06", "CA-07", "CA-07 (01)", "CA-07 (04)", "CA-08", "CA-08 (01)", "CA-08 (02)", "CA-09" ], "CM": [ "CM-01", "CM-02", "CM-02 (02)", "CM-02 (03)", "CM-02 (07)", "CM-03", "CM-03 (02)", "CM-03 (04)", "CM-04", "CM-04 (02)", "CM-05", "CM-05 (01)", "CM-05 (05)", "CM-06", "CM-06 (01)", "CM-07", "CM-07 (01)", "CM-07 (02)", "CM-07 (05)", "CM-08", "CM-08 (01)", "CM-08 (03)", "CM-09", "CM-10", "CM-11", "CM-12", "CM-12 (01)" ], "CP": [ "CP-01", "CP-02", "CP-02 (01)", "CP-02 (03)", "CP-02 (08)", "CP-03", "CP-04", "CP-04 (01)", "CP-06", "CP-06 (01)", "CP-06 (03)", "CP-07", "CP-07 (01)", "CP-07 (02)", "CP-07 (03)", "CP-08", "CP-08 (01)", "CP-08 (02)", "CP-09", "CP-09 (01)", "CP-09 (08)", "CP-10", "CP-10 (02)" ], "IA": [ "IA-01", "IA-02", "IA-02 (01)", "IA-02 (02)", "IA-02 (05)", "IA-02 (06)", "IA-02 (08)", "IA-02 (12)", "IA-03", "IA-04", "IA-04 (04)", "IA-05", "IA-05 (01)", "IA-05 (02)", "IA-05 (06)", "IA-05 (07)", "IA-06", "IA-07", "IA-08", "IA-08 (01)", "IA-08 (02)", "IA-08 (04)", "IA-11", "IA-12", "IA-12 (02)", "IA-12 (03)", "IA-12 (05)" ], "IR": [ "IR-01", "IR-02", "IR-03", "IR-03 (02)", "IR-04", "IR-04 (01)", "IR-05", "IR-06", "IR-06 (01)", "IR-06 (03)", "IR-07", "IR-07 (01)", "IR-08", "IR-09", "IR-09 (02)", "IR-09 (03)", "IR-09 (04)" ], "MA": [ "MA-01", "MA-02", "MA-03", "MA-03 (01)", "MA-03 (02)", "MA-03 (03)", "MA-04", "MA-05", "MA-05 (01)", "MA-06" ], "MP": [ "MP-01", "MP-02", "MP-03", "MP-04", "MP-05", "MP-06", "MP-07" ], "PE": [ "PE-01", "PE-02", "PE-03", "PE-04", "PE-05", "PE-06", "PE-06 (01)", "PE-08", "PE-09", "PE-10", "PE-11", "PE-12", "PE-13", "PE-13 (01)", "PE-13 (02)", "PE-14", "PE-15", "PE-16", "PE-17" ], "PL": [ "PL-01", "PL-02", "PL-04", "PL-04 (01)", "PL-08", "PL-10", "PL-11" ], "PS": [ "PS-01", "PS-02", "PS-03", "PS-03 (03)", "PS-04", "PS-05", "PS-06", "PS-07", "PS-08", "PS-09" ], "RA": [ "RA-01", "RA-02", "RA-03", "RA-03 (01)", "RA-05", "RA-05 (02)", "RA-05 (03)", "RA-05 (05)", "RA-05 (11)", "RA-07", "RA-09" ], "SA": [ "SA-01", "SA-02", "SA-03", "SA-04", "SA-04 (01)", "SA-04 (02)", "SA-04 (09)", "SA-04 (10)", "SA-05", "SA-08", "SA-09", "SA-09 (01)", "SA-09 (02)", "SA-09 (05)", "SA-10", "SA-11", "SA-11 (01)", "SA-11 (02)", "SA-15", "SA-15 (03)", "SA-22" ], "SC": [ "SC-01", "SC-02", "SC-04", "SC-05", "SC-07", "SC-07 (03)", "SC-07 (04)", "SC-07 (05)", "SC-07 (07)", "SC-07 (08)", "SC-07 (12)", "SC-07 (18)", "SC-08", "SC-08 (01)", "SC-10", "SC-12", "SC-13", "SC-15", "SC-17", "SC-18", "SC-20", "SC-21", "SC-22", "SC-23", "SC-28", "SC-28 (01)", "SC-39", "SC-45", "SC-45 (01)" ], "SI": [ "SI-01", "SI-02", "SI-02 (02)", "SI-02 (03)", "SI-03", "SI-04", "SI-04 (01)", "SI-04 (02)", "SI-04 (04)", "SI-04 (05)", "SI-04 (16)", "SI-04 (18)", "SI-04 (23)", "SI-05", "SI-06", "SI-07", "SI-07 (01)", "SI-07 (07)", "SI-08", "SI-08 (02)", "SI-10", "SI-11", "SI-12", "SI-16" ], "SR": [ "SR-01", "SR-02", "SR-02 (01)", "SR-03", "SR-05", "SR-06", "SR-08", "SR-10", "SR-11", "SR-11 (01)", "SR-11 (02)", "SR-12" ] }, "force": "MUST" }, "d": { "statement": "Providers seeking FedRAMP Rev5 Class D Certification MUST include at least the following NIST SP 800-53 Rev. 5 controls in their Security Decision Record:", "rev5_controls_list": { "AC": [ "AC-01", "AC-02", "AC-02 (01)", "AC-02 (02)", "AC-02 (03)", "AC-02 (04)", "AC-02 (05)", "AC-02 (07)", "AC-02 (09)", "AC-02 (11)", "AC-02 (12)", "AC-02 (13)", "AC-03", "AC-04", "AC-04 (04)", "AC-04 (21)", "AC-05", "AC-06", "AC-06 (01)", "AC-06 (02)", "AC-06 (03)", "AC-06 (05)", "AC-06 (07)", "AC-06 (08)", "AC-06 (09)", "AC-06 (10)", "AC-07", "AC-08", "AC-10", "AC-11", "AC-11 (01)", "AC-12", "AC-14", "AC-17", "AC-17 (01)", "AC-17 (02)", "AC-17 (03)", "AC-17 (04)", "AC-18", "AC-18 (01)", "AC-18 (03)", "AC-18 (04)", "AC-18 (05)", "AC-19", "AC-19 (05)", "AC-20", "AC-20 (01)", "AC-20 (02)", "AC-21", "AC-22" ], "AT": [ "AT-01", "AT-02", "AT-02 (02)", "AT-02 (03)", "AT-03", "AT-04" ], "AU": [ "AU-01", "AU-02", "AU-03", "AU-03 (01)", "AU-04", "AU-05", "AU-05 (01)", "AU-05 (02)", "AU-06", "AU-06 (01)", "AU-06 (03)", "AU-06 (04)", "AU-06 (05)", "AU-06 (06)", "AU-06 (07)", "AU-07", "AU-07 (01)", "AU-08", "AU-09", "AU-09 (02)", "AU-09 (03)", "AU-09 (04)", "AU-10", "AU-11", "AU-12", "AU-12 (01)", "AU-12 (03)" ], "CA": [ "CA-01", "CA-02", "CA-02 (01)", "CA-02 (02)", "CA-02 (03)", "CA-03", "CA-03 (06)", "CA-06", "CA-07", "CA-07 (01)", "CA-07 (04)", "CA-08", "CA-08 (01)", "CA-08 (02)", "CA-09" ], "CM": [ "CM-01", "CM-02", "CM-02 (02)", "CM-02 (03)", "CM-02 (07)", "CM-03", "CM-03 (01)", "CM-03 (02)", "CM-03 (04)", "CM-03 (06)", "CM-04", "CM-04 (01)", "CM-04 (02)", "CM-05", "CM-05 (01)", "CM-05 (05)", "CM-06", "CM-06 (01)", "CM-06 (02)", "CM-07", "CM-07 (01)", "CM-07 (02)", "CM-07 (05)", "CM-08", "CM-08 (01)", "CM-08 (02)", "CM-08 (03)", "CM-08 (04)", "CM-09", "CM-10", "CM-11", "CM-12", "CM-12 (01)", "CM-14" ], "CP": [ "CP-01", "CP-02", "CP-02 (01)", "CP-02 (02)", "CP-02 (03)", "CP-02 (05)", "CP-02 (08)", "CP-03", "CP-03 (01)", "CP-04", "CP-04 (01)", "CP-04 (02)", "CP-06", "CP-06 (01)", "CP-06 (02)", "CP-06 (03)", "CP-07", "CP-07 (01)", "CP-07 (02)", "CP-07 (03)", "CP-07 (04)", "CP-08", "CP-08 (01)", "CP-08 (02)", "CP-08 (03)", "CP-08 (04)", "CP-09", "CP-09 (01)", "CP-09 (02)", "CP-09 (03)", "CP-09 (05)", "CP-09 (08)", "CP-10", "CP-10 (02)", "CP-10 (04)" ], "IA": [ "IA-01", "IA-02", "IA-02 (01)", "IA-02 (02)", "IA-02 (05)", "IA-02 (06)", "IA-02 (08)", "IA-02 (12)", "IA-03", "IA-04", "IA-04 (04)", "IA-05", "IA-05 (01)", "IA-05 (02)", "IA-05 (06)", "IA-05 (07)", "IA-05 (08)", "IA-05 (13)", "IA-06", "IA-07", "IA-08", "IA-08 (01)", "IA-08 (02)", "IA-08 (04)", "IA-11", "IA-12", "IA-12 (02)", "IA-12 (03)", "IA-12 (04)", "IA-12 (05)" ], "IR": [ "IR-01", "IR-02", "IR-02 (01)", "IR-02 (02)", "IR-03", "IR-03 (02)", "IR-04", "IR-04 (01)", "IR-04 (02)", "IR-04 (04)", "IR-04 (06)", "IR-04 (11)", "IR-05", "IR-05 (01)", "IR-06", "IR-06 (01)", "IR-06 (03)", "IR-07", "IR-07 (01)", "IR-08", "IR-09", "IR-09 (02)", "IR-09 (03)", "IR-09 (04)" ], "MA": [ "MA-01", "MA-02", "MA-02 (02)", "MA-03", "MA-03 (01)", "MA-03 (02)", "MA-03 (03)", "MA-04", "MA-04 (03)", "MA-05", "MA-05 (01)", "MA-06" ], "MP": [ "MP-01", "MP-02", "MP-03", "MP-04", "MP-05", "MP-06", "MP-06 (01)", "MP-06 (02)", "MP-06 (03)", "MP-07" ], "PE": [ "PE-01", "PE-02", "PE-03", "PE-03 (01)", "PE-04", "PE-05", "PE-06", "PE-06 (01)", "PE-06 (04)", "PE-08", "PE-08 (01)", "PE-09", "PE-10", "PE-11", "PE-11 (01)", "PE-12", "PE-13", "PE-13 (01)", "PE-13 (02)", "PE-14", "PE-14 (02)", "PE-15", "PE-15 (01)", "PE-16", "PE-17", "PE-18" ], "PL": [ "PL-01", "PL-02", "PL-04", "PL-04 (01)", "PL-08", "PL-10", "PL-11" ], "PS": [ "PS-01", "PS-02", "PS-03", "PS-03 (03)", "PS-04", "PS-04 (02)", "PS-05", "PS-06", "PS-07", "PS-08", "PS-09" ], "RA": [ "RA-01", "RA-02", "RA-03", "RA-03 (01)", "RA-05", "RA-05 (02)", "RA-05 (03)", "RA-05 (04)", "RA-05 (05)", "RA-05 (08)", "RA-05 (11)", "RA-07", "RA-09" ], "SA": [ "SA-01", "SA-02", "SA-03", "SA-04", "SA-04 (01)", "SA-04 (02)", "SA-04 (05)", "SA-04 (09)", "SA-04 (10)", "SA-05", "SA-08", "SA-09", "SA-09 (01)", "SA-09 (02)", "SA-09 (05)", "SA-10", "SA-11", "SA-11 (01)", "SA-11 (02)", "SA-15", "SA-15 (03)", "SA-16", "SA-17", "SA-21", "SA-22" ], "SC": [ "SC-01", "SC-02", "SC-03", "SC-04", "SC-05", "SC-07", "SC-07 (03)", "SC-07 (04)", "SC-07 (05)", "SC-07 (07)", "SC-07 (08)", "SC-07 (10)", "SC-07 (12)", "SC-07 (18)", "SC-07 (20)", "SC-07 (21)", "SC-08", "SC-08 (01)", "SC-10", "SC-12", "SC-12 (01)", "SC-13", "SC-15", "SC-17", "SC-18", "SC-20", "SC-21", "SC-22", "SC-23", "SC-24", "SC-28", "SC-28 (01)", "SC-39", "SC-45", "SC-45 (01)" ], "SI": [ "SI-01", "SI-02", "SI-02 (02)", "SI-02 (03)", "SI-03", "SI-04", "SI-04 (01)", "SI-04 (02)", "SI-04 (04)", "SI-04 (05)", "SI-04 (10)", "SI-04 (11)", "SI-04 (12)", "SI-04 (14)", "SI-04 (16)", "SI-04 (18)", "SI-04 (19)", "SI-04 (20)", "SI-04 (22)", "SI-04 (23)", "SI-05", "SI-05 (01)", "SI-06", "SI-07", "SI-07 (01)", "SI-07 (02)", "SI-07 (05)", "SI-07 (07)", "SI-07 (15)", "SI-08", "SI-08 (02)", "SI-10", "SI-11", "SI-12", "SI-16" ], "SR": [ "SR-01", "SR-02", "SR-02 (01)", "SR-03", "SR-05", "SR-06", "SR-08", "SR-09", "SR-09 (01)", "SR-10", "SR-11", "SR-11 (01)", "SR-11 (02)", "SR-12" ] }, "force": "MUST" } }, "reference": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations", "reference_url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final", "affects": ["Providers"], "terms": ["Security Decision Record (SDR)"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CSF-ACP": { "name": "Assign Control Parameters", "statement": "Providers MUST assign all organization-defined control parameters, following FedRAMP Rev5 Controls Guidance, and ensure that all control parameter assignments are documented in the Security Decision Record (SDR).", "force": "MUST", "affects": ["Providers"], "terms": ["Security Decision Record (SDR)"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CSF-FFG": { "name": "Follow FedRAMP Rev5 Controls Guidance", "statement": "Providers MUST follow FedRAMP Rev5 Controls Guidance for the implementation and documentation of all applicable controls.", "force": "MUST", "affects": ["Providers"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "FRC-CSF-RDY": { "name": "FedRAMP Ready Conversion", "statement": "Providers with FedRAMP Rev5 Ready status MUST convert to a FedRAMP Certification by whichever of the follow dates is later: the expiration of their annual assessment or November 17, 2026 (the legacy FedRAMP Ready status will be entirely removed on December 31, 2027).", "notes": [ "The simplest conversion in most cases would be to a FedRAMP 20x Class A Certification.", "Cloud services that do not wish to convert or do not meet conversion criteria will be renamed Legacy FedRAMP Ready and otherwise retired from FedRAMP Ready." ], "force": "MUST", "affects": ["Providers"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "IEC": { "info": { "name": "Incident Evaluation and Communication", "short_name": "IEC", "web_name": "incident-evaluation-and-communication", "purpose": "The Incident Evaluation and Communication rules explain how providers must communicate incident information to FedRAMP and government customers when they are affected by an incident or likely to be affected by an incident.", "status": "stable", "tag": "assurance", "subsets": { "FRP": { "name": "FedRAMP Responsibilities", "description": "These rules apply to FedRAMP.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["FedRAMP"] } }, "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to providers with FedRAMP Certifications of any type.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } }, "flows": [ { "activity": "Incident Evaluation and Communication", "description": "This workflow illustrates the process for evaluating incidents and persistently notifying all affected parties during the incident if it is a FedRAMP Reportable Incident.", "steps": [ { "from": "An incident is identified.", "to": "IEC-CSO-EFR" }, { "from": "IEC-CSO-EFR", "to": "Incident Evaluation and Communication is complete.", "description": "No" }, { "from": "IEC-CSO-EFR", "to": "IEC-CSO-EFI", "description": "Yes, and the PAIN will be estimated." }, { "from": "IEC-CSO-EFR", "to": "IEC-CSO-DPR", "description": "Yes, but the PAIN will not be estimated." }, { "from": "IEC-CSO-DPR", "to": "IEC-CSO-IIR", "description": "Reporting clock starts, using default PAIN-5 timeframes for reporting." }, { "from": "IEC-CSO-EFI", "to": "IEC-CSO-IIR", "description": "Reporting clock starts, using estimated PAIN timeframes for reporting." }, { "from": "IEC-CSO-IIR", "to": "IEC-CSO-OIR", "description": "Ongoing persistent reporting until incident is resolved." }, { "from": "IEC-CSO-OIR", "to": "IEC-CSO-FIR", "description": "Incident is resolved." }, { "from": "IEC-CSO-FIR", "to": "Incident Evaluation and Communication are complete." } ], "nodes": { "An incident is identified": "start", "IEC-CSO-EFR": "decision", "IEC-CSO-EFI": "decision", "IEC-CSO-DPR": "process", "IEC-CSO-IIR": "process", "IEC-CSO-OIR": "process", "IEC-CSO-FIR": "process", "Incident Evaluation and Communication are complete.": "end" } } ], "20x": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } } }, "rev5": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2027-01-01", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-06-01", "until_next_assessment": false } } } } }, "data": { "all": { "FRP": { "IEC-FRP-ORV": { "name": "Ongoing Review", "statement": "FedRAMP MUST periodically review FedRAMP Incident Evaluation and Communication implementation with providers based on lack of reporting or other information.", "corrective_actions": [ "FedRAMP will request a Corrective Action Plan when a provider is unaware of the rules or has failed to implement proper procedures.", "FedRAMP will grant a 3 month grace period to implement proper procedures pending remediation and possible revocation of FedRAMP Certification." ], "force": "MUST", "affects": ["FedRAMP"], "terms": ["Incident"], "updated": [ { "date": "2026-07-02", "comment": "Update terminology from \"Response\" to \"Communication\" in FedRAMP Incident Evaluation rules." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "CSO": { "IEC-CSO-EFR": { "name": "Evaluate FedRAMP Reportability", "statement": "Providers MUST promptly evaluate incidents to determine if they affect confidentiality or integrity of federal customer data or are likely to affect confidentiality or integrity of federal customer data; such incidents are FedRAMP Reportable Incidents and must be reported following the FedRAMP Incident Evaluation and Communication rules.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "An incident log showing an example of one or more incidents being evaluated including the reason for the determination. The log can be from real incidents, simulated incidents, or a combination of sources." ] }, "terms": [ "FedRAMP Reportable Incident", "Federal Customer Data", "Incident", "Likely", "Promptly" ], "updated": [ { "date": "2026-07-02", "comment": "Update terminology from \"Response\" to \"Communication\" in FedRAMP Incident Evaluation rules." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IEC-CSO-DPR": { "name": "Default PAIN Rating", "statement": "Providers MUST treat FedRAMP Reportable Incidents as if they have a Potential Agency Impact N-rating (PAIN) of 5 UNLESS they promptly estimate the PAIN rating following the rule in IEC-CSO-EFI (Estimate Federal Impact).", "related": ["IEC-CSO-EFI"], "force": "MUST", "affects": ["Providers"], "terms": [ "FedRAMP Reportable Incident", "Incident", "Potential Agency Impact", "Promptly" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IEC-CSO-IIR": { "name": "Initial Incident Report", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications SHOULD responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:", "following_information": [ "Contact information for the federal incident response coordinator", "Provider's internally assigned tracking identifier", "Description of the incident", "Timeline of the incident, including start time, time and source of detection, time of completed FedRAMP Reportable Incident evaluation, and other major incident milestones determined by the provider", "Historically and currently estimated Potential Agency Impact N-rating (PAIN) of the incident, including an explanation of the evaluation following the requirements in IEC-CSO-EFI (Estimate Federal Impact) (if applicable)", "Functional impact to federal agency customers (include impact to confidentiality and/or integrity and the impacted federal customer data types)", "Estimated recovery plan, milestones, and timelines", "List of likely affected customer agencies" ], "force": "SHOULD", "pain_timeframes": { "1": { "iir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Initial Incident Report" } }, "2": { "iir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Initial Incident Report" } }, "3": { "iir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Initial Incident Report" } }, "4": { "iir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Initial Incident Report" } }, "5": { "iir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Initial Incident Report" } } }, "artifacts": { "all": [ "An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } }, "b": { "statement": "Providers with Class B Certifications MUST responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:", "following_information": [ "Contact information for the federal incident response coordinator.", "Provider's internally assigned tracking identifier", "Description of the incident", "Timeline of the incident, including start time, time and source of detection, time of completed FedRAMP Reportable Incident evaluation, and other major incident milestones determined by the provider", "Historically and currently estimated Potential Agency Impact N-rating (PAIN) of the incident, including an explanation of the evaluation following the requirements in IEC-CSO-EFI (Estimate Federal Impact) (if applicable)", "Functional impact to federal agency customers (include impact to confidentiality and/or integrity and the impacted federal customer data types)", "Estimated recovery plan, milestones, and timelines", "List of likely affected customer agencies" ], "force": "MUST", "pain_timeframes": { "1": { "iir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Initial Incident Report" } }, "2": { "iir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Initial Incident Report" } }, "3": { "iir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Initial Incident Report" } }, "4": { "iir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Initial Incident Report" } }, "5": { "iir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Initial Incident Report" } } }, "artifacts": { "all": [ "An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } }, "c": { "statement": "Providers with Class C Certifications MUST responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:", "following_information": [ "Contact information for the federal incident response coordinator.", "Provider's internally assigned tracking identifier", "Description of the incident", "Timeline of the incident, including start time, time and source of detection, time of completed FedRAMP Reportable Incident evaluation, and other major incident milestones determined by the provider", "Historically and currently estimated Potential Agency Impact N-rating (PAIN) of the incident, including an explanation of the evaluation following the requirements in IEC-CSO-EFI (Estimate Federal Impact) (if applicable)", "Functional impact to federal agency customers (include impact to confidentiality and/or integrity and the impacted federal customer data types)", "Estimated recovery plan, milestones, and timelines", "List of likely affected customer agencies" ], "force": "MUST", "pain_timeframes": { "1": { "iir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Initial Incident Report" } }, "2": { "iir": { "timeframe_type": "hours", "timeframe_num": 24, "description": "Initial Incident Report" } }, "3": { "iir": { "timeframe_type": "hours", "timeframe_num": 1, "description": "Initial Incident Report" } }, "4": { "iir": { "timeframe_type": "hours", "timeframe_num": 1, "description": "Initial Incident Report" } }, "5": { "iir": { "timeframe_type": "hours", "timeframe_num": 1, "description": "Initial Incident Report" } } }, "artifacts": { "all": [ "An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } }, "d": { "statement": "Providers with Class D Certifications MUST responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item:", "following_information": [ "Contact information for the federal incident response coordinator.", "Provider's internally assigned tracking identifier", "Description of the incident", "Timeline of the incident, including start time, time and source of detection, time of completed FedRAMP Reportable Incident evaluation, and other major incident milestones determined by the provider", "Historically and currently estimated Potential Agency Impact N-rating (PAIN) of the incident, including an explanation of the evaluation following the requirements in IEC-CSO-EFI (Estimate Federal Impact) (if applicable)", "Functional impact to federal agency customers (include impact to confidentiality and/or integrity and the impacted federal customer data types)", "Estimated recovery plan, milestones, and timelines", "List of likely affected customer agencies" ], "force": "MUST", "pain_timeframes": { "1": { "iir": { "timeframe_type": "hours", "timeframe_num": 1, "description": "Initial Incident Report" } }, "2": { "iir": { "timeframe_type": "hours", "timeframe_num": 1, "description": "Initial Incident Report" } }, "3": { "iir": { "timeframe_type": "hours", "timeframe_num": 0.25, "description": "Initial Incident Report" } }, "4": { "iir": { "timeframe_type": "hours", "timeframe_num": 0.25, "description": "Initial Incident Report" } }, "5": { "iir": { "timeframe_type": "hours", "timeframe_num": 0.25, "description": "Initial Incident Report" } } }, "artifacts": { "all": [ "An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } } }, "related": ["IEC-CSO-EFI"], "affects": ["Providers"], "schema": { "name": "FedRAMP Incident Report (IEC-CSO-IIR / IEC-CSO-OIR / IEC-CSO-FIR)", "url": "https://fedramp.gov/schemas/fedramp-incident-report-schema-2026-06-24.json" }, "notification": [ { "party": "FedRAMP", "method": "email", "target": "fedramp_security@fedramp.gov", "name": "fedramp_security@fedramp.gov" }, { "party": "Agency Customers", "method": "varies", "target": "varies by agency", "name": "Follow agency-specific incident reporting procedures" }, { "party": "All Necessary Parties", "method": "update", "target": "trust center", "name": "Provider's Trust Center or USDA Connect" } ], "terms": [ "All Affected Parties", "FedRAMP Reportable Incident", "Incident", "Initial Incident Report (IIR)", "Responsibly" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IEC-CSO-OIR": { "name": "Ongoing Incident Reports", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications SHOULD responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the following additional information that is available and/or the current relevant status for each item:", "following_information": [ "Observed incident activity", "Indicators of compromise", "Related Common Vulnerabilities and Exposures (CVE) identifier (if applicable)", "Root cause", "Response and recovery activities" ], "force": "SHOULD", "pain_timeframes": { "1": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } }, "2": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } }, "3": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } }, "4": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } }, "5": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } } }, "artifacts": { "all": [ "An Ongoing Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } }, "b": { "statement": "Providers with Class B Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the following additional information that is available and/or the current relevant status for each item:", "following_information": [ "Observed incident activity", "Indicators of compromise", "Related Common Vulnerabilities and Exposures (CVE) identifier, if applicable", "Root cause", "Response and recovery activities" ], "force": "MUST", "pain_timeframes": { "1": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } }, "2": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } }, "3": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } }, "4": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } }, "5": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } } }, "artifacts": { "all": [ "An Ongoing Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } }, "c": { "statement": "Providers with Class C Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the following additional information that is available and/or the current relevant status for each item:", "following_information": [ "Observed incident activity", "Indicators of compromise", "Related Common Vulnerabilities and Exposures (CVE) identifier, if applicable", "Root cause", "Response and recovery activities" ], "force": "MUST", "pain_timeframes": { "1": { "oir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Ongoing Incident Report" } }, "2": { "oir": { "timeframe_type": "hours", "timeframe_num": 24, "description": "Ongoing Incident Report" } }, "3": { "oir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Ongoing Incident Report" } }, "4": { "oir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Ongoing Incident Report" } }, "5": { "oir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Ongoing Incident Report" } } }, "artifacts": { "all": [ "An Ongoing Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } }, "d": { "statement": "Providers with Class D Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the following additional information that is available and/or the current relevant status for each item:", "following_information": [ "Observed incident activity", "Indicators of compromise", "Related Common Vulnerabilities and Exposures (CVE) identifier, if applicable", "Root cause", "Response and recovery activities" ], "force": "MUST", "pain_timeframes": { "1": { "oir": { "timeframe_type": "hours", "timeframe_num": 24, "description": "Ongoing Incident Report" } }, "2": { "oir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Ongoing Incident Report" } }, "3": { "oir": { "timeframe_type": "hours", "timeframe_num": 3, "description": "Ongoing Incident Report" } }, "4": { "oir": { "timeframe_type": "hours", "timeframe_num": 3, "description": "Ongoing Incident Report" } }, "5": { "oir": { "timeframe_type": "hours", "timeframe_num": 3, "description": "Ongoing Incident Report" } } }, "artifacts": { "all": [ "An Ongoing Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } } }, "affects": ["Providers"], "schema": { "name": "FedRAMP Incident Report (IEC-CSO-IIR / IEC-CSO-OIR / IEC-CSO-FIR)", "url": "https://fedramp.gov/schemas/fedramp-incident-report-schema-2026-06-24.json" }, "notification": [ { "party": "FedRAMP", "method": "email", "target": "fedramp_security@fedramp.gov", "name": "fedramp_security@fedramp.gov" }, { "party": "Agency Customers", "method": "varies", "target": "varies by agency", "name": "Follow agency-specific incident reporting procedures" }, { "party": "All Necessary Parties", "method": "update", "target": "trust center", "name": "Provider's Trust Center or USDA Connect" } ], "terms": [ "All Affected Parties", "FedRAMP Reportable Incident", "Incident", "Responsibly", "Vulnerability Response" ], "updated": [ { "date": "2026-09-13", "comment": "Removed the extra the in all statements." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IEC-CSO-FIR": { "name": "Final Incident Report", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.", "force": "MUST", "pain_timeframes": { "1": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 3, "description": "Final Incident Report" } }, "2": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 3, "description": "Final Incident Report" } }, "3": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 3, "description": "Final Incident Report" } }, "4": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 3, "description": "Final Incident Report" } }, "5": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 3, "description": "Final Incident Report" } } }, "artifacts": { "all": [ "An Final Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } }, "b": { "statement": "Providers with Class B Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.", "force": "MUST", "pain_timeframes": { "1": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 3, "description": "Final Incident Report" } }, "2": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 3, "description": "Final Incident Report" } }, "3": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 3, "description": "Final Incident Report" } }, "4": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 3, "description": "Final Incident Report" } }, "5": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 3, "description": "Final Incident Report" } } }, "artifacts": { "all": [ "An Final Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } }, "c": { "statement": "Providers with Class C Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.", "force": "MUST", "pain_timeframes": { "1": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Final Incident Report" } }, "2": { "fir": { "timeframe_type": "bizdays", "timeframe_num": 1, "description": "Final Incident Report" } }, "3": { "fir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Final Incident Report" } }, "4": { "fir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Final Incident Report" } }, "5": { "fir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Final Incident Report" } } }, "artifacts": { "all": [ "An Final Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } }, "d": { "statement": "Providers with Class D Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information.", "force": "MUST", "pain_timeframes": { "1": { "fir": { "timeframe_type": "hours", "timeframe_num": 24, "description": "Final Incident Report" } }, "2": { "fir": { "timeframe_type": "hours", "timeframe_num": 6, "description": "Final Incident Report" } }, "3": { "fir": { "timeframe_type": "hours", "timeframe_num": 3, "description": "Final Incident Report" } }, "4": { "fir": { "timeframe_type": "hours", "timeframe_num": 3, "description": "Final Incident Report" } }, "5": { "fir": { "timeframe_type": "hours", "timeframe_num": 3, "description": "Final Incident Report" } } }, "artifacts": { "all": [ "An Final Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources." ] } } }, "affects": ["Providers"], "schema": { "name": "FedRAMP Incident Report (IEC-CSO-IIR / IEC-CSO-OIR / IEC-CSO-FIR)", "url": "https://fedramp.gov/schemas/fedramp-incident-report-schema-2026-06-24.json" }, "notification": [ { "party": "FedRAMP", "method": "email", "target": "fedramp_security@fedramp.gov", "name": "fedramp_security@fedramp.gov" }, { "party": "Agency Customers", "method": "varies", "target": "varies by agency", "name": "Follow agency-specific incident reporting procedures" }, { "party": "All Necessary Parties", "method": "update", "target": "trust center", "name": "Provider's Trust Center or USDA Connect" } ], "terms": [ "All Affected Parties", "Final Incident Report (FIR)", "Incident", "Responsibly" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IEC-CSO-EFI": { "name": "Estimate Federal Impact", "statement": "Providers SHOULD promptly estimate the likely adverse impact of an incident on agency customers to assign a Potential Agency Impact N-rating; this step is called Incident Rating.", "following_information_bullets": [ "**N1** for a likely minimal customer effect on 1 or more agencies.", "**N2** for a likely narrow customer effect on 1 or more agencies.", "**N3** for a likely disruptive customer effect on 1 agency.", "**N4** for a likely debilitating customer effect on 1 agency or a likely disruptive customer effect on more than 1 agency.", "**N5** for a likely debilitating customer effect on more than 1 agency." ], "note": "All incidents must be assigned a default PAIN-5 as required by IEC-CSO-DPR (Default PAIN Rating) if this step is not completed.", "related": ["IEC-CSO-DPR"], "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "An incident log showing an example of one or more incidents being evaluated including the reason for the determination. The log can be from real incidents, simulated incidents, or a combination of sources." ] }, "schema": { "name": "FedRAMP Incident Report (IEC-CSO-IIR / IEC-CSO-OIR / IEC-CSO-FIR)", "url": "https://fedramp.gov/schemas/fedramp-incident-report-schema-2026-06-24.json" }, "terms": [ "Debilitating Customer Effect", "Disruptive Customer Effect", "Incident", "Likely", "Minimal Customer Effect", "Narrow Customer Effect", "Potential Agency Impact", "Promptly" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IEC-CSO-AIR": { "name": "Automated Incident Reporting", "statement": "Providers SHOULD use automation to minimize human intervention in the process of reporting FedRAMP Reportable Incidents to all affected parties.", "danger": "Modern cloud services should not be reporting incidents by hand-crafting emails!", "force": "SHOULD", "affects": ["Providers"], "terms": [ "All Affected Parties", "FedRAMP Reportable Incident", "Incident" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "IVV": { "info": { "name": "Independent Verification and Validation", "short_name": "IVV", "web_name": "independent-verification-and-validation", "purpose": "This ruleset explains the expectations for independent verification and validation assessments.", "status": "stable", "tag": "assurance", "subsets": { "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to cloud service providers obtaining and maintaining any FedRAMP Certification.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "IAS": { "name": "General Independent Assessor Responsibilities", "description": "These rules apply to independent assessment services supporting all FedRAMP Certification types.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Assessors"] } } }, "20x": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } }, "subsets": { "CSX": { "name": "20x-Specific Provider Responsibilities", "description": "These rules apply to providers for FedRAMP 20x Certifications.", "applicability": { "types": ["20x"], "paths": ["Program"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } }, "rev5": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2027-01-01", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } }, "subsets": { "CSF": { "name": "Rev5-Specific Provider Responsibilities", "description": "These rules apply to providers for FedRAMP Rev5 Certifications.", "applicability": { "types": ["Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } } }, "data": { "all": { "CSO": { "IVV-CSO-FIA": { "name": "FedRAMP Independent Assessments", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications MAY persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.", "force": "MAY", "timeframe_type": "years", "timeframe_num": 1 }, "b": { "statement": "Providers with Class B Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.", "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 }, "c": { "statement": "Providers with Class C Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.", "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 }, "d": { "statement": "Providers with Class D Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.", "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 } }, "notes": [ "The first such completed assessment is typically called an \"initial assessment\" while following assessments are called \"annual assessments.\"", "The specific requirements for independent verification and validation assessments are documented by the FedRAMP Certification Class and Type.", "The option for assessment by FedRAMP directly is limited to cloud services that are explicitly prioritized by FedRAMP, in consultation with the FedRAMP Board and the federal Chief Information Officers Council; this is _extremely_ rare.", "FedRAMP Recognized independent assessment services are listed on the FedRAMP Marketplace." ], "affects": ["Providers"], "terms": [ "Certification Class", "FedRAMP Independent Assessment", "FedRAMP Recognized", "Persistently", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-CSO-SEI": { "name": "Supply Evidence of Implementation", "statement": "Providers MUST supply evidence to all necessary assessors of the implementation of the measures that have been documented to meet FedRAMP Practices; this evidence is the result of verification.", "note": "For example, if the documentation says that firewall rules are used to block traffic then the cloud service provider would verify that firewall rules are in place to block traffic and supply that evidence to assessors (preferably by allowing them to see how firewall configurations are deployed from a source of truth).", "force": "MUST", "affects": ["Providers"], "terms": [ "All Necessary Assessors", "FedRAMP Practices", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-CSO-SEE": { "name": "Supply Evidence of Effectiveness", "statement": "Providers MUST supply evidence to all necessary assessors of the effectiveness of the measures that have been implemented to meet FedRAMP Practices; this evidence is the result of validation.", "note": "For example, after verifying that firewalls are configured to block traffic following IVV-CSO-SEI (Supply Evidence of Implementation), the provider would validate that traffic is actually being blocked and supply evidence of that validation to assessors (such as by allowing them to see metrics on the traffic that is blocked vs not).", "related": ["IVV-CSO-SEI"], "force": "MUST", "affects": ["Providers"], "terms": [ "All Necessary Assessors", "FedRAMP Practices", "Validation" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-CSO-ICP": { "name": "Inclusion in Certification Package", "statement": "Providers MUST supply the results of FedRAMP independent assessments in their FedRAMP Certification Package without inappropriate modification.", "notes": [ "Inappropriate modification in this context means changing the underlying intent/etc. of the content provided by the independent assessment service - the content itself may be modified for presentation, formatting, etc. as needed.", "This rule is related to IVV-IAS-VIP (Verify Inclusion in Certification Package)." ], "related": ["IVV-IAS-VIP"], "force": "MUST", "affects": ["Providers"], "terms": [ "Certification Package", "FedRAMP Independent Assessment", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-CSO-DUS": { "name": "Document Use of Representative Samples", "statement": "Providers MUST document and explain the use of representative samples during verification and validation when using representative samples as allowed by IVV-CSO-USR (Use Representative Samples).", "related": ["IVV-CSO-USR"], "force": "MUST", "affects": ["Providers"], "terms": ["Validation", "Verification"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-CSO-STE": { "name": "Supply Technical Explanations", "statement": "Providers SHOULD supply all necessary assessors with technical explanations, demonstrations, and other relevant supporting information about the technical capabilities they employ to address FedRAMP rules; this SHOULD be supplied as necessary to ensure the assessor can effectively complete verification and validation.", "force": "SHOULD", "affects": ["Providers"], "terms": [ "All Necessary Assessors", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-CSO-USR": { "name": "Use Representative Samples", "statement": "Providers MAY use representative samples as appropriate during verification and validation.", "note": "Many modern cloud services using effective automation do not need to use representative sampling and are capable of persistently verifying and validating the majority of their security measures automatically.", "force": "MAY", "affects": ["Providers"], "terms": ["Persistently", "Validation", "Verification"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-CSO-RAA": { "name": "Receiving Assessor Advice", "statement": "Providers MAY ask for and accept advice from their assessor during assessment regarding techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their verification, validation and reporting procedures, UNLESS doing so is likely to compromise the objectivity and integrity of the assessment.", "force": "MAY", "affects": ["Providers"], "terms": ["Likely", "Validation", "Verification"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "IAS": { "IVV-IAS-VIM": { "name": "Verify Implementation", "statement": "Assessors MUST verify that the measures implemented by the cloud service offering matches the measures they documented to meet FedRAMP Practices.", "note": "This requires reviewing the actual measures themselves at a technical level, such as reviewing underlying code as appropriate; don't simply review documentation or screenshots.", "force": "MUST", "affects": ["Assessors"], "terms": [ "Cloud Service Offering", "FedRAMP Practices", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-IAS-VEF": { "name": "Validate Effectiveness", "statement": "Assessors MUST validate the effectiveness of the implemented measures to ensure they have the intended outcome for meeting FedRAMP Practices.", "note": "This requires reviewing the actual measures themselves at a technical level, such as reviewing underlying code as appropriate; don't simply review documentation or screenshots.", "force": "MUST", "affects": ["Assessors"], "terms": ["FedRAMP Practices", "Validation"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-IAS-SUM": { "name": "Assessment Summary", "statement": "Assessors MUST supply the provider with a high-level summary of their assessment process and findings for each FedRAMP Practice; this summary will be included by the provider in the FedRAMP Security Decision Record for the cloud service offering.", "note": "FedRAMP does not require a separate Security Assessment Plan or Security Assessment Report for FedRAMP 20x or FedRAMP Rev5 Certifications; this information is expected to be included in the Security Decision Record by the cloud service provider.", "force": "MUST", "affects": ["Assessors"], "terms": [ "Cloud Service Offering", "FedRAMP Practices", "Security Decision Record (SDR)" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-IAS-OSA": { "name": "Overall Summary of Assessment", "statement": "Assessors MUST supply the provider with an overall summary of the verification and validation assessment results, including any resulting failures or areas of dispute; this summary will be included by the provider in the FedRAMP Certification Package Overview for the cloud service offering.", "note": "FedRAMP does not supply a template for this summary and encourages independent assessment services to optimize for the best customer experience in the creation of these materials.", "force": "MUST", "affects": ["Assessors"], "terms": [ "Certification Package", "Cloud Service Offering", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-IAS-VIP": { "name": "Verify Inclusion in Certification Package", "statement": "Assessors MUST verify that information supplied during a FedRAMP independent assessment is included in the FedRAMP Certification Package by the provider without inappropriate modification.", "note": "This rule is related to IVV-CSO-ICP (Inclusion in Certification Package).", "related": ["IVV-CSO-ICP"], "force": "MUST", "affects": ["Assessors"], "terms": [ "Certification Package", "FedRAMP Independent Assessment", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-IAS-EPX": { "name": "Engage Provider Experts", "statement": "Assessors SHOULD engage provider experts in discussion to understand the decisions made by the provider and inform expert qualitative assessment, and SHOULD perform independent research to test such information as part of the expert qualitative assessment process.", "force": "SHOULD", "affects": ["Assessors"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-IAS-SHA": { "name": "Sharing Advice", "statement": "Assessors MAY share advice with providers they are assessing about techniques and procedures that will improve the provider's security posture or the effectiveness, clarity, and accuracy of their verification, validation and reporting procedures, UNLESS doing so is likely to compromise the objectivity and integrity of the assessment.", "force": "MAY", "affects": ["Assessors"], "terms": ["Likely", "Validation", "Verification"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "20x": { "CSX": { "IVV-CSX-AIA": { "name": "Annual Independent Assessments for 20x", "varies_by_class": { "a": { "statement": "Providers with 20x Class A Certifications MUST meet the expectations of their underlying alternative security framework as part of their persistent independent verification and validation assessment.", "force": "MUST" }, "b": { "statement": "Providers with 20x Class B Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.", "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 }, "c": { "statement": "Providers with 20x Class C Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.", "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 }, "d": { "statement": "Providers with 20x Class D Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.", "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 } }, "affects": ["Providers"], "terms": [ "FedRAMP Independent Assessment", "Persistently", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "rev5": { "CSF": { "IVV-CSF-AIA": { "name": "Annual Independent Assessments for Rev5", "varies_by_class": { "b": { "statement": "Providers with Rev5 Class B Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:", "rev5_controls_list": { "AC": ["AC-02", "AC-03"], "AU": [ "AU-02", "AU-03", "AU-04", "AU-05", "AU-06", "AU-08", "AU-11", "AU-12" ], "CA": ["CA-08"], "CM": ["CM-05", "CM-06", "CM-07", "CM-08"], "CP": ["CP-04"], "IA": [ "IA-02", "IA-02 (01)", "IA-02 (02)", "IA-02 (08)", "IA-02 (12)", "IA-04", "IA-05" ], "IR": ["IR-04"], "PE": ["PE-03"], "RA": ["RA-05", "RA-05 (02)"], "SA": ["SA-09"], "SC": [ "SC-07", "SC-08", "SC-12", "SC-13", "SC-21", "SC-28" ], "SI": ["SI-03"] }, "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 }, "c": { "statement": "Providers with Rev5 Class C Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:", "rev5_controls_list": { "AC": [ "AC-02", "AC-02 (01)", "AC-02 (02)", "AC-02 (03)", "AC-02 (04)", "AC-02 (05)", "AC-02 (07)", "AC-02 (09)", "AC-02 (12)", "AC-02 (13)", "AC-03", "AC-06", "AC-06 (02)", "AC-06 (05)", "AC-06 (10)", "AC-17 (02)" ], "AU": [ "AU-02", "AU-03", "AU-03 (01)", "AU-04", "AU-05", "AU-06", "AU-06 (01)", "AU-06 (03)", "AU-08", "AU-11", "AU-12" ], "CA": ["CA-08 (01)", "CA-08 (02)"], "CM": [ "CM-05", "CM-06", "CM-06 (01)", "CM-07", "CM-07 (01)", "CM-07 (02)", "CM-07 (05)", "CM-08" ], "CP": ["CP-04"], "IA": [ "IA-02", "IA-02 (01)", "IA-02 (02)", "IA-02 (05)", "IA-02 (06)", "IA-02 (08)", "IA-02 (12)", "IA-04", "IA-05" ], "IR": ["IR-03", "IR-04", "IR-04 (01)"], "MA": ["MA-03 (02)"], "PE": ["PE-03"], "RA": ["RA-05", "RA-05 (02)", "RA-05 (03)"], "SA": ["SA-09", "SA-11 (01)"], "SC": [ "SC-07", "SC-07 (03)", "SC-07 (04)", "SC-07 (05)", "SC-07 (07)", "SC-07 (08)", "SC-07 (12)", "SC-07 (18)", "SC-08", "SC-12", "SC-13", "SC-21", "SC-28", "SC-45 (01)" ], "SI": [ "SI-03", "SI-04 (01)", "SI-04 (02)", "SI-04 (16)", "SI-04 (23)", "SI-06", "SI-07", "SI-07 (01)", "SI-10" ] }, "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 }, "d": { "statement": "Providers with Rev5 Class D Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:", "rev5_controls_list": { "AC": [ "AC-02", "AC-02 (01)", "AC-02 (02)", "AC-02 (03)", "AC-02 (04)", "AC-02 (05)", "AC-02 (07)", "AC-02 (09)", "AC-02 (11)", "AC-02 (12)", "AC-02 (13)", "AC-03", "AC-06", "AC-06 (02)", "AC-06 (03)", "AC-06 (05)", "AC-06 (08)", "AC-06 (10)", "AC-17 (02)" ], "AU": [ "AU-02", "AU-03", "AU-03 (01)", "AU-04", "AU-05", "AU-05 (01)", "AU-05 (02)", "AU-06", "AU-06 (01)", "AU-06 (03)", "AU-06 (04)", "AU-06 (05)", "AU-06 (06)", "AU-06 (07)", "AU-08", "AU-10", "AU-11", "AU-12", "AU-12 (01)", "AU-12 (03)" ], "CA": ["CA-08 (01)", "CA-08 (02)"], "CM": [ "CM-05", "CM-06", "CM-06 (01)", "CM-06 (02)", "CM-07", "CM-07 (01)", "CM-07 (02)", "CM-07 (05)", "CM-08" ], "CP": ["CP-04"], "IA": [ "IA-02", "IA-02 (01)", "IA-02 (02)", "IA-02 (05)", "IA-02 (06)", "IA-02 (08)", "IA-02 (12)", "IA-04", "IA-05" ], "IR": [ "IR-03", "IR-04", "IR-04 (01)", "IR-04 (02)", "IR-04 (04)", "IR-04 (06)" ], "MA": ["MA-03 (02)"], "PE": ["PE-03"], "RA": ["RA-05", "RA-05 (02)", "RA-05 (03)"], "SA": ["SA-09", "SA-11 (01)"], "SC": [ "SC-07", "SC-07 (03)", "SC-07 (04)", "SC-07 (05)", "SC-07 (07)", "SC-07 (08)", "SC-07 (12)", "SC-07 (18)", "SC-07 (20)", "SC-07 (21)", "SC-08", "SC-12", "SC-13", "SC-21", "SC-28", "SC-45 (01)" ], "SI": [ "SI-03", "SI-04 (01)", "SI-04 (02)", "SI-04 (10)", "SI-04 (16)", "SI-04 (19)", "SI-04 (20)", "SI-04 (23)", "SI-06", "SI-07", "SI-07 (01)", "SI-10" ] }, "force": "MUST", "timeframe_type": "years", "timeframe_num": 1 } }, "affects": ["Providers"], "terms": ["FedRAMP Independent Assessment"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-CSF-MCA": { "name": "Mandatory Control Assessment", "statement": "Providers MUST have all applicable Rev5 Controls included in FedRAMP independent assessments every 3 years but are not required to have all Rev5 Controls included in the same FedRAMP independent assessment.", "note": "Traditionally this has been done by reviewing a rotating selection of Rev5 Controls at each annual assessment, however this requirement is a ceiling and not a floor. See IVV-CSF-PCA (Preferred Control Assessment) for FedRAMP's recommended approach to Rev5 control assessments.", "related": ["IVV-CSF-PCA"], "force": "MUST", "affects": ["Providers"], "timeframe_type": "years", "timeframe_num": 3, "terms": ["FedRAMP Independent Assessment"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-CSF-ACF": { "name": "Assessment of Rev5 Controls with Findings", "statement": "Providers MUST have Rev5 Controls with negative findings from the previous FedRAMP independent assessment included in the next FedRAMP independent assessment.", "force": "MUST", "affects": ["Providers"], "terms": ["FedRAMP Independent Assessment"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "IVV-CSF-PCA": { "name": "Preferred Control Assessment", "statement": "Providers SHOULD include all applicable Rev5 Controls in each FedRAMP independent assessment.", "force": "SHOULD", "affects": ["Providers"], "terms": ["FedRAMP Independent Assessment"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "MAS": { "info": { "name": "Minimum Assessment Scope", "short_name": "MAS", "web_name": "minimum-assessment-scope", "purpose": "The Minimum Assessment Scope rules help providers define assessment boundaries narrowly enough to avoid unnecessary review of components that do not affect the offering's security. These rules still ensure the assessment includes the resources and connections needed to understand the offering's confidentiality, integrity, and availability.", "status": "stable", "tag": "boundary", "subsets": { "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to providers for any type of FedRAMP Certification.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } }, "20x": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } } }, "rev5": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2027-01-01", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } } } }, "data": { "all": { "CSO": { "MAS-CSO-IIR": { "name": "Identify Information Resources", "statement": "Providers MUST identify a set of information resources to assess for FedRAMP Certification that includes all information resources that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering; this set of information resources is the cloud service offering.", "notes": [ "Certain categories of cloud computing products and services are specified as entirely outside the scope of FedRAMP by the Director of the Office of Management and Budget. All such products and services are therefore not included in the cloud service offering for FedRAMP. For more, see https://fedramp.gov/scope.", "Software produced by cloud service providers that is delivered separately for installation on agency systems and not operated in a shared responsibility model (typically including agents, application clients, mobile applications, etc. that are not fully managed by the cloud service provider) is not a cloud computing product or service and is entirely outside the scope of FedRAMP under the FedRAMP Certification Act. All such software is therefore not included in the cloud service offering for FedRAMP. For more, see https://fedramp.gov/scope.", "All aspects of the cloud service offering are determined and maintained by the cloud service provider in accordance with related FedRAMP Certification rules and documented by the cloud service provider in their FedRAMP Certification Package." ], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "A machine readable output containing all required data of the components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.", "A human readable explanation of how the machine readable output is derived.", "The code for the automated process used to generate the machine readable output." ] }, "terms": [ "Certification Package", "Cloud Service Offering", "Federal Customer Data", "Handle", "Information Resource", "Likely" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MAS-CSO-FLO": { "name": "Information Flows and Security Categories", "statement": "Providers MUST clearly identify, document, and explain information flows and security categories for ALL information resources or sets of information resources in the cloud service offering.", "note": "Information resources (including third-party information resources) MAY vary by security category as appropriate to the type of information handled by or impacted by the information resource.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "A machine readable output containing all required data of the permitted connections between components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.", "A human readable explanation of how the machine readable output is derived.", "The code for the automated process used to generate the machine readable output." ] }, "terms": [ "Cloud Service Offering", "Handle", "Information Resource", "Security Category", "Third-Party Information Resource" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MAS-CSO-TPR": { "name": "Third-Party Information Resources", "statement": "Providers MUST address the potential impact to federal customer data from third-party information resources used by the cloud service offering, ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES, by documenting the following information about each applicable third-party information resource:", "following_information": [ "General usage and configuration", "Explanation or justification for use", "Mitigation measures in place to reduce the potential impact to federal customer data", "Compensating controls in place to reduce the potential impact to federal customer data" ], "related": ["MAS-CSO-IIR"], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "A machine readable output containing all required data of the third-party information resources of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.", "A human readable explanation of how the machine readable output is derived.", "The code for the automated process used to generate the machine readable output." ] }, "schema": { "name": "FedRAMP Certification Package Overview (FRC-CSO-PKG)", "url": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json" }, "terms": [ "Cloud Service Offering", "Federal Customer Data", "Information Resource", "Initial Incident Report (IIR)", "Third-Party Information Resource" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MAS-CSO-MDI": { "name": "Metadata Inclusion", "statement": "Providers MUST include metadata (including metadata about federal customer data) in the Minimum Assessment Scope ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES.", "related": ["MAS-CSO-IIR"], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "A machine readable output containing all required data of the metadata collected or maintained by the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.", "A human readable explanation of how the machine readable output is derived.", "The code for the automated process used to generate the machine readable output." ] }, "terms": [ "Federal Customer Data", "Information Resource", "Initial Incident Report (IIR)" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MAS-CSO-SUP": { "name": "Supplemental Information", "statement": "Providers MAY include additional materials about other information resources that are not part of the cloud service offering in a FedRAMP Certification Package supplement; these resources will not be FedRAMP Certified and MUST be clearly marked and separated from the cloud service offering.", "note": "This is intended to allow inclusion of things like security materials for apps, supplemental marketing collateral, and other information that is not part of the cloud service offering but may be useful to agencies.", "force": "MAY", "affects": ["Providers"], "terms": [ "Certification Package", "Cloud Service Offering", "FedRAMP Certified", "Information Resource" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "MKT": { "info": { "name": "Marketplace Listing", "short_name": "MKT", "web_name": "marketplace-listing", "purpose": "The Marketplace Listing rules define how FedRAMP decides which cloud service offerings, assessors, and advisors may be listed in the FedRAMP Marketplace. These rules help agencies and other customers rely on the Marketplace as a consistent source of eligible services and supporting organizations, while requiring listed organizations to supply accurate, accessible, and machine-readable information.", "status": "stable", "tag": "other", "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2026-07-04", "optional_adoption": "2026-07-04", "grace": { "default": "2026-07-04", "until_next_assessment": false } } }, "subsets": { "FRP": { "name": "FedRAMP Responsibilities", "description": "These rules apply to FedRAMP activities related to the FedRAMP Marketplace.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["A", "B", "C", "D"], "affects": ["FedRAMP"] } }, "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to providers seeking a listing in the FedRAMP Marketplace.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["A", "B", "C", "D"], "affects": ["Providers"] } }, "IAS": { "name": "General Assessor Responsibilities", "description": "These rules apply to independent assessment services seeking a listing in the FedRAMP Marketplace.", "applicability": { "types": [], "paths": [], "classes": [], "affects": ["Assessors"] } }, "CAS": { "name": "General Advisor Responsibilities", "description": "These rules apply to consulting and advisory services seeking a listing in the FedRAMP Marketplace.", "applicability": { "types": [], "paths": [], "classes": [], "affects": ["Advisors"] } }, "IIP": { "name": "Provider Responsibilities for Initial Implementation Phase Listings", "description": "FedRAMP allows cloud service providers that are actively preparing to obtain a FedRAMP Certification to apply for listing in the FedRAMP Marketplace. All cloud service providers must obtain a Initial Implementation Phase Marketplace Listing before they can apply for FedRAMP Certification. These rules apply to providers seeking a Initial Implementation Phase listing in the FedRAMP Marketplace.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": [], "affects": ["Providers"] } } } }, "data": { "all": { "FRP": { "MKT-FRP-SOF": { "name": "Scope of FedRAMP", "statement": "FedRAMP MUST NOT list cloud service offerings in the Marketplace or perform any FedRAMP Certification activities unless it determines the cloud service offering is within the scope of FedRAMP.", "reference": "Scope of FedRAMP", "reference_url": "https://fedramp.gov/scope", "force": "MUST NOT", "affects": ["FedRAMP"], "terms": ["Cloud Service Offering"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "CSO": { "MKT-CSO-MLR": { "name": "Marketplace Listing Requirements", "statement": "Providers MUST address at least these FedRAMP rules to apply for a new FedRAMP Marketplace listing OR to request updates to an existing listing:", "following_information": [ "Certification Data Sharing: CDS-CSO-PUB (Public Information)" ], "related": ["CDS-CSO-PUB"], "force": "MUST", "affects": ["Providers"], "terms": ["Certification Data"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MKT-CSO-PML": { "name": "Provider Marketplace Listing Requests", "statement": "Providers MUST notify FedRAMP using the FedRAMP Marketplace Providing Listing Request Form to request a listing in the FedRAMP Marketplace.", "note": "FedRAMP does not accept applications for a FedRAMP Marketplace Listing via email!", "force": "MUST", "affects": ["Providers"], "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=50939227168027", "name": "FedRAMP Marketplace Provider Listing Request Form" } ], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "IAS": { "MKT-IAS-OFR": { "name": "Only FedRAMP Recognized Assessors", "statement": "Assessors MUST obtain and maintain FedRAMP Recognition to be listed in the FedRAMP Marketplace.", "force": "MUST", "affects": ["Assessors"], "terms": ["FedRAMP Recognized"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MKT-IAS-WEB": { "name": "Website Requirements for Assessors", "statement": "Assessors MUST have an appropriate web site that publicly supplies at least the following information in human-readable and JSON formats:", "following_information": [ "General description of the independent assessment service", "Contact information", "Types of independent services offered", "Optional: Positive attestations from customers or customer references" ], "force": "MUST", "affects": ["Assessors"], "artifacts": { "all": [ "URL to the human-readable data.", "URL to the machine-readable data." ] }, "schema": { "name": "FedRAMP Assessor Information Schema", "url": "https://fedramp.gov/schemas/fedramp-assessor-information-schema-2026-06-24.json" }, "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MKT-IAS-LRQ": { "name": "Listing Requests for Assessors", "statement": "Assessors MUST complete the Assessor Listing Request Form to request listing in the FedRAMP Marketplace.", "force": "MUST", "affects": ["Assessors"], "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52060327520795", "name": "[For Assessors/Advisors] Marketplace Listing Form" } ], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "CAS": { "MKT-CAS-WEB": { "name": "Website Requirements for Advisors", "statement": "Advisors MUST have an appropriate web site that publicly supplies at least the following information in consistent machine-readable and human-readable formats:", "following_information": [ "General description of the consulting or advisory service", "Contact information", "Types of consulting or advisory services offered", "Optional: Positive attestations from customers or customer references" ], "force": "MUST", "affects": ["Advisors"], "artifacts": { "all": [ "URL to the human-readable data.", "URL to the machine-readable data." ] }, "schema": { "name": "FedRAMP Advisory Service Information Schema", "url": "https://fedramp.gov/schemas/fedramp-advisor-information-schema-2026-06-24.json" }, "terms": ["Machine-Readable"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MKT-CAS-LRQ": { "name": "Listing Requests for Advisors", "statement": "Advisors MUST complete the Advisor Listing Request Form to request listing in the FedRAMP Marketplace.", "force": "MUST", "affects": ["Advisors"], "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52060327520795", "name": "[For Assessors/Advisors] Marketplace Listing Form" } ], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MKT-CAS-RFR": { "name": "Advisor Responses to FedRAMP", "statement": "Advisors MUST reply to all requests from @fedramp.gov or @gsa.gov email addresses sent to the contact information provided in their advisor listing within 5 business days.", "corrective_actions": [ "If an advisor fails to respond to a request within 5 business days, FedRAMP will send a follow-up email.", "If an advisor fails to respond to the follow-up email within 5 business days, FedRAMP will remove their listing from the Marketplace.", "Advisors removed from the Marketplace for failure to respond to FedRAMP will not be eligible for listing for at least 6 months unless there are extenuating circumstances." ], "force": "MUST", "affects": ["Advisors"], "timeframe_type": "bizdays", "timeframe_num": 5, "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "IIP": { "MKT-IIP-AGU": { "name": "Agency Use Cases", "statement": "Providers MUST demonstrate that a cloud service offering is intended for one of the following use cases:", "following_information": [ "Direct Use: The product will be used directly by agency customers for integration into a federal information system that falls within the scope of 44 USC § 3506 and will receive an agency Authorization to Operate.", "Indirect Use: The product will be included as a third-party information resource in other cloud service offerings that are directly used by agency customers." ], "notes": [ "FedRAMP will not list products or services that are outside the explicit statutory scope of FedRAMP; See MKT-FRP-SOF (Scope of FedRAMP).", "Services used by private companies to meet other compliance requirements (such as CMMC) that do not also meet one of the above use cases are outside the scope of FedRAMP." ], "related": ["MKT-FRP-SOF"], "force": "MUST", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "Information Resource", "Third-Party Information Resource" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MKT-IIP-DCP": { "name": "Demonstrating Continuous Progress", "statement": "Providers MUST demonstrate continuous progress towards a FedRAMP Certification, documented in their Trust Center or website and updated at least quarterly; progress is measured by the provider against documented goals and milestones.", "note": "This is an opportunity for a business to showcase its goals and progress, and should be seen as a marketing and customer experience challenge instead of a compliance challenge.", "force": "MUST", "affects": ["Providers"], "terms": ["Trust Center"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "MKT-IIP-DLA": { "name": "Deadline for Assessment", "statement": "Providers MUST demonstrate that an assessment for a FedRAMP Certification Class B, C, or D has been scheduled within 2 years of initial listing in the Initial Implementation Phase.", "corrective_actions": [ "If a provider fails to schedule an assessment for a FedRAMP Certification Class B, C, or D within 2 years of initial listing in the Initial Implementation Phase, FedRAMP will remove their listing from the Marketplace until they provide evidence of a scheduled assessment." ], "force": "MUST", "affects": ["Providers"], "timeframe_type": "years", "timeframe_num": 2, "terms": ["Certification Class"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "REC": { "info": { "name": "FedRAMP Recognition of Independent Assessment Services", "short_name": "REC", "web_name": "fedramp-recognition", "purpose": "The FedRAMP Recognition of independent assessment services rules explain the requirements for assessors to obtain and maintain FedRAMP Recognition in order to support the FedRAMP Certification process.", "status": "stable", "tag": "other", "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2026-07-04", "optional_adoption": "2026-07-04", "grace": { "default": "2026-07-04", "until_next_assessment": false } } }, "subsets": { "FRP": { "name": "FedRAMP Responsibilities", "description": "These rules apply to FedRAMP when evaluating independent assessment services for initial or ongoing FedRAMP Recognition.", "applicability": { "types": [], "paths": [], "classes": [], "affects": ["FedRAMP"] } }, "IAS": { "name": "General Independent Assessor Responsibilities", "description": "These rules apply to independent assessment services seeking to obtain or maintain FedRAMP Recognition.", "applicability": { "types": [], "paths": [], "classes": [], "affects": ["Assessors"] } } } }, "data": { "all": { "FRP": { "REC-FRP-FOC": { "name": "Foreign Ownership Collection", "statement": "FedRAMP MUST maintain a process to collect foreign ownership, control, or influence declarations from FedRAMP Recognized assessors and updates to those declarations.", "force": "MUST", "affects": ["FedRAMP"], "terms": ["FedRAMP Recognized"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-FRP-RAO": { "name": "Recognized Assessors Only", "statement": "FedRAMP MUST NOT accept verification, validation, or other attestations from independent assessors who are not FedRAMP Recognized.", "force": "MUST NOT", "affects": ["FedRAMP"], "terms": ["FedRAMP Recognized", "Validation", "Verification"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-FRP-DRD": { "name": "Double Revocation Disqualification", "statement": "FedRAMP MUST NOT restore FedRAMP Recognition for an assessor after FedRAMP has revoked that assessor's FedRAMP Recognition 2 times.", "force": "MUST NOT", "affects": ["FedRAMP"], "terms": ["FedRAMP Recognized"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "IAS": { "REC-IAS-ACC": { "name": "A2LA Accreditation", "statement": "Assessors MUST obtain and maintain accreditation through the American Association for Laboratory Accreditation (A2LA) Cybersecurity Inspection Body Program to qualify for FedRAMP Recognition.", "note": "FedRAMP will remove FedRAMP Recognition immediately after the American Association for Laboratory Accreditation notifies FedRAMP that an assessor's accreditation has lapsed.", "force": "MUST", "affects": ["Assessors"], "terms": ["FedRAMP Recognized"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-ADA": { "name": "Actually Do Assessments", "statement": "Assessors MUST complete at least 2 initial or ongoing assessments for Class B, C, or D FedRAMP Certifications every 2 years to maintain FedRAMP Recognition.", "note": "For a newly FedRAMP Recognized Assessor, this rule applies beginning on the initial date of FedRAMP Recognition if that date is later than 2026-06-01.", "corrective_actions": [ "FedRAMP will notify assessors when they are within 6 months of losing FedRAMP Recognition under this rule and request a corrective action plan.", "Assessors whose corrective action plan is not accepted will lose FedRAMP Recognition and must supply an alternative corrective action plan to move toward renewed FedRAMP Recognition." ], "force": "MUST", "affects": ["Assessors"], "timeframe_type": "years", "timeframe_num": 2, "terms": ["FedRAMP Recognized"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-PSC": { "name": "Policy and Standards Compliance", "statement": "Assessors MUST maintain compliance with the latest American Association for Laboratory Accreditation (A2LA) R311 - Specific Requirements - Federal Risk and Authorization Management Program to maintain FedRAMP Recognition.", "reference": "A2LA Public Documents", "reference_url": "https://portal.a2la.org/documents/", "force": "MUST", "affects": ["Assessors"], "terms": ["FedRAMP Recognized"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-ANR": { "name": "Annual Surveillance Assessment", "statement": "Assessors MUST achieve a favorable annual surveillance assessment by the American Association for Laboratory Accreditation (A2LA) to maintain FedRAMP Recognition.", "corrective_actions": [ "Assessors have 75 days to complete corrective actions for nonconformances identified by the American Association for Laboratory Accreditation (A2LA)during a surveillance assessment. If an assessor exceeds the 75 day resolution timeframe, A2LA will supply FedRAMP with a narrative of the assessor's current status, the assessor will be designated as in Remediation in the FedRAMP Marketplace, and the assessor must supply a corrective action plan to FedRAMP." ], "force": "MUST", "affects": ["Assessors"], "timeframe_type": "years", "timeframe_num": 1, "terms": ["FedRAMP Recognized"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-RAS": { "name": "Full A2LA Reassessment", "statement": "Assessors MUST achieve a favorable full reassessment by the American Association for Laboratory Accreditation (A2LA) at least once every 2 years to maintain FedRAMP Recognition.", "corrective_actions": [ "Assessors have 75 days to complete corrective actions for nonconformances identified by the American Association for Laboratory Accreditation during a reassessment. If an assessor exceeds the 75 day resolution timeframe, the American Association for Laboratory Accreditation will supply FedRAMP with a narrative of the assessor's current status, the assessor will be designated as In Remediation in the FedRAMP Marketplace, and the assessor must supply a corrective action plan to FedRAMP." ], "force": "MUST", "affects": ["Assessors"], "timeframe_type": "years", "timeframe_num": 2, "terms": ["FedRAMP Recognized"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-RAR": { "name": "Re-entry after Revocation", "statement": "Assessors MUST satisfy all American Association for Laboratory Accreditation (A2LA) re-entry conditions before regaining FedRAMP Recognition after revocation.", "note": "A revocation may require extended time in revoked status while the assessor demonstrates acceptable performance in the A2LA Cybersecurity Inspection Body Program before seeking FedRAMP Recognition again.", "force": "MUST", "affects": ["Assessors"], "terms": ["FedRAMP Recognized"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-RQU": { "name": "Roles and Qualifications", "statement": "Assessors MUST staff FedRAMP assessments with all roles required by the American Association for Laboratory Accreditation (A2LA) R311, including personnel who meet the qualifications for each role, unless FedRAMP publishes a specific exception for a limited pilot or other explicitly scoped process.", "corrective_actions": [ "FedRAMP may require a consultation meeting, corrective action plan, or revocation for failure to comply." ], "force": "MUST", "affects": ["Assessors"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-AFI": { "name": "Annual Foreign Interest Reports", "statement": "Assessors MUST report information relating to any foreign interest, foreign influence, or foreign control of the independent assessment service to FedRAMP annually.", "force": "MUST", "affects": ["Assessors"], "timeframe_type": "years", "timeframe_num": 1, "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52006681154587", "name": "FedRAMP Foreign Ownership, Control, or Influence Declaration Form" } ], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-CFI": { "name": "Changes in Foreign Interest", "statement": "Assessors MUST report updated information relating to any foreign interest, foreign influence, or foreign control of the independent assessment service within 48 hours of any change in foreign ownership or control.", "force": "MUST", "affects": ["Assessors"], "timeframe_type": "hours", "timeframe_num": 48, "notification": [ { "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52006681154587", "name": "FedRAMP Foreign Ownership, Control, or Influence Declaration Form" } ], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-PST": { "name": "Performance Standards", "statement": "Assessors MUST meet FedRAMP performance standards for assessor deliverables to support independent, risk-based reviews by FedRAMP and federal agencies, including at least:", "following_information": [ "Complete Assessment Packages: Supplies complete and thoroughly prepared documents on the first submission.", "Deliverable Quality: Ensures documentation content is clear, complete, concise, and consistent.", "Deliverable Format: Follows applicable FedRAMP rules.", "Timeliness and Responsiveness: Delivers documents on time according to the schedule agreed to by the federal government, provider, and assessor.", "Testing Accuracy and Completeness: Ensures accurate and complete testing of a cloud service offering in accordance with ISO 17020 and FedRAMP security rules.", "Assessment Integrity: Submits independent assessments of provider security implementations that are not influenced by provider demands.", "Chain of Custody: Preserves the integrity and chain of custody of assessor-authored documents and provider-supplied evidence used in FedRAMP assessments." ], "force": "MUST", "affects": ["Assessors"], "terms": ["Cloud Service Offering"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-CAP": { "name": "Corrective Action Plan", "statement": "Assessors MUST supply a corrective action plan when FedRAMP requires one for performance standards deficiencies or organizational risks.", "force": "MUST", "affects": ["Assessors"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-INV": { "name": "Invalid Deliverables", "statement": "Assessors MUST treat deliverables prepared, performed, or submitted by personnel who do not meet required role qualifications as invalid for FedRAMP purposes.", "force": "MUST", "affects": ["Assessors"], "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "REC-IAS-SEP": { "name": "Advisory Separation", "statement": "Assessors MUST NOT perform a FedRAMP independent assessment of the same cloud service offering within 2 years after supplying advisory or consulting services for that offering, unless FedRAMP publishes a specific exception for a limited pilot or other explicitly scoped process.", "corrective_actions": [ "FedRAMP may require a consultation meeting, corrective action plan, or revocation for failure to comply." ], "force": "MUST NOT", "affects": ["Assessors"], "timeframe_type": "years", "timeframe_num": 2, "terms": [ "Cloud Service Offering", "FedRAMP Independent Assessment" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "SCG": { "info": { "name": "Secure Configuration Guide", "short_name": "SCG", "web_name": "secure-configuration-guide", "purpose": "The Secure Configuration Guide rules help agencies and other customers understand how to configure a cloud service offering securely. These rules require providers to clearly explain the security impact of common settings so customers can make informed configuration choices.", "status": "stable", "tag": "materials", "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-03-01", "maintain": "2026-03-01", "grace": { "default": "2026-07-01", "until_next_assessment": false } } }, "subsets": { "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to providers with FedRAMP Certifications of any type.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "ENH": { "name": "Enhanced Capabilities", "description": "These recommendations apply to providers with FedRAMP Certifications of any type.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } }, "data": { "all": { "CSO": { "SCG-CSO-RSC": { "name": "Recommended Secure Configuration", "statement": "Providers MUST create, maintain, and make available recommendations for securely configuring their cloud services (the Secure Configuration Guide) that includes at least the following information:", "following_information": [ "Required: Instructions on how to securely access, configure, operate, and decommission top-level administrative accounts that control enterprise access to the entire cloud service offering.", "Required: Explanations of security-related settings that can be operated only by top-level administrative accounts and their security implications.", "Recommended: Explanations of security-related settings that can be operated only by privileged accounts and their security implications." ], "notes": [ "These rules refer to this guidance as a Secure Configuration Guide but cloud service providers may make this guidance available in various appropriate forms that provide the best customer experience.", "This guidance should explain how top-level administrative accounts and privileged accounts are named and referred to in the cloud service offering." ], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "URL to the human-readable data.", "URL to the machine-readable data." ] }, "schema": { "name": "FedRAMP Certification Package Overview (FRC-CSO-PKG)", "url": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json" }, "terms": [ "Cloud Service Offering", "Privileged Account", "Top-Level Administrative Account" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCG-CSO-AUP": { "name": "Use Instructions", "statement": "Providers MUST include instructions in the FedRAMP Certification Package that explain how to obtain and use the Secure Configuration Guide.", "note": "These instructions may appear in a variety of ways; it is up to the provider to do so in the most appropriate and effective ways for their specific customer needs.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "URL or explanation of how to request these materials.", "Explanation of how the provider decides whether or not to share these materials or other related policies." ] }, "terms": ["Certification Package"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCG-CSO-PUB": { "name": "Public Secure Configuration Guidance", "statement": "Providers SHOULD make the Secure Configuration Guide available publicly.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how to access this information", "or explanation why this functionality is not available" ] }, "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCG-CSO-SDF": { "name": "Secure Defaults", "statement": "Providers SHOULD set all settings to their recommended secure defaults for top-level administrative accounts and privileged accounts when initially provisioned.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how to access this information", "or explanation why this functionality is not available" ] }, "terms": [ "Privileged Account", "Top-Level Administrative Account" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "ENH": { "SCG-ENH-CMP": { "name": "Comparison Capability", "statement": "Providers SHOULD offer the capability to compare all current settings for top-level administrative accounts and privileged accounts to the recommended secure defaults.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how to access this information", "or explanation why this functionality is not available" ] }, "terms": [ "Privileged Account", "Top-Level Administrative Account" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCG-ENH-EXP": { "name": "Export Capability", "statement": "Providers SHOULD offer the capability to export all security settings in a machine-readable format.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how to access this information", "or explanation why this functionality is not available" ] }, "terms": ["Machine-Readable"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCG-ENH-API": { "name": "API Capability", "statement": "Providers SHOULD offer the capability to view and adjust security settings via an API or similar capability.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how to access this information", "or explanation why this functionality is not available" ] }, "terms": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCG-ENH-MRG": { "name": "Machine-Readable Guidance", "statement": "Providers SHOULD also provide the Secure Configuration Guide in a machine-readable format that can be used by customers or third-party tools to compare against current settings.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how to access this information", "or explanation why this functionality is not available" ] }, "terms": ["Machine-Readable"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCG-ENH-VRH": { "name": "Versioning and Release History", "statement": "Providers SHOULD provide versioning and a release history for recommended secure default settings for top-level administrative accounts and privileged accounts as they are adjusted over time.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how to access this information", "or explanation why this functionality is not available" ] }, "terms": [ "Privileged Account", "Top-Level Administrative Account" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "SCN": { "info": { "name": "Significant Change Notification", "short_name": "SCN", "web_name": "significant-change-notification", "purpose": "The Significant Change Notification rules supply a simple framework allowing providers to make significant changes to their own products while keeping agency customers in the loop. These rules organize significant changes into clear categories so agencies can understand the expected risk and make authorization decisions accordingly.", "status": "stable", "tag": "assurance", "subsets": { "FRP": { "name": "FedRAMP Responsibilities", "description": "These rules apply to FedRAMP.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["FedRAMP"] } }, "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to providers with FedRAMP Certifications of any type.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "ADP": { "name": "Adaptive Changes", "description": "These rules apply to all adaptive significant changes.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "RTR": { "name": "Routine Recurring Changes", "description": "These rules apply to all routine recurring significant changes.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "TRF": { "name": "Transformative Changes", "description": "These rules apply to all transformative significant changes.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } }, "20x": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } } }, "rev5": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2027-01-01", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-06-01", "until_next_assessment": false } } } } }, "data": { "all": { "FRP": { "SCN-FRP-CAP": { "name": "Corrective Action Plan Conditions", "statement": "FedRAMP MAY require providers to delay significant changes beyond the standard Significant Change Notification period and/or submit significant changes for approval in advance as a condition of a formal FedRAMP Corrective Action Plan or other agreement.", "note": "The circumstances and conditions of such a Corrective Action Plan will vary and be documented in the Correcive Action Plan.", "force": "MAY", "affects": ["FedRAMP"], "terms": ["Significant Change"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "CSO": { "SCN-CSO-EVA": { "name": "Evaluate Changes", "statement": "Providers MUST evaluate all potential significant changes to determine the type of significant change and follow the appropriate Significant Change Notification rules.", "following_information": [ "Is it a significant change? --> Continue evaluation and follow the Significant Change Notification rules.", "If it is, is it an FedRAMP Certification class change? --> This requires a new assessment and cannot be done under the Significant Change Notification rules.", "If it is not, is it a routine recurring change? --> Follow the Routine Recurring Change rules (SCN-RTR Routine Recurring Changes).", "If it is not, is it a transformative change? --> Follow the Transformative Change rules (SCN-TRF Transformative Changes).", "If it is not, then it is an adaptive change --> Follow the Adaptive Change rules (SCN-ADP Adaptive Changes)." ], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "Evidence of significant change evaluation including a description fo the change, the determined type, and an explanation for the decision. At least one example must be provided for each type of change. Real examples are prefered but the provider may use fictitious examples as long as the example provides evidence of the decision making process." ] }, "schema": { "name": "FedRAMP Significant Change Notification (SCN-CSO-INF)", "url": "https://fedramp.gov/schemas/fedramp-significant-change-notifications-schema-2026-06-24.json" }, "terms": [ "Adaptive Change", "Certification Class", "Certification Class Change", "Routine Recurring Change", "Significant Change", "Transformative Change" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-CSO-MAR": { "name": "Maintain Audit Records", "statement": "Providers MUST maintain auditable records of the significant change evaluation activities required by SCN-CSO-EVA (Evaluate Changes) and make them available to FedRAMP as requested.", "note": "These audit records must be available to FedRAMP on request; these records do not need to be included in the FedRAMP Certification Package by default and do not need to be emailed to FedRAMP continuously.", "related": ["SCN-CSO-EVA"], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how FedRAMP can obtain this information." ] }, "terms": ["Certification Package", "Significant Change"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-CSO-INF": { "name": "Required Information", "statement": "Providers MUST include at least the following information in Significant Change Notifications:", "following_information": [ "Service Offering FedRAMP ID", "Assessor Name (if applicable)", "Related Vulnerability (if applicable)", "Significant Change type and explanation of categorization", "Short description of change", "Reason for change", "Summary of customer impact, including changes to services and customer configuration responsibilities", "Plan and timeline for the change, including for the verification, assessment, and/or validation of impacted Key Security Indicators or Rev5 Controls", "Copy of the business or security impact analysis", "Name and title of approver" ], "note": "Structure of the information may vary depending on how the provider tracks this internally.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "A recent Significant Change Notification or sample Significant Change Notification" ] }, "schema": { "name": "FedRAMP Significant Change Notification (SCN-CSO-INF)", "url": "https://fedramp.gov/schemas/fedramp-significant-change-notifications-schema-2026-06-24.json" }, "terms": [ "Significant Change", "Validation", "Verification", "Vulnerability" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-CSO-HIS": { "name": "Historical Notifications", "statement": "Providers MUST keep 12 months of historical Significant Change Notifications available with their FedRAMP Certification Data.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "Explanation of how FedRAMP can obtain this information." ] }, "terms": ["Certification Data", "Significant Change"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-CSO-HRM": { "name": "Human and Machine-Readable Notifications", "statement": "Providers MUST make ALL Significant Change Notifications and related audit records available in human-readable and JSON formats.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "URL or explanation of how to request these materials.", "Explanation of how the provider decides whether or not to share these materials or other related policies." ] }, "schema": { "name": "FedRAMP Significant Change Notifications Schema", "url": "https://fedramp.gov/schemas/fedramp-significant-change-notifications-schema-2026-06-24.json" }, "terms": ["Significant Change"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-CSO-ARI": { "name": "Additional Relevant Information", "statement": "Providers MAY include additional relevant information in Significant Change Notifications.", "note": "This allows providers to convey whatever additional information they think is relevant without worrying about negative consequences from not following an exact template.", "force": "MAY", "affects": ["Providers"], "terms": ["Significant Change"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-CSO-NOM": { "name": "Notification Mechanisms", "statement": "Providers MAY notify necessary parties in a variety of ways as long as the mechanism for notification is clearly documented in the FedRAMP Certification Package and easily accessible.", "notes": [ "The sharing mechanism should be designed based on the needs of the provider and their customers and may vary between providers.", "The default sharing mechanism for most providers during the SCN beta was to send an email to agency customers and upload a copy of the notification to the provider's secure sharing location." ], "force": "MAY", "affects": ["Providers"], "artifacts": { "all": ["Current list of available notification mechanisms"] }, "terms": ["Certification Package"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-CSO-EMG": { "name": "Emergency Changes", "statement": "Providers MAY execute significant changes (including transformative changes) during an emergency or incident without following the Significant Change Notification rules in advance. In such emergencies, providers MUST follow all relevant procedures, notify all necessary parties, retroactively provide all Significant Change Notification materials, and complete appropriate assessment after the incident.", "note": "Procedures for emergency changes should be documented in the FedRAMP Certification Package.", "force": "MAY", "affects": ["Providers"], "terms": [ "All Necessary Parties", "Certification Package", "Incident", "Significant Change", "Transformative Change" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "ADP": { "SCN-ADP-NTF": { "name": "Notification Requirements", "statement": "Providers MUST notify all necessary parties within 10 business days after finishing adaptive changes, also including the following information:", "following_information": [ "Summary of any new risks identified and/or vulnerabilities resulting from the change (if applicable)" ], "notes": [ "Activities that match the adaptive significant change type are a frequent and normal part of iteratively improving a service by deploying new functionality or modifying existing functionality in a way that is typically transparent to customers and does not introduce significant new security risks.", "In general, most changes that do not happen regularly will be adaptive changes. This change type deliberately covers a wide range of activities in a way that requires assessment and consideration." ], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "At least the most recent SCN notification including the date it was sent and the date the change was applied. Additional examples may be provided. If no SCN notifications have been sent then this artifact is not required." ] }, "examples": [ { "id": "Tips on adaptive changes", "key_tests": [ "Requires minimal changes to security plans or procedures", "Requires some careful planning and project management to implement, but does not rise to the level of planning required for transformative changes", "Requires verification of existing functionality and secure configuration after implementation" ], "examples": [ "Updates to operating systems, containers, virtual machines, software or libraries with known breaking changes, complex steps, or service disruption", "Deploying larger than normal incremental feature improvements in code or libraries that are the work of multiple weeks of development efforts but are not considered a major new service", "Changing cryptographic modules where the new module meets the same standards and characteristics of the former", "Replacing a like-for-like component where some security plan or procedure adjustments are required (e.g., scanning tool or managed database swap)", "Adding models to existing approved AI services without exposing federal customer data to new services" ] } ], "timeframe_type": "bizdays", "timeframe_num": 10, "notification": [ { "party": "All Necessary Parties", "method": "update", "target": "FedRAMP Certification Data", "name": "FedRAMP Certification Data" } ], "terms": [ "Adaptive Change", "All Necessary Parties", "Regularly", "Significant Change", "Vulnerability" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "RTR": { "SCN-RTR-NNR": { "name": "No Notification Requirements", "statement": "Providers SHOULD NOT make formal Significant Change Notifications for routine recurring changes; this type of change is exempted from notification requirements.", "notes": [ "Activities that match the routine recurring significant change type are performed regularly and routinely by cloud service providers to address flaws or vulnerabilities, address incidents, and generally perform the typical maintenance and service delivery changes expected during day-to-day operations.", "These changes leverage mature processes and capabilities to identify, mitigate, and remediate risks as part of the change. They are often entirely automated and may occur without human intervention, even though they have an impact on security of the service.", "If the activity does not occur regularly and routinely then it cannot be a significant change of this type (e.g., replacing all physical firewalls to remediate a vulnerability is obviously not regular or routine)." ], "force": "SHOULD NOT", "affects": ["Providers"], "examples": [ { "id": "Tips on ongoing operations", "key_tests": [ "Routine care and feeding by staff during normal duties", "No major impact to service availability", "Does not require executive approval" ], "examples": [ "Provisioning or deprovisioning capacity to support service elasticity", "Changing or tuning performance configurations for instances or services", "Updating and maintaining operational handling of information flows and protection across physical and logical networks (e.g., updating firewall rules)", "Generating or refreshing API or access tokens" ] }, { "id": "Tips on vulnerability management", "key_tests": [ "Minor, incremental patching or updates", "Significant refactoring or migration process NOT required", "No breaking changes" ], "examples": [ "Updating security service or endpoint signatures", "Routine patching of devices, operating systems, software or libraries", "Updating and deploying code that applies normal fixes and improvements as part of a regular development cycle", "Vulnerability remediation activity that simply replaces a known-bad component(s) with a better version of the exact same thing, running in the exact same way with no changes to processes" ] } ], "terms": [ "Incident", "Regularly", "Routine Recurring Change", "Significant Change", "Vulnerability" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "TRF": { "SCN-TRF-NIP": { "name": "Notification of Initial Plans", "statement": "Providers MUST notify all necessary parties of initial plans for transformative changes at least 30 business days before starting transformative changes, including a summary of any likely security impacts or changes in risk.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "At least the most recent initial SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required." ] }, "timeframe_type": "bizdays", "timeframe_num": 30, "notification": [ { "party": "All Necessary Parties", "method": "update", "target": "FedRAMP Certification Data", "name": "FedRAMP Certification Data" } ], "terms": [ "All Necessary Parties", "Likely", "Transformative Change" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-TRF-NFP": { "name": "Notification of Final Plans", "statement": "Providers MUST notify all necessary parties of final plans for transformative changes at least 10 business days before starting transformative changes, including updates to all previously sent information.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "At least the most recent final SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required." ] }, "timeframe_type": "bizdays", "timeframe_num": 10, "notification": [ { "party": "All Necessary Parties", "method": "update", "target": "FedRAMP Certification Data", "name": "FedRAMP Certification Data" } ], "terms": ["All Necessary Parties", "Transformative Change"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-TRF-NAF": { "name": "Notification After Finishing", "statement": "Providers MUST notify all necessary parties within 5 business days after finishing transformative changes, including updates to all previously sent information.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "At least the most recent post deployment SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required." ] }, "timeframe_type": "bizdays", "timeframe_num": 5, "notification": [ { "party": "All Necessary Parties", "method": "update", "target": "FedRAMP Certification Data", "name": "FedRAMP Certification Data" } ], "terms": ["All Necessary Parties", "Transformative Change"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-TRF-NAV": { "name": "Notification After Verification", "statement": "Providers MUST notify all necessary parties within 5 business days after completing the verification, assessment, and/or validation of transformative changes, also including the following information:", "following_information": [ "Updates to all previously sent information", "Summary of any new risks identified and/or vulnerabilities resulting from the change (if applicable)", "Copy of the security assessment report (if applicable)" ], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "At least the most recent after verification SCN notification for a transformative change including the date it was sent and the date the change was applied. Additional examples may be provided. If no transformative SCN notifications have been sent then this artifact is not required." ] }, "timeframe_type": "bizdays", "timeframe_num": 5, "notification": [ { "party": "All Necessary Parties", "method": "update", "target": "FedRAMP Certification Data", "name": "FedRAMP Certification Data" } ], "terms": [ "All Necessary Parties", "Transformative Change", "Validation", "Verification", "Vulnerability" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-TRF-UPD": { "name": "Update Documentation", "statement": "Providers MUST publish updated service documentation and other materials to reflect transformative changes within 30 business days after finishing transformative changes.", "note": "This requirement is focused on service documentation like user guides, information listed in the marketplace, and other such materials; it does not require updating the system security plan or FedRAMP Certification Package.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "Date of the most recent transformative change and the date of the corresponding documentation update. If no documentation updates were required as the result of this change, explain how this was determined." ] }, "timeframe_type": "bizdays", "timeframe_num": 30, "terms": ["Certification Package", "Transformative Change"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SCN-TRF-TPR": { "name": "Third-Party Review", "statement": "Providers SHOULD engage a third-party assessor to review the scope and impact of the planned change before starting transformative changes if human validation is necessary; such reviews SHOULD be limited to security decisions that require human validation.", "note": "Activities that match the transformative significant change type are rare for a cloud service offering, adjusted for the size, scale, and complexity of the service. Small cloud service offerings may go years without transformative changes, while hyperscale providers may release multiple transformative changes per year.", "force": "SHOULD", "affects": ["Providers"], "artifacts": { "all": [ "Third Party assesment report OR explanation why a third party assessor was not engaged" ] }, "examples": [ { "id": "Tips on transformative changes", "key_tests": [ "Alters the service risk profile or require new or significantly different actions to address customer responsibilities", "Requires significant new design, development and testing with discrete associated project planning, budget, marketing, etc.", "Requires extensive updates to security assessments, documentation, and how a large number of security requirements are met and validated" ], "examples": [ "The addition, removal, or replacement of a critical third party service that handles a significant portion of information (e.g., IaaS change)", "Increasing the security categorization of a service within the offering that actively handles federal customer data (does NOT include impact change of entire offering - see FedRAMP Certification class change)", "Replacement of underlying management planes or paradigm shift in workload orchestration (e.g., bare-metal servers or virtual machines to containers, migration to kubernetes)", "Datacenter migration where large amounts of federal customer data is moved across boundaries different from normal day-to-day operations", "Adding a new AI-based capability that impacts federal customer data in a different way than existing services or capabilities (such as integrating a new third-party service or training on federal customer data)" ] } ], "terms": [ "Cloud Service Offering", "Significant Change", "Transformative Change", "Validation" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "SDR": { "info": { "name": "Security Decision Record", "short_name": "SDR", "web_name": "security-decision-record", "purpose": "The Security Decision Record replaced a traditional System Security Plan with a persistently maintained, verified, and validated record of the security decisions made by the cloud service provider over the lifecycle of their cloud service offering.", "status": "stable", "tag": "materials", "subsets": { "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to providers for FedRAMP Certifications of any type.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } }, "20x": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2026-07-04", "maintain": "2027-01-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-01-01", "until_next_assessment": true } } }, "subsets": { "CSX": { "name": "20x-Specific Provider Responsibilities", "description": "These rules apply to providers for FedRAMP 20x Certifications.", "applicability": { "types": ["20x"], "paths": ["Program"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } }, "rev5": { "effective": { "is": "required", "current_status": "Consolidated Rules for 2026", "date": { "obtain": "2027-01-01", "maintain": "2027-08-01", "optional_adoption": "2026-07-04", "grace": { "default": "2027-08-01", "until_next_assessment": true } } }, "subsets": { "CSF": { "name": "Rev5-Specific Provider Responsibilities", "description": "These rules apply to providers for FedRAMP Rev5 Certifications.", "applicability": { "types": ["Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } } }, "data": { "all": { "CSO": { "SDR-CSO-FRR": { "name": "FedRAMP Rules", "statement": "Providers MUST supply a Security Decision Record, in both human-readable and JSON formats, that includes at least all of the following information for each applicable FedRAMP rule:", "following_information": [ "Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.", "Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.", "Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.", "Independent verification.", "Independent validation.", "Any responses or clarifications to the comments in the independent verification or validation.", "Rule-specific artifacts (if applicable)." ], "force": "MUST", "affects": ["Providers"], "schema": { "name": "FedRAMP Security Decision Record Schema", "url": "https://fedramp.gov/schemas/fedramp-security-decision-record-schema-2026-06-24.json" }, "terms": [ "Artifacts", "Security Decision Record (SDR)", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SDR-CSO-MTD": { "name": "Security Decision Record Metadata", "statement": "Providers MUST also include the following basic metadata in their Security Decision Record:", "following_information": [ "Version", "Date and time of last update", "Source of update" ], "force": "MUST", "affects": ["Providers"], "terms": ["Security Decision Record (SDR)"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "20x": { "CSX": { "SDR-CSX-KSI": { "name": "Key Security Indicators", "statement": "Providers MUST also include short and simple high-level summaries of at least the following for each applicable Key Security Indicator:", "following_information": [ "Explanation of measures (and their objectives) that demonstrate the Key Security Indicator, or an explanation of the reason and resulting risk to customers for not having measures available for that Key Security Indicator.", "Explanation of the cycle for any measures that are implemented persistently (if applicable).", "Verification that the measures demonstrate the Key Security Indicator, or that the reason for not having them is accepted.", "Verification that the automation in place is accurate and sufficient to demonstrate appropriate measures for the Key Security Indicator, or that automation is not necessary for each measure.", "Validation that the measures are accurately produced and are in place and working as intended, or that the reason for not having them is valid." ], "force": "MUST", "affects": ["Providers"], "schema": { "name": "FedRAMP Security Decision Record Schema", "url": "https://fedramp.gov/schemas/fedramp-security-decision-record-schema-2026-06-24.json" }, "terms": ["Persistently", "Validation", "Verification"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "SDR-CSX-KMT": { "name": "Key Security Indicator Metrics", "varies_by_class": { "a": { "statement": "Providers with 20x Class A Certifications MAY also include historical metrics in their Security Decision Record.", "force": "MAY" }, "b": { "statement": "Providers with 20x Class B Certifications MUST also include historical metrics in their Security Decision Record, supplying at least the following information for each applicable Key Security Indicator:", "following_information": [ "Summary of each metric over the past 30 days", "Summary of metric up to the past year (where available)" ], "force": "MUST" }, "c": { "statement": "Providers with 20x Class C Certifications MUST also include historical metrics in their Security Decision Record, supplying at least the following information for each applicable Key Security Indicator:", "following_information": [ "Summary of each metric over the past 30 days", "Summary of metric up to the past year (where available)", "All daily metric data up to the past year (where available)" ], "force": "MUST" }, "d": { "statement": "Providers with 20x Class D Certifications MUST significantly supersede the minimum requirements for lower Classes, with specifics to be set during the 20x Phase 4 Pilot.", "force": "MUST" } }, "affects": ["Providers"], "schema": { "name": "FedRAMP Security Decision Record Schema", "url": "https://fedramp.gov/schemas/fedramp-security-decision-record-schema-2026-06-24.json" }, "terms": ["Security Decision Record (SDR)"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "rev5": { "CSF": { "SDR-CSF-CTF": { "name": "Rev5 Controls", "statement": "Providers MUST also include short and simple high-level summaries of at least the following for each applicable Rev5 Control:", "following_information": [ "Any organization-defined parameter values.", "Implementation status, one of Implemented, Partially Implemented, Planned, Alternative Implementation, or Not Applicable.", "The mechanisms or activities that address the control, including inheritance from another cloud service offering if applicable.", "The verification that is in place to ensure the implementation is appropriate for the control.", "The validation that is in place to ensure the implementation is working as intended.", "Independent verification.", "Independent validation.", "Any responses or clarifications to the comments in the independent verification or validation.", "Control-specific artifacts (if applicable)." ], "force": "MUST", "affects": ["Providers"], "terms": [ "Artifacts", "Cloud Service Offering", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "VDR": { "info": { "name": "Vulnerability Detection and Response", "short_name": "VDR", "web_name": "vulnerability-detection-and-response", "purpose": "The Vulnerability Detection and Response rules require providers to continuously identify, analyze, prioritize, mitigate, and remediate vulnerabilities and related exposures through automated systems. These rules give providers flexibility in implementation while ensuring agencies receive the information needed to support ongoing authorization decisions.", "status": "stable", "tag": "boundary", "effective": { "is": "required", "current_status": "Mandated by CISA BOD 26-04", "date": { "obtain": "2026-12-07", "maintain": "2026-12-07", "optional_adoption": "2026-07-04", "grace": { "default": "2027-03-07", "until_next_assessment": false } } }, "subsets": { "CSO": { "name": "General Provider Responsibilities", "description": "These rules apply to all providers with FedRAMP Certifications of any type.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "TFR": { "name": "Timeframes", "description": "These rules apply to timeframes for vulnerability detection and response.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } }, "data": { "all": { "CSO": { "VDR-CSO-DET": { "name": "Vulnerability Detection", "statement": "Providers MUST systematically, persistently, and promptly discover and identify vulnerabilities within their cloud service offering using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities; this process is called vulnerability detection. Vulnerability detection includes persistently verifying and validating that information resources and processes are operating as intended and documented for FedRAMP Practices.", "danger": "Vulnerability Detection and Response includes all efforts to identify weaknesses in a system and is NOT limited to traditional vulnerability scanning or testing. An out-of-date control statement in the Security Decision Record is a vulnerability that must be detected and remediated just like any other vulnerability.", "notes": [ "FedRAMP's vulnerability detection (and response) rules are intended to set modern expectations for maintaining the security of a cloud service. Historical FedRAMP guidance on vulnerability scanning or continuous monitoring generally focused only on CVE-type vulnerabilities while leaving other types of vulnerabilities and exposures unaddressed.", "Providers are encouraged to leverage their existing holistic security review, architecture review, and similar processes to meet these requirements. FedRAMP strongly discourages providers from implementing separate vulnerability detection and response processes for FedRAMP reporting that are operated by independent compliance branches unless these processes are consuming data directly from the areas of the cloud service that actively maintain it." ], "force": "MUST", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "FedRAMP Practices", "Incident", "Information Resource", "Persistently", "Promptly", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-CSO-RES": { "name": "Vulnerability Response", "statement": "Providers MUST systematically, persistently, and promptly track, evaluate, monitor, mitigate, remediate, assess exploitation of, report, and otherwise manage all detected vulnerabilities within their cloud service offering; this process is called vulnerability response.", "notes": [ "If it is not possible to fully mitigate vulnerabilities or remediate vulnerabilities, providers SHOULD instead partially mitigate vulnerabilities promptly, progressively, and persistently.", "FedRAMP does not use the terms \"mitigation\" and \"remediation\" interchangeably. Mitigation is the process of reducing the risk and impact of a vulnerability through partial mitigation and even full mitigation; remediation is the process of entirely eliminating the vulnerability. A fully mitigated vulnerability will still exist (with negligible risk) until it has been remediated. This separation is based on the plain language definitions of these words.", "Please refer to FedRAMP Definitions for strict interpretation in the FedRAMP context." ], "force": "MUST", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "Fully Mitigated Vulnerability", "Partially Mitigated Vulnerability", "Persistently", "Promptly", "Remediated Vulnerability", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-CSO-FAV": { "name": "Failures Are Vulnerabilities", "statement": "Providers MUST treat problems or failures with their vulnerability detection and response processes as vulnerabilities.", "force": "MUST", "affects": ["Providers"], "terms": [ "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-CSO-DFR": { "name": "Design For Resilience", "statement": "Providers SHOULD make design and architecture decisions for their cloud service offering that mitigate the risk of vulnerabilities by default AND decrease the risk and complexity of vulnerability detection and response.", "force": "SHOULD", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-CSO-ADT": { "name": "Automate Detection", "statement": "Providers SHOULD use automated services to improve and streamline vulnerability detection and response.", "force": "SHOULD", "affects": ["Providers"], "terms": [ "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-CSO-DAC": { "name": "Detect After Changes", "statement": "Providers SHOULD automatically perform vulnerability detection on representative samples of new or significantly changed information resources.", "force": "SHOULD", "affects": ["Providers"], "terms": [ "Information Resource", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-CSO-MSP": { "name": "Maintain Security", "statement": "Providers SHOULD NOT weaken the security of information resources to facilitate vulnerability scanning, detection, or assessment activities.", "force": "SHOULD NOT", "affects": ["Providers"], "terms": [ "Information Resource", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-CSO-AKE": { "name": "Avoid KEVs", "statement": "Providers SHOULD NOT deploy or otherwise activate new machine-based information resources with Known Exploited Vulnerabilities.", "force": "SHOULD NOT", "affects": ["Providers"], "terms": [ "Information Resource", "Known Exploited Vulnerability (KEV)", "Machine-Based (Information Resources)", "Vulnerability" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-CSO-SIR": { "name": "Sampling", "statement": "Providers MAY sample effectively identical information resources, especially machine-based information resources, when performing vulnerability detection UNLESS doing so would decrease the efficiency or effectiveness of vulnerability detection.", "force": "MAY", "affects": ["Providers"], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "TFR": { "VDR-TFR-NMV": { "name": "Non-Machine Verification and Validation", "statement": "Providers MUST verify and validate the status of non-machine-based information resources at least once every 3 months.", "force": "MUST", "affects": ["Providers"], "timeframe_type": "months", "timeframe_num": 3, "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-TFR-PDD": { "name": "Persistent Drift Detection", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 3 months.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 3 }, "b": { "statement": "Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every month.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 1 }, "c": { "statement": "Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 14 days.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 14 }, "d": { "statement": "Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 7 days.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 7 } }, "affects": ["Providers"], "terms": [ "Drift", "Information Resource", "Likely", "Persistently", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-TFR-PCD": { "name": "Persistently Complete Detection", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 6 }, "b": { "statement": "Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 6 }, "c": { "statement": "Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 1 }, "d": { "statement": "Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 1 } }, "affects": ["Providers"], "terms": [ "Drift", "Information Resource", "Likely", "Persistently", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-TFR-PVR": { "name": "Mitigation and Remediation Expectations", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability.", "force": "SHOULD", "pain_timeframes": { "1": {}, "2": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 96, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 160, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 192, "description": "Not Likely Exploitable Vulnerability" } }, "3": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 32, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 64, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 192, "description": "Not Likely Exploitable Vulnerability" } }, "4": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 8, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 32, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 64, "description": "Not Likely Exploitable Vulnerability" } }, "5": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 4, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 8, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 32, "description": "Not Likely Exploitable Vulnerability" } } } }, "b": { "statement": "Providers with Class B Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:", "force": "SHOULD", "pain_timeframes": { "1": {}, "2": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 96, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 160, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 192, "description": "Not Likely Exploitable Vulnerability" } }, "3": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 32, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 64, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 192, "description": "Not Likely Exploitable Vulnerability" } }, "4": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 8, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 32, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 64, "description": "Not Likely Exploitable Vulnerability" } }, "5": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 4, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 8, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 32, "description": "Not Likely Exploitable Vulnerability" } } } }, "c": { "statement": "Providers with Class C Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:", "force": "SHOULD", "pain_timeframes": { "1": {}, "2": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 48, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 128, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 192, "description": "Not Likely Exploitable Vulnerability" } }, "3": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 16, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 32, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 128, "description": "Not Likely Exploitable Vulnerability" } }, "4": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 4, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 8, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 64, "description": "Not Likely Exploitable Vulnerability" } }, "5": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 2, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 4, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 16, "description": "Not Likely Exploitable Vulnerability" } } } }, "d": { "statement": "Providers with Class D Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the maximum timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:", "force": "SHOULD", "pain_timeframes": { "1": {}, "2": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 24, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 96, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 192, "description": "Not Likely Exploitable Vulnerability" } }, "3": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 8, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 16, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 64, "description": "Not Likely Exploitable Vulnerability" } }, "4": { "irv_lev": { "timeframe_type": "days", "timeframe_num": 2, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 8, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 32, "description": "Not Likely Exploitable Vulnerability" } }, "5": { "irv_lev": { "timeframe_type": "hours", "timeframe_num": 12, "description": "Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nirv_lev": { "timeframe_type": "days", "timeframe_num": 1, "description": "Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability" }, "nlev": { "timeframe_type": "days", "timeframe_num": 8, "description": "Not Likely Exploitable Vulnerability" } } } } }, "related": ["VER-EVA-EPA"], "affects": ["Providers"], "terms": [ "Fully Mitigated Vulnerability", "Likely", "Partially Mitigated Vulnerability", "Potential Agency Impact", "Remediated Vulnerability", "Vulnerability" ], "updated": [ { "date": "2026-07-01", "comment": "Added relevent terms and related controls. No change to the requirement." }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-TFR-RMN": { "name": "Remaining Vulnerabilities", "statement": "Providers SHOULD mitigate or remediate remaining vulnerabilities during routine operations as determined necessary by the provider.", "force": "SHOULD", "affects": ["Providers"], "terms": ["Vulnerability"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-TFR-KEV": { "name": "Remediate KEVs", "statement": "Providers SHOULD remediate Known Exploited Vulnerabilities according to the due dates in the CISA Known Exploited Vulnerabilities Catalog (even if the vulnerability has been fully mitigated) as required by CISA Binding Operational Directive (BOD) 26-04 or any successor guidance from CISA.", "reference": "CISA BOD 26-04", "reference_url": "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk", "force": "SHOULD", "affects": ["Providers"], "terms": ["Known Exploited Vulnerability (KEV)", "Vulnerability"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VDR-TFR-PSD": { "name": "Persistent Sample Detection", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 14 days.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 14 }, "b": { "statement": "Providers with Class B Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 7 days.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 7 }, "c": { "statement": "Providers with Class C Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 3 days.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 3 }, "d": { "statement": "Providers with Class D Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once per day.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 1 } }, "affects": ["Providers"], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Persistently", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "20x": { "TFR": { "VDR-TFR-MVX": { "name": "Persistent Machine Verification and Validation for 20x", "varies_by_class": { "a": { "statement": "Providers of FedRAMP 20x Class A offerings SHOULD verify and validate the status of machine-based information resources at least once every month.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 1 }, "b": { "statement": "Providers of FedRAMP 20x Class B offerings MUST verify and validate the status of machine-based information resources at least once every 7 days.", "force": "MUST", "timeframe_type": "days", "timeframe_num": 7 }, "c": { "statement": "Providers of FedRAMP 20x Class C offerings MUST verify and validate the status of machine-based information resources at least once every 3 days.", "force": "MUST", "timeframe_type": "days", "timeframe_num": 3 } }, "affects": ["Providers"], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "rev5": { "TFR": { "VDR-TFR-MVF": { "name": "Persistent Machine Verification and Validation for Rev5", "varies_by_class": { "b": { "statement": "Providers of FedRAMP Rev5 Class B offerings SHOULD verify and validate the status of machine-based information resources at least once every month.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 1 }, "c": { "statement": "Providers of FedRAMP Rev5 Class C offerings MUST verify and validate the status of machine-based information resources at least once every month.", "force": "MUST", "timeframe_type": "months", "timeframe_num": 1 }, "d": { "statement": "Providers of FedRAMP Rev5 Class D offerings MUST verify and validate the status of machine-based information resources at least once every month.", "force": "MUST", "timeframe_type": "months", "timeframe_num": 1 } }, "affects": ["Providers"], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Validation", "Verification" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } } } }, "VER": { "info": { "name": "Vulnerability Evaluation and Reporting", "short_name": "VER", "web_name": "vulnerability-evaluation-and-reporting", "purpose": "The Vulnerability Evaluation and Reporting rules require cloud service providers to determine when vulnerabilities are likely to impact federal customers and report the status of such vulnerabilities to all necessary parties.", "status": "stable", "tag": "assurance", "effective": { "is": "required", "current_status": "Mandated by CISA BOD 26-04", "date": { "obtain": "2026-12-07", "maintain": "2026-12-07", "optional_adoption": "2026-07-04", "grace": { "default": "2027-03-07", "until_next_assessment": false } } }, "subsets": { "FRP": { "name": "FedRAMP Responsibilities", "description": "These rules apply to FedRAMP when setting expectations for specific cloud service providers.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["FedRAMP"] } }, "AGM": { "name": "Agency Guidance", "description": "These rules for agencies apply to all agencies using a FedRAMP Certification.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Agencies"] } }, "EVA": { "name": "Evaluation", "description": "These rules apply to the evaluation of vulnerabilities.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "RPT": { "name": "Reporting", "description": "These rules apply to reporting related to vulnerability detection and response.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } }, "TFR": { "name": "Timeframes", "description": "These rules apply to timeframes for vulnerability detection and response.", "applicability": { "types": ["20x", "Rev5"], "paths": ["Program", "Agency"], "classes": ["B", "C", "D"], "affects": ["Providers"] } } } }, "data": { "all": { "FRP": { "VER-FRP-ARP": { "name": "Additional Requirements", "statement": "FedRAMP MAY require providers to share additional vulnerability information, alternative reports, or to report at an alternative frequency as a condition of a FedRAMP Corrective Action Plan or other agreements with federal agencies.", "force": "MAY", "affects": ["FedRAMP"], "terms": ["Vulnerability"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-FRP-ADV": { "name": "Sensitive Details", "statement": "FedRAMP MAY require providers to share additional information or details about vulnerabilities, including sensitive information that would likely lead to exploitation, as part of review, response or investigation by necessary parties.", "force": "MAY", "affects": ["FedRAMP"], "terms": ["Likely", "Vulnerability", "Vulnerability Response"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "AGM": { "VER-AGM-RVR": { "name": "Review Vulnerability Reports", "statement": "Agencies SHOULD review the information provided in vulnerability reports at appropriate and reasonable intervals commensurate with the expectations and risk posture indicated by their Authorization to Operate, and SHOULD use automated processing and filtering of machine readable information from cloud service providers.", "note": "FedRAMP recommends that agencies only review overdue and accepted vulnerabilities Potential Agency Impact N-rating > 2 unless the cloud service provider recommends mitigations or the service is included in a higher risk federal information system. Furthermore, accepted vulnerabilities generally only need to be reviewed when they are added or during an updated risk assessment due to changes in the agency's use or authorization.", "force": "SHOULD", "affects": ["Agencies"], "terms": [ "Accepted Vulnerability", "Potential Agency Impact", "Vulnerability" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-AGM-MAP": { "name": "Maintain Agency Plans of Action and Milestones", "statement": "Agencies SHOULD use vulnerability information reported by the Provider to maintain Plans of Action and Milestones for agency security programs when relevant according to agency security policies (such as if the agency takes action to mitigate the risk of exploitation or authorized the continued use of a cloud service with accepted vulnerabilities that put agency information systems at risk).", "force": "SHOULD", "affects": ["Agencies"], "terms": [ "Accepted Vulnerability", "FedRAMP Certified", "Vulnerability" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "EVA": { "VER-EVA-ELX": { "name": "Evaluate Exploitability", "statement": "Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are likely exploitable vulnerabilities.", "notes": [ "The simple reality is that most traditional vulnerabilities discovered by scanners or during assessment are not likely to be exploitable; exploitation typically requires an unrealistic set of circumstances that will not occur during normal operation. The likelihood of exploitation will vary depending on so many factors that FedRAMP will not recommend a specific framework for approaching this beyond these rules.", "The proof, ultimately, is in the pudding - providers who regularly evaluate vulnerabilities as not likely exploitable without careful consideration are more likely to suffer from an adverse impact where the root cause was an exploited vulnerability that was improperly evaluated. If done recklessly or deliberately, such actions will have a negative impact on a provider's FedRAMP Certification." ], "force": "MUST", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "Likely", "Likely Exploitable Vulnerability (LEV)", "Regularly", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-EVA-EIR": { "name": "Evaluate Internet-Reachability", "statement": "Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are internet-reachable vulnerabilities.", "notes": [ "FedRAMP focuses on internet-reachable (rather than internet-accessible) to ensure that any service that might receive a payload from the internet is prioritized if that service has a vulnerability that can be triggered by processing the data in the payload.", "The simplest way to prevent exploitation of internet-reachable vulnerabilities is to intercept, inspect, filter, sanitize, reject, or otherwise deflect triggering payloads before they are processed by the vulnerable resource; once this prevention is in place the vulnerability should no longer be considered an internet-reachable vulnerability.", "A classic example of an internet-reachable vulnerability on systems that are not typically internet-accessible is [SQL injection](https://en.wikipedia.org/wiki/SQL_injection), where an application stack behind a load balancer and firewall with no ability to route traffic to or from the internet can receive a payload indirectly from the internet that triggers the manipulation or compromise of data in a database that can only be accessed by an authorized connection from the application server on a private network.", "Another simple example is the infamous Log4Shell (https://en.wikipedia.org/wiki/Log4Shell) vulnerability from 2021, where exploitation was possible via vulnerable internet-reachable resources deep in the application stack that were often not internet-accessible themselves." ], "force": "MUST", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "FedRAMP Certified", "Internet-Reachable Vulnerability (IRV)", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-EVA-EPA": { "name": "Estimate Potential Agency Impact", "statement": "Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to estimate the potential agency impact of exploitation on government customers AND assign one of the following Potential Agency Impact N-ratings (PAIN):", "following_information_bullets": [ "**N1**: Exploitation could be expected to have minimal customer effects on one or more agencies that use the cloud service offering.", "**N2**: Exploitation could be expected to have narrow customer effects on one or more agencies that use the cloud service offering.", "**N3**: Exploitation could be expected to have a disruptive customer effect on one agency that uses the cloud service offering.", "**N4**: Exploitation could be expected to have a debilitating customer effect on one agency that uses the cloud service offering OR a disruptive customer effect on more than one federal agency that uses the cloud service offering.", "**N5**: Exploitation could be expected to have a debilitating customer effect on more than one agency that uses the cloud service offering." ], "force": "MUST", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "Debilitating Customer Effect", "Disruptive Customer Effect", "Minimal Customer Effect", "Narrow Customer Effect", "Potential Agency Impact", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-EVA-AIA": { "name": "Assume It's Automatable", "statement": "Providers MUST assume the exploitation of vulnerabilities can be automated UNLESS they have evidence proving otherwise.", "force": "MUST", "affects": ["Providers"], "terms": ["Vulnerability"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-EVA-GRV": { "name": "Group Vulnerabilities", "statement": "Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to identify logical groupings of affected information resources that may improve the efficiency and effectiveness of vulnerability response by consolidating further activity; FedRAMP Vulnerability Detection and Response rules are then applied to these consolidated groupings of vulnerabilities instead of each individual detected instance.", "force": "SHOULD", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "Information Resource", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-EVA-EFP": { "name": "Evaluate False Positives", "statement": "Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to determine if they are false positive vulnerabilities.", "force": "SHOULD", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "False Positive Vulnerability", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-EVA-EFA": { "name": "Evaluation Factors", "statement": "Providers SHOULD consider at least the following factors when considering the context of the cloud service offering to evaluate detected vulnerabilities:", "following_information": [ "**Criticality**: How important are the systems or information that might be impacted by the vulnerability?", "**Reachability**: How might a threat actor reach the vulnerability and how likely is that?", "**Exploitability**: How easy is it for a threat actor to exploit the vulnerability and how likely is that?", "**Detectability**: How easy is it for a threat actor to become aware of the vulnerability and how likely is that?", "**Prevalence**: How much of the cloud service offering is affected by the vulnerability?", "**Privilege**: How much privileged authority or access is granted or can be gained from exploiting the vulnerability?", "**Proximate Vulnerabilities**: How does this vulnerability interact with previously detected vulnerabilities, especially partially or fully mitigated vulnerabilities?", "**Known Threats**: How might already known threats leverage the vulnerability and how likely is that?" ], "force": "SHOULD", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "Fully Mitigated Vulnerability", "Likely", "Vulnerability", "Vulnerability Detection" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "RPT": { "VER-RPT-PER": { "name": "Persistent Reporting", "statement": "Providers MUST report vulnerability detection and response activity (including persistent verification and validation) to all necessary parties persistently, summarizing ALL activity since the previous report; these reports are FedRAMP Certification Data and are subject to FedRAMP Certification Data Sharing rules.", "force": "MUST", "affects": ["Providers"], "schema": { "name": "FedRAMP Vulnerability Detail Report (VER-RPT-VDT)", "url": "https://fedramp.gov/schemas/fedramp-vulnerability-detail-report-schema-2026-06-24.json" }, "terms": [ "All Necessary Parties", "Certification Data", "Persistently", "Validation", "Verification", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-RPT-VDT": { "name": "Vulnerability Details", "statement": "Providers MUST include the following information (if applicable) on detected vulnerabilities when reporting on vulnerability detection and response activity, UNLESS it is an accepted vulnerability:", "following_information": [ "Provider's internally assigned tracking identifier", "Time and source of the detection", "Time of completed evaluation", "Is it an internet-reachable vulnerability or not?", "Is it a likely exploitable vulnerability or not?", "Historically and currently estimated Potential Agency Impact N-rating of exploitation", "Time and Potential Agency Impact N-rating of each completed and evaluated reduction in Potential Agency Impact N-rating", "Estimated time and target Potential Agency Impact N-rating of next reduction in Potential Agency Impact N-rating", "Is it currently or is it likely to become an overdue vulnerability or not? If so, explain.", "Any supplementary information the provider responsibly determines will help federal agencies assess or mitigate the risk to their federal customer data within the cloud service offering resulting from the vulnerability", "Final disposition of the vulnerability" ], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "A recent vulnerability report or a sample vulnerability report" ] }, "schema": { "name": "FedRAMP Vulnerability Detail Report (VER-RPT-VDT)", "url": "https://fedramp.gov/schemas/fedramp-vulnerability-detail-report-schema-2026-06-24.json" }, "terms": [ "Accepted Vulnerability", "Cloud Service Offering", "Federal Customer Data", "Internet-Reachable Vulnerability (IRV)", "Likely", "Likely Exploitable Vulnerability (LEV)", "Overdue Vulnerability", "Potential Agency Impact", "Responsibly", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-RPT-AVI": { "name": "Accepted Vulnerability Info", "statement": "Providers MUST include the following information on accepted vulnerabilities when reporting on vulnerability detection and response activity:", "following_information": [ "Provider's internally assigned tracking identifier", "Time and source of the detection", "Time of completed evaluation", "Is it an internet-reachable vulnerability or not?", "Is it a likely exploitable vulnerability or not?", "Currently estimated Potential Agency Impact N-rating", "Explanation of why this is an accepted vulnerability", "Any supplementary information the provider determines will responsibly help federal agencies assess or mitigate the risk to their federal customer data within the cloud service offering resulting from the accepted vulnerability" ], "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "A recent vulnerability report or a sample vulnerability report" ] }, "schema": { "name": "FedRAMP Accepted Vulnerability Info (VER-RPT-AVI)", "url": "https://fedramp.gov/schemas/fedramp-accepted-vulnerability-info-schema-2026-06-24.json" }, "terms": [ "Accepted Vulnerability", "Cloud Service Offering", "Federal Customer Data", "Internet-Reachable Vulnerability (IRV)", "Likely", "Likely Exploitable Vulnerability (LEV)", "Potential Agency Impact", "Responsibly", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-RPT-NID": { "name": "Responsible Disclosure", "statement": "Providers MUST NOT irresponsibly disclose specific sensitive information about vulnerabilities that would likely lead to exploitation, but MUST disclose sufficient information for informed risk-based decision-making to all necessary parties.", "note": "This requirement will be superseded in the event of formal action related to an investigation or corrective action plan.", "force": "MUST NOT", "affects": ["Providers"], "terms": ["All Necessary Parties", "Likely", "Vulnerability"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-RPT-HLO": { "name": "High-Level Overviews", "statement": "Providers SHOULD include high-level overviews of ALL vulnerability detection and response activities conducted during this period for the cloud service offering; this includes vulnerability disclosure programs, bug bounty programs, penetration testing, assessments, etc.", "force": "SHOULD", "affects": ["Providers"], "terms": [ "Cloud Service Offering", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-RPT-RPD": { "name": "Responsible Public Disclosure", "statement": "Providers MAY responsibly disclose vulnerabilities publicly or with other parties if the provider determines doing so will NOT likely lead to exploitation.", "force": "MAY", "affects": ["Providers"], "terms": ["Likely", "Responsibly", "Vulnerability"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } }, "TFR": { "VER-TFR-MHR": { "name": "Monthly Activity Report", "statement": "Providers MUST report vulnerability detection and response activity to all necessary parties in a consistent format that is human readable at least monthly.", "force": "MUST", "affects": ["Providers"], "artifacts": { "all": [ "A recent vulnerability report or a sample vulnerability report" ] }, "timeframe_type": "months", "timeframe_num": 1, "terms": [ "All Necessary Parties", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-TFR-MAV": { "name": "Mark Accepted Vulnerabilities", "statement": "Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability.", "force": "MUST", "affects": ["Providers"], "timeframe_type": "days", "timeframe_num": 192, "terms": ["Accepted Vulnerability", "Vulnerability"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-TFR-MRH": { "name": "Historical Activity", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications MAY make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information MAY be updated persistently, at least once every month.", "force": "MAY", "timeframe_type": "months", "timeframe_num": 1, "artifacts": { "all": [ "URL and access instructions for historical vulnerability detection and response activity in machine readable format" ] } }, "b": { "statement": "Providers with Class B Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every month.", "force": "SHOULD", "timeframe_type": "months", "timeframe_num": 1, "artifacts": { "all": [ "URL and access instructions for historical vulnerability detection and response activity in machine readable format", "or an explanation of why machine readable content is not being provided" ] } }, "c": { "statement": "Providers with Class C Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 14 days.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 14, "artifacts": { "all": [ "URL and access instructions for historical vulnerability detection and response activity in machine readable format", "or an explanation of why machine readable content is not being provided" ] } }, "d": { "statement": "Providers with Class D Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 7 days.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 7, "artifacts": { "all": [ "URL and access instructions for historical vulnerability detection and response activity in machine readable format", "or an explanation of why machine readable content is not being provided" ] } } }, "affects": ["Providers"], "schema": { "name": "FedRAMP Historical Vulnerability Evaluation and Reporting Activity (VER-TFR-MRH)", "url": "https://fedramp.gov/schemas/fedramp-historical-ver-activity-schema-2026-06-24.json" }, "terms": [ "All Necessary Parties", "Persistently", "Vulnerability", "Vulnerability Detection", "Vulnerability Response" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-TFR-EVU": { "name": "Evaluate Vulnerabilities Quickly", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 14 days of detection.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 14 }, "b": { "statement": "Providers with Class B Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 7 days of detection.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 7 }, "c": { "statement": "Providers with Class C Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 5 days of detection.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 5 }, "d": { "statement": "Providers with Class D Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 2 days of detection.", "force": "SHOULD", "timeframe_type": "days", "timeframe_num": 2 } }, "affects": ["Providers"], "terms": ["Vulnerability", "Vulnerability Detection"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-TFR-IRI": { "name": "Internet-Reachable Incidents", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications MAY treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.", "force": "MAY" }, "b": { "statement": "Providers with Class B Certifications MAY treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.", "force": "MAY" }, "c": { "statement": "Providers with Class C Certifications SHOULD treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.", "force": "SHOULD" }, "d": { "statement": "Providers with Class D Certifications SHOULD treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.", "force": "SHOULD" } }, "affects": ["Providers"], "terms": [ "FedRAMP Reportable Incident", "Incident", "Likely", "Likely Exploitable Vulnerability (LEV)", "Partially Mitigated Vulnerability", "Potential Agency Impact", "Vulnerability" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "VER-TFR-NRI": { "name": "Non-Internet-Reachable Incidents", "varies_by_class": { "a": { "statement": "Providers with Class A Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.", "force": "MAY" }, "b": { "statement": "Providers with Class B Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.", "force": "MAY" }, "c": { "statement": "Providers with Class C Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.", "force": "MAY" }, "d": { "statement": "Providers with Class D Certifications SHOULD treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.", "force": "SHOULD" } }, "affects": ["Providers"], "terms": [ "FedRAMP Reportable Incident", "Incident", "Likely", "Likely Exploitable Vulnerability (LEV)", "Partially Mitigated Vulnerability", "Potential Agency Impact", "Vulnerability" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] } } }, "20x": {}, "rev5": {} } } }, "KSI": { "CED": { "id": "KSI-CED", "name": "Cybersecurity Education", "web_name": "cybersecurity-education", "short_name": "CED", "status": "stable", "indicators": { "KSI-CED-RAT": { "name": "Reviewing All Training", "statement": "The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.", "controls": [ "cp-3", "ir-2", "ps-6", "at-2", "at-2.2", "at-2.3", "at-3.5", "at-4", "ir-2.3", "at-3", "sr-11.1" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Incident", "Persistently", "Vulnerability Response"] } } }, "CMT": { "id": "KSI-CMT", "name": "Change Management", "web_name": "change-management", "short_name": "CMT", "status": "stable", "indicators": { "KSI-CMT-LMC": { "name": "Logging Changes", "statement": "Modifications to the cloud service offering are logged and monitored.", "controls": [ "au-2", "cm-3", "cm-3.2", "cm-4.2", "cm-6", "cm-8.3", "ma-2" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Cloud Service Offering"] }, "KSI-CMT-RMV": { "name": "Redeploying vs Modifying", "statement": "Changes to machine-based information resources are executed through the redeployment of version controlled resources rather than direct modification wherever reasonable.", "controls": [ "cm-2", "cm-3", "cm-5", "cm-6", "cm-7", "cm-8.1", "si-3" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": [ "Information Resource", "Machine-Based (Information Resources)" ] }, "KSI-CMT-RVP": { "name": "Reviewing Change Procedures", "statement": "The effectiveness of documented change management procedures is persistently reviewed.", "controls": ["cm-3", "cm-3.2", "cm-3.4", "cm-5", "cm-7.1", "cm-9"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-CMT-VTD": { "name": "Validating Throughout Deployment", "statement": "Persistent testing and validation of changes throughout deployment is automated.", "controls": ["cm-3", "cm-3.2", "cm-4.2", "si-2"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently", "Validation"] } } }, "CNA": { "id": "KSI-CNA", "name": "Cloud Native Architecture", "web_name": "cloud-native-architecture", "short_name": "CNA", "status": "stable", "indicators": { "KSI-CNA-DFP": { "name": "Defining Functionality and Privileges", "statement": "The functionality and privileges for infrastructure and services are strictly defined.", "controls": ["cm-2", "si-3"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "KSI-CNA-EIS": { "name": "Enforcing Intended State", "controls": ["ca-2.1", "ca-7.1"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "varies_by_class": { "b": { "statement": "**Optional:** Automated services are used to persistently assess the security of all machine-based information resources and automatically enforce their intended operational state." }, "c": { "statement": "Automated services are used to persistently assess the security of all machine-based information resources and automatically enforce their intended operational state." } }, "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Persistently" ] }, "KSI-CNA-IBP": { "name": "Implementing Best Practices", "statement": "The use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance.", "controls": ["ac-17.3", "cm-2", "pl-10"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Persistently" ] }, "KSI-CNA-MAT": { "name": "Minimizing Attack Surface", "statement": "Machine-based information resources are persistently reviewed to ensure they have a minimal attack surface and that lateral movement is minimized if compromised.", "controls": [ "ac-17.3", "ac-18.1", "ac-18.3", "ac-20.1", "ca-9", "sc-7.3", "sc-7.4", "sc-7.5", "sc-7.8", "sc-8", "sc-10", "si-10", "si-11", "si-16" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Persistently" ] }, "KSI-CNA-OFA": { "name": "Optimizing for Availability", "statement": "Machine-based information resources are persistently reviewed to ensure they are appropriately optimized for high availability and rapid recovery.", "controls": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Persistently" ] }, "KSI-CNA-RNT": { "name": "Restricting Network Traffic", "statement": "Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.", "controls": ["ac-17.3", "ca-9", "cm-7.1", "sc-7.5", "si-8"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Persistently" ] }, "KSI-CNA-RVP": { "name": "Reviewing Protections", "statement": "The effectiveness of protection against denial of service attacks and other unwanted activity for machine-based information resources is persistently reviewed.", "controls": ["sc-5", "si-8", "si-8.2"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Persistently" ] }, "KSI-CNA-ULN": { "name": "Using Logical Networking", "statement": "Logical networking and related capabilities are used and persistently reviewed to enforce traffic flow controls.", "controls": [ "ac-12", "ac-17.3", "ca-9", "sc-4", "sc-7", "sc-7.7", "sc-8", "sc-10" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] } } }, "IAM": { "id": "KSI-IAM", "name": "Identity and Access Management", "web_name": "identity-and-access-management", "short_name": "IAM", "status": "stable", "indicators": { "KSI-IAM-AAM": { "name": "Automating Account Management", "statement": "The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.", "controls": [ "ac-2.2", "ac-2.3", "ac-2.13", "ac-6.7", "ia-4.4", "ia-12", "ia-12.2", "ia-12.3", "ia-12.5" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "KSI-IAM-APM": { "name": "Adopting Passwordless Methods", "statement": "Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.", "controls": [ "ac-3", "ia-5.1", "ia-5.2", "ia-5.6", "ia-6", "ac-2", "ia-2", "ia-2.1", "ia-2.2", "ia-2.8", "ia-5", "ia-8", "sc-23" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "KSI-IAM-ELP": { "name": "Ensuring Least Privilege", "statement": "Identity and access management measures are used and persistently reviewed to ensure each user or device can only access the resources they need.", "controls": [ "ac-2.5", "ac-2.6", "ac-3", "ac-4", "ac-6", "ac-12", "ac-14", "ac-17", "ac-17.1", "ac-17.2", "ac-17.3", "ac-20", "ac-20.1", "cm-2.7", "cm-9", "ia-2", "ia-3", "ia-4", "ia-4.4", "ia-5.2", "ia-5.6", "ia-11", "ps-2", "ps-3", "ps-4", "ps-5", "ps-6", "sc-4", "sc-20", "sc-21", "sc-22", "sc-23", "sc-39", "si-3" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-IAM-JIT": { "name": "Authorizing Just-in-Time", "statement": "A least-privileged, role and attribute-based, and just-in-time security authorization model is used and persistently reviewed for all user and non-user accounts and services.", "controls": [ "ac-2", "ac-2.1", "ac-2.2", "ac-2.3", "ac-2.4", "ac-2.6", "ac-3", "ac-4", "ac-5", "ac-6", "ac-6.1", "ac-6.2", "ac-6.5", "ac-6.7", "ac-6.9", "ac-6.10", "ac-7", "ac-20.1", "ac-17", "au-9.4", "cm-5", "cm-7", "cm-7.2", "cm-7.5", "cm-9", "ia-4", "ia-4.4", "ia-7", "ps-2", "ps-3", "ps-4", "ps-5", "ps-6", "ps-9", "ra-5.5", "sc-2", "sc-23", "sc-39" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-IAM-SNU": { "name": "Securing Non-User Authentication", "statement": "Appropriately secure authentication methods are used and persistently reviewed for non-user accounts and services.", "controls": [ "ac-2", "ac-2.2", "ac-4", "ac-6.5", "ia-3", "ia-5.2", "ra-5.5" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-IAM-SUS": { "name": "Responding to Suspicious Activity", "statement": "Accounts with privileged access are disabled or otherwise secured in response to suspicious activity.", "controls": [ "ac-2", "ac-2.1", "ac-2.3", "ac-2.13", "ac-7", "ps-4", "ps-8" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Vulnerability Response"] } } }, "INR": { "id": "KSI-INR", "name": "Incident Response", "web_name": "incident-response", "short_name": "INR", "status": "stable", "indicators": { "KSI-INR-AAR": { "name": "Generating After Action Reports", "statement": "Incident after action reports are generated and lessons learned are persistently incorporated.", "controls": ["ir-3", "ir-4", "ir-4.1", "ir-8"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Incident", "Persistently"] }, "KSI-INR-RIR": { "name": "Reviewing Incident Response Procedures", "statement": "The effectiveness of documented incident response procedures is persistently reviewed.", "controls": [ "ir-4", "ir-4.1", "ir-6", "ir-6.1", "ir-6.3", "ir-7", "ir-7.1", "ir-8", "ir-8.1", "si-4.5" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Incident", "Persistently", "Vulnerability Response"] }, "KSI-INR-RPI": { "name": "Reviewing Past Incidents", "statement": "Past incidents are persistently reviewed for patterns or vulnerabilities that were not previously apparent or identified.", "controls": ["ir-3", "ir-4", "ir-4.1", "ir-5", "ir-8"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Incident", "Persistently", "Vulnerability"] } } }, "MLA": { "id": "KSI-MLA", "name": "Monitoring, Logging, and Auditing", "web_name": "monitoring-logging-and-auditing", "short_name": "MLA", "status": "stable", "indicators": { "KSI-MLA-ALA": { "name": "Authorizing Log Access", "controls": ["si-11"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "varies_by_class": { "b": { "statement": "**Optional:** A least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity." }, "c": { "statement": "A least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity." } }, "terms": ["Persistently"] }, "KSI-MLA-EVC": { "name": "Evaluating Configurations", "statement": "The configuration of machine-based information resources, especially infrastructure as code, is persistently evaluated and tested.", "controls": ["ca-7", "cm-2", "cm-6", "si-7.7"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Persistently" ] }, "KSI-MLA-LET": { "name": "Logging Event Types", "statement": "A list of information resources and event types that will be logged, monitored, and audited is maintained and persistently reviewed to ensure these activities occur.", "controls": [ "ac-2.4", "ac-6.9", "ac-17.1", "ac-20.1", "au-2", "au-7.1", "au-12", "si-4.4", "si-4.5", "si-7.7" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Information Resource", "Persistently"] }, "KSI-MLA-OSM": { "name": "Operating SIEM Capability", "statement": "A Security Information and Event Management (SIEM) or similar system(s) is used and persistently reviewed for centralized, tamper-resistant logging of events, activities, and changes.", "controls": [ "ac-17.1", "ac-20.1", "au-2", "au-3", "au-3.1", "au-4", "au-5", "au-6.1", "au-6.3", "au-7", "au-7.1", "au-8", "au-9", "au-11", "ir-4.1", "si-4.2", "si-4.4", "si-7.7" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-MLA-RVL": { "name": "Reviewing Logs", "statement": "Logs are persistently reviewed and audited.", "controls": [ "ac-2.4", "ac-6.9", "au-2", "au-6", "au-6.1", "si-4", "si-4.4" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] } } }, "PIY": { "id": "KSI-PIY", "name": "Policy and Inventory", "web_name": "policy-and-inventory", "short_name": "PIY", "status": "stable", "indicators": { "KSI-PIY-GIV": { "name": "Generating Inventories", "statement": "Authoritative sources are used to automatically generate real-time inventories of all information resources when needed.", "controls": [ "cm-2.2", "cm-7.5", "cm-8", "cm-8.1", "cm-12", "cm-12.1", "cp-2.8" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Information Resource"] }, "KSI-PIY-RES": { "name": "Reviewing Executive Support", "statement": "Executive support for achieving the provider's security goals is persistently reviewed and demonstrated.", "controls": [], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-PIY-RIS": { "name": "Reviewing Investments in Security", "statement": "The effectiveness of the provider's investments in achieving security goals is persistently reviewed.", "controls": [ "ac-5", "ca-2", "cp-2.1", "cp-4.1", "ir-3.2", "pm-3", "sa-2", "sa-3", "sr-2.1" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-PIY-RSD": { "name": "Reviewing Security in the SDLC", "statement": "The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.", "controls": [ "ac-5", "au-3.3", "cm-3.4", "pl-8", "pm-7", "sa-3", "sa-8", "sc-4", "sc-18", "si-10", "si-11", "si-16" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-PIY-RVD": { "name": "Reviewing Vulnerability Disclosures", "statement": "The effectiveness of the provider's vulnerability disclosure program is persistently reviewed.", "controls": ["ra-5.11"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently", "Vulnerability"] } } }, "RPL": { "id": "KSI-RPL", "name": "Recovery Planning", "web_name": "recovery-planning", "short_name": "RPL", "status": "stable", "indicators": { "KSI-RPL-ABO": { "name": "Aligning Backups with Objectives", "statement": "The alignment of machine-based information resource backups with defined recovery objectives is persistently reviewed.", "controls": ["cm-2.3", "cp-6", "cp-9", "cp-10", "cp-10.2", "si-12"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Persistently" ] }, "KSI-RPL-ARP": { "name": "Aligning Recovery Plan", "statement": "The alignment of recovery plans with defined recovery objectives is persistently reviewed.", "controls": [ "cp-2", "cp-2.1", "cp-2.3", "cp-4.1", "cp-6", "cp-6.1", "cp-6.3", "cp-7", "cp-7.1", "cp-7.2", "cp-7.3", "cp-8", "cp-8.1", "cp-8.2", "cp-10", "cp-10.2" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-RPL-RRO": { "name": "Reviewing Recovery Objectives", "statement": "The desired Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and persistently reviewed for alignment with the provider's business needs and capabilities.", "controls": ["cp-2.3", "cp-10"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-RPL-TRC": { "name": "Testing Recovery Capabilities", "statement": "The capability to recover from incidents and contingencies aligned with defined recovery objectives is persistently tested.", "controls": [ "cp-2.1", "cp-2.3", "cp-4", "cp-4.1", "cp-6", "cp-6.1", "cp-9.1", "cp-10", "ir-3", "ir-3.2" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Incident", "Persistently"] } } }, "SCR": { "id": "KSI-SCR", "name": "Supply Chain Risk", "web_name": "supply-chain-risk", "short_name": "SCR", "status": "stable", "indicators": { "KSI-SCR-MIT": { "name": "Mitigating Supply Chain Risk", "statement": "Persistently identify, review, and mitigate potential supply chain risks.", "controls": [ "ac-20", "ra-3.1", "sa-9", "sa-10", "sa-11", "sa-15.3", "sa-22", "si-7.1", "sr-5", "sr-6", "ca-7.4", "sc-18" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently"] }, "KSI-SCR-MON": { "name": "Monitoring Supply Chain Risk", "statement": "Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.", "controls": [ "ac-20", "ca-3", "ir-6.3", "ps-7", "ra-5", "sa-9", "si-5", "sr-5", "sr-6", "sr-8" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Information Resource", "Vulnerability"] } } }, "SVC": { "id": "KSI-SVC", "name": "Service Configuration", "web_name": "service-configuration", "short_name": "SVC", "status": "stable", "indicators": { "KSI-SVC-ACM": { "name": "Automating Configuration Management", "statement": "The configuration of machine-based information resources is managed using automation and persistently reviewed for drift.", "controls": [ "ac-2.4", "cm-2", "cm-2.2", "cm-2.3", "cm-6", "cm-7.1", "pl-9", "pl-10", "sa-5", "si-5", "sr-10" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": [ "Drift", "Information Resource", "Machine-Based (Information Resources)", "Persistently" ] }, "KSI-SVC-ASM": { "name": "Automating Secret Management", "statement": "Management, protection, and regular rotation of digital keys, certificates, and other secrets is automated and persistently reviewed.", "controls": ["ac-17.2", "ia-5.2", "ia-5.6", "sc-12", "sc-17"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Persistently", "Regularly"] }, "KSI-SVC-EIS": { "name": "Evaluating and Improving Security", "statement": "Information resources are persistently evaluated for opportunities to improve security and those improvements are persistently made.", "controls": [ "cm-7.1", "cm-12.1", "ma-2", "pl-8", "sc-7", "sc-39", "si-2.2", "si-4", "sr-10" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": ["Information Resource", "Persistently"] }, "KSI-SVC-PRR": { "name": "Preventing Residual Risk", "controls": ["sc-4"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "varies_by_class": { "b": { "statement": "**Optional:** Plans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data." }, "c": { "statement": "Plans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data." } }, "terms": [ "Federal Customer Data", "Information Resource", "Likely", "Persistently" ] }, "KSI-SVC-RUD": { "name": "Removing Unwanted Data", "controls": ["si-12.3", "si-18.4"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "varies_by_class": { "b": { "statement": "**Optional:** Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage." }, "c": { "statement": "Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage." } }, "terms": ["Federal Customer Data", "Promptly"] }, "KSI-SVC-SIN": { "name": "Securing Information", "statement": "Information is encrypted or otherwise secured from unwanted access or modification.", "controls": [ "ac-1", "ac-17.2", "cp-9.8", "sc-8", "sc-8.1", "sc-13", "sc-20", "sc-21", "sc-22", "sc-23", "sc-28", "sc-28.1" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, "KSI-SVC-VCM": { "name": "Validating Communications", "controls": ["sc-23", "si-7.1"], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "varies_by_class": { "b": { "statement": "**Optional:** The authenticity and integrity of communications between machine-based information resources is persistently validated using automation." }, "c": { "statement": "The authenticity and integrity of communications between machine-based information resources is persistently validated using automation." } }, "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Persistently", "Validation" ] }, "KSI-SVC-VRI": { "name": "Validating Resource Integrity", "statement": "Use cryptographic methods to validate the integrity of machine-based information resources.", "controls": [ "cm-2.2", "cm-8.3", "sc-13", "sc-23", "si-7", "si-7.1", "sr-10" ], "updated": [ { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ], "terms": [ "Information Resource", "Machine-Based (Information Resources)", "Validation" ] } } } }, "CTL": { "AC": { "AC-06-01": { "parameters": [ { "parameterId": "ac-06.01_odp.02", "value": "all functions not publicly accessible" }, { "parameterId": "ac-06.01_odp.05", "value": "all security-relevant information not publicly available" } ] }, "AC-20": { "guidance": [ "The interrelated controls of AC-20, CA-3, and SA-9 should be differentiated as follows:", "AC-20 describes system access to and from external systems.", "CA-3 describes documentation of an agreement between the respective system owners when data is exchanged between the CSO and an external system.", "SA-9 describes the responsibilities of external system owners. These responsibilities would typically be captured in the agreement required by CA-3." ] }, "AC-06-02": { "parameters": [ { "parameterId": "ac-06.02_odp", "value": "all security functions" } ] }, "AC-06-08": { "parameters": [ { "parameterId": "ac-06.08_odp", "value": "any software except software explicitly documented" } ] } }, "AU": { "AU-06": { "guidance": [ "This activity is considered vulnerability detection and is subject to the Vulnerability Detection and Response rules." ] }, "AU-06-05": { "guidance": [ "This activity is considered vulnerability detection and is subject to the Vulnerability Detection and Response rules." ] }, "AU-10": { "parameters": [ { "parameterId": "au-10_odp", "value": "at least actions including the addition, modification, deletion, approval, sending, or receiving of data" } ] }, "AU-12": { "parameters": [ { "parameterId": "au-12_odp.01", "value": "at least all information system and network components where audit capability is deployed/available" } ] } }, "CA": { "CA-07": { "guidance": [ "Follow the FedRAMP Continuous Collaborative Monitoring, Significant Change Notification, Vulnerability Detection and Response, and Vulnerability Evaluation and Reporting rules." ] }, "CA-08": { "guidance": [ "Penetration testing is part of vulnerability detection and is subject to the Vulnerability Detection and Response rules." ] }, "CA-02": { "parameters": [ { "parameterId": "ca-02_odp.02", "value": "individuals or roles to include FedRAMP and agency customers" } ] }, "CA-02-03": { "parameters": [ { "parameterId": "ca-02.03_odp.01", "value": "any FedRAMP Recognized independent assessment service" } ] } }, "CM": { "CM-01": { "guidance": ["Follow the Significant Change Notification rules."] }, "CM-08": { "guidance": [ "Follow the FedRAMP Continuous Collaborative Monitoring, Significant Change Notification, Vulnerability Detection and Response, and Vulnerability Evaluation and Reporting rules." ] }, "CM-11": { "parameters": [ { "parameterId": "cm-11_odp.03", "value": "Continuously (via CM-7 (5))" } ] }, "CM-12": { "guidance": ["Follow the FedRAMP Minimum Assessment Scope rules."] }, "CM-12-01": { "guidance": ["Follow the FedRAMP Minimum Assessment Scope rules."] }, "CM-14": { "guidance": [ "If digital signatures/certificates are unavailable, alternative cryptographic integrity checks (hashes, self-signed certs, etc.) can be utilized." ] } }, "CP": { "CP-07-01": { "guidance": [ "The service provider may determine what is considered a sufficient degree of separation between the primary and alternate processing sites, based on the types of threats that are of concern. For one particular type of threat (i.e., hostile cyber attack), the degree of separation between sites will be less relevant." ] }, "CP-02-03": { "parameters": [ { "parameterId": "cp-02.03_odp.02", "value": "time period defined in service provider and organization Service Level Agreements" } ] }, "CP-10-04": { "parameters": [ { "parameterId": "cp-10.04_odp", "value": "time period consistent with the restoration time-periods defined in the service provider and organization Service Level Agreements" } ] } }, "IA": { "IA-02": { "guidance": [ "Multi-factor authentication must be phishing-resistant. In accordance with current CISA Guidance. Current CISA guidance can be found here: https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf" ] }, "IA-02-01": { "guidance": [ "Multi-factor authentication must be phishing-resistant. In accordance with current CISA Guidance. Current CISA guidance can be found here: https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf" ] }, "IA-02-02": { "guidance": [ "Multi-factor authentication must be phishing-resistant. In accordance with current CISA Guidance. Current CISA guidance can be found here: https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf" ] }, "IA-02-08": { "parameters": [ { "parameterId": "ia-02.08_odp", "value": "privileged accounts; non-privileged accounts" } ] }, "IA-05": { "varies_by_class": { "b": { "guidance": [ "Authenticators must be compliant with the most recent NIST Digital Identity Guidelines IAL, AAL, FAL level 1.", "IA-5 Guidance: FedRAMP requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE)." ] }, "c": { "guidance": [ "Authenticators must be compliant with the most recent NIST Digital Identity Guidelines IAL, AAL, FAL level 2.", "IA-5 Guidance: FedRAMP requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE)." ] }, "d": { "guidance": [ "Authenticators must be compliant with the most recent NIST Digital Identity Guidelines IAL, AAL, FAL level 3.", "IA-5 Guidance: FedRAMP requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE)." ] } }, "updated": [ { "date": "2026-07-14", "comment": "Update guidance to direct users to the latest NIST Digital Identity Guidelines and remove references to specific instances of SP 800-63." } ] }, "IA-02-06": { "parameters": [ { "parameterId": "ia-02.06_odp.01", "value": "local, network and remote" }, { "parameterId": "ia-02.06_odp.02", "value": "privileged accounts; non-privileged accounts" } ] }, "IA-04-04": { "parameters": [ { "parameterId": "ia-04.04_odp", "value": "contractors; foreign nationals" } ] } }, "IR": { "IR-01": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-02": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-02-01": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-02-02": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-03": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-03-02": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-04": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-04-01": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-04-02": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-04-04": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-04-06": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-04-11": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-05": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-05-01": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-06": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-06-01": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-06-03": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-07": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-07-01": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-08": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-09": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-09-02": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-09-03": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] }, "IR-09-04": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] } }, "MA": { "MA-05": { "guidance": [ "CSPs should clearly document nationality requirements (or lack of) for maintenance personnel where applicable." ] }, "MA-05-01": { "guidance": [ "Only MA-5 (1) (a) (1) is required by FedRAMP Class C Baseline." ] } }, "PS": { "PS-07": { "guidance": [ "CSPs MUST clearly document any nationality requirements for any account type within its platform. If none exists, this must also be explicitly stated." ] } }, "RA": { "RA-05": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "RA-05-02": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "RA-05-03": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "RA-05-04": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "RA-05-05": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "RA-05-08": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "RA-05-11": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "RA-07": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] } }, "SA": { "SA-05": { "guidance": ["Follow the FedRAMP Secure Configuration Guide rules."] }, "SA-09-05": { "varies_by_class": { "c": { "parameters": [ { "parameterId": "sa-09.05_odp.01", "value": "information processing, information or data, AND system services" }, { "parameterId": "sa-09.05_odp.03", "value": "all federal customer data" } ] }, "d": { "parameters": [ { "parameterId": "sa-09.05_odp.01", "value": "information processing, information or data, AND system services" }, { "parameterId": "sa-09.05_odp.02", "value": "U.S./U.S. Territories or geographic locations where there is U.S. jurisdiction" }, { "parameterId": "sa-09.05_odp.03", "value": "all federal customer data" } ] } } }, "SA-09-02": { "parameters": [ { "parameterId": "sa-09.02_odp", "value": "all external systems where federal customer data is processed or stored" } ] } }, "SC": { "SC-07": { "guidance": [ "SC-7 (b) may be met by using any technical capability or complement of capabilities that ensures logical separation between publicly accessible components and internal networks by preventing traversal without inspection and authorization; traffic may not flow unrestricted from publicly accessible components to internal networks." ] }, "SC-13": { "guidance": ["Follow the FedRAMP Cryptographic Module Use rules."] } }, "SI": { "SI-02": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "SI-02-02": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "SI-04": { "guidance": [ "Follow all applicable rules within the Vulnerability and Detection Response and Incident Communication Procedure guidance." ] }, "SI-04-01": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "SI-04-02": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "SI-04-04": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "SI-04-05": { "guidance": [ "Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules." ] }, "SI-05": { "guidance": [ "Follow the FedRAMP Addressing FedRAMP Communication rules." ] }, "SI-08": { "guidance": [ "When CSO sends email on behalf of the government as part of the business offering, Control Description should include implementation of Domain-based Message Authentication, Reporting & Conformance (DMARC) on the sending domain for outgoing messages as described in DHS Binding Operational Directive (BOD) 18-01. https://www.cisa.gov/news-events/directives", "SI-8 Guidance: CSPs should confirm DMARC configuration (where appropriate) to ensure that policy=reject and the rua parameter includes reports@dmarc.cyber.dhs.gov. DMARC compliance should be documented in the SI-08 control implementation solution description, and list the FROM: domain(s) when emails are sent on behalf of the government." ] } }, "SR": { "SR-03": { "guidance": [ "CSO must document and maintain the supply chain custody, including replacement devices, to ensure the integrity of the devices before being introduced to the boundary." ] }, "SR-08": { "guidance": [ "Follow the FedRAMP Incident Evaluation and Communication rules." ] } } } }