Skip to content

FedRAMP Certification

This ruleset explains how cloud service offerings obtain and maintain FedRAMP Certification across certification classes and paths.

Subsets

Effective Date(s) & Overall Applicability for 20x

  • Required (Consolidated Rules for 2026)
  • Optional Adoption: 2026-07-04
  • Obtain: 2026-07-04
  • Maintain: 2027-01-01
  • Grace Ends: On the first FedRAMP independent assessment completed after 2027-01-01

General Provider Responsibilities

These rules apply to cloud service providers obtaining and maintaining any FedRAMP Certification.

FedRAMP Certification Profile

FRC-CSO-FCP

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers MUST identify a target FedRAMP Certification Profile and apply all relevant FedRAMP Practices to the cloud service offering.


Note: Information resources (including third-party information resources) MAY vary by security category as appropriate to the type of information handled by or impacted by the information resource.


Terms: Certification Profile, Cloud Service Offering, FedRAMP Practices, Handle, Information Resource, Security Category, Third-Party Information Resource

FedRAMP Certification Package

FRC-CSO-PKG

Changelog:

  • 2026-07-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers seeking a Class A Certification MUST supply a complete FedRAMP Certification Package to FedRAMP for initial certification; the FedRAMP Certification Package MUST include at least the following information:

  1. A Certification Package Overview
  2. An External Framework Mapping

Terms: Certification Package, Initial Certification

FedRAMP JSON Schemas

FRC-CSO-JSN

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule.


Note: FedRAMP JSON schemas are designed to be lightweight and flexible to establish a minimum set of structured information while allowing providers to improve on the format and structure of the information as needed to meet their needs and the needs of their customers.


Terms: Machine-Readable

Maintain Responsibility and Accountability

FRC-CSO-MRA

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers MUST maintain responsibility and accountability for the accuracy and completeness of all information in the FedRAMP Certification Package, especially when they engage a third party (such as an independent assessor, advisory service, or external tools) to supply information on their behalf.


Terms: Certification Package

Pick One Program Certification Type

FRC-CSO-POP

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers MUST NOT seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering; pick one type.


Note: This rule does not prevent a provider from seeking and maintaining a FedRAMP Rev5 Agency Certification and a FedRAMP 20x Program Certification for the same cloud service offering, however, doing so is strongly discouraged due to the increased complexity and risk of confusion for all parties.


Terms: Cloud Service Offering

FedRAMP Class A Certification Rules

These are specific rules that apply to providers seeking FedRAMP Class A Certifications.

Approved Alternative Security Frameworks

FRC-CLA-ASF

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers seeking a FedRAMP Class A Certification MUST have completed a certification or equivalent process, including an independent assessment if applicable, from one of the following alternative security frameworks:

  1. FedRAMP Rev5 (including FedRAMP Ready) at any historical Impact Level
  2. SOC 2 Type II
  3. GovRAMP at any Impact Level

Terms: Security Category

External Assessment Materials

FRC-CLA-EAM

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers seeking a FedRAMP Class A Certification MUST supply the full materials from the alternative security assessment to all necessary parties as part of the FedRAMP Certification Package.


Terms: All Necessary Parties, Certification Package

Address FedRAMP Rules for Class A

FRC-CLA-AFR

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers seeking a Class A FedRAMP Certification of any Type MUST address all rules in this FedRAMP Class A Certification subset (FRC-CLA) AND the following additional FedRAMP rules; the appropriate artifacts or information mapping for all rules MUST be supplied in the FedRAMP Certification Package.

  1. FedRAMP Certification: FRC-CSO-PKG (FedRAMP Certification Package)
  2. FedRAMP Certification: FRC-CSO-JSN (FedRAMP JSON Schemas)
  3. FedRAMP Certification: FRC-CSO-POP (Pick One Program Certification Type)
  4. Minimum Assessment Scope: MAS-CSO-IIR (Identify Information Resources)
  5. Certification Data Sharing: CDS-CSO-PUB (Public Information)
  6. Certification Data Sharing: CDS-CSO-UTC (Use Trust Centers)
  7. Certification Data Sharing: CDS-UTC-AAD (Agency Access Denial)
  8. Addressing FedRAMP Communication: AFC-CSO-INB (Maintain a FedRAMP Security Inbox)
  9. Addressing FedRAMP Communication: AFC-CSO-RCV (Receive Email Without Disruption)
  10. Addressing FedRAMP Communication: AFC-CSO-CRA (Complete Required Actions)
  11. Incident Evaluation and Communication: IEC-CSO-EFR (Evaluate FedRAMP Reportability)
  12. Vulnerability Detection and Response: VDR-CSO-DET (Vulnerability Detection)
  13. Collaborative Continuous Monitoring: CCM-OCR-AVL (Report Availability)
  14. Collaborative Continuous Monitoring: CCM-OCR-NRD (Next Report Date)
  15. Key Security Indicators: KSI-CMT-LMC (Logging Changes)
  16. Key Security Indicators: KSI-CNA-RNT (Restricting Network Traffic)
  17. Key Security Indicators: KSI-CED-RAT (Reviewing All Training)
  18. Key Security Indicators: KSI-IAM-AAM (Automating Account Management)
  19. Key Security Indicators: KSI-INR-RIR (Reviewing Incident Response Procedures)
  20. Key Security Indicators: KSI-SVC-SIN (Securing Information)

Notes:

  • Some of these specific FedRAMP rules may not have similar counterparts in external frameworks and providers will need to implement new processes to follow these rules.
  • In general, for each of these FedRAMP requirements, providers should include a sufficiently detailed summary that reviewers will not need to dig into the related security framework materials to understand the related decisions - just saying "see SOC 2 report" is not particularly helpful.
  • Information about how the provider addresses the included Key Security Indicators are required for both Rev5 and 20x Class A Certifications.

Terms: Artifacts, Certification Data, Certification Package, Certification Type, FedRAMP Security Inbox, Incident, Information Resource, Initial Incident Report (IIR), Ongoing Certification Report (OCR), Trust Center, Vulnerability, Vulnerability Detection, Vulnerability Response

Optional Independent Verification and Validation

FRC-CLA-IVV

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers seeking a FedRAMP Class A Certification MAY have the FedRAMP Certification Package independently verified and validated by a FedRAMP Recognized assessor before submission to FedRAMP.


Terms: Certification Package, FedRAMP Recognized, Validation, Verification

Applying for FedRAMP Certification

These rules apply to cloud service providers who have met all other relevant rules and are ready to apply for any FedRAMP Certification.

Marketplace Listing First

FRC-APP-MLF

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers MUST be listed in the FedRAMP Marketplace before applying for FedRAMP Certification, including:

  1. FedRAMP Marketplace: MKT-CSO-MLR (Marketplace Listing Requirements),
  2. FedRAMP Marketplace: MKT-CSO-PML (Provider Marketplace Listing Requests)
  3. FedRAMP Marketplace: MKT-IIP-AGU (Agency Use Cases)
  4. FedRAMP Marketplace: MKT-IIP-DCP (Demonstrating Continuous Progress)

Applying for FedRAMP Certification

FRC-APP-AFC

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers MUST complete the FedRAMP Certification Application Form at https://fedramp.gov/forms/provider-listing-request/ in full to request an initial assessment by FedRAMP.

Reference: FedRAMP Certification Application Form

Fresh FedRAMP Certification Package

FRC-APP-FCP

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers MUST supply a fresh initial FedRAMP Certification Package that shows the current status of the cloud service offering as verified and validated by the provider within the previous 7 days.


Terms: Certification Package, Cloud Service Offering, Validation, Verification

Fresh Independent Assessment

FRC-APP-FIA

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized Independent Assessment Service within the previous 3 months.


Terms: FedRAMP Independent Assessment, FedRAMP Recognized

No Third-Party Applicants

FRC-APP-NTP

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers MUST NOT use a third party to apply for a FedRAMP Certification on their behalf; this includes independent assessment services.


Notes:

  • FedRAMP previously allowed independent assessment services to submit applications on behalf of providers, but this caused confusion about who was responsible for the application and the information in it. Providers should apply directly to ensure clear accountability.
  • Providers may use third parties to help them prepare their application and assessment materials for submission.

Updating Stale Assessments

FRC-APP-USA

Changelog:

  • 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.

Providers MAY freshen a stale initial independent verification and validation assessment by having a FedRAMP Recognized independent assessment service review any changes between the original assessment and the current status of the cloud service offering in place of a full re-assessment, UNLESS the stale assessment is more than 9 months old.


Terms: Cloud Service Offering, FedRAMP Recognized, Validation, Verification

Comments