Skip to content

Certification Package Overview

The Certification Package Overview rules outline the expectations for a simple overview of the cloud service offering that must be included within a FedRAMP Certification Package. This overview replaces the historically required base System Security Plan for FedRAMP Rev5 and is intended to provide a clear, concise, and consistent summary of the offering and the information included in the package to help customers understand the offering at a high level.

Subsets

Effective Date(s) & Overall Applicability for 20x

  • Required (Consolidated Rules for 2026)
  • Optional Adoption: 2026-07-04
  • Obtain: 2026-07-04
  • Maintain: 2027-01-01
  • Grace Ends: On the first FedRAMP independent assessment completed after 2027-01-01

General Provider Responsibilities

These rules apply to providers for FedRAMP Certifications of any type.

Type: 20x
Path: ProgramAgency
Class: Class B
Audience: Providers

Overview of the Cloud Service Offering

CPO-CSO-OVR

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

Providers MUST supply a Certification Package Overview within their FedRAMP Certification Package, in both human-readable and JSON formats, that includes at least all of the information required by the following rules:

  1. Certification Package Overview: CPO-CSO-MTD (Certification Package Overview Metadata)
  2. Certification Data Sharing: CDS-CSO-PUB (Public Information)
  3. Certification Data Sharing: CDS-CSO-SVC (Public Service List)
  4. Certification Data Sharing: CDS-CSO-IRP (Include Relevant Policies)
  5. Minimum Assessment Scope: MAS-CSO-IIR (Identify Information Resources)
  6. Minimum Assessment Scope: MAS-CSO-FLO (Information Flows and Security Categories)
  7. Minimum Assessment Scope: MAS-CSO-TPR (Third-Party Information Resources)
  8. Using Cryptographic Modules: CMU-CSO-CMD (Cryptographic Module Documentation)
  9. Independent Verification and Validation: IVV-CSO-ICP (Inclusion in Certification Package)

Notes:

  • For FedRAMP Rev5, the Certification Package Overview replaces the historically required System Security Plan (not including appendices).
  • This list of rules may not apply to all FedRAMP Certification Classes or Types - if a rule does not apply then the information is not required.

Terms: Certification Class, Certification Data, Certification Package, Information Resource, Initial Incident Report (IIR), Security Category, Third-Party Information Resource, Validation, Verification

Certification Package Overview Metadata

CPO-CSO-MTD

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

Providers MUST also include the following basic metadata in their Certification Package Overview:

  1. Name, title, and contact information of official that is responsible and accountable for the FedRAMP Certification Package
  2. Version
  3. Date and time of last update
  4. Source of update

Terms: Certification Package

20x-Specific Provider Responsibilities

These rules apply to providers for FedRAMP 20x Certifications.

Type: 20x
Path: Program
Class: Class B
Audience: Providers

Certification Package Maintenance for 20x

CPO-CSX-CPM

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

Providers with 20x Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every month.

Timeframe: 1 month


Notes:

  • Providers are expected to maintain their FedRAMP Certification Package using automation as changes occur to ensure they are never out of date.
  • This rule does not require or expect persistent human review of all materials in this cadence.

Terms: Certification Package, Persistently

Comments