Cryptographic Module Use¶
The Cryptographic Module Use rules clarify how providers should select and use cryptographic modules. These rules allow risk-based decisions for some services while still encouraging validated cryptographic modules whenever they are technically feasible and reasonable.
Effective Date(s) & Overall Applicability for Rev5
- Required (Consolidated Rules for 2026)
- Optional Adoption Allowed: 2026-07-04
- Obtaining Initial Certification: 2027-01-01
- Maintaining Ongoing Certification: 2027-01-01
- Grace Period Ends: 2027-06-01
Cloud Service Provider Responsibilities¶
These rules apply to providers for FedRAMP Certifications.
Path: ProgramAgency
Class: Class C
Audience: Providers
Cryptographic Module Documentation¶
CMU-CSO-CMD
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers MUST document the cryptographic modules used in each service (or groups of services that use the same modules) where cryptographic services are used to protect federal customer data, including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.
Terms: Federal Customer Data, Validation
Using Validated Cryptographic Modules¶
CMU-CSO-UVM
Changelog:
-
2026-10-10: Added a note clarifying that new algorithms in update streams of modules are not included in the scope of updates to validated cryptographic modules.
-
2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers with Class C Certifications SHOULD use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.
Note: Cryptographic modules include specific algorithms by definition; if an update stream of a cryptographic module adds new algorithms that were not previously validated then those algorithms can not be considered within the scope of update stream usage under these rules as they are new algorithms within the module that have never been validated.
Terms: Federal Customer Data, Validation
Configuration of Agency Tenants¶
CMU-CSO-CAT
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers SHOULD configure agency tenants by default to use cryptographic services that use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when such modules are available.
Terms: Validation