---
title: 'Outcome from the FY26 Q4 FedRAMP Security Inbox Test'
tabTitle: 'Outcome from the FY26 Q4 FedRAMP Security Inbox Test'
indexTitle: 'Outcome from the FY26 Q4 FedRAMP Security Inbox Test'
description: 'This notice describes the outcome from the FedRAMP Security Inbox Test conducted on 07/07/2026'
noticeDate: 2026-07-22T04:00:00-04:00
noticeId: NTC-0016
---

The [Addressing FedRAMP Communication](https://www.fedramp.gov/2026/reference/addressing-fedramp-communication/) rules (formerly FedRAMP Security Inbox) have been formally required for all FedRAMP Certified cloud service offerings since January 5, 2026, with the grace period for adoption expiring on July 1, 2026\. These rules were created in late 2025 after communications from FedRAMP regarding [CISA Emergency Directive 25-03](https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices) systematically failed to reach cloud service providers due to poorly maintained inboxes and ticketing systems. These new rules made it clear that cloud service providers must receive and address FedRAMP communication in a consistent and timely manner to maintain FedRAMP Certification. Providers that do not receive and address FedRAMP communication will lose their FedRAMP Certification.

The Addressing FedRAMP Communication rules also established a quarterly testing system: FedRAMP would ensure that cloud service providers maintained active channels for critical communication from FedRAMP by testing this on a quarterly basis. The [FY26 Q4 Quarterly Test](https://www.fedramp.gov/notices/0015/) was performed in July 2026, and was the third Quarterly Test. This test was the first one that took place after the expiration of the grace period, therefore is the first test that comes with immediate repercussions for cloud service providers.

652 (99%) cloud service offerings responded to the FY26 Q4 Quarterly Test. 10 (1%) FedRAMP Certified cloud service offerings failed and are being placed in remediation, pending revocation of their FedRAMP Certification.

FedRAMP is posting this public notice because the providers of these cloud service offerings have not responded to any communication from FedRAMP. We sent an initial email to the security contact on file on 7/7/26 to initiate the Quarterly Test. We sent follow-up emails to the security contact and the sales contact on file on 7/10/26, 7/13/26, and twice on 7/14/26 to all providers who had not yet responded. We searched FedRAMP repositories and info@fedramp.gov tickets to find recent alternative contacts in advance of the response deadline. Additionally, we contacted agency customers of unresponsive offerings to enlist their help in contacting the provider and have still received no response.

## Providers In Remediation (Pending Revocation)

**The providers of these cloud service offerings have until 3:00pm EDT on Tuesday, August 4, 2026 to contact FedRAMP with a Corrective Action Plan that explains how they will meet all Addressing FedRAMP Communication rules.** This Corrective Action Plan must include a deadline of August 31, 2026 for implementation.

**Failure to contact FedRAMP with a Corrective Action Plan by August 4 will result in revocation of FedRAMP Certification on August 5, 2026\.** Contact must be initiated by sending an email to [info@fedramp.gov](mailto:info@fedramp.gov) while cc’ing [fedramp\_security@fedramp.gov](mailto:fedramp_security@fedramp.gov) and [pete@fedramp.gov](mailto:pete@fedramp.gov).

| FRID         | CSP                                                                                                   | CSO                                                       | Impact Level       |
| :----------- | :---------------------------------------------------------------------------------------------------- | :-------------------------------------------------------- | :----------------- |
| F1309252456  | Rectitude 369                                                                                         | Rectitude 369 Government Cloud (Formerly GDT)             | Class C (Moderate) |
| F1404043549  | Accenture Federal Services                                                                            | Accenture Federal Cloud ERP                               | Class C (Moderate) |
| FR1932554201 | Forcepoint                                                                                            | ONE – Security Service Edge (SSE) – CASB/DLP/SWG/ZTNA/RBI | Class C (Moderate) |
| FR1908649566 | Aruba Networks                                                                                        | Aruba Central                                             | Class C (Moderate) |
| FR2022243058 | CGI Federal                                                                                           | Momentum Enterprise Suite                                 | Class C (Moderate) |
| FR2110056334 | Center for Translational Data Science (CTDS), University of Chicago and Open Commons Consortium (OCC) | Gen3 Data Commons Service                                 | Class B (Low)      |
| FR2113346550 | OpenWater Software                                                                                    | OpenWater Awards                                          | Class B (Low)      |
| FR2118080669 | Knightscope, Inc.                                                                                     | Knightscope Autonomous Security Robot (Knightscope ASR)   | Class C (Moderate) |
| FR2224739070 | National Resident Matching Program                                                                    | iMatch                                                    | Class C (Moderate) |
| FR2403745080 | ATOM EVSE                                                                                             | Atom Power, Inc \- ATOM EVSE                              | Class B (Low)      |

## Related Partial Remediation

In addition to the providers that failed to respond entirely, some cloud service providers failed to respond in a timely manner. FedRAMP is in active communication with these providers and will also expect a Corrective Action Plan from these providers by August 4, 2026; this Corrective Action Plan must also outline a plan to follow the Addressing FedRAMP Communications rules by August 31, 2026\.

These providers will not be publicly named or publicly placed in remediation as long as they provide a Corrective Action Plan by the deadline, however all agencies have been notified of the deficiency.

## A General Reminder

The most common mistake we continue to see with FedRAMP Security Inboxes is that a provider does not ensure it is properly configured to receive email from FedRAMP \- if the method you have given us to contact you bounces when we send you an email, what do you expect to happen next?

We encourage all entities listed on the FedRAMP Marketplace (cloud service providers, assessors, etc.) to regularly validate that your listed contacts can receive email **from an external domain**.

## Thank You

The vast majority of FedRAMP Certified cloud service providers responded to the FY26 Quarterly Test rapidly and effectively, proving that this mechanism is functional at scale and that businesses who adapt to changing FedRAMP requirements are able to easily address priority communication from FedRAMP. This is more important than ever with the release of the Consolidated Rules for 2026, as simply doing things the same way is no longer acceptable. We are not yet publishing the response times for all cloud service providers but plan to integrate reporting on this into the FedRAMP Marketplace over the next year. Cloud service providers that prioritize customer experience and response to critical communications from FedRAMP deserve to be highlighted for their effective programs as this sends a strong signal to potential customers.
