<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/">
<channel>
  <title>FedRAMP Notices</title>
  <link>https://fedramp.gov/notices</link>
  <description>The latest formal notices from FedRAMP.</description>
  <language>en-us</language>
  <lastBuildDate>Tue, 07 Jul 2026 08:00:00 GMT</lastBuildDate>
  <managingEditor>pete@fedramp.gov (Pete Waterman - FedRAMP Director)</managingEditor>
  <webMaster>pete@fedramp.gov (Pete Waterman - FedRAMP Director)</webMaster>
  <ttl>60</ttl>
  <image>
    <url>https://fedramp.gov/fedramp-logo-inverse.svg</url>
    <title>FedRAMP Notices</title>
    <link>https://fedramp.gov/notices</link>
  </image>
  <atom:link href="https://fedramp.gov/notices/rss" rel="self" type="application/rss+xml" />
  
    <item>
      <title>Emergency Test: FY26 Q4 FedRAMP Security Inbox Test</title>
      <link>https://fedramp.gov/notices/0015</link>
      <description>FedRAMP Quarterly Test for 2026 Q4</description>
      <content:encoded><![CDATA[<p>This notice is an official <strong>Emergency Test</strong> from FedRAMP. This quarterly test will confirm the functionality and effectiveness of your <a href="https://www.fedramp.gov/2026/providers/20x/rules/addressing-fedramp-communication/">FedRAMP Security Inbox</a>.</p>
<p><strong>As a reminder, cloud service providers must route Emergency designated messages to a senior security official for their awareness.</strong></p>
<h1>You must complete the required actions <strong>by Tuesday, July 14, 2026 at 5:00PM Eastern Time.</strong></h1>
<h2><strong>FedRAMP Response to CISA BOD 26-04:</strong></h2>
<p><a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk">CISA BOD 26-04</a> strongly aligns with FedRAMP’s Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER) rules. Cloud service providers should be familiar with the VDR and the planned migration of all services from legacy vulnerability scanning to an exposure and threat-based approach. The VER contains the evaluation and reporting rules from the VDR in a separate ruleset for convenience.</p>
<p><strong>Any cloud service provider that follows the Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules will meet the timelines, prioritization requirements, and approach set out in BOD 26-04.</strong></p>
<p>Unfortunately cloud service providers who are not actively working to transition to the new FedRAMP vulnerability rules will not be able to provide the assurance that agencies will require under BOD 26-04; the legacy monthly vulnerability scanning process that most FedRAMP Rev5 Certified cloud services currently follow is insufficient.</p>
<p>An update to the mandatory continuous monitoring processes is required for all FedRAMP Rev5 customers to ensure federal information is appropriately protected by all FedRAMP Certified cloud service offerings in a way that aligns with this updated Binding Operational Directive for the federal government.</p>
<h3><strong>To address BOD 26-04:</strong></h3>
<p>1. The Vulnerability Detection and Response rules will be mandatory for all cloud service offerings obtaining or maintaining FedRAMP Certification effective December 7, 2026.<br>
2. The Vulnerability Evaluation and Reporting rules will be mandatory for all cloud service offerings obtaining or maintaining FedRAMP Certification effective December 7, 2026.<br>
3. Additional reporting guidance will be provided for cloud service offerings that are not following the Certification Data Sharing rules yet.<br>
4. FedRAMP will provide a grace period through March 7, 2027 where cloud service offerings may maintain their FedRAMP Certification under a corrective action plan (which will include notice to all agencies). After this date, FedRAMP Certification will be revoked for all cloud service offerings not following these rules.</p>
<h2><strong>20x Pilot Updates:</strong></h2>
<p>FedRAMP is removing the 12 month certification window for 20x pilot participants. Follow the <a href="https://www.fedramp.gov/2026/providers/updating/deadlines/20x/"><strong>Maintain</strong> timeline</a> for the 20x applicable rules. You must show progress toward adopting the full 20x ruleset at your applicable Class level in your quarterly collaborative continuous monitoring meetings.</p>
<p>FedRAMP will be updating your Marketplace listing to include the pilot designation in your FedRAMP certification class until you complete a final certification package with all applicable rules addressed. The annual assessment dates will be updated to 03/07/2027 to reflect the CR26 adoption grace window.</p>
<p>Failure to show progress or meet CR26 Maintain / Grace period dates will result in revocation of pilot certification and delisting from the FedRAMP Marketplace.</p>
<h2><strong>Required Actions:</strong></h2>
<p>Provide the following information for your cloud service offering to FedRAMP by completing the Emergency Test Form:</p>
<p>1. Your email.<br>
2. Your FedRAMP ID: <strong>@fr_id</strong><br>
3. Your unique code: <strong>@unique_code</strong><br>
4. Confirmation that you will adopt the <a href="https://www.fedramp.gov/2026/providers/20x/rules/vulnerability-detection-and-response/">Vulnerability Detection and Response</a> and the <a href="https://www.fedramp.gov/2026/providers/20x/rules/vulnerability-evaluation-and-reporting/">Vulnerability Evaluation and Reporting</a> rules by <strong>December 7, 2026</strong> to maintain your FedRAMP certification in compliance with <a href="https://www.fedramp.gov/notices/0014/">NTC-0014</a>.<br>
5. Confirmation of your awareness of the other <a href="https://www.fedramp.gov/2026/providers/updating/deadlines/20x/">CR26 important deadlines</a> that went into effect June 24, 2026.</p>
<h3><strong>Emergency Test Form:</strong></h3>
<p>Providers will receive an email with the link to the Emergency Test Form. Providers <strong>MUST</strong> complete the Emergency Test Form to receive credit for responding to this test. Email responses will not be accepted.</p>
<h2><strong>Corrective Action:</strong></h2>
<p>Failure to respond to this FedRAMP Security Inbox test will result in revocation of your FedRAMP certification and removal from the FedRAMP Marketplace in accordance with the <a href="https://www.fedramp.gov/2026/providers/updating/deadlines/#understanding-ruleset-effective-dates">Grace Ends</a> milestone.</p>
<p>FedRAMP’s ability to communicate directly with cloud service providers in the FedRAMP Marketplace is a critical component of ongoing authorization. Thank you for ensuring the government’s ongoing access to secure cloud services by maintaining open communication channels with us.</p>
<p><strong>-FedRAMP Security Team</strong></p>
]]></content:encoded>
      <pubDate>Tue, 07 Jul 2026 08:00:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0015</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0015.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0015.jpg" />
    </item>
    <item>
      <title>FedRAMP Response to CISA BOD 26-04 (Prioritizing Security Updates Based on Risk)</title>
      <link>https://fedramp.gov/notices/0014</link>
      <description>This Public Notice describes the changes FedRAMP will make in the Consolidated Rules for 2026 to align with CISA Binding Operational Directive 26-04.</description>
      <content:encoded><![CDATA[<p>On June 10, 2026, CISA released <a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk">Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk</a>. This Binding Operational Directive (BOD)reprioritizes vulnerability remediation based on public exposure, Known Exploited Vulnerability status, automatability, and technical impact.</p>
<p>This Public Notice explains that FedRAMP will now require mandatory adoption of the new FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules by December 7, 2026 to align with CISA BOD 26-04.</p>
<h2>Alignment with Updated FedRAMP Rules</h2>
<p>This CISA BOD strongly aligns with FedRAMP’s upcoming <a href="https://fedramp.gov/2026/reference/vulnerability-detection-and-response/">Vulnerability Detection and Response</a> (VDR) and <a href="https://fedramp.gov/2026/reference/vulnerability-evaluation-and-reporting/">Vulnerability Evaluation and Reporting</a> (VER) rules that will be finalized with the Consolidated Rules for 2026 by the end of June. These rules were introduced originally in August of 2025 in RFC-0012 then released as the VDR process in late 2025 for FedRAMP 20x. A Rev5 Open Beta of the VDR ran from February to May of this year.</p>
<p>Cloud service providers should be familiar with the VDR and the planned migration of all services from legacy vulnerability scanning to an exposure and threat-based approach. The VER, first introduced in the Public Preview of the Consolidated Rules for 2026, contains the evaluation and reporting rules from the VDR in a separate ruleset for convenience.</p>
<p>Any cloud service provider that follows the Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules will meet the timelines, prioritization requirements, and approach set out in BOD 26-04. The VDR and VER rules address BOD 26-04 requirements as follows:</p>
<ol>
<li>
<p><a href="https://fedramp.gov/2026/reference/vulnerability-evaluation-and-reporting/#evaluate-internet-reachability">VER-EVA-EIR (Evaluate Internet-Reachability)</a> requires an evaluation to determine if vulnerabilities are likely reachable over the internet. This requirement exceeds the BOD 26-04 requirement to evaluate if vulnerabilities are publicly exposed.</p>
</li>
<li>
<p><a href="https://fedramp.gov/2026/reference/vulnerability-evaluation-and-reporting/#evaluate-exploitability">VER-EVA-ELX (Evaluate Exploitability)</a> requires an evaluation to determine if vulnerabilities are likely exploitable. This addresses the requirements in BOD 26-04 to assess KEV Status and Exploit Automation.</p>
</li>
<li>
<p><a href="https://fedramp.gov/2026/reference/vulnerability-evaluation-and-reporting/#evaluation-factors">VER-EVA-EFA (Evaluation Factors)</a> expects evaluations to consider many factors that supplement the KEV Status, Exploit Automation, and Technical Impact evaluation required by BOD 26-04.</p>
</li>
<li>
<p><a href="https://fedramp.gov/2026/reference/vulnerability-evaluation-and-reporting/#assume-its-automatable">VER-EVA-AIA (Assume It’s Automatable)</a> is a new rule added to the VER rules that requires providers to assume exploits are automatable by default, unless they have evidence providing otherwise. This exceeds the requirements in BOD 26-04 to evaluate Exploit Automation.</p>
</li>
<li>
<p><a href="https://fedramp.gov/2026/reference/vulnerability-detection-and-response/#remediate-kevs">VDR-TFR-KEV (Remediate Kevs)</a> requires the remediation of KEVs according to the timelines in BOD 26-04 unless there are valid technical reasons not to do so.</p>
</li>
<li>
<p><a href="https://fedramp.gov/2026/reference/vulnerability-detection-and-response/#vulnerability-response">VDR-CSO-RES (Vulnerability Response)</a> requires the ongoing mitigation and remediation of vulnerabilities. This allows flexibility in addressing BOD 26-04 requirements to remediate specific vulnerabilities as cloud service providers may mitigate a vulnerability until it no longer is automatable or internet-reachable and therefore does not require full remediation.</p>
</li>
</ol>
<p>BOD 26-04 requires agencies to update processes along the following timelines:</p>
<ul>
<li>
<p>By August 7, 2026, agency policies must support ongoing vulnerability remediation.</p>
</li>
<li>
<p>By December 7, 2026, agencies must begin evaluating and remediating vulnerabilities following the timelines in BOD 26-04.</p>
</li>
</ul>
<p>FedRAMP has confirmed with CISA that cloud service providers following the Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules will meet or exceed the expectations for the protection of federal information required by BOD 26-04 while providing the necessary assurance to FedRAMP and their agency customers.</p>
<h2>Updated Continuous Monitoring Requirements for All Cloud Services</h2>
<p>Unfortunately cloud service providers who are not actively working to transition to the new FedRAMP vulnerability rules will not be able to provide the assurance that agencies will require under BOD 26-04; the legacy monthly vulnerability scanning process that most FedRAMP Rev5 Certified cloud services currently follow is insufficient.</p>
<p>An update to the mandatory continuous monitoring processes is required for all FedRAMP Rev5 customers to ensure federal information is appropriately protected by all FedRAMP Certified cloud service offerings in a way that aligns with this updated Binding Operational Directive for the federal government.</p>
<p>Mandatory adoption of the Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules was planned for June 1, 2027 with a grace period extending until January 1, 2028. The release of BOD 26-04 makes it clear that CISA will not accept slow incremental adoption of updated vulnerability detection and response methodologies to protect the U.S. Government. FedRAMP is required to align with guidance from CISA on the protection of federal information and cloud service providers who wish to maintain FedRAMP Certification must be able to meet government-wide assurance requirements such as those in BOD 26-04.</p>
<p><strong>To address BOD 26-04, FedRAMP will update the Consolidated Rules for 2026 prior to final release at the end of June as follows:</strong></p>
<ol>
<li>
<p>The Vulnerability Detection and Response rules will be mandatory for all cloud service offerings obtaining or maintaining FedRAMP Certification effective December 7, 2026.</p>
</li>
<li>
<p>The Vulnerability Evaluation and Reporting rules will be mandatory for all cloud service offerings obtaining or maintaining FedRAMP Certification effective December 7, 2026.</p>
</li>
<li>
<p>Additional reporting guidance will be provided for cloud service offerings that are not following the Certification Data Sharing rules yet.</p>
</li>
<li>
<p>FedRAMP will provide a grace period through March 7, 2027 where cloud service offerings may maintain their FedRAMP Certification under a corrective action plan (which will include notice to all agencies). After this date, FedRAMP Certification will be revoked for all cloud service offerings not following these rules.</p>
</li>
</ol>
<p><strong>Providers are fully responsible for ensuring they are aware of and follow FedRAMP Rules to obtain or maintain FedRAMP Certification.</strong> FedRAMP will notify all providers using the FedRAMP Security Inbox in addition to this Public Notice, and will communicate this Public Notice over all social media channels.</p>
<p>Please note that these rules may undergo minor changes during the final two weeks of the Public Preview of the Consolidated Rules for 2026. Providers should still familiarize themselves with the rules and begin preparing to follow them as quickly as possible. This notice will be updated once the Consolidated Rules for 2026 are finalized to avoid confusion in the future.</p>
<p>Cloud service providers are reminded that the timeframes stipulated in both FedRAMP’s Rules and CISA’s BOD 26-04 are maximum timeframes. Providers should mitigate and/or remediate vulnerabilities much faster than the maximum timeframe.</p>
]]></content:encoded>
      <pubDate>Tue, 16 Jun 2026 13:35:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0014</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0014.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0014.jpg" />
    </item>
    <item>
      <title>Initial Outcome of Rev5 Baseline RFCs (RFC-0026 through RFC-0030)</title>
      <link>https://fedramp.gov/notices/0013</link>
      <description>This Initial Outcome describes the changes FedRAMP will make to FedRAMP Rev5 requirements following RFC-0026 through RFC-0030.</description>
      <content:encoded><![CDATA[<p>FedRAMP released a series of proposed Rev5 guidance updates in late April, including RFC-0026 through RFC-0030. These proposed guidance updates were part of a broader set of changes being made to FedRAMP throughout the past year as a result of <a href="https://www.fedramp.gov/20x/">FedRAMP 20x</a> - a wide-scale rearchitecture of FedRAMP required by the <a href="https://www.fedramp.gov/docs/authority/law/">FedRAMP Authorization Act</a> and <a href="https://www.fedramp.gov/docs/authority/m-24-15/">OMB Memorandum M-24-15</a>.</p>
<p>In general, the changes FedRAMP proposed to Rev5 are intended to ensure that cloud service providers who have legacy FedRAMP Rev5 Certifications will be expected to provide a balanced level of automated assurance compared to FedRAMP 20x Certifications. This Public Notice explains the initial outcomes from these specific RFCs within the context of related RFCs and their outcomes; it is intended to summarize a subset of outcomes without reviewing the entirety of these changes.</p>
<p>FedRAMP is currently finalizing the Consolidated Rules for 2026, and has made that work available in advance of completion as a <a href="https://preview.fedramp.gov/2026">Public Preview</a>. The Consolidated Rules for 2026 will be finalized before the end of June 2026, and will incorporate the changes outlined in this and other outcomes from previous RFCs.</p>
<h2>The Future of FedRAMP Rev5</h2>
<p>FedRAMP has been clear since the announcement of FedRAMP 20x that an initial outcome from FedRAMP 20x will be the complete replacement of the FedRAMP Rev5 process. The current end date for new FedRAMP Rev5 Certifications is targeted at June 11, 2027; the current end date for existing FedRAMP Rev5 Certifications has not been finalized but is likely to be no later than 2029.</p>
<p>After considerable discussion with the community and in alignment with priorities set by the White House, FedRAMP will accelerate the transition for FedRAMP Rev5 by continuing to bring the responsibility, accountability, and flexibility of FedRAMP 20x to FedRAMP Rev5 in the near term. These mandated initial changes will make it easier for cloud service providers to transition to FedRAMP 20x over time by shifting their approach to align with the assurance expectations of FedRAMP 20x.</p>
<ul>
<li>
<p>FedRAMP is removing the vast majority of FedRAMP-assigned control parameter values for all FedRAMP Rev5 baselines in the Consolidated Rules for 2026, to address both of these problems.</p>
</li>
<li>
<p>FedRAMP is removing nearly all FedRAMP-specific control guidance that established additional rules and requirements from the FedRAMP Rev5 baselines in the Consolidated Rules for 2026.</p>
</li>
</ul>
<p>Additional information on these decisions is shared below.</p>
<h2>Removing FedRAMP-assigned Control Parameter Values</h2>
<p>The FedRAMP Rev5 controls, built from the NIST SP 800-53 Rev 5, have a significant number of <em>organization-defined</em> control parameter values. The process for assigning control parameter values is described in the <a href="https://csrc.nist.gov/pubs/sp/800/53/b/upd1/final">NIST SP 800-53B</a> as follows:</p>
<p><em>“Controls and control enhancements containing embedded parameters (i.e., assignment and controls and control enhancements to support specific organizational requirements. After the application of scoping considerations and the selection of compensating controls, organizations review the controls and control enhancements for assignment or selection operations and determine the appropriate organization-defined values for the identified parameters. The parameter values may be driven by mission or business requirements, or the values may be prescribed by laws, executive orders, directives, regulations, policies, standards, guidelines, or industry best practices.”</em></p>
<p>Historically, FedRAMP defined the vast majority of the organization-defined control parameter values in the FedRAMP Rev5 based on further guidance that organizations who work together frequently may develop a mutually agreeable set of control parameter values. These assigned values were set, in general, based on older standards agreed to by the Department of War and the Department of Homeland Security prior to any adoption of commercial cloud services.</p>
<p>FedRAMP 20x is built on the foundational idea that cloud service providers should be incentivized to make their commercial cloud service offerings available to the federal government instead of building gov-specific versions. FedRAMP-assigned values have the opposite effect by forcing a different approach that often does not align with commercial cloud service goals for many different reasons.</p>
<p>FedRAMP-assigned values have another critical negative impact: establishing a “minimum bar” for control parameters also effectively establishes a ceiling. There are almost no cloud service providers that try to exceed the FedRAMP-assigned values in their System Security Plan. If a FedRAMP-assigned value says something must be done at least every 30 days then it becomes a goal for all providers to only ensure they do this every 30 days, even when their commercial offering might actually take this action daily in a modern high-speed security environment.</p>
<p><strong>Outcome: FedRAMP is removing the vast majority of FedRAMP-assigned control parameter values for all FedRAMP Rev5 baselines in the Consolidated Rules for 2026, to address both of these problems.</strong></p>
<p>Cloud service providers will be expected to follow NIST rules to assign their own actual organization-defined control parameter values based on the actions taken by the cloud service, and identify these assignments within their System Security Plan (or future Security Decision Record) for review by FedRAMP and agencies. FedRAMP believes this will lead to more secure control implementations and more accurate control documentation.</p>
<h2>Removing Outdated FedRAMP Control Guidance</h2>
<p>FedRAMP also historically issued additional FedRAMP-specific control guidance that established additional rules and requirements for the implementation of government-specific demands on controls, similar to FedRAMP-assigned control parameters. Most of this control guidance was rooted in the historical FedRAMP JAB authorization process, also based on default historical implementations established by the Department of War and the Department of Homeland Security for their own information systems.</p>
<p>These additional requirements created the same problems as FedRAMP-assigned control parameter values, encouraging cloud service providers and assessors to focus on a typically older government-specific approach that is often inappropriate for a commercial cloud service and in some cases results in degraded security in a modern environment.</p>
<p>FedRAMP is now separately establishing explicit FedRAMP Rules for obtaining and maintaining a FedRAMP Certification. The Consolidated Rules for 2026 are designed to outline all the applicable rules that are uniquely necessary for a cloud service to assure government customers that their information will be properly secured. These rules are sufficient for both FedRAMP 20x and Rev5 type Certifications and replace control guidance in most situations.</p>
<p><strong>Outcome: FedRAMP is removing nearly all FedRAMP-specific control guidance that established additional rules and requirements from the FedRAMP Rev5 baselines in the Consolidated Rules for 2026.</strong></p>
<p>FedRAMP-specific requirements are instead implemented within the FedRAMP Rules. This change eliminates a significant number of hidden requirements that in most situations did not improve the security of a cloud service offering.</p>
<p>Control guidance will primarily be limited to tips and helpful information for otherwise confusing situations moving forward.</p>
<h2>Completing the Transition from Legacy Templates</h2>
<p>FedRAMP has historically required specific document and spreadsheet-based templates with rich formatting that required considerable manual effort to maintain. As cloud service providers transition to the Consolidated Rules for 2026 they will notice a new construct for FedRAMP materials - the Certification Package rules primarily list the minimum mandatory information and provide a simple JSON schema for sharing that information in a semi-structured machine-readable format.</p>
<p>Cloud service providers will be allowed to innovate on the details of how they present this information within the machine-readable format, and the considerable flexibility in the production of human-readable materials means cloud service providers may now focus on providing the optimum customer experience for both commercial and government customers for sharing information about their specific cloud service offering and its environment.</p>
<p>The new FedRAMP Certification Package will be comprised of the following primary documents:</p>
<ul>
<li>The <a href="https://preview.fedramp.gov/2026/reference/certification-package-overview/"><strong>Certification Package Overview</strong></a> replaces most of the traditional System Security Plan and consolidates information about the cloud service offering and its boundary.</li>
<li>The <a href="https://preview.fedramp.gov/2026/reference/security-decision-record/"><strong>Security Decision Record</strong></a> replaces the control implementation aspects of the System Security Plan and Security Assessment Report by consolidating information about each FedRAMP Practice, including rules, Rev5 Controls, and Key Security Indicators.</li>
<li>The <a href="https://preview.fedramp.gov/2026/reference/secure-configuration-guide/"><strong>Secure Configuration Guide</strong></a> replaces the Control Implementation Summary / Customer Responsibility Matrix and consolidates information about the customer responsibilities in a way that allows the cloud service provider flexibility to ensure the service is safely adopted without following a control template. FedRAMP will separately work with agencies to create standardized baselines that clearly separate the responsibilities so they can engage in the RMF process correctly.</li>
</ul>
<h2>Pending Replacement of FedRAMP Rev5</h2>
<p>FedRAMP would like to remind all cloud service providers that FedRAMP 20x is intended to replace FedRAMP Rev5. No date has been set for the complete replacement of existing FedRAMP Rev5 Certifications but the Office of Management and Budget may do so at any time. Cloud service providers that adopt all of these changes to FedRAMP Rev5 will be much better positioned to transition to FedRAMP 20x as needed.</p>
<p>FedRAMP will stop accepting new FedRAMP Rev5 Certification requests on June 11, 2027. Providers may wish to consider carefully whether or not to invest in a Certification Type that is being actively replaced.</p>
<h2>Mandatory Adoption</h2>
<p>In general, all cloud service offerings that have current FedRAMP Rev5 Certifications will need to adopt this new approach during their first FedRAMP independent assessment that is completed after January 1, 2027. Start planning now!</p>
<p>For new cloud service offerings seeking to obtain a FedRAMP Rev5 Certification, all of these requirements must be met for any application after January 1, 2027.</p>
<p>FedRAMP is currently targeting the end of June for the formal release of the FedRAMP Consolidated Rules for 2026, but providers can review all of the rules being finalized in the <a href="https://preview.fedramp.gov/2026">Public Preview</a>.</p>
<h2>General Comment Themes</h2>
<p>Due to the sweeping nature of this public notice and the rollup of many different RFCs that typically had very specific targeted feedback and commentary, FedRAMP is not supplying a breakdown of general comment themes and responding to them in this initial outcome.</p>
]]></content:encoded>
      <pubDate>Tue, 16 Jun 2026 13:30:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0013</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0013.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0013.jpg" />
    </item>
    <item>
      <title>Initial Outcome of RFC-0031 Updated Incident Communications Procedures</title>
      <link>https://fedramp.gov/notices/0012</link>
      <description>This Initial Outcome describes the changes FedRAMP will make to Incident Communications Procedures in response to RFC-0031.</description>
      <content:encoded><![CDATA[<p>The final significant guidance overhaul for the FedRAMP Consolidated Rules for 2026 was posted in <a href="https://www.fedramp.gov/rfcs/0031/">RFC-0031 Updated Incident Communication Procedures</a> on April 8, 2026. This RFC proposed updated guidance to long-standing historical Incident Communications Procedures that most cloud service providers <strong>were not properly following</strong> to establish a measurable framework that would ensure government agencies are properly notified of incidents that are likely to impact them.</p>
<p>Most importantly, the proposed guidance continued FedRAMP’s initiative to establish different expectations for services based on the FedRAMP Certification Class (or historical assured impact level) to ensure that expectations for Class D (High) services align correctly with agency customer expectations for mission-critical capabilities where a small incident could result in catastrophic damage to the federal government.</p>
<p>Many stakeholders, including trade associations, weighed in on this RFC with valuable insights and feedback. FedRAMP’s overall intent for implementing these changes remains unchanged after feedback, however many aspects of the final rules will be adjusted based on feedback.</p>
<p>The changes discussed in this Public Notice can be reviewed in context in the current Public Preview of the FedRAMP Consolidated Rules for 2026:</p>
<ul>
<li><a href="https://www.fedramp.gov/2026/reference/incident-evaluation-and-communication/">Incident Communication Procedures Complete Ruleset Reference</a>
<ul>
<li><em>Note: We are still working on some look-and-feel improvements in the human-readable versions of these materials.</em></li>
</ul>
</li>
<li><a href="https://fedramp.gov/2026/reference/vulnerability-detection-and-response/">Vulnerability Detection and Response Complete Ruleset Reference</a></li>
<li><a href="https://fedramp.gov/2026/definitions/">FedRAMP Definitions</a></li>
</ul>
<p><strong>These updated Incident Evaluation and Response rules will take effect on July 4, 2026 and will be mandatory as follows:</strong></p>
<ul>
<li>Any cloud service provider seeking to obtain a 20x Certification: July 4, 2026</li>
<li>Any cloud service provider seeking to obtain or maintain a Rev5 Certification: January 1, 2027</li>
<li>Any cloud service provider seeking to maintain their current pilot 20x Certification: January 1, 2027</li>
</ul>
<p><em>FedRAMP strongly encourages cloud service providers to adopt these updated procedures prior to the mandatory date.</em></p>
<h2>Changes to Potential Adverse Impact and Adverse Effects</h2>
<p>RFC-0031 leverages the approach from the Vulnerability Detection and Response rules for estimating the Potential Adverse Impact N (PAIN) rating for the entire government based on the likely Adverse Effects on customers of a cloud service. We have re-defined all of these terms from the perspective of a cloud service provider instead of a federal agency but the reuse of these long-standing terms with specific federal agency meaning continues to cause confusion with FedRAMP stakeholders.</p>
<p>One significant lesson of the past year for FedRAMP is that we must move away from using “dual-use” terms that mean one thing to federal agencies and a different thing for private companies. We must discontinue use of Potential Adverse Impact and Adverse Effects and replace this terminology with appropriate terms that apply only to private companies and that make sense within the overall context of a FedRAMP Certification and agency use of a commercial cloud service.</p>
<p>The following changes to this terminology will apply broadly across the FedRAMP Consolidated Rules for 2026, including the Vulnerability Detection and Response rules and the Incident Communication Procedures:</p>
<ol>
<li>
<p><em>Potential Adverse Impact</em> will be replaced with the plain language <a href="https://fedramp.gov/2026/definitions/#potential-agency-impact"><strong><em>Potential Agency Impact</em></strong></a> to reflect the underlying intent that what is being measured is the potential impact to federal agencies using the cloud service. The definition of Potential Agency Impact will be as follows:</p>
<p>The estimated cumulative effect of unauthorized access, disruption, harm, or other adverse impacts to all agencies using the cloud service that are likely to result from security incidents or the exploitation of vulnerabilities in the cloud service offering; as estimated following appropriate FedRAMP rules to calculate the Potential Agency Impact N-rating (PAIN).</p>
</li>
<li>
<p><em>Adverse Effects</em> will be replaced with the plain language <em>Customer Effects</em>, with the levels replaced with more appropriate plain language terminology for measuring the effects that a disruption would have on customers using the service.</p>
<p>a. <em>Catastrophic Adverse Effect</em> is replaced with <a href="https://fedramp.gov/2026/definitions/#debilitating-customer-effect"><strong><em>Debilitating Customer Effect</em></strong></a>: An unwanted customer effect that interrupts use of the cloud service for most users or compromises the integrity or confidentiality of most federal customer data. If the adverse customer effect is unknown then it should be treated as if it is debilitating until proven otherwise.</p>
<p>b. <em>Serious Adverse Effect</em> is replaced with <a href="https://fedramp.gov/2026/definitions/#disruptive-customer-effect"><strong><em>Disruptive Customer Effect</em></strong></a>: An unwanted customer effect that interrupts use of the cloud service for many users for less than 24 hours, or that compromises the integrity or confidentiality of large amounts or many types of federal customer data.</p>
<p>c. <em>Limited Adverse Effect</em> is replaced with <a href="https://fedramp.gov/2026/definitions/#narrow-customer-effect"><strong><em>Narrow Customer Effect</em></strong></a>: An unwanted customer effect that interrupts use of the cloud service for some users for less than 12 hours, or that compromises the integrity or confidentiality of an extremely limited amount and type of federal customer data.</p>
<p>d. <em>Negligible Adverse Effect</em> is replaced with <a href="https://fedramp.gov/2026/definitions/#minimal-customer-effect"><strong><em>Minimal Customer Effect</em></strong></a>: An unwanted customer effect that is only noticeable by some users. This includes minor inconveniences such as reduced performance.</p>
</li>
</ol>
<h2>Overall Impact on Incident Communication Procedures</h2>
<p>The following aspects of the proposed Updated Incident Communication Procedures will be changed in the Consolidated Rules for 2026:</p>
<ol>
<li>
<p><strong>Availability Reporting rules</strong> will move from Incident Communication Procedures into the Certification Data Sharing ruleset, required sharing will be limited to all necessary parties (the RFC required this to be public), and this will be a requirement instead of a recommendation for Class B Certifications.</p>
<p>a. The Certification Data Sharing ruleset is a more appropriate home for this updated rule since it isn’t really about incident reporting procedures anymore.</p>
<p>b. FedRAMP recognizes that some cloud services are configured such that only an active customer would be able to determine if their specific tenant instance is down and in such cases sharing this information with the public is unnecessary or even inappropriate.</p>
<p>c. <strong>See:</strong> <a href="https://fedramp.gov/2026/reference/certification-data-sharing/#availability-reporting">CDS-CSO-AVR (Availability Reporting)</a></p>
</li>
<li>
<p><em>Federal reportable incidents</em> will be renamed <a href="https://fedramp.gov/2026/definitions/#fedramp-reportable-incident"><strong><em>FedRAMP reportable incidents</em></strong></a> to clarify that these are FedRAMP Certification requirements, unrelated to other types of incidents that should be reported to the government under other laws or agreements.</p>
</li>
<li>
<p>Evaluation of an incident to estimate the Potential Agency Impact N (PAIN) rating for the federal government will be optional; providers that do not estimate the PAIN will be required to report all incidents as if they are PAIN5 by default.</p>
<p>a. This change allows providers to maintain a single automated workflow against a single timeline to operate a simpler process with better customer experience if they determine this is in their business interest.</p>
<p>b. <strong>See:</strong> <a href="https://www.fedramp.gov/2026/reference/incident-evaluation-and-communication/#default-pain-rating">ICP-CSO DPR (Default PAIN Rating</a>) and <a href="https://www.fedramp.gov/2026/reference/incident-evaluation-and-communication/#estimate-federal-impact">ICP-CSO-EFI (Estimate Federal Impact)</a></p>
</li>
<li>
<p>Clarification will be added to indicate that initial “evaluation” of the incident for FedRAMP Incident Communication Procedures is completed when it has been determined to be a FedRAMP reportable incident and the Potential Agency Impact N (PAIN) rating has been estimated (if applicable).</p>
<p>a. The purpose of this evaluation is to determine if a notification is necessary and how that notification should proceed, so the notification requirement rules need to explicitly reference these rules to avoid confusion if they are read by themselves.</p>
<p>b. <strong>See:</strong> <a href="https://www.fedramp.gov/2026/reference/incident-evaluation-and-communication/#activity-workflow-incident-communications">Activity Workflow: Incident Communications</a></p>
</li>
<li>
<p>A new SHOULD rule will be created to strongly encourage the adoption of automated incident communication capabilities.</p>
<p>a. Providers should not be hand-crafting artisanal incident notifications and personally sending them to all affected parties. These should be managed centrally, automatically triggered based on movement between statuses, and automatically sent with all appropriate updates on the timeframes expected to all affected parties.</p>
<p>b. <strong>See:</strong> <a href="https://www.fedramp.gov/2026/reference/incident-evaluation-and-communication/#automated-incident-reporting">ICP-CSO-AIR (Automated Incident Reporting)</a></p>
</li>
<li>
<p><strong>Incident Reports:</strong> Reporting rules that require the inclusion of information will be rephrased to clarify that the requirement is a timely notification with as much information as is available - if information is not available then that’s fine, send what you have. Minor changes will be made to the default expected additional information for incident reports. An additional requirement will be added for incident reporting that will require the cloud service provider to include a list of likely affected customer agencies in the notification. Requirements for incident reports will now vary slightly by Class.</p>
<p>a. <strong>See:</strong> <a href="https://www.fedramp.gov/2026/reference/incident-evaluation-and-communication/#initial-incident-report">ICP-CSO-IIR (Initial Incident Report)</a> and <a href="https://www.fedramp.gov/2026/reference/incident-evaluation-and-communication/#ongoing-incident-reports">ICP-CSO-OIR (Ongoing Incident Report)</a></p>
</li>
<li>
<p>FedRAMP will no longer expect private companies to report incidents regarding agency customers directly to CISA. Instead, agencies using these cloud services will be expected to do so based on the identified impact to their own agency services.</p>
<p>a. This will help CISA establish the actual scope of impact to the federal government as they are not otherwise aware of what agencies are using these cloud services or how they are using them - having individual agencies reporting this information based on the measured impact within the context of their use provides more appropriate data.</p>
<p>b. Please note some cloud service providers may have legacy contract agreements that supersede this.</p>
</li>
<li>
<p>Based on the updated and clarified definitions, the Incident Report Timeframes will be adjusted as follows:</p>
<p>a. Class D (High) N5, N4, and N3 timeframes will all require 15min IIR, 3hr OIR, and 3hr FIR.</p>
<p>b. Class C (Moderate) N5, N4, and N3 will require all 1hr IIR, 6hr OIR, 6hr FIR.</p>
<p>c. Class B (Low) and Class A (Pilot) N5, N4, and N3 will all require 6hr IIR.</p>
<p>d. All other requirements will stay the same.</p>
<p>e. It’s worth noting that a PAIN5 or PAIN4 incident should effectively never occur in a Class D or Class C service under normal operations if they are built properly, and PAIN3 incidents should be incredibly rare.</p>
<p>f. <strong>See:</strong> <a href="https://www.fedramp.gov/2026/reference/incident-evaluation-and-communication/#initial-incident-report">ICP-CSO-IIR (Initial Incident Report)</a>, <a href="https://www.fedramp.gov/2026/reference/incident-evaluation-and-communication/#ongoing-incident-reports">ICP-CSO-OIR (Ongoing Incident Report)</a>, and <a href="https://www.fedramp.gov/2026/reference/incident-evaluation-and-communication/#final-incident-report">ICP-CSO-FIR (Final Incident Report)</a>.</p>
</li>
</ol>
<hr>
<h2>General Comment Themes</h2>
<p>This section contains additional optional insights and background on this RFC. It is information dense and does not add any critical information beyond that expressed earlier in this outcome.</p>
<p>This section is intended for FedRAMP stakeholders who always request additional information to understand decisions and are willing to invest considerable time in reviewing additional context.</p>
<p><strong>Concerns about reporting timeframes:</strong></p>
<p>The timeframes proposed in this RFC, and carried forward into the final rules, are based on the expectation that cloud service providers will use modern incident management systems that include automatic communication capabilities to ensure that all affected parties will receive timely notification of incidents so that they can respond appropriately. This is especially critical for FedRAMP Certified Class D services where such incidents are likely to have a catastrophic adverse effect on a federal agency customer and cause significant damage to the U.S. government.</p>
<p>Providers are strongly encouraged to exceed these required time frames and drive this number as close to 0 as possible across all levels of FedRAMP Certification. Incident communication is a critical customer experience necessity where every minute can result in harm to the public because of the likely impact to federal customer data.</p>
<p>That said, the definitions of these events are designed to truly identify very serious events. A PAIN5 event should be on the level of a hundred-year flood, a circumstance where a massive series of chained events led to an impact that is nearly unimaginable or there was a significant gap in the security protocols that are expected to be in place. Examples of this from FedRAMP’s experience are incredibly rare and typically involve rogue or compromised administrative accounts that were used maliciously to destroy a cloud service from within (or, in 2026, an AI agent given far too many permissions and left to act without proper limits and oversight). These are circumstances where every moment matters for customers.</p>
<p><strong>Evaluating Potential Adverse Impact to the federal government:</strong></p>
<p>FedRAMP has reused the common “potential adverse impact” terminology from government information security standards with explicit definitions that are intended to help a cloud service provider estimate the potential adverse impact of a vulnerability or incident to the entire federal government.</p>
<p>This is done by calculating the likely adverse effect, defined by four categories: negligible, limited, serious, and catastrophic. These effects are calculated based on metrics that a cloud service provider can measure, such as a degradation in performance for all users or unauthorized disclosure of all customer data in a system. The expectation is that a cloud service provider will estimate the effect on users of their service, not the actual effect on the agency or its mission.</p>
<p>The cloud service provider then supplies sufficient information the agency customer so that the agency itself can determine the actual potential adverse effect on agency operations, which is why incident communications and vulnerability detection and response are so critical - they must assume, to some degree, that the agency is using the service for critical services commensurate with the FedRAMP Certification Class commitments.</p>
<p>Recently FedRAMP has made a concerted effort to move away from terms that legal or policy frameworks apply explicitly to federal government information systems in order to clarify that private companies are not subject to these rules even if their service is included in a federal information system. We’ve updated this set of terminology and expectations to align with this approach by removing the reuse of standard federal terminology.</p>
<p><strong>Reporting clock on evaluation:</strong></p>
<p>Many folks commented about the lack of clarity in when the “clock starts” for the notification requirements because we used the phrase “within [time] of evaluation” without making it clear that evaluation was the outcome of 2 specific rules that require evaluating the incident to determine if it was likely to affect confidentiality or integrity of federal data along with the potential impact to agencies. It should be clear that once a cloud service provider has determined that an incident is likely to have an impact on an agency customer and evaluated what that overall impact is likely to be, that the next step is immediate notification about this. By this time most of the information about the incident will be available as it may be hours or even days into initial incident detection and response activities.</p>
<p>In short, the clock only starts for reporting when the organization has appropriately (and promptly) come to the conclusion that the incident must be reported. At that point action must be taken at all reasonable speed to perform the notification.</p>
<p>This is also why the entire timeline is requested - it is not a violation of these procedures if a cloud service provider regularly waits for days after identifying an incident before they evaluate the incident to determine if it’s likely to affect federal customer data, but it’s very likely to cause customer agencies to re-evaluate their use of a service that does not take federal customers seriously.</p>
<p><strong>Confusion related to CIRCIA reporting:</strong></p>
<p>CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act, which requires regulatory activities related to critical infrastructure by the Cybersecurity and Infrastructure Security Agency. This act, and these regulations, are related to national security and other similar interests regarding covered entities that experience incidents in their own operation regardless of whether or not they have federal agency customers.</p>
<p>CIRCIA is entirely unrelated to FedRAMP and is entirely irrelevant in the context of FedRAMP Certification. FedRAMP has nothing to do with CIRCIA and vice versa.</p>
<p>FedRAMP Incident Communication Procedures create requirements specific to reporting incidents that are likely to affect <em>federal customer information</em> that is handled by cloud service providers under a contract or other agreement with that federal agency. This is not to provide overall intelligence or insight into incidents related to potential national security interests but is intended to ensure that a federal agency customer is immediately notified of an incident so that the federal agency can begin triage and related incident response activities as required by federal policy.</p>
<p>We may have inadvertently caused some of this confusion by using the term “federal reportable incident” for incidents that impact federal customer data inside a cloud service provider, and will rename this term to “FedRAMP reportable incident” to be clear that this is entirely about the relationship a FedRAMP Certified cloud service provider will have with its customer agencies.</p>
<p><strong>Resetting the default definition of incident and creating a separate category of reportable incidents:</strong></p>
<p>In this update to Incident Communication Procedures, FedRAMP rescoped the definition of <em>incident</em> to include all incidents so that we could add an evaluation phase to incident management in a way that made sense. As long as the definition included only those incidents that affected federal customer data there was a bit of a race condition - how could a cloud service provider evaluate an incident to determine if it was likely to affect federal customer data if an incident was by definition likely to affect federal customer data? This would result in no incidents ever being identified or evaluated.</p>
<p>Resetting the definition of incident to a general definition prevents any confusion that incidents should be handled, tracked, and otherwise managed by a cloud service provider following its policies whether or not the incidents have been determined to affect federal customer data. It enables the basic evaluation process so that at some point in the lifecycle of an incident it can be evaluated to determine if it’s likely to impact federal customer data along with the potential agency impact across the government. Only when this evaluation shows that it’s likely to impact federal customer data, especially the confidentiality or integrity of such data, does it need to be reported to all affected parties.</p>
<p>We think most of the confused feedback about the change to this definition was the result of folks writing down feedback during their first time reading through the policy since it should be obvious a few paragraphs later that the scope of reporting has been reduced overall, not increased. We strongly encourage folks to read through an entire RFC to understand the whole context before providing feedback on specific sections early in the document.</p>
<p><strong>Requests for templates and other incident reporting schemas:</strong></p>
<p>FedRAMP encourages cloud service providers to compete by providing better customer experiences for their customers in the reporting of Certification Data such as Incident Reports. We do not provide schemas or templates for this reporting to encourage thoughtful implementations that go far beyond a basic spreadsheet or generic ordered lists.</p>
<p>This has been a consistent shift with FedRAMP over the past year and will be carried across the FedRAMP Consolidated Rules for 2026 with the removal of nearly all templates. Cloud service providers are strongly encouraged to engage user experience designers and do their own research based on their own potential capabilities to provide the best possible customer experience for all of their customers.</p>
<p>That said: We are currently considering including basic JSON schemas for a few critical aspects of specific reporting to create a standardized approach here. These will be included in the Consolidated Rules for 2026. The intent is only to identify high level structure for certain reporting situations in a machine-readable format while encouraging metadata and additional information to be supplied in the most effective way.</p>
<p><strong>Reporting federal agency impacts directly to CISA:</strong></p>
<p>Historically FedRAMP has applied federal agency standards directly to private companies running cloud services and treated them as if they are government entities, instead of a private company providing a service to the government. This included the requirement for cloud service providers to follow federal incident reporting guidelines from CISA to report incidents directly to CISA. We kept this requirement in the proposed updated Incident Communication Procedures because it’s always been that way and we wanted to ensure that CISA was in the loop when such incidents happen, but have not interrogated the requirement under the current posture of FedRAMP.</p>
<p>Commenters rightly pointed out that this requirement does not align with the current direction and posture of FedRAMP. Cloud service providers do not and can not understand the actual impact to agency operations caused by an incident on their platform, and therefore should not be reporting such incidents to CISA on behalf of agency customers. Instead of ensuring clear information is transmitted to CISA, this reporting requirement creates additional noise.</p>
<p>For example, a cloud service provider may determine during an incident that all federal agency customer data in their platform has been exposed and exfiltrated; without insight into what this type of data is, reporting of such an incident would be a significant concern to CISA. It may turn out that the agency does not care at all about this data and that it’s already just public information it copied from elsewhere, resulting in no actual incident of importance at all, wasting everyone’s time. Or it may turn out to be highly sensitive data that could expose the federal government to extremely high risk. In any situation on that spectrum, it is the responsibility of the affected <strong>agency</strong> to notify CISA of the details of the incident based on the impact to agency functions or services.</p>
<p>This makes incident reporting from cloud service providers to agency customers all the more critical, as agencies will need to immediately evaluate the incident to determine the impact to their own functions and services in order to report it to CISA. Therefore we have decreased the maximum timeframes for notifications of incidents with a high potential adverse impact so that providers will rapidly communicate this information to agencies, but we have removed the expectation that providers report directly to CISA themselves. Agencies will receive additional guidance to ensure they understand the importance of notifying CISA directly of incidents that impact them.</p>
]]></content:encoded>
      <pubDate>Wed, 03 Jun 2026 20:20:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0012</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0012.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0012.jpg" />
    </item>
    <item>
      <title>Initial Outcome of RFC-0025 Retrospective on the Public Comment Process</title>
      <link>https://fedramp.gov/notices/0011</link>
      <description>This Initial Outcome describes the changes FedRAMP will make to the RFC process based on RFC-0025.</description>
      <content:encoded><![CDATA[<p>FedRAMP’s Requests for Comment (RFC) process is designed to share potential guidance changes early to gather feedback before decisions are finalized. Unlike more traditional government comment processes, which can be lengthy and highly procedural, FedRAMP uses RFCs as a practical way to test ideas, refine guidance, and improve outcomes.</p>
<p>RFC-0025, opened on March 18, 2026, invited feedback on how FedRAMP has managed this new RFC process. The strongest theme in the responses was a request for more insight into how comments shape final guidance, and this Initial Outcome responds by outlining planned improvements to future RFCs while addressing key themes raised by commenters.</p>
<p>We’ve enjoyed reading and discussing all of your feedback during this time - during a busy RFC period we often spend hours arguing about the things you have written. FedRAMP is demonstrably better because of the RFC process and we want to encourage many more stakeholders to interact directly with us in the FedRAMP Community. We’re not quite there yet, but we’ll know when we’re successful when more people are actually commenting instead of just talking about RFCs on social media platforms!</p>
<h2>Changes to Future RFCs</h2>
<p>FedRAMP will make the following changes to our Request For Comments process based on this retrospective:</p>
<ol>
<li>Initial Outcomes will all include a “General Comment Themes” or similar section that summarizes key themes and how FedRAMP responded to those themes in shaping the outcome.</li>
<li>In rare situations, the comment window may be extended past 30 days. Future RFCs will clarify that individual, partial comments about specific issues throughout the comment window are strongly preferred over large consolidated comments submitted at the end of the window.</li>
<li>Open RFCs will be limited to a maximum of 3 simultaneous RFCs at any given time.</li>
<li>A public comment form option will return, replacing the option to submit comments over email (except for federal agencies).</li>
</ol>
<p>GitHub will continue to be our primary mechanism for interacting with the public in the FedRAMP Community. Stakeholders are strongly encouraged to participate in this forum.</p>
<h2>General Comment Themes</h2>
<p>This section contains additional optional insights and background on this RFC. It is information dense and does not add any critical information beyond that expressed earlier in this outcome. This section is intended for FedRAMP stakeholders who always request additional information to understand decisions and are willing to invest considerable time in reviewing additional context.</p>
<h3>Sharing Insight on How Public Comment Shapes Outcomes</h3>
<p>FedRAMP considers every public comment both individually and as part of the broader feedback received. Specific edits, such as clarifying language or correcting errors, may be incorporated directly. Broader themes are reviewed more carefully in light of the overall intent and purpose of the proposed guidance.</p>
<p>The most important factor for FedRAMP is the intent and purpose of the proposed guidance - this usually, but not always, remains unchanged by public comment. We do not intend to address comments about the intent or purpose a second time by reinforcing them during the outcome unless there is a considerable change to the intent or purpose during the outcome. (See <a href="https://www.fedramp.gov/notices/0002/">Outcome from RFC-0019 Reporting Assessment Costs</a> as an example of public comment overriding the original intent or purpose of an RFC)</p>
<p>We began sharing Initial Outcomes to help folks quickly understand the results of RFCs before things are integrated into larger documentation or policy updates, and intend to continue this process. We have avoided sharing explanations of why certain themes or comments were not incorporated but moving forward we will add a section similar to this one that addresses the major common themes with additional explanation of how they were handled.</p>
<p>Many commenters requested a detailed comment-by-comment disposition; this is not and will not be part of the formal FedRAMP public comment process due to the extensive burden and lack of utility for addressing every single statement in every single public comment. The public is welcome to engage FedRAMP in discussion in the FedRAMP Community about any topic and any time.</p>
<h3>Length of the Public Comment Window</h3>
<p>Many commenters brought up the 30 day default public comment window and raised concerns about the difficulty of reviewing, gathering, and creating detailed responses in that time frame; many requested longer time-frames.</p>
<p>The intent of FedRAMP’s RFC process is to generate rapid partial comments on specific issues; incredibly long consolidated responses, especially those from groups of cloud service providers, are not what FedRAMP is looking for. We consider all comments, but parsing through broad thematic comments representing many different sections with many different stakeholders is unnecessarily complex.</p>
<p>Our short comment windows are designed to incentivize early participation with partial comments, and commenters are strongly encouraged to supply separate comments for separate things. We prefer many different perspectives from individual members of the public or individual companies, and intentionally do not provide extra time for consolidation because that weakens the incentive for individual comments. Early and frequent participation encourages additional participation, allows commenters to respond to other commenters, and generally provides richer feedback.</p>
<p>In the future, FedRAMP will consider extending comment windows if a significant amount of proposed guidance is being adjusted at the same time. At the same time, FedRAMP will clarify that we expect early and frequent partial comment, and that commenters who provide large consolidated comments at the end of the window are not ideal.</p>
<h3>Too Many RFCs at the Same Time!</h3>
<p>Yup, fair.</p>
<p>This past year FedRAMP has been under intense pressure (mostly from you, the stakeholder community) to rapidly address long-standing issues with the FedRAMP process at high speed. Stakeholders were expected to invest considerable time in following FedRAMP and maintaining insight and awareness into these changes on purpose.</p>
<p>During the next year we expect most RFCs to be small or targeted around a specific theme, such as for the FedRAMP 20x Class D pilot. These RFCs will be targeted at folks who are ready and able to invest the time and effort necessary to keep up with FedRAMP. We will still post multiple RFCs at the same time so that folks can approach them together in context, but will limit them in the future to avoid “RFC bombs” of many simultaneous RFCs across a wide variety of subjects.</p>
<h3>Anonymity and Accessibility for Commenting</h3>
<p>Various commenters indicated a desire to comment anonymously, or expressed concerns about the accessibility of GitHub discussions for comments. The primary option to address this feedback would be for FedRAMP to move all RFCs to <a href="http://Regulations.gov">Regulations.gov</a>, but that would significantly reduce the feeling of community and create a much higher barrier to entry. We expect that folks expressing concerns on the difficulty of using FedRAMP’s RFC process may not have seen the way most government programs are forced to handle this activity.</p>
<p>GitHub will continue to be our primary mechanism for collecting and displaying public comment, using a community-based modern platform that we are authorized to use, following a process that has been vetted and approved by our Office of General Counsel.</p>
<p>In the future, we will also create a public form that will allow anonymous comments. At the same time, we will stop accepting public comments sent via email or attached via documents (agencies will still be allowed to submit via email), so that we can automate the process of publicly sharing comments that are not submitted in GitHub.</p>
<h3>Providing Extensive Context on each RFC</h3>
<p>Several commenters asked for before-and-after comparisons, additional background, and broader context in future Requests for Comment. FedRAMP understands why that information can be helpful, especially for stakeholders who are newer to a topic or reviewing a proposal quickly.</p>
<p>At the same time, FedRAMP has found that very long Requests for Comment are harder to review and reduce participation. In many cases we have seen that additional background links and other information is entirely ignored by commenters as they dive into specific statements or write down feedback linearly without considering the entire context. For that reason, FedRAMP will continue aiming for shorter, clearer Requests for Comment that focus on the proposed change and the feedback needed from the community.</p>
<h3>Publicizing New RFCs</h3>
<p>A surprising number of commenters indicated that they were unaware of RFCs in process until late in the comment period.</p>
<p>FedRAMP announces RFCs through several channels, including email updates, social media, the FedRAMP website Changelog, the Changelog RSS feed, and Community Updates. We effectively saturate all of our official channels when an RFC is posted, but do not have an official way to reach stakeholders that are outside these official channels.</p>
<p>The best way to receive FedRAMP updates is to subscribe to the FedRAMP email list using the “Subscribe” button under “Keep Up to Date” at the bottom of the FedRAMP website. FedRAMP uses this list for meaningful updates and does not intend to overwhelm subscribers with unnecessary messages.</p>
<p>FedRAMP will continue using multiple announcement channels, but stakeholders who want to stay closely informed should subscribe to email updates, follow FedRAMP on social media, or subscribe to the Changelog RSS feed.</p>
]]></content:encoded>
      <pubDate>Wed, 27 May 2026 20:30:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0011</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0011.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0011.jpg" />
    </item>
    <item>
      <title>FedRAMP Response to CISA V1 ED 25-03</title>
      <link>https://fedramp.gov/notices/0010</link>
      <description>FedRAMP has been tasked with ensuring all federal agencies have the information they need from cloud services to respond to this Emergency Directive. This will avoid massive duplicative work for agencies and all cloud services.</description>
      <content:encoded><![CDATA[<p>This is a real emergency and <strong>action is required</strong> in response to <a href="https://www.cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices">CISA V1: ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices</a>. This is NOT a test.</p>
<p>FedRAMP has been tasked with ensuring all federal agencies have the information they need from cloud services to respond to this Emergency Directive. This will avoid massive duplicative work for agencies and all cloud services.</p>
<p>Providers MUST complete required actions and report status to FedRAMP (Step 8) by <strong>5:00 PM ET April 29, 2026</strong> regardless of impact level.</p>
<p><strong>PLEASE URGENTLY TAKE THE FOLLOWING REQUIRED ACTIONS IN ORDER!</strong></p>
<ol>
<li>
<p>Providers MUST review <a href="https://www.cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices">CISA V1: Emergency Directive 25-03</a> to understand affected systems.</p>
</li>
<li>
<p>Providers MUST identify all public-facing Cisco Firepower 1000, 2100, 4100, 9300 series and Secure Firewall 200, 1200, 3100, 4200, and 6100 series devices within the FedRAMP boundary for their cloud service offering(s).</p>
<p><em>If no in-scope systems are identified, <strong>skip to step 8.</strong> Steps 3-7 are not required if no in-scope systems are identified. If in-scope systems are identified, proceed to step 3.</em></p>
</li>
<li>
<p>Providers SHOULD collect logs from affected systems as outlined in the <a href="https://www.cisa.gov/news-events/directives/supplemental-direction-ed-25-03-core-dump-and-hunt-instructions">Supplemental Direction ED 25-03: Core Dump and Hunt Instructions</a> to assist with hunt activities.</p>
</li>
<li>
<p>Providers MUST evaluate all identified devices for indicators of compromise. If any indication of compromise or anomalous behavior is found or there is any suspected impact to federal systems, providers MUST follow the <a href="https://www.fedramp.gov/docs/rev5/playbook/csp/continuous-monitoring/incident-communication/">FedRAMP Incident Communication Procedures</a>, which includes reporting to CISA and agency customers.</p>
<p>a. Providers SHOULD use CISA’s <a href="https://www.cisa.gov/news-events/analysis-reports/ar26-112a">FIRESTARTER Backdoor Malware Analysis Report</a> and/or other available threat intelligence reports to evaluate for indicators of compromise.</p>
<p>b. Providers MAY submit core dumps of Cisco devices to CISA’s <a href="https://www.cisa.gov/resources-tools/services/malware-next-generation-analysis">Malware Next Gen portal</a> for evaluation.</p>
</li>
<li>
<p>If no indicators of compromise are present, providers MUST apply Cisco-provided updates to all of the CVEs identified in the Emergency Directive by <strong>11:59PM EST on April 24, 2026.</strong> This includes:</p>
<p>a. The software updates to address CVE-2025-20333 and CVE-2025-20362, if not already patched; and,</p>
<p>b. The recently released patch created for this specific persistence issue (links provided by device type in CISA’s step-by-step <a href="https://www.cisa.gov/news-events/directives/supplemental-direction-ed-25-03-core-dump-and-hunt-instructions">Core Dump and Hunt Instructions</a>).</p>
</li>
<li>
<p>Providers MUST perform a hard reset of the device(s) by physically unplugging the device’s power supply, as a reboot is not sufficient to expunge the malware, no later than <strong>April 29, 2026</strong>.</p>
</li>
<li>
<p>Providers MUST upload supplemental information to the Incident Response folder in the FedRAMP repository and notify all agency customer Authorizing Official (or ISSO) POCs with notification of the completed action(s).</p>
<ul>
<li>
<p><strong>File Format</strong>: Files should be compatible with modern spreadsheet applications. Acceptable file formats are Comma Separated Values (csv) or Microsoft Excel (xlsx).</p>
</li>
<li>
<p><strong>Filename</strong>: ED-25-03-V1-Response-[FRID]</p>
</li>
</ul>
<p>Note: Replace the [FRID] placeholder with your corresponding information.</p>
<ul>
<li><strong>Recommended content</strong>:
<ul>
<li>
<p>List of the type(s) of affected systems.</p>
</li>
<li>
<p>Summary of actions taken and results, including the collection of artifacts, patching, and hunting actions.</p>
</li>
<li>
<p>Additional information you wish to provide to customers</p>
</li>
</ul>
</li>
</ul>
</li>
<li>
<p>Complete the FedRAMP V1: Emergency Directive 25-03 Response Form by <strong>5:00 PM ET April 29, 2026</strong>.</p>
<p><em>Please Note: Cloud service providers will have received an email in their FedRAMP Security Inbox with a link to the form. This Public Notice does not include the link!</em></p>
</li>
</ol>
<p><strong>Corrective Action</strong></p>
<p>Corrective action will include public notification that the provider is not following FedRAMP Security Inbox rules.</p>
<p><strong>Additional Background</strong></p>
<p>If any indication of compromise or anomalous behavior is found or there is any suspected impact to federal systems, follow the <a href="https://www.fedramp.gov/docs/rev5/playbook/csp/continuous-monitoring/incident-communication/">FedRAMP Incident Communication Procedures</a>, which includes reporting to CISA and agency customers.</p>
<p>This email has also been posted as a FedRAMP Notification here: <a href="http://fedramp.gov/notices/0010">fedramp.gov/notices/0010</a></p>
<p>If you have any questions, please reach out to <a href="mailto:info@fedramp.gov">info@fedramp.gov</a> and <a href="mailto:CyberDirectives@cisa.dhs.gov">CyberDirectives@cisa.dhs.gov</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Apr 2026 18:00:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0010</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0010.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0010.jpg" />
    </item>
    <item>
      <title>Initial Outcome from RFC-0024 Rev5 Machine-Readable Packages</title>
      <link>https://fedramp.gov/notices/0009</link>
      <description>RFC-0024 Rev5 Machine-Readable Packages was closed on March 11, 2026. This notice explains the initial outcome from public comment and the next steps for FedRAMP.</description>
      <content:encoded><![CDATA[<p><a href="https://fedramp.gov/rfcs/0024">RFC-0024 FedRAMP Rev5 Machine-Readable Packages</a> was closed on March 11, 2026. This notice explains the initial outcome from public comment and identifies next steps for FedRAMP related to this proposal. The official outcome from this RFC will be included in the FedRAMP Consolidated Rules for 2026 (CR26) that will be published by the end of June 2026; those rules will be valid until December 31, 2028.</p>
<p>We are especially grateful for the considerable thoughtful public comment on this RFC and will work hard to chart a course that aligns the expectations of the government with those that provide commercial services for its use.</p>
<h2>Overview</h2>
<p>FedRAMP 20x was designed to open the federal market to thousands of new cloud services that invest in automation capabilities to demonstrate continuously validated security metrics. FedRAMP has nearly completed the first two pilot phases for FedRAMP 20x and is nearing release of formal FedRAMP 20x requirements and wide-scale adoption of this new certification type. Every single FedRAMP 20x certification package will include machine-readable authorization data across the entire scope of the authorization package, from initial security materials to ongoing authorization reports including data on significant changes and vulnerabilities. FedRAMP anticipates an explosion in adoption of automation capabilities government-wide as agencies suddenly have access to the exact automation data they have requested for many years.</p>
<p>Cloud service providers with traditional FedRAMP Rev5 certifications will face considerable competition from those with FedRAMP 20x certifications. The difference in initial and ongoing authorization experience for agencies will be stark and difficult to overcome if FedRAMP Rev5 requirements remain focused around manual documentation. FedRAMP cannot simply abandon the 500+ cloud services that have invested in FedRAMP Rev5 certifications by allowing them to stagnate while new services with FedRAMP 20x certifications provide superior continuous assurance and higher quality integrations.</p>
<p>FedRAMP acknowledges that a significant majority of public comments on RFC-0024 expressed deep concerns about the complexity of adopting a modern approach to managing legacy security materials after years of investment in a manual process. FedRAMP must chart a course that ensures adequate information is available to agencies even as the expectations of agencies grow and change, but commenters have nearly universally requested additional time to prepare for adopting a modern approach. Therefore, FedRAMP will update both the expected requirements and timelines to enable gradual adoption over a much longer period of time while still ensuring that all Rev5 providers have modernized their approach within two years.</p>
<p>In the Consolidated Rules for 2026, FedRAMP will outline explicit requirements for machine-readable packages for Rev5, generally aligned with those proposed in RFC-0024. This will include providing detailed instructions of exactly what should be in machine-readable formats and options for the general structure of those formats, along with integration into FedRAMP compatible trust centers to ensure agencies can eventually consume this information via API. This data and these mechanisms will be provided by industry in alignment with FedRAMP’s mandate to set policies that enable industry innovation to provide the solutions.</p>
<p>Members of the community may discuss this initial outcome and ask clarifying questions as needed in the <a href="https://github.com/FedRAMP/community/discussions/137">General discussion / Q&#x26;A on Rev improvements and changes in 2026</a> thread in the FedRAMP Community and attend <a href="https://fedramp.gov/events">FedRAMP Rev5 Community Updates</a> for live Q&#x26;A.</p>
<h2><strong>Initial Outcome</strong></h2>
<blockquote>
<p><strong><em>Detailed information, requirements, and timelines for all items below will be provided in the Consolidated Rules for 2026.</em></strong></p>
</blockquote>
<p>All of the proposed requirements in RFC-0024 will be modified in the Consolidated Rules for 2026, though many will carry forward in the same spirit.</p>
<p>Broadly, the following changes will be made, based on public comment, to the rules and approach initially proposed in RFC-0024:</p>
<ol>
<li>
<p><strong>Comprehensive machine-readable authorization data will only be required for FedRAMP Rev5 Class D (High) certifications.</strong></p>
<p>a. Rev5 Class D (High) certified providers will be required to create and maintain per-service authorization materials as proposed.</p>
<p>b. Rev5 Class D (High) certified providers will be required to integrate significant changes into their authorization materials twice per year (once during annual assessment, once halfway between annual assessments) instead of within 30 days of a significant change.</p>
<p>c. This will cover all authorization materials for both initial and ongoing authorization.</p>
</li>
<li>
<p><strong>Some machine-readable authorization data will be required for FedRAMP Rev5 Class A (Pilot), Class B (Low), and Class C (Moderate) certifications; the bulk of authorization data will be required in a semi-structured text format similar to the current approach.</strong></p>
<p>a. DOCX and XLSX will be retired as an acceptable format in favor of simple text-based equivalents.</p>
<p>b. This will cover all authorization materials for both initial and ongoing authorization. Detailed information, requirements, and timelines will be provided in the Consolidated Rules for 2026.</p>
</li>
<li>
<p><strong>The following Rev5 Balance Improvement Releases will be folded into the default FedRAMP Rev5 certification requirements (replacing existing requirements as appropriate), including the requirement to produce related materials in a machine-readable format:</strong></p>
<p>a. Minimum Assessment Scope replaces the traditional authorization boundary approach and eliminates the need for excessively complex authorization boundary diagrams</p>
<p>b. Significant Change Notifications replaces the traditional significant change request process</p>
<p>c. Collaborative Continuous Monitoring replaces part of the traditional monthly continuous monitoring approach</p>
<p>d. Vulnerability Detection and Response replaces the traditional vulnerability scanning and POA&#x26;M approach</p>
<p>e. Authorization Data Sharing replaces the traditional Secure Repository approach for centralizing authorization materials</p>
<p>f. Each of the above Balance Improvement Releases will have minor adjustments made as they are finalized for the Consolidated Rules for 2026.</p>
</li>
<li>
<p><strong>FedRAMP will not require diagrams or illustrations after the transition to the Minimum Assessment Scope.</strong></p>
<p>a. There is no expectation in the Minimum Assessment Scope of a traditional Authorization Boundary Diagram that contains every single service and flow in a single diagram. Instead, providers have flexibility to present the structure of their information resources across multiple levels of abstraction and grouping in a way that factors for continuous change within the environment and makes the most sense for their particular service.</p>
</li>
<li>
<p><strong>FedRAMP Rev5 Class C (Moderate) and Class D (High) certifications will strongly encourage the use of machine-generated deterministic telemetry in their authorization data where feasible, with a focus on the Minimum Assessment Scope, Significant Change Notifications, and Vulnerability Detection and Response processes.</strong></p>
<p>a. Providers will be encouraged to go beyond traditional Rev5 processes and “minimum control requirements” to find ways to demonstrate their security commitments instead of simply writing narrative text about them. This process will include flexibility for providers based on their own unique environment and the best customer experience.</p>
</li>
<li>
<p><strong>All providers will still be required to ensure basic human-readable materials are available as requested by all necessary parties, and will be required to generate these materials from the relevant machine-readable materials during production.</strong></p>
</li>
</ol>
<p>a. FedRAMP will encourage flexibility in human-readable materials to ensure cloud service providers are considering the best customer experience for conveying data about their unique environment. As long as the underlying machine-readable information is consistent, providers will not be penalized for providing an optimal customer experience in their human-readable materials.</p>
<p>b. This will cover all authorization materials for both initial and ongoing authorization.</p>
<h2><strong>Partnering with Industry</strong></h2>
<p>FedRAMP will not produce, manage, or operate services or software to help cloud service providers produce machine-readable materials. Government programs are not adept at providing this type of service in general due to restrictions and regulations, and attempting to do so would ensure a poor experience for cloud service providers and agencies. Furthermore, building and maintaining such services would require an increase in budget of 3-5x or more for FedRAMP and take several years, neither of which are an option.</p>
<p>Innovative solutions for maintaining and producing security materials must be provided by industry; this is the only way to ensure a wide-ranging set of options and alternatives that can compete to provide better capabilities and improve the customer experience for all stakeholders. To enable and encourage innovative solutions from industry, FedRAMP will establish informal partnerships with non-profit organizations that seek to support open source or other public domain capabilities for enabling the adoption of automation-related capabilities.</p>
<p>The <a href="https://oscalfoundation.org/">OSCAL Foundation</a> is one such established industry partner that provides capabilities, education, and a community to help cloud service providers modernize their approach to managing security materials, including free general membership. Other organizations that are interested in establishing informal partnerships with FedRAMP should reach out to <a href="mailto:pete@fedramp.gov">pete@fedramp.gov</a> to discuss opportunities.</p>
<p>At a minimum, FedRAMP will expect informal partner organizations to produce, maintain, and share templates and other materials that align with FedRAMP requirements and to help providers with transitioning from legacy manual materials. FedRAMP will establish the general requirements and ensure the templates and other materials are adequate for use, but FedRAMP will not dictate the underlying structure or approach. Approved organizations, templates, and other materials will be hosted by the organization and linked to in FedRAMP’s official documentation.</p>
<h2><strong>Initial Expected Timelines</strong></h2>
<p>The dates and milestones below may change in the final release of the Consolidated Rules for 2026, however none of the dates below will move forward in time.</p>
<h3><strong>Dates and Milestones for FedRAMP Certified Services</strong></h3>
<p>The following timelines are expected to be published as part of the FedRAMP Consolidated Rules for 2026 related to this notice; these timelines will apply to <strong>cloud services that have an active FedRAMP Certification</strong> on the date of each milestone:</p>
<p>| Anticipated Deadline | Milestone                                                                                                                                                                                      |
| :------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 2027-01-01           | Mandatory adoption of the <strong>Significant Change Notifications</strong> process for all Rev5 cloud services.                                                                                            |
| 2027-01-01           | Mandatory adoption of the <strong>Minimum Assessment Scope</strong> before or during the next annual assessment for a cloud service.                                                                        |
| 2027-04-02           | Mandatory adoption of the <strong>Collaborative Continuous Monitoring</strong> process for all Rev5 cloud services.                                                                                         |
| 2027-06-01           | Mandatory adoption of the <strong>Vulnerability Detection and Response</strong> process for all Rev5 cloud services.                                                                                        |
| 2027-08-01           | Mandatory adoption of the <strong>Authorization Data Sharing</strong> process for all Rev5 cloud services. The <a href="http://Connect.gov">Connect.gov</a> portal will be retired.                                    |
| 2027-11-01           | Rev5 Class A (Pilot), Class B (Low), and Class C (Moderate) certified cloud services must provide semi-structured text based authorization data before or during their next annual assessment. |
| 2027-11-01           | Rev5 Class D (High) certified cloud services must provide comprehensive machine-readable authorization data before or during their next annual assessment.                                     |</p>
<p>Progressive corrective action for failure to meet the requirements in these milestones will be applied quarterly.</p>
<h3><strong>Dates and Milestones for New FedRAMP Certifications</strong></h3>
<p>The following timelines are expected to be published as part of the FedRAMP Consolidated Rules for 2026 related to this notice; these timelines will apply to <strong>new submissions for FedRAMP Certification</strong> after the date of each milestone:</p>
<p>| Anticipated Deadline | Milestone                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| :------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 2027-01-01           | Rev5 Class A (Pilot), Class B (Low), and Class C (Moderate) submissions for FedRAMP Certification must provide semi-structured text based authorization data and adopt the following Rev5 Balance Improvement Releases: Minimum Assessment Scope Significant Change Notifications Collaborative Continuous Monitoring Vulnerability Detection and Response Authorization Data Sharing (this will apply to changes in the security categorization of a service) A grace period will be applied to any cloud service that was In Process with an Agency prior to 2026-10-01. |
| 2027-05-01           | Rev5 Class D (High) submissions for FedRAMP Certification must provide comprehensive machine-readable authorization data and adopt the following Rev5 Balance Improvement Releases: Minimum Assessment Scope Significant Change Notifications Collaborative Continuous Monitoring Vulnerability Detection and Response Authorization Data Sharing (this will apply to changes in the security categorization of a service) A grace period will be applied to any cloud service that was In Process with an Agency prior to 2026-10-01.                                     |</p>
]]></content:encoded>
      <pubDate>Wed, 25 Mar 2026 21:50:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0009</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0009.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0009.jpg" />
    </item>
    <item>
      <title>Initial Outcome from RFC-0023 Rev5 Program Certifications</title>
      <link>https://fedramp.gov/notices/0008</link>
      <description>RFC-0023 Rev5 Program Certifications was closed on February 26, 2026. This notice explains the initial outcome from public comment and the next steps for FedRAMP.</description>
      <content:encoded><![CDATA[<p><a href="https://www.fedramp.gov/rfcs/0023/">RFC-0023 Rev5 Program Certifications</a> proposed a short-term option to help cloud service providers that had already heavily invested in the FedRAMP Rev5 agency authorization path but either lost their agency sponsor or have struggled to obtain an agency sponsor during the last year due to unexpected government-wide staffing and budget changes.</p>
<p>A full traditional Rev5 security assessment review is expensive and time consuming for the government and requires careful balancing and planning for an agency. FedRAMP relies on the distribution of assessment review across the government to scale the program because it has never been funded or staffed to tackle assessment review on behalf of the entire government. This situation has not changed, and FedRAMP has no intention of removing sponsorship or taking on the full traditional Rev5 assessment review for everyone; FedRAMP is simply not capable of doing so without multiple years of increased targeted appropriations and planning.</p>
<p>To address this problem in the long term, FedRAMP has been building a new approach that reduces the initial review burden so that it can directly handle the initial assessment review on behalf of all agencies for a base level of demand, then scale with resources and personnel as additional funding is unlocked as a result of its success. This approach is well-known as <a href="https://www.fedramp.gov/20x">FedRAMP 20x</a> and FedRAMP has been applying lessons learned in the 20x approach to Rev5 via mostly optional Balance Improvement Releases.</p>
<p>Rev5 Program Certification, with initial assessment review <em>and</em> ongoing certification via continuous monitoring being performed directly by FedRAMP, can only be available to a limited number of cloud service providers that adopt the Balance Improvement Releases necessary to lower the burden for FedRAMP. Any cloud service provider that is unable to adopt these requirements will need to pursue the agency sponsor path to locate a government agency that has the funding and resources to perform the more burdensome traditional review and continuous monitoring.</p>
<h2><strong>A Quick Recap</strong></h2>
<p>Many of the details in this Initial Outcome will be confusing for stakeholders who have not kept up with recent RFCs and their initial outcomes posted by FedRAMP over the past few months. The information below is a quick recap of relevant information, though stakeholders are strongly encouraged to read the full set of RFCs and their outcomes for context.</p>
<ol>
<li>
<p><strong>FedRAMP Consolidated Rules for 2026 will be published by the end of June 2026.</strong> These will integrate many changes, apply to all cloud service providers by December 31, 2026, and will be valid until December 31, 2028.</p>
</li>
<li>
<p><strong>FedRAMP Certification will be the new label for a FedRAMP authorization.</strong> This is to avoid the frequent confusion between a FedRAMP authorization (done by FedRAMP) and an authorization to operate (done by agencies).</p>
</li>
<li>
<p><strong>FedRAMP will transition labels for requirements and baselines from impact levels to Certification Classes.</strong> Class A Certifications will be time-limited for initial testing and piloting while Class B, C, and D Certifications will initially map to historical FR Low/Li-SaaS, FR Moderate, and FR High requirements.</p>
</li>
<li>
<p><strong>FedRAMP Certifications of various types and classes will be available via the current Agency Authorization or new Program Certification paths.</strong> The Agency Authorization path is the traditional “agency sponsor” path for initial review that allows an agency to invest the resources up front by sponsoring a FedRAMP Certification for a cloud service it wants to use. The Program Certification path allows FedRAMP to review the product initially and does not require an agency sponsor, but has considerable restrictions on availability.</p>
</li>
</ol>
<p>All types of FedRAMP Certifications as well as all current and historical FedRAMP authorizations regardless of name or title <strong>are not government-wide authorizations to operate</strong> that allow any agency to use the product without meeting statutory and policy requirements for an authorization to operate. Many public commenters continue to misunderstand this fundamental fact of the law: an agency will <strong><em>always</em></strong> be required to perform a review of the security materials in a FedRAMP package to determine the risk of using it and current policy requires them to follow the NIST Risk Management Framework to implement an authorization to operate.</p>
<p>FedRAMP’s goal is to make this process dead simple for agencies so that they can make such determinations and perform an ATO within days or weeks.</p>
<h2><strong>Initial Outcome for FedRAMP Ready</strong></h2>
<p>The full details for implementing next steps for FedRAMP Ready will be published in the Consolidated Rules for 2026, however FedRAMP will immediately begin publicizing the pending retirement of FedRAMP Ready as planned.</p>
<p>The high level initial outcomes from RFC-0023 for FedRAMP Ready are:</p>
<ol>
<li>
<p><strong>FedRAMP will retire FedRAMP Ready on July 28, 2026 as proposed in RFC-0023.</strong> No FedRAMP Ready submissions will be accepted after this date.</p>
<p>a. Rev5 Class A Certifications will be available at this time and these requirements will not vary considerably from those for FedRAMP Ready so that cloud services working towards FedRAMP Ready can shift easily into the new profile.</p>
</li>
<li>
<p>Instead of simply retiring FedRAMP Ready as proposed in RFC-0023, FedRAMP will provide an alternative path for cloud service providers to convert their FedRAMP Ready or FedRAMP Ready assessment into a Class A FedRAMP Certification.</p>
<p>b. Cloud services that do not wish to or do not meet the requirements for conversion will be renamed “Legacy FedRAMP Ready” and otherwise retired as proposed in RFC-0023.</p>
</li>
</ol>
<h2><strong>Initial Outcome for Implementing Program Certification</strong></h2>
<p>FedRAMP will establish a tightly scoped Rev5 Program Certification with strict application criteria and limited commitments; the full criteria, requirements, and expectations will be published as part of the FedRAMP Consolidated Rules for 2026 by the end of June 2026.</p>
<p>This Rev5 Program Certification option will be deployed in stages, as follows:</p>
<ol>
<li>
<p><strong>Stage 1:</strong> Rev5 Class A Certifications will be available to cloud services that are FedRAMP Ready. Rev5 Class A Certifications will replace FedRAMP Ready. Providers will need to meet a few requirements to convert from FedRAMP Ready but it will be light touch initially.</p>
</li>
<li>
<p><strong>Stage 2:</strong> Rev5 Class B and Class C Certifications will be available through Program Certification to cloud services that are willing to adopt the required Balance Improvement Releases <strong>and met at least one of the following criteria between 1/1/2025 and 3/1/2026</strong>:</p>
<p>a. FedRAMP Ready on the FR Marketplace</p>
<p>b. In Process on the FR Marketplace</p>
<p>c. Completed a FedRAMP Ready assessment with a Readiness Assessment (RAR)</p>
<p>d. Completed a full FedRAMP assessment with a Security Assessment Plan and Security Assessment Report (SAP/SAR)</p>
</li>
</ol>
<p>Additional instructions and requirements will align with those proposed in RFC-0023 and will be shared publicly prior to opening the pipeline for Program Certifications. This opportunity for qualifying cloud services will be available until Rev5 is retired.</p>
<blockquote>
<p><em>Please do not reach out to FedRAMP about additional information or next steps until the formal criteria, path, and requirements are published! All relevant details will be shared with the public at the same time to ensure fairness.</em></p>
</blockquote>
<p>During Stage 1 and 2, FedRAMP will evaluate the impact to the program and establish requirements and timelines for additional stages based on real-world metrics.</p>
<p>In Stage 3, tentatively, FedRAMP hopes to open Rev5 Class A Certifications to any cloud service provider using an external security framework that is 80%+ compatible with FedRAMP Rev5 requirements. Then to open Rev5 Class B and C Certifications to specific types of GRC automation tools and services with proven agency demand.</p>
<h2><strong>Additional Initial Outcome Specifics</strong></h2>
<p>Additional specific outcomes from RFC-0023 that will be implemented in the Consolidated Rules for 2026 follow:</p>
<ol>
<li>
<p>FedRAMP will <strong>not</strong> implement the proposed “trusted assessor” definition or related requirements proposed in RFC-0023.</p>
<p>a. Thanks to astute public comment, FedRAMP is particularly concerned that this requirement might lead to cloud service providers establishing a contract with a “trusted assessor” that loses that status prior to completing the assessment, creating an issue that is beyond the control of the cloud service provider while unfairly punishing them.</p>
<p>b. <strong>LPC-GEN-ATA Assessment By Trusted Assessor</strong> will <strong>not</strong> be implemented.</p>
</li>
<li>
<p><strong>LPC-GEN-MBA Mandatory Balance Improvement Release Adoption</strong> will <strong>not</strong> be implemented.</p>
</li>
<li>
<p><strong>LPC-GEN-LMR Legacy Machine-Readable Package Requirements</strong> will <strong>not</strong> be implemented specifically for Rev5 Program Certifications.</p>
</li>
<li>
<p><strong>LPC-GEN-LVL Level Limited</strong> will be updated to Class Limited and clarify that FedRAMP will only provide sponsorless Class A, B, or C FedRAMP Certifications. Class D FedRAMP Certifications will continue to require an agency sponsor.</p>
<p>a. Cloud service providers that are unable to secure an agency sponsor for a Class D FedRAMP Certification are welcome to apply for a Class C FedRAMP Certification from FedRAMP directly and make any additional control implementations available in an addendum to their authorization package for agencies to encourage adoption in agency information systems with a High security objective.</p>
</li>
<li>
<p><strong>LPC-TIM-EOL End of Life for Legacy Program Certification</strong> will be updated to align the end of life for the end of legacy program certification with the end of life for new Rev5 authorizations overall. (<a href="https://www.fedramp.gov/20x/#phased-delivery-of-fedramp-20x">this is currently planned to be in 20x Phase 5, FY27 Q3 to FY Q4</a>)</p>
<p>a. This change will ensure a sponsorless option is available during the entire remaining lifecycle of the FedRAMP Rev5 Certification path.</p>
</li>
<li>
<p><strong>LPC-FRX-GRC Prioritization of Some GRC Tools</strong> will be reworked along with an entirely different pipeline process; in general, GRC tools that can be used by agencies to ingest machine-readable authorization data from other cloud services will continue to be prioritized.</p>
</li>
<li>
<p><strong>LPC-GEN-IBR Implement Balance Releases</strong> will be implemented without any significant change in response to public comment.</p>
<p>a. Program Certification for Rev5 is available only <em>because of</em> the Balance Improvement Release process. If a cloud service provider is unable to implement the requirements in these Balance Improvement Releases then FedRAMP would not be able to provide sufficient resources to maintain their Program Certification.</p>
<p>b. Cloud service providers that are not able to implement Balance Improvement Releases can still obtain a FedRAMP Certification through a sponsoring agency.</p>
</li>
<li>
<p><strong>LPC-GEN-IRI Included Required Information</strong> will be implemented without any significant change in response to public comment beyond striking the loss of “trusted assessor” status as such no longer applies.</p>
</li>
<li>
<p>All of the final rules will be updated to match the most recent naming conventions in FedRAMP Machine Readable Documentation, so many of the names will change.</p>
</li>
</ol>
]]></content:encoded>
      <pubDate>Fri, 06 Mar 2026 18:40:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0008</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0008.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0008.jpg" />
    </item>
    <item>
      <title>Initial Outcome from RFC-0022 Leveraging External Frameworks</title>
      <link>https://fedramp.gov/notices/0007</link>
      <description>RFC-0022 Leveraging External Frameworks was closed on February 26, 2026. This notice explains the initial outcome from public comment and the next steps for FedRAMP.</description>
      <content:encoded><![CDATA[<p>FedRAMP will publish the FedRAMP Consolidated Rules for 2026 (CR26) by the end of June, 2026; these rules will be valid until December 31, 2028.</p>
<p>These Consolidated Rules will formalize the initial requirements for Class A FedRAMP Certification based on the proposed requirements from RFC-0022 and the initial outcome from public comment shared below. This initial outcome, as written, may only make sense if you have reviewed the original RFC, other concurrent RFCs, and the initial outcome notices from the other concurrent RFCs; if you have not done so you may wish to wait for the FedRAMP Consolidated Rules for 2026 where all of this will be published together in context.</p>
<h2>Explanation of Outcome</h2>
<p>As explained in RFC-0022, Class A FedRAMP Certifications will exist to meet the specific mandate from M-24-15 to establish a path for leveraging external security frameworks and provide procedures for pilot uses of temporary FedRAMP Certifications. This path addresses gaps in the FedRAMP process that has caused agencies to perform their own pilot authorizations without following the FedRAMP process and promoting government-wide reuse. Agencies should not be required to invest considerable resources up front for sponsoring a cloud service prior to use, and cloud services should not need to invest significant resources in federal-specific processes to be used by agencies.</p>
<p>These updates after public comment clarify the intent of this process, maintain compliance with the underlying mandate from M-24-15, and explain how this path will integrate into other changes as part of the FedRAMP Consolidated Rules for 2026.</p>
<p>Class A FedRAMP Certifications will only be available through Program Certification (directly by the FedRAMP PMO without an agency sponsor) and will be available for both Rev5 and 20x <strong>with different requirements</strong>. The expected requirements for Rev5 Class A FedRAMP Certifications will be described in the initial outcome from RFC-0023.</p>
<p>In response to public comment, cloud service providers who receive a Class A FedRAMP Certification will be given 2 years (instead of 1 year) to obtain a Class B, C, or D FedRAMP Certification and will have some flexibility around that deadline based on scheduling with an independent assessor. This change will apply to all cloud services in the Preparation phase.</p>
<p>This initial outcome also explains that external frameworks will be adopted incrementally over time, depending on demand, throughput, and relevance. The most frequently leveraged external framework by agencies today for pilot authorizations is SOC 2 Type II and that is where FedRAMP will start for 20x Class A FedRAMP Certifications. FedRAMP is aware of the limitations of this external security framework and will establish some initial guardrails, but Class A FedRAMP Certifications are intended to be transitory and replaced by a Class B, C, or D FedRAMP Certification that will require addressing all relevant FedRAMP rules. FedRAMP is not providing a bridge from external frameworks to other classes of FedRAMP Certification. No reciprocity is intended or will be granted in this process. Any provider seeking long term or non-pilot use by an agency will need to pursue a different class of FedRAMP Certification.</p>
<p>Otherwise, most of the updates outlined in the initial outcome are minor changes and clarifications based on public comment.</p>
<h2>Initial Outcome Details</h2>
<p>The following changes from the rules proposed in RFC-0022 are planned in the FedRAMP Consolidated Rules for 2026 based on public comment:</p>
<ol>
<li>
<p>Class A FedRAMP Certifications will be the label for cloud services in the Preparation phase that have met initial requirements for negligible or low risk pilot use by agencies.</p>
<p>a. This will replace the “FedRAMP Validated Level 1” label initially proposed.</p>
<p>b. Cloud service providers MUST meet the requirements to be listed on the FedRAMP Marketplace in the Preparation phase to apply for a Class A FedRAMP Certification, including being a cloud service within the scope of FedRAMP (intended for direct or indirect use by multiple federal agencies).</p>
</li>
<li>
<p>FedRAMP will provide the materials and process necessary for cloud service providers to request Class A FedRAMP Certifications prior to opening a pipeline.</p>
</li>
<li>
<p>FedRAMP will provide the materials and process necessary for agency adoption of Class A FedRAMP Certifications prior to opening a pipeline.</p>
</li>
<li>
<p><strong>MKT-LEF-MAP Mapping to Key Security Indicators:</strong> The primary path for Class A FedRAMP Certifications maintained by FedRAMP will be designed for FedRAMP 20x and reflect the requirements proposed in RFC-0022.</p>
<p>a. This Certification Class is designed for industry companies that have not invested in the Rev5 path, using initial assessment of security posture via Key Security Indicators and other 20x requirements.</p>
<p>b. Paths for Rev5 FedRAMP Certification are already available for providers who have invested in the Rev5 path, and an alternative path for Rev5 Class A FedRAMP Certifications will be established based on the outcome from RFC-0023 Rev5 Program Certification.</p>
</li>
<li>
<p><strong>MKT-LEF-ASF Approved Security Frameworks:</strong> The list of initial approved security frameworks will be limited initially with specific instructions to ensure gradual and responsible implementation; implementation for specific frameworks will be staggered over time based on the level of effort and the depth of the review pipeline.</p>
<p>a. SOC 2 Type II, as the widest used external security framework with the least applicability to the Rev5 process, will be leveraged as the initial test case for Class A FedRAMP Certifications of this type. FedRAMP is aware of concerns about the quality and reliability of SOC 2 Type II audits and current trends with these audits as stated in public comment, however, the purpose of this path is to incentivize the investment in a different FedRAMP Certification that requires stricter implementation and assessment before any agency would use the service beyond a negligible or low risk pilot.</p>
</li>
<li>
<p><strong>MKT-LEF-DFV Deadline for FedRAMP Validation</strong> will be removed, and separate instructions will be provided to agencies to encourage them to establish conditional agreements during any Authorization to Operate for a pilot or test that the cloud service will invest in a different class of FedRAMP Certification appropriate to the agency use case if the agency wishes to continue use past the pilot.</p>
</li>
<li>
<p><strong>MKT-PRE-DLA Deadline for Authorization</strong>, initially proposed in RFC-0021, will be updated to require a cloud service offering to demonstrate that it has scheduled an Independent Verification &#x26; Validation (20x) or Independent Assessment (Rev5) for a Class B, C, or D Certification within <strong>2 years</strong> of initial listing in the Preparation phase.</p>
<p>a. This updated requirement will apply to Class A FedRAMP Certified offerings as they will remain in the Preparation phase.</p>
<p>b. This eases the pressure on cloud services that initiate a Preparation phase listing while providing flexibility in the event they are ready for an assessment but are unable to schedule such before the deadline.</p>
<p>c. This update was not included in <a href="https://www.fedramp.gov/notices/0005/">NTC-0005 Initial Outcome from RFC-0021</a> because it is a result of public comment in this RFC.</p>
</li>
<li>
<p><strong>MKT-LEF-NLR Negligible or Low Risk Use Cases</strong> will be removed and <strong>MKT-LEF-LIO Low Impact Only</strong> will be updated to clarify that agencies SHOULD deploy compensating controls if a Class A FedRAMP Certification is used for an agency ATO with higher security objectives or for non-pilot use cases.</p>
</li>
<li>
<p><strong>MKT-LEF-ROQ Require Ongoing FedRAMP Qualification</strong> will be removed and this general principle will be addressed separately in agency guidance (agencies are required by M-24-15 to obtain and maintain FedRAMP Certifications for services they use, so FedRAMP does not need to emphasize this for Class A FedRAMP Certifications).</p>
</li>
<li>
<p>The proposed updates to the Minimum Assessment Scope are no longer necessary after updates to the Minimum Assessment Scope in v0.9.0; <a href="https://www.fedramp.gov/docs/20x/minimum-assessment-scope/#information-flows-and-security-objectives">MAS-CSO-TPR</a> requires addressing the potential impact to federal customer data from third-party information resources regardless of the FedRAMP Certification status of those resources.</p>
</li>
<li>
<p>All of the final rules will be updated to match the most recent naming conventions in FedRAMP Machine Readable Documentation, so many of the names will change.</p>
</li>
</ol>
]]></content:encoded>
      <pubDate>Tue, 03 Mar 2026 22:05:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0007</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0007.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0007.jpg" />
    </item>
    <item>
      <title>Emergency Directive 26-03 Mitigate Vulnerabilities in Cisco-SD WAN Systems</title>
      <link>https://fedramp.gov/notices/0006</link>
      <description>This is a real emergency and action is required in response to CISA Emergency Directive 26-03: Mitigate Vulnerabilities in Cisco-SD WAN Systems. This is NOT a test.</description>
      <content:encoded><![CDATA[<p>The following email is being sent by FedRAMP to all cloud service providers in the FedRAMP Marketplace on the evening of February 25, 2026.</p>
<h2><strong>Subject Line:</strong> Emergency: FedRAMP Response to CISA ED 26-03</h2>
<p>This is a real emergency and <strong>action is required</strong> in response to <a href="https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems">CISA Emergency Directive 26-03: Mitigate Vulnerabilities in Cisco-SD WAN Systems</a>. This is NOT a test.</p>
<p>FedRAMP has been tasked with ensuring all federal agencies have the information they need from cloud services to respond to this Emergency Directive. This will avoid massive duplicative work for agencies and all cloud services.</p>
<p>Providers MUST complete all required actions and report status to FedRAMP (Step 7) by <strong>5:00 PM ET February 27, 2026</strong> regardless of impact level (this timeline has been set by CISA, not FedRAMP).</p>
<p><strong>PLEASE URGENTLY TAKE THE FOLLOWING REQUIRED ACTIONS IN ORDER!</strong></p>
<ol>
<li>
<p>Providers MUST review <a href="https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems">Emergency Directive 26-03</a> to understand affected systems.</p>
</li>
<li>
<p>Providers MUST identify all in-scope affected systems (Cisco SD-WAN) within the FedRAMP-authorized boundary for their cloud service offering(s).</p>
<p><em>If no in-scope systems are identified, <strong>skip to step 7.</strong></em></p>
</li>
<li>
<p>Providers SHOULD collect logs from affected systems as outlined in the <strong>Collect</strong> section of the <a href="https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems">Emergency Directive</a> to assist with hunt activities.</p>
</li>
<li>
<p>Providers MUST apply <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v">Cisco-provided updates</a> to all of the CVEs identified in the Emergency Directive by <strong>5:00 PM ET February 27, 2026</strong>.</p>
</li>
<li>
<p>Providers SHOULD perform hunt and hardening activities as recommended by <a href="https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems">Supplemental Direction ED 26-03: Hunt and Hardening Guidance for Cisco SD-WAN Systems</a>.</p>
</li>
<li>
<p>Providers MUST upload supplemental information to the Incident Response folder in the FedRAMP repository and notify all agency customer Authorizing Official (or ISSO) POCs with notification of the completed action(s).</p>
<ul>
<li>
<p><strong>File Format</strong></p>
<p>Files should be compatible with modern spreadsheet applications. Acceptable file formats are Comma Separated Values (csv) or Microsoft Excel (xlsx).</p>
</li>
<li>
<p><strong>Filename</strong></p>
<p>ED-26-03-Response-[FRID]</p>
<p>Note: Please replace the [FRID] placeholder with your corresponding information.</p>
</li>
<li>
<p><strong>Recommended content</strong></p>
<ul>
<li>List of the type(s) of affected systems.</li>
<li>Summary of actions taken and results, including the collection of artifacts, patching, and hunting actions.</li>
<li>Additional information you wish to provide to customers</li>
</ul>
</li>
</ul>
</li>
<li>
<p>Complete FedRAMP’s Emergency Directive 26-03 Response Form by <strong>5:00 PM ET February 27, 2026</strong>. (the URL for this form was emailed to cloud service providers directly)</p>
</li>
</ol>
<p><strong>Corrective Action</strong></p>
<p>Corrective actions based on the Security Inbox process DO NOT apply to this notification due to previously announced testing timelines.</p>
<p>Corrective actions MAY apply based on Incident Response or Continuous Monitoring deficiencies relating to this Emergency Directive Response.</p>
<p><strong>Additional Background</strong></p>
<p>If any indication of compromise or anomalous behavior is found or there is any suspected impact to federal systems, please make sure to follow the <a href="https://www.fedramp.gov/docs/rev5/playbook/csp/continuous-monitoring/incident-communication/">FedRAMP Incident Communication Procedures</a>, which includes reporting to CISA US-CERT and agency customers.</p>
<p>If you have any questions, please reach out to <a href="mailto:info@fedramp.gov">info@fedramp.gov</a> and <a href="mailto:CyberDirectives@cisa.dhs.gov">CyberDirectives@cisa.dhs.gov</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 25 Feb 2026 22:55:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0006</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0006.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0006.jpg" />
    </item>
    <item>
      <title>Initial Outcome from RFC-0021 Expanding the FedRAMP Marketplace</title>
      <link>https://fedramp.gov/notices/0005</link>
      <description>RFC-0021 Expanding the FedRAMP Marketplace was closed on February 19, 2026. This notice explains the initial outcome from public comment and the next steps for FedRAMP.</description>
      <content:encoded><![CDATA[<p><a href="https://www.fedramp.gov/rfcs/0020/">RFC-0021 Expanding the FedRAMP Marketplace</a> was closed on February 19, 2026. This notice explains the initial outcome from public comment and the next steps for FedRAMP. FedRAMP will publish the FedRAMP Consolidated Rules for 2026 (CR26) by the end of June, 2026; these rules will be valid until December 31, 2028.</p>
<h2><strong>Initial Outcome</strong></h2>
<p>The following changes from the rules proposed in RFC-0021 are planned in the FedRAMP Consolidated Rules for 2026 based on public comment:</p>
<ol>
<li>
<p>FedRAMP <strong>will not</strong> request, store, or publish pricing information for cloud services, independent assessors, or advisory services on the FedRAMP Marketplace.</p>
<p>a. <strong>MKT-GEN-SPI Service Pricing Information</strong> will be struck.</p>
<p>b. <strong>MKT-ADV-WEB Website Requirements</strong> and <strong>MKT-RIA-WEB Website Requirements</strong> will be modified appropriately.</p>
<p>c. Agencies and other FedRAMP stakeholders have regularly requested that FedRAMP provide this information in a centralized place, however public comment has made it clear that many stakeholders do not want to participate. This gives FedRAMP a clear public explanation for why this information will not be available in the FedRAMP Marketplace.</p>
</li>
<li>
<p><strong>MKT-ADV-ATT Attestation Requirements</strong> will be rewritten as an optional rule; FedRAMP <strong>will not</strong> require advisory services to maintain positive attestations from cloud service providers to be listed on the FedRAMP Marketplace.</p>
</li>
<li>
<p><strong>MKT-RIA-ATT Attestation Requirements</strong> will be modified to require an independent assessor to complete at least 2 assessments (initial or annual) every 2 years to maintain recognition.</p>
<p>a. <strong>MKT-RIA-ATT Attestation Requirements</strong> will begin the 2 year clock at either the date of FedRAMP recognition OR the date of publishing, whichever is most recent. This provides all current and future FedRAMP-recognized independent assessors 2 years to meet this requirement before it applies indefinitely.</p>
<p>b. <strong>MKT-RIA-ATT Attestation Requirements</strong> will continue to include the grace period of 6 months but will add a path to prevent loss of recognition if the independent assessor demonstrates intent to perform the required assessments with the timelines being outside of their control.</p>
<p>c. Some commenters inadvertently reinforced this requirement by explaining they had paid considerable cost to obtain an A2LA Accreditation with the sole intent of providing advisory services, however A2LA Accreditation and the related FedRAMP recognition process do not assess a company’s knowledge of FedRAMP or their ability to provide advisory services because it is intended only for independent assessors. This problem is exactly the confusion FedRAMP intends to address with this requirement.</p>
</li>
<li>
<p><strong>MKT-GEN-DOD Demonstration of Ongoing Demand</strong> will be updated to only apply to cloud services without an agency authorization to operate and the overall application will be clarified.</p>
<p>a. Providers that are not following the Authorization Data Sharing standard will be exempt from sharing agency package request information as FedRAMP manages that process for USDA Connect.</p>
<p>b. FedRAMP will add a note clarifying that this is to help FedRAMP justify the use of government resources to support Program Certification and similar processes overall by providing aggregate numbers and is not intended as an oversight mechanism to punish providers who are struggling with demand.</p>
</li>
<li>
<p><strong>MKT-GEN-PKO Pick One: 20x or Rev5</strong> will be updated to be more explicitly clear that Program Certification is the path outlined in RFC-0023 where FedRAMP is the sponsor for initial and ongoing authorization and that the requirement to pick one path applies to Program Certification only.</p>
<p>a. Cloud services with a 20x Certification are welcome to pursue an agency sponsored authorization to also obtain and maintain a FedRAMP Certification for Rev5. These Certifications would need to be maintained separately, following separate Rev5 and 20x processes. This would be very complicated for a company and likely result in significant confusion but FedRAMP does not have a reason to prevent this today.</p>
<p>b. FedRAMP itself will not provide a Program Certification for both paths due to the issues mentioned above, however; it would certainly be a waste of time, resources, and effort for FedRAMP to perform duplicative work itself.</p>
</li>
<li>
<p><strong>MKT-PRE-DCP Demonstrating Continuous Progress</strong> will be updated to clarify that continuous progress will be measured by the cloud service provider against goals it must include in the Ongoing Authorization Reports.</p>
<p>a. This is an opportunity for a business to showcase its goals and progress in a way that any potential customer can review and should be seen as a marketing and future customer experience opportunity.</p>
</li>
<li>
<p><strong>MKT-FRX-TAT Target Authorization Time</strong> will be updated to clarify that FedRAMP won’t throw someone under a 1 month penalty bus if there is a minor issue with a submission that is easy to correct.</p>
<p>a. This penalty is for situations when a package is demonstrably insufficient or FedRAMP has to repeatedly ask for additional information such that it is impossible to make a decision in a timely manner without wasting time and resources.</p>
<p>b. The note incorrectly mentioned a 3 month waiting period; the penalty is intended only to be 1 month.</p>
</li>
<li>
<p>FedRAMP will provide a JSON schema for the required web information for independent assessors and advisory services in the FedRAMP Consolidated Rules for 2026.</p>
<p>a. <strong>MKT-ADV-WEB Website Requirements</strong> and <strong>MKT-RIA-WEB Website Requirements</strong> will be updated to include this JSON schema and information about validation.</p>
</li>
<li>
<p>All of the final rules will be updated to match the most recent naming conventions in FedRAMP Machine Readable Documentation, so many of the names will change.</p>
</li>
</ol>
<h2><strong>Explanation</strong></h2>
<p>RFC-0021 received 41 comments in total, with a wide variety of focus for the comment content (appropriate to the various themes within RFC-0021). Comments were generally targeted at very specific areas and many aspects of the RFC received little attention. FedRAMP is making adjustments in specific areas that take into account concerns raised by the community where feedback did not conflict with the underlying goal or purpose of a proposed rule.</p>
<p>The adjustments are outlined in detail in the Initial Outcome section and summarized as follows:</p>
<ol>
<li>
<p>Pricing information will not be required because pretty much all industry commenters raised concerns, even though pretty much all agency commenters were strongly appreciative of the proposed change.</p>
</li>
<li>
<p>Advisory services and independent assessors will not need to maintain public attestations from customers. At least initially, advisory service listings will not require demonstration of quality.</p>
</li>
<li>
<p>FedRAMP-recognized independent assessors will be expected to perform at least 2 assessments every 2 years, instead of 3, along with many other changes and clarifications. This requirement is directly targeted at withdrawing recognition from companies that are causing confusion by seeking FedRAMP-recognition as an independent assessor when they do not actually intend to actually provide assessment services; it is not intended to punish active assessment services for circumstances outside their control.</p>
</li>
<li>
<p>The limit on Program Certification to either Rev5 or 20x will remain in place because FedRAMP itself can not waste resources on duplicative reviews and continuous monitoring. It’s possible there was some confusion here from commenters because this limit only applied to Program Certification where FedRAMP itself is the primary “sponsor” of a service (FedRAMP 20x is entirely sponsored by FedRAMP, and this rule applies to that and the proposed Rev5 Program Certification sponsored by FedRAMP in RFC-0023).</p>
</li>
<li>
<p>As FedRAMP delivers the Consolidated Rules for 2026, it will clarify that FedRAMP may defer corrective action if early notification with a well documented and achievable corrective action plan is supplied in advance of the corrective action being triggered. Corrective action is not intended to punish services acting in good faith on a technicality; it is for services that are simply failing to meet requirements.</p>
</li>
<li>
<p>Various other requirements and recommendations will be clarified, templates will be provided as appropriate, and everything will be implemented within the full context of the FedRAMP Consolidated Rules for 2026.</p>
</li>
</ol>
<p>Thank you for participating in the FedRAMP public comment process!</p>
]]></content:encoded>
      <pubDate>Wed, 25 Feb 2026 17:05:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0005</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0005.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0005.jpg" />
    </item>
    <item>
      <title>Initial Outcome from RFC-0020 FedRAMP Authorization Designations</title>
      <link>https://fedramp.gov/notices/0004</link>
      <description>RFC-0020 FedRAMP Authorization Designations was closed on February 19, 2026. This notice explains the initial outcome from public comment and the next steps for FedRAMP.</description>
      <content:encoded><![CDATA[<p><a href="https://www.fedramp.gov/rfcs/0020/">RFC-0020 FedRAMP Authorization Designations</a> was closed on February 19, 2026. This notice explains the initial outcome from public comment and the next steps for FedRAMP. FedRAMP will publish the FedRAMP Consolidated Rules for 2026 (CR26) by the end of June, 2026; these rules will be valid until December 31, 2028.</p>
<h2><strong>Initial Outcome</strong></h2>
<p>The following changes from the initial proposed designations in RFC-0020 are planned in the FedRAMP Consolidated Rules for 2026 based on public comment:</p>
<ol>
<li>
<p>The single official label for all FedRAMP authorizations will be <strong>FedRAMP Certification</strong> or <strong>FedRAMP Certified</strong>.</p>
<p>a. This aligns with the definition of a FedRAMP authorization in the <a href="https://www.fedramp.gov/docs/authority/law/definitions/#b-additional-definitions">FedRAMP Authorization Act</a> which states that a FedRAMP authorization is a certification by FedRAMP.</p>
<p>b. Any cloud service with a FedRAMP Certification is FedRAMP authorized for the purposes of meeting statutory or regulatory requirements, including adequacy for use by an agency to authorize the operation of that cloud service within a federal information system.</p>
<p>c. There will not be separate designations (such as “FedRAMP Validated”) for 20x and Rev5; FedRAMP concurs with many commenters that this will ultimately create additional confusion for procurement and other discussions. FedRAMP will provide filters in the marketplace to differentiate these paths instead.</p>
</li>
<li>
<p>FedRAMP will not create additional certification baselines that factor for corrective actions or the implementation of recommendations in the FedRAMP Consolidated Rules for 2026.</p>
<p>a. Proposing new levels for this caused significant confusion as many commenters believed the requirements for the existing baselines would also change. FedRAMP is not intending to change requirements as part of this process, only to provide labels for the existing requirements that better align to FedRAMP’s responsibility and authority.</p>
<p>b. FedRAMP will separately share information about optional processes and corrective actions with agencies, using the FedRAMP Marketplace.</p>
</li>
<li>
<p>FedRAMP will not use the term “levels” or numbers for the new baseline labels to avoid confusion with the DOD/DOW Impact Level/IL system.</p>
<p>a. The new labels for each baseline will align to a FedRAMP Certification Class (A, B, C, or D).</p>
<p>b. This better reflects that the baseline defines the scope of the assessment and certification by FedRAMP, not the total quality or security of the cloud service.</p>
</li>
<li>
<p>FedRAMP will continue with 4 baselines of assessment in the Consolidated Rules for 2026, with each requiring a different amount (and sometimes type or frequency) of information for FedRAMP Certification as they currently do. There will only be minor changes to the baselines themselves.</p>
<p>a. The labels for these baselines will change, with a transition period where the old and new labels will be linked. FedRAMP will provide full details and expectations in the Consolidated Rules for 2026.</p>
<p>b. Rev5: Class A will be a new pilot baseline, Class B will include the current Li-Saas and Low baselines, Class C will include the current Moderate baseline, and Class D will include the current High baseline.</p>
<p>c. 20x: These requirements will be formalized within the FedRAMP Consolidated Rules for 2026 and will align with Rev5 Classes.</p>
</li>
</ol>
<h2><strong>Explanation</strong></h2>
<p>A fundamental lifecycle change for FedRAMP occurred when the <a href="https://www.fedramp.gov/docs/authority/law/">FedRAMP Authorization Act</a> was passed and <a href="https://www.fedramp.gov/docs/authority/m-24-15/">OMB Memorandum M-24-15</a> was released. FedRAMP was not simply established in law or updated by these changes in statute and policy; instead, a very different program was established in its place with the same name.</p>
<p>As FedRAMP continues to align with these massively changed authorities and responsibilities there will be changes that fundamentally alter historical approaches to FedRAMP that are no longer relevant or applicable due to the rescission of the original FedRAMP. We acknowledge that for many stakeholders these changes continue to be confusing or frustrating at times but FedRAMP MUST operate in a different way to meet these new requirements; making changes now will reduce confusion in the future as FedRAMP grows.</p>
<p>The FedRAMP Authorization Act defines a FedRAMP authorization as simply <em>“a certification that a cloud computing product or service has completed a FedRAMP authorization process.”</em> The outcome of this process is a “FedRAMP authorization package” which is defined by the Act as <em>“the essential information that can be used by an agency to determine whether to authorize the operation of an information system.”</em> This naturally leads to the labels FedRAMP Certification for “FedRAMP authorization” and FedRAMP Certification Package for “FedRAMP authorization package.”</p>
<p>As explained in RFC-0020, a FedRAMP Certification is not a guarantee that a cloud service has met all requirements to be appropriate for use by an agency at a given FIPS 199 security category. FedRAMP does not have the authority to make this determination on behalf of an agency authorizing official. Agencies may use a FedRAMP Certification Package to authorize the inclusion of a cloud service in an agency information system at any security category they deem appropriate following the Risk Management Framework. OMB Memorandum M-24-15 and modern FedRAMP policies in general encourage agencies to use FedRAMP materials as the base for such decisions, and explicitly encourage the appropriate use of a FedRAMP Certification at different security categories (“impact levels”) than the FedRAMP Certification itself.</p>
<p>Many commenters inadvertently reinforced the critical misconception that a FedRAMP assessment baseline labeled with a FIPS 199 security category was a de facto acceptance of risk for agency use at that security category. This is incorrect, the FedRAMP assessment baseline identifies the depth and complexity of the information provided by the cloud service provider, not the overall security of a system. The outcome of the FedRAMP assessment and authorization process is a package of reusable materials to massively simplify the process for agencies to review and accept risks themselves, categorized by the amount of information available. This is the government-wide statutory and policy responsibility of FedRAMP today, providing the process for agencies to consistently manage the risk of using cloud services.</p>
<p>For all of these reasons, as proposed in RFC-0020, FedRAMP must establish proper labels that demonstrate the purpose and intent of the new FedRAMP. These labels do not change the requirements, purpose, or use of a FedRAMP authorization but over time will reduce the continuous confusion (clearly indicated in public comment) about the purpose and use of a FedRAMP Certification.</p>
]]></content:encoded>
      <pubDate>Wed, 25 Feb 2026 17:01:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0004</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0004.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0004.jpg" />
    </item>
    <item>
      <title>Notification of Planned FY26 Q2 FedRAMP Security Inbox Test</title>
      <link>https://fedramp.gov/notices/0003</link>
      <description>FedRAMP will be performing a planned quarterly Emergency Test of the FedRAMP Security Inbox for all cloud service providers between March 2 and March 13, 2026.</description>
      <content:encoded><![CDATA[<p>FedRAMP recently published a mandatory balance improvement release for all cloud service providers called the <a href="https://www.fedramp.gov/docs/rev5/balance/fedramp-security-inbox/">FedRAMP Security Inbox</a>. These requirements are mandatory and went into effect on January 5, 2026. The requirements in this policy are designed to ensure that FedRAMP can directly contact the security teams of FedRAMP authorized cloud services during an emergency.</p>
<p>This policy also requires FedRAMP to perform quarterly tests to ensure all cloud service providers are complying with these requirements. FedRAMP is required to share public notice at least 10 business days in advance of such a test to ensure that cloud service providers are not surprised. This message serves as the required public notice (NTC-0003). The public record of this notice is available at <a href="https://fedramp.gov/notices/0003">https://fedramp.gov/notices/0003</a>.</p>
<h2>FY26 Q2 Emergency Test</h2>
<p>FedRAMP will trigger the FY26 Q2 Emergency Test during normal business hours (8am-5pm Eastern Time) between March 2 and March 13, 2026.</p>
<p>This Emergency Test email will come from <a href="mailto:fedramp_security@gsa.gov">fedramp_security@gsa.gov</a> and will clearly specify the actions that cloud service providers are expected to take in reaction to receiving this message.</p>
<p>The actions FedRAMP will expect cloud services to take for the FY26 Q2 Emergency Test follow:</p>
<p>The email will contain the FedRAMP ID, a unique code for each cloud service offering, and a link to a Google Form. The unique code ensures that the form is submitted in response to the email received from FedRAMP for the correct cloud service offering.</p>
<p>Providers will be required to submit the following information in the Google Form for each cloud service offering:</p>
<ul>
<li>The FedRAMP ID of the cloud service offering</li>
<li>The unique three-word code received in the FedRAMP Emergency Test email</li>
<li>The name, title, and email of a preferred contact for follow up from FedRAMP if needed</li>
<li>Are you aware of the <a href="https://www.fedramp.gov/docs/rev5/balance/secure-configuration-guide/">FedRAMP Secure Configuration Guide rules</a> that are mandatory for all cloud service providers as of March 1, 2026?</li>
<li>Have you met the requirements and recommendations in the <a href="https://www.fedramp.gov/docs/rev5/balance/secure-configuration-guide/">FedRAMP Secure Configuration Guide</a> rules?</li>
<li>Where can FedRAMP or federal agencies find your Secure Configuration Guide?</li>
</ul>
<p>Response times will be tracked and reviewed by FedRAMP; individual response times may be published as a security metric.</p>
<p>FedRAMP Security Team</p>
<h2>A Special Email Test</h2>
<p>To help cloud service providers ensure they are prepared, FedRAMP will be sending an individual informational notice the FedRAMP Security Inbox email address on file with a copy of this message. If you are a cloud service provider and do not receive an informational notification by Monday, February 23, please contact info@fedramp.gov immediately to begin troubleshooting any possible problems with your FedRAMP Security Inbox.</p>
]]></content:encoded>
      <pubDate>Wed, 18 Feb 2026 17:03:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0003</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0003.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0003.jpg" />
    </item>
    <item>
      <title>Outcome from RFC-0019 Reporting Assessment Costs</title>
      <link>https://fedramp.gov/notices/0002</link>
      <description>RFC-0019 Reporting Assessment Costs was closed on February 12, 2026. After reviewing public comments, FedRAMP will not finalize or implement the proposed cost reporting requirements at this time.</description>
      <content:encoded><![CDATA[<p>The proposed rules from <a href="https://www.fedramp.gov/rfcs/0019/">RFC-0019 Reporting Assessment Costs</a> <strong>will not be finalized or implemented by FedRAMP.</strong></p>
<p>Cloud service providers and FedRAMP-recognized independent assessment services will not be required to report information to FedRAMP regarding the expenses incurred for any assessment at this time. This determination may be reconsidered in the future, however a new public comment period would be required.</p>
<h2>Explanation</h2>
<p>On January 13, 2026, FedRAMP proposed reporting requirements to gather assessment costs in <a href="https://www.fedramp.gov/rfcs/0019/">RFC-0019</a> to help address the statutory responsibility in <a href="https://www.fedramp.gov/docs/authority/law/gsa/#a-roles-and-responsibilities">44 USC § 3609 (a) (10) (A)</a> to <em>"regularly review, in consultation with the FedRAMP Board … the costs associated with independent assessment services…"</em></p>
<p>RFC-0019 generated more public comments than many previous FedRAMP RFCs, with 30 distinct commenters supplying 48 comments on the proposed requirements. FedRAMP appreciates the many carefully considered comments that addressed the underlying potential impact to industry and the associated concerns for companies. This notice summarizes and explains the outcome from RFC-0019 Reporting Assessment Costs.</p>
<p>The primary theme FedRAMP identified in public comments was that collecting this information would impose a burden on cloud service providers that was not relevant to the assessment and authorization of cloud computing services. Assessment costs are paid by cloud service providers as part of a commercial agreement with an assessment organization that does not involve the government; therefore, FedRAMP would be collecting proprietary business information. Some commenters even indicated that companies might choose to deliberately obfuscate or falsify their assessment cost reporting to protect themselves.</p>
<p>A critical secondary theme was that the cost paid by any particular cloud service provider for an assessment would only be relevant to the experience of that specific provider due to the wide variance in scope and complexity across providers. Commenters indicated that these costs could not <strong>and should not</strong> be compared across providers.</p>
<p>Overall, public comments have made it clear that implementing the proposed requirements would create a significant problem for some companies who might choose to reject it, would likely create significant problems for FedRAMP in oversight and management of the information, and might cause a slew of other issues due to the perception that, effectively, this is none of FedRAMP’s business and that the cost of services between private-sector entities should be left to private-sector entities to negotiate.</p>
<p>FedRAMP concurs with the public that requiring businesses to report on the costs of assessment services for FedRAMP-related assessment is unreasonable. As a result, FedRAMP will not implement these requirements and will only be able to rely on limited publicly available information to review the cost of assessment services.</p>
]]></content:encoded>
      <pubDate>Wed, 18 Feb 2026 17:01:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0002</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0002.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0002.jpg" />
    </item>
    <item>
      <title>Introducing FedRAMP Public Notices</title>
      <link>https://fedramp.gov/notices/0001</link>
      <description>Introducing FedRAMP Public Notices, a simple service to keep stakeholders in the loop on updates and announcements from FedRAMP.</description>
      <content:encoded><![CDATA[<p>FedRAMP Public Notices is a new addition to FedRAMP's communications channels that establishes a single place for simple and clear notifications about program updates, policy changes, and operational guidance.</p>
<p>This system should make it easier for folks to stay informed or catch up on important updates where action may be necessary. FedRAMP's other communication channels include:</p>
<ul>
<li>The <a href="https://fedramp.gov/blog">FedRAMP Blog</a> provides big picture updates in large information dumps.</li>
<li>Our <a href="https://public.govdelivery.com/accounts/USGSA/subscriber/new">email subscriber list</a> regularly communicates smaller updates over email, but these are not archived and may be easy to miss.</li>
<li>FedRAMP's <a href="https://www.linkedin.com/showcase/gsa-fedramp/about/">social media on linkedin</a> actively communicates about smaller updates as well, but are also easy to miss.</li>
<li>The <a href="https://github.com/FedRAMP/community/discussions">FedRAMP Community discussions</a> on GitHub are a great place for discussing FedRAMP, but it includes far more than just general notices.</li>
</ul>
<h2>Key Features of FedRAMP Public Notices</h2>
<ul>
<li><strong>Easy to Catch Up:</strong> All historical notices are available in one place with summaries that make it easy to catch up on occasional visits.</li>
<li><strong>Easy to Follow:</strong> An RSS feed allows simple integration into the communication platform of your choice so updates aren't missed.</li>
<li><strong>Targeted Content:</strong> Notices are focused on just the key facts you need to know - we won't use notices to send general reminders or provide social updates that are more appropriate via other channels.</li>
</ul>
<h2>What's Next</h2>
<p>Set up your system of choice to <a href="https://fedramp.gov/notices/rss.xml">monitor the RSS feed</a> for new notices and stand by for key updates!</p>
]]></content:encoded>
      <pubDate>Wed, 18 Feb 2026 17:00:00 GMT</pubDate>
      <guid>https://fedramp.gov/notices/0001</guid>
      <media:content url="https://fedramp.gov/notices/thumbnail/0001.jpg" medium="image" type="image/jpeg" />
      <media:thumbnail url="https://fedramp.gov/notices/thumbnail/0001.jpg" />
    </item>
</channel>
</rss>