FedRAMP

Federal Risk and Authorization Management Program · General Services Administration (GSA) / FedRAMP PMO · Official site

US federal program standardizing security authorization for cloud services used by federal agencies. CR26 Consolidated Rules (June 2026) mandate machine-readable OSCAL packages by September 2026 and full rule compliance by January 2027.

Timeline

FedRAMP opens 2 new Requests for Comment Draft consultation us

FedRAMP has opened 2 new Requests for Comment. This provides an opportunity for stakeholders to review and provide feedback on proposed changes or policies. Participants should submit their comments …

Source

FedRAMP Consolidated Ruleset for 2026 (CR26) is released New version us

FedRAMP has released the Consolidated Ruleset for 2026 (CR26), establishing the updated framework for federal cloud security authorization. This update provides cloud service providers with revised s…

Source Action required

FedRAMP adds RFC-0025 New document us

FedRAMP has added RFC-0025 to its request for comments series. The specific details of this RFC are not provided in the available documentation.

Source

FedRAMP updates certain rev5 templates Amendment us

FedRAMP has released updates to certain revision 5 templates. These updates reflect refinements to the compliance and assessment documentation requirements for cloud service providers operating under…

Source Action required

FedRAMP opens new Request for Comment Draft consultation us

FedRAMP has published a new Request for Comment (RFC) for public input. This allows stakeholders to review and provide feedback on proposed changes or updates to FedRAMP requirements and processes. C…

Source

FedRAMP updates scope guidance per M-24-15 memo Guidance us

FedRAMP has updated its guidance on the scope of the FedRAMP program in response to the M-24-15 presidential memo and following the closure of RFC-0010. This update clarifies what systems and service…

Source

FedRAMP rescinds subnet whitepaper Withdrawal us

FedRAMP has formally rescinded its subnet whitepaper, removing it from the body of authoritative guidance. Cloud service providers and assessors that previously relied on this whitepaper for subnet-r…

Source Action required

FedRAMP adds new Request for Comments Draft consultation us

FedRAMP has published a new Request for Comments (RFC) seeking public input on a proposed policy or technical matter. This allows stakeholders to review and provide feedback on FedRAMP's initiatives.…

Source

Monitoring

Watched by 1 official source. Watching since 10 September 2026. Last checked 1 hour, 41 minutes ago.