FedRAMP
Federal Risk and Authorization Management Program · General Services Administration (GSA) / FedRAMP PMO · Official site
US federal program standardizing security authorization for cloud services used by federal agencies. CR26 Consolidated Rules (June 2026) mandate machine-readable OSCAL packages by September 2026 and full rule compliance by January 2027.
Timeline
FedRAMP has opened 2 new Requests for Comment. This provides an opportunity for stakeholders to review and provide feedback on proposed changes or policies. Participants should submit their comments …
FedRAMP opened a new Request for Comment (RFC) concerning offerings by government entities. This RFC seeks public input on government cloud service offerings and related requirements. Stakeholders in…
FedRAMP has updated its Consolidated Rules for 2026 to clarify existing rules and correct issues in the FedRAMP JSON schemas. The updates address both procedural clarifications in the regulatory fram…
FedRAMP has released version 2026.06.25.01 of the Consolidated Rules for 2026 and introduced a mini-game feature. Organizations working with FedRAMP authorization should review the updated rules for …
FedRAMP has released the Consolidated Ruleset for 2026 (CR26), establishing the updated framework for federal cloud security authorization. This update provides cloud service providers with revised s…
FedRAMP has published Public Notice NTC-0012, which documents the outcome of Request for Comment (RFC-0031) concerning updated incident communications procedures. This notice formalizes the changes a…
FedRAMP has renamed all 'FedRAMP Authorization' designations to 'FedRAMP Certification' and replaced impact level designations with a new classification system using classes A, B, C, and D. This term…
FedRAMP has published NOTICE-0010 as an official response to CISA V1: ED 25-03. This notice provides FedRAMP's position and guidance on how the CISA directive applies to the FedRAMP authorization pro…
FedRAMP has added RFC-0031 Updated Incident Communications Procedures to its compliance framework. This new procedure updates how cloud service providers must communicate security incidents to govern…
FedRAMP has published NOTICE-0009 detailing the initial outcome of RFC-0024 concerning FedRAMP Rev5 machine-readable packages, and released information about the FedRAMP Cybersecurity Service. This n…
FedRAMP has published five new Requests for Comments (RFCs 0026-0030) related to Rev5 updates and improvements. These RFCs provide guidance on proposed changes to the FedRAMP authorization program. C…
FedRAMP has added RFC-0025 to its request for comments series. The specific details of this RFC are not provided in the available documentation.
FedRAMP published a public notice with the initial outcome of RFC-0023 Rev5 regarding Program Certifications that do not require a sponsor. This update reflects FedRAMP's evolving certification frame…
FedRAMP has published a public notice outlining the initial outcomes of RFC-0022, which addresses the use of external security frameworks within the FedRAMP authorization process. This notice provide…
FedRAMP has released updates to certain revision 5 templates. These updates reflect refinements to the compliance and assessment documentation requirements for cloud service providers operating under…
FedRAMP has published significant updates to its 20x content, including more comprehensive phase two information and the launch of an official documentation page. These updates aim to provide cloud s…
FedRAMP has refreshed its Rev5 documentation suite, deprecating outdated documents and publishing an entirely new Continuous Monitoring Playbook. This update provides cloud service providers and auth…
FedRAMP has published a new Request for Comment (RFC) for public input. This allows stakeholders to review and provide feedback on proposed changes or updates to FedRAMP requirements and processes. C…
FedRAMP has added ChatGPT by OpenAI to its List of Prioritized AI Services, reflecting the agency's focus on accelerating the authorization of AI-based solutions for federal use. This means ChatGPT i…
FedRAMP has updated its guidance on the scope of the FedRAMP program in response to the M-24-15 presidential memo and following the closure of RFC-0010. This update clarifies what systems and service…
FedRAMP has formalized and published the FedRAMP 20x Authorization Data Standard (ADS), previously known as RFC-0011 Standard for Storing and Sharing Authorization Data. Minor changes have also been …
FedRAMP has published a new page outlining AI prioritization criteria. This addition helps cloud service providers and federal agencies understand how artificial intelligence assessments are prioriti…
FedRAMP has formally rescinded its subnet whitepaper, removing it from the body of authoritative guidance. Cloud service providers and assessors that previously relied on this whitepaper for subnet-r…
FedRAMP has updated its 20x Phase One pilot page to include a submission deadline of August 19, 2025. This deadline clarifies the timeline for vendors seeking to participate in the 20x Phase One pilo…
FedRAMP has released updated guidance and external project information. This publication provides current resources for cloud service providers and federal agencies involved in the FedRAMP authorizat…
FedRAMP has published documentation for the Phase One pilot authorization process. This process outlines the streamlined authorization pathway for cloud service providers seeking federal compliance c…
FedRAMP has published a new Request for Comments (RFC) seeking public input on a proposed policy or technical matter. This allows stakeholders to review and provide feedback on FedRAMP's initiatives.…
Monitoring
Watched by 1 official source. Watching since 10 September 2026. Last checked 1 hour, 41 minutes ago.