Skip to content
Quzara LLCSep 22, 202611 min read

Federal Agency FedRAMP Obligations in 2026: A Guide for ISSOs, ISSMs, and CISOs

FedRAMP agency obligations at a glance: The FedRAMP Consolidated Rules for 2026 (CR26) identify 24 rules that apply directly to federal agencies: 13 mandatory (MUST/MUST NOT) and 11 recommended (SHOULD/SHOULD NOT). AGU rules are live now with no grace period. VER-AGM becomes mandatory December 7, 2026 under NTC-0014 and CISA BOD 26-04. CCM-AGM phases in through mid-2027.

The three rules most agencies will break: Requiring additional information beyond FedRAMP (AGU-AGC-NAR) · Requiring a specific certification type or path in procurement (AGU-AGC-TPP) · Blocking a certified offering from following FedRAMP rules, which has no head-of-agency exception (AGU-USE-AFR)

See the full rule-by-rule breakdown on the Quzara Agency Assurance page →

What CR26 Means for Agencies

The FedRAMP Consolidated Rules for 2026 are machine-readable, version-controlled, and publicly maintained at github.com/FedRAMP/rules. They do not create 24 brand-new legal duties. Instead, they make explicit what was already embedded in OMB Memorandum M-24-15, FISMA, OMB Circular A-130, and FIPS-200, and they assign those obligations directly to agencies.

Of the 246 total FedRAMP rules across 17 families, 24 apply directly to agencies: 13 are mandatory (MUST/MUST NOT) and 11 are recommended (SHOULD/SHOULD NOT). The mandatory rules are enforceable obligations. The recommended rules describe how FedRAMP expects a mature agency program to operate, and two of them (VER-AGM) carry a hard external deadline through CISA BOD 26-04 that makes them functionally mandatory by December 7, 2026.

Three Rule Families, One Program

Agency obligations fall across three rule families:

FamilyRulesStatus
AGU, Agency Use of FedRAMP Certified Cloud Services20 rulesLive, July 4, 2026. No grace period.
CCM-AGM, Collaborative Continuous Monitoring, Agency Guidance2 rulesPhasing in by provider type through mid-2027.
VER-AGM, Vulnerability Evaluation and Reporting, Agency Guidance2 rulesMandatory December 7, 2026 (NTC-0014). Grace to March 7, 2027 only under a Corrective Action Plan with FedRAMP notice.

AGU is live now. If your agency is already using FedRAMP-certified cloud services and has not verified compliance with its 20 rules, you are already out of alignment.

The 13 Mandatory Obligations

AGU-AGC-AIP: Maintain agency-wide FedRAMP policy

Your agency policy must align with M-24-15. This is the umbrella rule from which all other AGU obligations follow.

AGU-AGC-GRC: Make your GRC tooling machine-readable

Your internal governance, risk, compliance, and inventory tools must be able to produce and ingest machine-readable artifacts in the formats FedRAMP specifies. A spreadsheet-based program does not satisfy this rule.

AGU-AGC-NAA: Notify FedRAMP when you authorize a cloud service

On authorizing use of any cloud service within FedRAMP scope, notify FedRAMP with the required information set.

AGU-AGC-NAI: Notify FedRAMP after requesting additional information

Notification follows the request. No pre-approval is needed. Clarifying questions and general questions about Certification Data are exempt.

AGU-AGC-NAR: Do not require information beyond FedRAMP requirements (MUST NOT)

Agencies MUST NOT require information or materials beyond what FedRAMP requires without a demonstrable-need determination by the agency head or authorized delegate, plus FedRAMP notification afterward. Clarifying questions and general questions about Certification Data are exempt.

AGU-AGC-TPP: Do not require a specific Certification Type or Path (MUST NOT)

Agencies MUST NOT require Rev5, 20x, Program Authorization, or Agency Authorization without a demonstrable-need determination and FedRAMP notification. Procurement language is the most common place this rule is broken.

AGU-SPN-MRC: Follow the current rules when sponsoring

When initiating an agency-sponsored FedRAMP Certification, follow the most recent FedRAMP Consolidated Rules.

AGU-USE-ABU: Complete the ATO process for systems that include certified offerings

FedRAMP Certification is not Authorization to Operate. Every federal information system that incorporates a certified cloud service offering still needs its own completed ATO.

AGU-USE-AFR: Allow certified offerings to follow FedRAMP rules

This rule carries no head-of-agency exception. Agency requirements that conflict with FedRAMP rules are impermissible, full stop.

AGU-USE-NFC: Notify FedRAMP about rescission-level concerns

When an Ongoing Certification Report, Quarterly Review, or other Certification Data raises concerns that would likely result in ATO rescission, notify FedRAMP.

AGU-USE-RCF: Collaborate with FedRAMP on conflicts

When agency-specific security determinations conflict with the FedRAMP Certification Package, work it through FedRAMP rather than imposing requirements unilaterally. This is the formal mechanism for pushing back on a provider.

AGU-USE-RSG: Review the Secure Configuration Guide and configure to it

Review provider-supplied Secure Configuration Guides and configure relevant security settings accordingly. Re-review when the guide version changes or a Security Change Notice shifts customer configuration responsibilities.

CCM-AGM-ROR: Review each Ongoing Certification Report (MUST)

Understand how changes to the offering may affect the federal information systems that include it in their authorization boundary.

  • Applies to 20x providers from January 2027
  • Applies to Rev5 providers from April 2027, with grace to October 2027

The Three Rules Your Agency Will Break by Habit

These are the rules where most agency security teams run into problems, because the habits they encode are deeply ingrained.

1. Requiring additional information (AGU-AGC-NAR)

Sending a security questionnaire to a cloud provider is a reflex for most ISSO teams. Under CR26, that questionnaire is a compliance event. Before any additional-information request goes out, your agency needs a classification step: Is this a clarifying question (exempt)? An additional-information request (notify FedRAMP afterward, no determination needed)? Or an additional requirement (agency head or delegate determination required, then notify FedRAMP)?

The compliant path is narrower than most teams expect.

2. Requiring a specific certification type or path (AGU-AGC-TPP)

Procurement language is the most common place this rule breaks. Specifying "FedRAMP High authorized" or "Rev5 only" in a solicitation, without a recorded demonstrable-need determination and FedRAMP notification, puts the agency out of compliance. Your contracts and procurement officers need to know about this rule.

3. Blocking a provider from following FedRAMP rules (AGU-USE-AFR)

Unlike NAR and TPP, this rule has no head-of-agency exception. If an agency requirement conflicts with FedRAMP rules, the agency requirement loses. There is no carve-out.

The compliant flow when you genuinely need more: (1) Classify the ask: clarification (exempt), additional-information request, or additional requirement/required type-path. (2) Additional-information request: submit the request, then notify FedRAMP afterward via the Additional Information form (NAI, MUST); no pre-determination needed. (3) Additional requirement or required type/path: agency head or delegate records a demonstrable-need determination, then notify FedRAMP (NAR/TPP). (4) Keep the record: the request, the determination where one applied, and the notification.

The December 7 Deadline: VDR and VER

Vulnerability Disclosure Reports (VDR) and Vulnerability Evaluation Reports (VER) apply to every FedRAMP Certified offering, all classes, Rev5 and 20x. December 7, 2026 is the date when VER-AGM becomes mandatory under NTC-0014 and CISA BOD 26-04.

Your agency obligations under VER-AGM:

  • Filter the provider's vulnerability report to vulnerabilities relevant to your use case and FISMA system
  • Compare provider PAIN ratings against your agency's own impact determination
  • Update your agency POA&Ms based on the filtered view
  • Where relevant under agency security policy, feed provider vulnerability data into your POA&Ms (including accepted vulnerabilities you continue to carry)

The two VER-AGM rules are SHOULD under CR26 alone, but CISA BOD 26-04 does not offer the same flexibility. Grace to March 7, 2027 is available only under a Corrective Action Plan with FedRAMP notice.

What providers must send you (per VER):

Each VDT record must include: tracking ID, detection time and source, evaluation time, internet-reachability and exploitability determination, PAIN rating (N1–N5, current and historical), each completed impact reduction with timing, overdue status with explanation, and final disposition. Accepted vulnerabilities are reported separately as AVI records.

Reports are delivered at minimum monthly (human-readable) and persistently (machine-readable, validated against FedRAMP-published VDT and AVI JSON schemas). Class D providers detect on the tightest cadence: daily for machine-based resources, every 7 days for drift-prone resources, monthly for non-drift resources.

For more on what providers must deliver and how the December 7 date applies to CSPs, see the FedRAMP VDR and VER requirements guide.

For continuous monitoring support across your FedRAMP-certified cloud environments, Cybertorch provides FedRAMP Class D (High) authorized SOC-as-a-Service staffed by US-citizen analysts who integrate directly with your agency's incident intake and triage workflows.

The Quarterly CCM Rhythm

For every Class B–D provider your agency uses, the CCM cycle runs as follows:

  1. Provider publishes the OCR. Every three months; next publish date is public (CCM-OCR-NRD).
  2. Agency reviews it (CCM-AGM-ROR, MUST). Does anything change the risk tolerance documented in your ATO? Weight review depth by Security Category (CCM-AGM-CSC, SHOULD).
  3. Quarterly Review meeting. Provider hosts. Mandatory for Class C/D, SHOULD for Class B, MAY for Class A. Occurs 3–10 business days after OCR publication. Your designated Senior Official attends (AGU-USE-DSO, SHOULD).
  4. Escalate if needed (AGU-USE-NFC, MUST). Notify FedRAMP when concerns would likely lead to ATO rescission. Notify the provider as well (AGU-USE-NPC, SHOULD).

The 8 things every OCR must contain

Per CCM-OCR-AVL, verify that your provider's report addresses all eight before marking it as reviewed:

  1. Changes to Certification Data since the last OCR
  2. Planned changes over the next 3+ months
  3. Accepted vulnerabilities (current status)
  4. Transformative changes made or planned
  5. Updated security, configuration, and usage recommendations
  6. Full list of agencies directly using the product
  7. FedRAMP Reportable Incidents, or attestation that none occurred
  8. Lessons learned and changes made or planned after Reportable Incidents

If a provider's OCR does not address all eight, it is not a compliant OCR. Your agency review should verify this before marking the report as reviewed.

What Your Providers Must Give You

Once your agency is a customer, you are a "necessary party" (FRD-ANP) under CR26. These are provider obligations, but knowing them tells you what to demand and what to escalate when a provider denies access.

RuleClassRequirement
CDS-TRC-USHB–DUninterrupted access to Certification Data. No per-request manual approvals.
CDS-TRC-PACB–DDocumented programmatic access to all Certification Data, including human-readable materials.
CDS-CSO-HADB–DHistorical OCR snapshots, kept for the life of the certification.
CDS-UTC-AADAllProvider must notify FedRAMP within 5 business days of denying an agency access request.
CDS-TRC-ACLB–D (SHOULD)Six months of access summaries; your portion available to you on request.
CDS-TRC-SSMB–D (SHOULD)Self-service user management within the trust center.

Rev5 migration watch (CDS-CSF-TCM): When a Rev5 provider migrates from USDA Connect to a trust center, they must notify your agency and leave forwarding instructions in the old secure folders. Every ingestion path changes at once. Watch for the migration notice.

On responsible sharing (CDS-CSO-RIS): Providers must share enough for authorization decisions but should not include exploit-enabling detail. Expect abstraction in vulnerability reports. AGU-USE-RCF is the formal mechanism to push back when abstraction becomes insufficiency.

Roles: Who Owns What

RolePrimary Responsibilities
Authorizing OfficialSigns ATOs; owns NFC decisions (AGU-USE-NFC)
Designated Senior OfficialRepresents agency at Quarterly Reviews; leads OCR review (AGU-USE-DSO, SHOULD)
CISOCompliance policy, risk thresholds, program tracking across all certified services
ISSO / Tenant AdminsSCG configuration settings, system-level review, day-to-day configuration compliance
SOC ProviderIncident intake; triage against agency systems
FedRAMP LiaisonShared inbox; ATO filings; NAI/NFC notifications to FedRAMP
Head-of-Agency DelegateNAR/TPP demonstrable-need determinations (the only authorized path to requiring extras)

90-Day Action Plan

Inventory and close the ATO loop

Build a complete inventory: every FedRAMP-certified service your agency uses, keyed by FedRAMP ID, linked to every FISMA system that includes it. Confirm each of those systems has a completed ATO (AGU-USE-ABU). Certification is not Authorization. Without this record you cannot run the rest of the program.

Name and connect

Designate your Senior Official and FedRAMP Liaison. Set up a shared agency inbox. Request trust-center access as a necessary party for all Class B–D providers you are currently authorized to use.

Govern requests

Stand up the additional-request gate and the FedRAMP notification log (covering NAR, NAI, TPP, and NAA). Before any security team sends a questionnaire or demands additional information from a provider, it passes through this gate. This is how you prevent AGU-AGC-NAR violations before they happen.

Start the rhythm

Calendar every provider's next OCR and Quarterly Review date (CCM-AGM-ROR, AGU-USE-ROR). Review SCGs per tenant (AGU-USE-RSG). Confirm your GRC tooling can produce and ingest FedRAMP machine-readable artifacts (AGU-AGC-GRC). The program runs on cadence. Build the calendar first.

For agencies looking to automate machine-readable compliance tracking and artifact ingestion, NISTcompliance.ai is built to handle the GRC data flows CR26 requires, including OSCAL and FedRAMP-format outputs.

How Quzara Supports Agency Programs

Quzara works directly with federal agency security teams on FedRAMP authorization, continuous monitoring, and the structural changes CR26 imposes on agency programs. Our advisory practice covers AGU governance setup, ATO boundary documentation, CCM rhythm design, and VER/VDR program readiness.

Explore the full rule-by-rule agency obligation breakdown or contact our team to discuss where your agency program stands today.

Rule citations are drawn from the FedRAMP Consolidated Rules 2026.09.13.02, version current as of September 2026. All rule IDs are verbatim from that file.

Discover More Topics