FedRAMP agency obligations at a glance: The FedRAMP Consolidated Rules for 2026 (CR26) identify 24 rules that apply directly to federal agencies: 13 mandatory (MUST/MUST NOT) and 11 recommended (SHOULD/SHOULD NOT). AGU rules are live now with no grace period. VER-AGM becomes mandatory December 7, 2026 under NTC-0014 and CISA BOD 26-04. CCM-AGM phases in through mid-2027.
The three rules most agencies will break: Requiring additional information beyond FedRAMP (AGU-AGC-NAR) · Requiring a specific certification type or path in procurement (AGU-AGC-TPP) · Blocking a certified offering from following FedRAMP rules, which has no head-of-agency exception (AGU-USE-AFR)
See the full rule-by-rule breakdown on the Quzara Agency Assurance page →
The FedRAMP Consolidated Rules for 2026 are machine-readable, version-controlled, and publicly maintained at github.com/FedRAMP/rules. They do not create 24 brand-new legal duties. Instead, they make explicit what was already embedded in OMB Memorandum M-24-15, FISMA, OMB Circular A-130, and FIPS-200, and they assign those obligations directly to agencies.
Of the 246 total FedRAMP rules across 17 families, 24 apply directly to agencies: 13 are mandatory (MUST/MUST NOT) and 11 are recommended (SHOULD/SHOULD NOT). The mandatory rules are enforceable obligations. The recommended rules describe how FedRAMP expects a mature agency program to operate, and two of them (VER-AGM) carry a hard external deadline through CISA BOD 26-04 that makes them functionally mandatory by December 7, 2026.
Agency obligations fall across three rule families:
| Family | Rules | Status |
|---|---|---|
| AGU, Agency Use of FedRAMP Certified Cloud Services | 20 rules | Live, July 4, 2026. No grace period. |
| CCM-AGM, Collaborative Continuous Monitoring, Agency Guidance | 2 rules | Phasing in by provider type through mid-2027. |
| VER-AGM, Vulnerability Evaluation and Reporting, Agency Guidance | 2 rules | Mandatory December 7, 2026 (NTC-0014). Grace to March 7, 2027 only under a Corrective Action Plan with FedRAMP notice. |
AGU is live now. If your agency is already using FedRAMP-certified cloud services and has not verified compliance with its 20 rules, you are already out of alignment.
Your agency policy must align with M-24-15. This is the umbrella rule from which all other AGU obligations follow.
Your internal governance, risk, compliance, and inventory tools must be able to produce and ingest machine-readable artifacts in the formats FedRAMP specifies. A spreadsheet-based program does not satisfy this rule.
On authorizing use of any cloud service within FedRAMP scope, notify FedRAMP with the required information set.
Notification follows the request. No pre-approval is needed. Clarifying questions and general questions about Certification Data are exempt.
Agencies MUST NOT require information or materials beyond what FedRAMP requires without a demonstrable-need determination by the agency head or authorized delegate, plus FedRAMP notification afterward. Clarifying questions and general questions about Certification Data are exempt.
Agencies MUST NOT require Rev5, 20x, Program Authorization, or Agency Authorization without a demonstrable-need determination and FedRAMP notification. Procurement language is the most common place this rule is broken.
When initiating an agency-sponsored FedRAMP Certification, follow the most recent FedRAMP Consolidated Rules.
FedRAMP Certification is not Authorization to Operate. Every federal information system that incorporates a certified cloud service offering still needs its own completed ATO.
This rule carries no head-of-agency exception. Agency requirements that conflict with FedRAMP rules are impermissible, full stop.
When an Ongoing Certification Report, Quarterly Review, or other Certification Data raises concerns that would likely result in ATO rescission, notify FedRAMP.
When agency-specific security determinations conflict with the FedRAMP Certification Package, work it through FedRAMP rather than imposing requirements unilaterally. This is the formal mechanism for pushing back on a provider.
Review provider-supplied Secure Configuration Guides and configure relevant security settings accordingly. Re-review when the guide version changes or a Security Change Notice shifts customer configuration responsibilities.
Understand how changes to the offering may affect the federal information systems that include it in their authorization boundary.
These are the rules where most agency security teams run into problems, because the habits they encode are deeply ingrained.
Sending a security questionnaire to a cloud provider is a reflex for most ISSO teams. Under CR26, that questionnaire is a compliance event. Before any additional-information request goes out, your agency needs a classification step: Is this a clarifying question (exempt)? An additional-information request (notify FedRAMP afterward, no determination needed)? Or an additional requirement (agency head or delegate determination required, then notify FedRAMP)?
The compliant path is narrower than most teams expect.
Procurement language is the most common place this rule breaks. Specifying "FedRAMP High authorized" or "Rev5 only" in a solicitation, without a recorded demonstrable-need determination and FedRAMP notification, puts the agency out of compliance. Your contracts and procurement officers need to know about this rule.
Unlike NAR and TPP, this rule has no head-of-agency exception. If an agency requirement conflicts with FedRAMP rules, the agency requirement loses. There is no carve-out.
The compliant flow when you genuinely need more: (1) Classify the ask: clarification (exempt), additional-information request, or additional requirement/required type-path. (2) Additional-information request: submit the request, then notify FedRAMP afterward via the Additional Information form (NAI, MUST); no pre-determination needed. (3) Additional requirement or required type/path: agency head or delegate records a demonstrable-need determination, then notify FedRAMP (NAR/TPP). (4) Keep the record: the request, the determination where one applied, and the notification.
Vulnerability Disclosure Reports (VDR) and Vulnerability Evaluation Reports (VER) apply to every FedRAMP Certified offering, all classes, Rev5 and 20x. December 7, 2026 is the date when VER-AGM becomes mandatory under NTC-0014 and CISA BOD 26-04.
Your agency obligations under VER-AGM:
The two VER-AGM rules are SHOULD under CR26 alone, but CISA BOD 26-04 does not offer the same flexibility. Grace to March 7, 2027 is available only under a Corrective Action Plan with FedRAMP notice.
What providers must send you (per VER):
Each VDT record must include: tracking ID, detection time and source, evaluation time, internet-reachability and exploitability determination, PAIN rating (N1–N5, current and historical), each completed impact reduction with timing, overdue status with explanation, and final disposition. Accepted vulnerabilities are reported separately as AVI records.
Reports are delivered at minimum monthly (human-readable) and persistently (machine-readable, validated against FedRAMP-published VDT and AVI JSON schemas). Class D providers detect on the tightest cadence: daily for machine-based resources, every 7 days for drift-prone resources, monthly for non-drift resources.
For more on what providers must deliver and how the December 7 date applies to CSPs, see the FedRAMP VDR and VER requirements guide.
For continuous monitoring support across your FedRAMP-certified cloud environments, Cybertorch provides FedRAMP Class D (High) authorized SOC-as-a-Service staffed by US-citizen analysts who integrate directly with your agency's incident intake and triage workflows.
For every Class B–D provider your agency uses, the CCM cycle runs as follows:
Per CCM-OCR-AVL, verify that your provider's report addresses all eight before marking it as reviewed:
If a provider's OCR does not address all eight, it is not a compliant OCR. Your agency review should verify this before marking the report as reviewed.
Once your agency is a customer, you are a "necessary party" (FRD-ANP) under CR26. These are provider obligations, but knowing them tells you what to demand and what to escalate when a provider denies access.
| Rule | Class | Requirement |
|---|---|---|
| CDS-TRC-USH | B–D | Uninterrupted access to Certification Data. No per-request manual approvals. |
| CDS-TRC-PAC | B–D | Documented programmatic access to all Certification Data, including human-readable materials. |
| CDS-CSO-HAD | B–D | Historical OCR snapshots, kept for the life of the certification. |
| CDS-UTC-AAD | All | Provider must notify FedRAMP within 5 business days of denying an agency access request. |
| CDS-TRC-ACL | B–D (SHOULD) | Six months of access summaries; your portion available to you on request. |
| CDS-TRC-SSM | B–D (SHOULD) | Self-service user management within the trust center. |
Rev5 migration watch (CDS-CSF-TCM): When a Rev5 provider migrates from USDA Connect to a trust center, they must notify your agency and leave forwarding instructions in the old secure folders. Every ingestion path changes at once. Watch for the migration notice.
On responsible sharing (CDS-CSO-RIS): Providers must share enough for authorization decisions but should not include exploit-enabling detail. Expect abstraction in vulnerability reports. AGU-USE-RCF is the formal mechanism to push back when abstraction becomes insufficiency.
| Role | Primary Responsibilities |
|---|---|
| Authorizing Official | Signs ATOs; owns NFC decisions (AGU-USE-NFC) |
| Designated Senior Official | Represents agency at Quarterly Reviews; leads OCR review (AGU-USE-DSO, SHOULD) |
| CISO | Compliance policy, risk thresholds, program tracking across all certified services |
| ISSO / Tenant Admins | SCG configuration settings, system-level review, day-to-day configuration compliance |
| SOC Provider | Incident intake; triage against agency systems |
| FedRAMP Liaison | Shared inbox; ATO filings; NAI/NFC notifications to FedRAMP |
| Head-of-Agency Delegate | NAR/TPP demonstrable-need determinations (the only authorized path to requiring extras) |
Build a complete inventory: every FedRAMP-certified service your agency uses, keyed by FedRAMP ID, linked to every FISMA system that includes it. Confirm each of those systems has a completed ATO (AGU-USE-ABU). Certification is not Authorization. Without this record you cannot run the rest of the program.
Designate your Senior Official and FedRAMP Liaison. Set up a shared agency inbox. Request trust-center access as a necessary party for all Class B–D providers you are currently authorized to use.
Stand up the additional-request gate and the FedRAMP notification log (covering NAR, NAI, TPP, and NAA). Before any security team sends a questionnaire or demands additional information from a provider, it passes through this gate. This is how you prevent AGU-AGC-NAR violations before they happen.
Calendar every provider's next OCR and Quarterly Review date (CCM-AGM-ROR, AGU-USE-ROR). Review SCGs per tenant (AGU-USE-RSG). Confirm your GRC tooling can produce and ingest FedRAMP machine-readable artifacts (AGU-AGC-GRC). The program runs on cadence. Build the calendar first.
For agencies looking to automate machine-readable compliance tracking and artifact ingestion, NISTcompliance.ai is built to handle the GRC data flows CR26 requires, including OSCAL and FedRAMP-format outputs.
Quzara works directly with federal agency security teams on FedRAMP authorization, continuous monitoring, and the structural changes CR26 imposes on agency programs. Our advisory practice covers AGU governance setup, ATO boundary documentation, CCM rhythm design, and VER/VDR program readiness.
Explore the full rule-by-rule agency obligation breakdown or contact our team to discuss where your agency program stands today.
Rule citations are drawn from the FedRAMP Consolidated Rules 2026.09.13.02, version current as of September 2026. All rule IDs are verbatim from that file.