FedRAMP Consolidated Rules for 2026
Agency Assurance Obligations

What the New Rules
Ask of Your Agency

The FedRAMP Consolidated Rules for 2026 identify 24 rules that directly affect agencies, 13 mandatory, 11 recommended. Providers became publishers. Agencies became consumers. Here is what that means operationally, rule by rule.

Built from the canonical machine-readable rules at github.com/FedRAMP/rules, version 2026.09.13.02, last updated 2026-09-13. Every rule ID cited is verbatim from that file.
VER-AGM Mandatory
December 7, 2026 · NTC-0014
--
days remaining
-- : -- : --
Hours
Minutes
Seconds
AGU rules: in effect since July 4, 2026
Grace to March 7, 2027 only under a CAP with agency notice
246
Total FedRAMP rules across 17 families
24
Rules that directly affect agencies
13
MUST / MUST NOT, mandatory obligations
11
SHOULD / SHOULD NOT, recommended practices

Three families, 24 rules

FedRAMP did not create 24 brand-new legal duties. CR26 identifies and makes machine-readable obligations most agencies already carry under M-24-15, FISMA, A-130, and FIPS-200. The operationally new demands are concentrated in a handful of rules.

AGU
20
Agency Use of FedRAMP Certified Cloud Services
9 general responsibilities · 10 use-of-certification rules · 1 sponsorship rule. Operationalizes M-24-15 §IV obligations and the FedRAMP Authorization Act. Status: placeholder in CR26 2026.09.13.02, cite M-24-15 as underlying authority.
Live · July 4, 2026 · No grace
CCM-AGM
2
Collaborative Continuous Monitoring, Agency Guidance
Review each applicable OCR (Class B–D providers); weight review depth by security category. 20x providers: obtain July 2026, maintain Jan 2027. Rev5 providers: obtain Jan 2027, maintain Apr 2027, grace Oct 2027.
Stable · Phased by provider type
VER-AGM
2
Vulnerability Evaluation and Reporting, Agency Guidance
Review vulnerability reports from every certified provider using filtering logic; maintain agency POA&Ms. Both rules are SHOULD (recommended), not MUST. Grace to March 7, 2027 only under a CAP with agency notice.
Mandatory · December 7, 2026

The 13 mandatory obligations

11 MUST rules and 2 MUST NOT rules. These are enforceable obligations, not recommendations. The three rules most agencies will break by habit are highlighted below in their own section.

1
AGU-AGC-AIP · MUST
MUST
Maintain agency-wide FedRAMP policy. Agency policy must align with the requirements in OMB Memorandum M-24-15. This is the umbrella rule the rest of AGU hangs from.
2
AGU-AGC-GRC · MUST
MUST
Make your GRC and inventory tooling machine-readable. Internal governance, risk, compliance, and inventory tools must be able to produce and ingest machine-readable artifacts in the formats FedRAMP identifies. A spreadsheet-based program does not satisfy this rule.
3
AGU-AGC-NAA · MUST
MUST
Notify FedRAMP when you authorize a cloud service. On authorizing use of any cloud service within the scope of FedRAMP, notify FedRAMP with the required information set.
4
AGU-AGC-NAI · MUST
MUST
Notify FedRAMP after requesting extra information. Notification follows the request, no pre-approval needed. Clarifying questions and general questions about Certification Data are exempt.
5
AGU-AGC-NAR · MUST NOT
MUST NOT
Do not require information beyond FedRAMP requirements. Not without a demonstrable-need determination by the agency head or an authorized delegate, plus notification to FedRAMP. Seeking clarification or asking general questions about Certification Data sits outside this rule.
6
AGU-AGC-TPP · MUST NOT
MUST NOT
Do not require a specific Certification Type or Path. You may not require Rev5 or 20x, or the Program or Agency path, without a demonstrable-need determination and FedRAMP notification. Procurement language is where this rule is most often broken.
7
AGU-SPN-MRC · MUST
MUST
Follow the current rules when you sponsor. When initiating an agency-sponsored FedRAMP Certification, follow the most recent FedRAMP Consolidated Rules.
8
AGU-USE-ABU · MUST
MUST
Complete the ATO process for systems that use certified offerings. Certification is not authorization. Every federal information system that includes a FedRAMP Certified cloud service offering still needs its own completed Authorization to Operate.
9
AGU-USE-AFR · MUST
MUST
Allow certified offerings to follow FedRAMP rules. This rule carries no head-of-agency exception. Agency requirements that conflict with FedRAMP rules are impermissible.
10
AGU-USE-NFC · MUST
MUST
Notify FedRAMP about rescission-level concerns. When an Ongoing Certification Report, Quarterly Review, or other Certification Data raises concerns for the authorizing official that would likely result in rescission of the ATO.
11
AGU-USE-RCF · MUST
MUST
Collaborate with FedRAMP on conflicts. When agency-specific security determinations conflict with the FedRAMP Certification Package, work it through with FedRAMP rather than imposing unilaterally. This is the formal mechanism for pushing back.
12
AGU-USE-RSG · MUST
MUST
Review the Secure Configuration Guide and configure to it. Review the guides supplied by providers and configure the relevant security settings. Re-review when the guide version changes or an SCN shifts customer configuration responsibilities.
13
CCM-AGM-ROR · MUST
MUST
Review each Ongoing Certification Report. Understand how changes to the offering may affect the federal information systems that include it in their boundary.
Applies to 20x providers from Jan 2027; Rev5 providers from Apr 2027 with grace to Oct 2027.

The 11 recommended practices

SHOULD and SHOULD NOT rules. Not enforceable in the way the 13 are, but they are how FedRAMP expects a mature agency program to run, and the two VER rules carry a hard external deadline anyway through CISA BOD 26-04.

1
AGU-AGC-LIA · SHOULD
SHOULD
Join the FedRAMP Agency Liaison program. Assign at least one federal employee as an active participant.
2
AGU-AGC-SIN · SHOULD
SHOULD
Stand up a shared FedRAMP agency inbox. A single official point of contact for FedRAMP-to-agency communication.
3
AGU-AGC-WKG · SHOULD
SHOULD
Participate in FedRAMP working groups. Communities of practice and stakeholder engagements, to supply feedback and align practice.
4
AGU-USE-CLA · SHOULD NOT
SHOULD NOT
Do not run on Class A past 12 months. Unless the offering is actively seeking Class B, C, or D. This is about your ATO, not a certification expiry.
5
AGU-USE-DSO · SHOULD
SHOULD
Designate a senior information security official. To review Ongoing Certification Reports and represent the agency at Quarterly Reviews.
6
AGU-USE-NPC · SHOULD
SHOULD
Notify the provider too. Formally tell the provider when concerns would likely result in rescission, not just FedRAMP.
7
AGU-USE-RIR · SHOULD
SHOULD
Consider third-party information resources. Those used by the offering and documented under MAS-CSO-TPR, during initial and ongoing authorization activity.
8
AGU-USE-ROR · SHOULD
SHOULD
Review each OCR against your ATO risk tolerance. The companion to CCM-AGM-ROR: does anything in this report change the risk tolerance documented in your ATO?
9
CCM-AGM-CSC · SHOULD
SHOULD
Weight review depth by Security Category. Use the Security Category in your ATO to decide how hard to look.
10
VER-AGM-RVR · SHOULD
SHOULD
Review vulnerability reports on a sensible interval. Commensurate with your ATO risk posture, using automated processing and filtering of the machine-readable feed.
11
VER-AGM-MAP · SHOULD
SHOULD
Feed provider vulnerability data into your POA&Ms. Where relevant under agency security policy, including accepted vulnerabilities you continue to live with.

AGU is live now, CCM and VER phase in to 2028

Build your program against today's inputs, USDA Connect packages, emailed notices, PDF deliverables, and let it improve as providers come online. The clean-API world is the destination, not the starting assumption.

Obligation
Jul 2026
Dec 2026
Mid 2027
2028
AGU (20 rules)
Live Jul 4, 2026 · No grace
Secure Config Guides (SCG)
Binding since Mar 2026 · Grace ended Jul 2026
VER-AGM (agency), CISA BOD 26-04
Optional Jul 4
Mandatory Dec 7, 2026 (NTC-0014)
Grace to Mar 7 2027 (CAP + notice only)
20x providers + CCM-AGM
Obtain trust centers Jul 2026
Maintain Jan 2027 · Grace to next assessment
Rev5 providers: trust centers (CDS)
Obtain Jan 2027 · Maintain Aug 2027
Grace Feb 2028
Rev5 + CCM-AGM: OCRs / Quarterly Reviews
Obtain Jan 2027 · Maintain Apr 2027 · Grace Oct 2027
FedRAMP Ready status
Convert by Nov 17, 2026 or assessment expiry
Removed Dec 31, 2027

The quarterly rhythm: report → review → meeting → escalate

For every Class B–D provider you use, a quarterly cycle of provider-published OCRs, agency review, optional quarterly meeting, and escalation if needed.

1
CCM-OCR-AVL
Provider publishes OCR
Every 3 months. Next date public (CCM-OCR-NRD). Snapshot aligned to each OCR and kept for the life of certification (CDS-CSO-HAD).
2
CCM-AGM-ROR · MUST
You review it
Does anything change the risk tolerance in your ATO? Depth by security category (CCM-AGM-CSC, SHOULD). Questions via CCM-OCR-FBM.
3
CCM-QTR-MTG
Quarterly Review
Provider hosts: MAY Class A · SHOULD B · MUST C/D. 3-10 business days after OCR. Your designated senior official attends (AGU-USE-DSO, SHOULD).
!
AGU-USE-NFC · MUST
Escalate if needed
Notify FedRAMP when concerns would likely lead to ATO rescission. Notify provider (AGU-USE-NPC, SHOULD).

The 8 things every OCR must contain

Per CCM-OCR-AVL, check that your provider's report addresses all eight before marking reviewed.

1
Changes to Certification Data since the last OCR
2
Planned changes over the next 3+ months
3
Accepted vulnerabilities (current status)
4
Transformative changes made or planned
5
Updated security, configuration, and usage recommendations
6
Full list of agencies directly using the product
7
FedRAMP Reportable Incidents, or attestation that none occurred
8
Lessons learned and changes made or planned after Reportable Incidents

Vulnerability reports: read the filtered few, not the firehose

VDR and VER bind every FedRAMP Certified offering, all classes, Rev5 and 20x. Class D carries the tightest clocks, not the only ones. Your own agency rules (VER-AGM) are SHOULD, recommended rather than mandatory, but CISA BOD 26-04 imposes its own agency timeline. The practical mandate is December 7, 2026.

What providers must send, VDT (ordinary vulnerabilities)
  • Tracking ID, detection time and source
  • Evaluation time; internet-reachable? likely exploitable?
  • PAIN rating (N1 to N5), current and historical
  • Each completed impact reduction with timing
  • Target of next reduction; overdue status with explanation
  • Agency-helpful supplementary information
  • Final disposition
AVI, Accepted vulnerabilities (separate record)
  • Tracking ID, detection time and source
  • Evaluation time; reachability; exploitability
  • Current PAIN rating only, not the full VDT history
  • Acceptance explanation
  • Agency-helpful supplementary information
  • Not the full VDT remediation timeline
Delivery format and cadence
  • Human-readable report at least monthly, MUST (VER-TFR-MHR)
  • Persistent reporting summarizing all activity since the previous report, MUST (VER-RPT-PER)
  • These reports are Certification Data, delivered under the CDS rules
  • Validated against FedRAMP's published VDT and AVI JSON schemas
  • Any vulnerability not fully mitigated within 192 days of evaluation becomes an accepted vulnerability (VER-TFR-MAV)
Detection cadence behind these reports varies by the provider's certification class, not by your agency. At Class D: representative samples of machine-based resources daily, drift-prone resources every 7 days, non-drift resources monthly (VDR-TFR-PSD / PDD / PCD, all SHOULD).
Your agency review obligations (VER-AGM)
  • Filter the report to vulnerabilities relevant to your use case and FISMA system
  • Compare provider PAIN against your agency's own impact determination
  • Update your agency POA&Ms based on the filtered view
  • Both VER-AGM rules are SHOULD, but CISA BOD 26-04 does not offer the same flexibility
  • Grace to March 7, 2027 only under a Corrective Action Plan with FedRAMP notice

The rules most agencies will break by habit

Questionnaires and custom evidence requests are deeply ingrained. CR26 places limits on them. The compliant path is narrower than most agency security teams expect.

AGU-AGC-NAR · MUST NOT
Requiring information beyond FedRAMP
Agencies MUST NOT require information or materials beyond what FedRAMP requires without a demonstrable-need determination by the agency head or authorized delegate, plus FedRAMP notification afterward.
Exempt: clarifying questions and general questions about Certification Data per M-24-15 §IV(a)
AGU-AGC-TPP · MUST NOT
Requiring a specific type or path
Agencies MUST NOT require a specific Certification Type (Rev5 or 20x) or Authorization Path (Program or Agency) without a demonstrable-need determination and FedRAMP notification. Procurement language must be reviewed against this rule.
Exception: agency head or authorized delegate records demonstrable need, then notifies FedRAMP
AGU-USE-AFR · MUST, No exception
Blocking a provider from following FedRAMP rules
Agencies MUST allow certified offerings to comply with FedRAMP rules. Unlike NAR and TPP, this rule carries NO head-of-agency exception. There is no carve-out. Agency requirements that conflict with FedRAMP rules are impermissible.
No exception available for this rule

The compliant flow when you genuinely need more: (1) Classify the ask, clarification (exempt), additional-information request, or additional requirement / required type-path. (2) Additional-information request: submit the request, then notify FedRAMP afterward via the Additional Information form (NAI, MUST), no pre-determination needed. (3) Additional requirement or required type/path: agency head or authorized delegate records a demonstrable-need determination, then notify FedRAMP (NAR/TPP). (4) Keep the record: the request, the determination where one applied, and the notification.

What applicable Class B–D providers must make available to you

Once you are a customer you are a "necessary party" (FRD-ANP). These are provider obligations, but knowing them tells you what to demand and what to escalate when a provider denies access.

MUST
CDS-TRC-USH · Class B–D
Uninterrupted access
No per-request manual approvals. FedRAMP prefers on-demand just-in-time provisioning. If a provider requires approval for every access request, they are not in compliance.
MUST
CDS-TRC-PAC · Class B–D
Documented programmatic access
Documented programmatic access to all Certification Data, including human-readable materials. The transport method is not mandated by the rule.
MUST
CDS-CSO-HAD · Class B–D
Historical snapshots
A snapshot aligned to each OCR, kept for the life of the certification. This is not in the Class A mandatory set.
MUST
CDS-UTC-AAD · All classes
Denials reported to FedRAMP
Provider must tell FedRAMP within 5 business days of denying an agency access request. Mandatory at Class A too via FRC-CLA-MFR. If you are denied access, FedRAMP should know within 5 days.
SHOULD
CDS-TRC-ACL · Class B–D
Your access logs on request
Six months of access summaries; your portion available to you. A recommended provider capability, not a hard requirement.
SHOULD
CDS-TRC-SSM · Class B–D
Self-service user management
Provision and manage your own users and services within the trust center without requiring provider intervention for each change.
Rev5 migration watch (CDS-CSF-TCM)

When a Rev5 provider migrates from USDA Connect to a trust center, they MUST notify you and leave instructions in the old secure folders. Every ingestion path changes at once, watch for this migration notice.

Responsible sharing (CDS-CSO-RIS)

Providers MUST share enough for authorization decisions but SHOULD NOT include exploit-enabling detail. Expect abstraction. Use AGU-USE-RCF when abstraction becomes insufficiency, this is the formal mechanism to push back.

Run it as one program: the system × service spine

Every agency action attaches to one relationship: Provider → CSO (FedRAMP ID) → Services consumed → FISMA system (ATO). The link record is where your judgment lives.

Proposed agency roles
Authorizing Official
Signs ATOs; owns NFC decisions (AGU-USE-NFC)
Designated Senior Official
Represents agency at Quarterly Reviews; leads OCR review (AGU-USE-DSO, SHOULD)
CISO / Compliance
Policy, thresholds, tracking across all certified services
ISSO / Tenant Admins
SCG settings, system-level review, day-to-day configuration compliance
SOC
Provider incident intake; triage against agency systems
FedRAMP Liaison
Shared inbox; ATO filings; NAI / NFC notifications to FedRAMP
Head-of-Agency Delegate
NAR / TPP demonstrable-need determinations (the only path to requiring extras)
First 90 days
1
Inventory and close the ATO loop
Build the inventory: every certified service, keyed by FedRAMP ID, linked to every FISMA system that includes it. Then confirm each of those systems has a completed ATO (AGU-USE-ABU). Certification is not authorization. Without this record you cannot run the rest.
2
Name and connect
Designate your Senior Official and FedRAMP Liaison; set up a shared inbox; request trust-center access as a necessary party for all Class B–D providers.
3
Govern requests
Stand up the additional-request gate and the FedRAMP notification log (NAR / NAI / TPP / NAA). Before any security team sends a questionnaire, it must pass through this gate.
4
Start the rhythm
Calendar every provider's next OCR and Quarterly Review (CCM-AGM-ROR, AGU-USE-ROR). Review SCGs per tenant (AGU-USE-RSG). Confirm your GRC tooling can produce and ingest FedRAMP machine-readable artifacts (AGU-AGC-GRC). The program runs on cadence, build the calendar first.
NISTcompliance.ai

One system of record for your provider portfolio

NISTcompliance.ai's Agency Cloud Assurance Hub centralizes your provider inventory, OCR review workflow, VER filtering, and FedRAMP notification log in one place.

Provider Inventory
Every certified offering keyed by FedRAMP ID, linked to your FISMA systems and ATOs. Provenance-tagged, stale feeds are visible, never silently trusted.
OCR Review Workflow
Structured quarterly review workflow with eight-point OCR checklist, risk-tolerance assessment, and FedRAMP notification filing for NFC escalations.
VER Filtering & POA&M
Filter provider VDT and AVI feeds to your relevant systems; compare PAIN against your agency's own impact determinations; generate and maintain agency POA&Ms.
Cybertorch® Division of Quzara, LLC FedRAMP Certified Class D (High) MDR · FR2214150164 · U.S.-citizen analysts · 24/7 GovCloud boundary